
technologyApr 2, 202535:25pending
AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl
About this episode
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor to the Microsoft Security Research Center (MSRC) leaderboards and a Most Valuable Researcher. Tobias shares his journey from IT support to uncovering vulnerabilities in Microsoft products. He discusses his participation in the upcoming Zero Day Quest hacking challenge and breaks down a recent discovery involving Power Automate, where he identified a security flaw that could be exploited via malicious URLs. Tobias explains how developers can mitigate such risks and the importance of strong proof-of-concept submissions in security research.
In This Episode You Will Learn:
Researching vulnerabilities in Power Automate, Power Automate Desktop, and Azure
The importance of user prompts to prevent unintended application behavior
Key vulnerabilities Tobias looks for when researching Microsoft products
Some Questions We Ask:
Have you submitted any AI-related findings to Microsoft or other bug bounty programs?
How does the lack of visibility into AI models impact the research process?
Has your approach to security research changed when working with AI versus traditional systems?
Resources:
View Tobias Diehl on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
Get every episode summarized
Each time The BlueHat Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The BlueHat Podcast

Hunting Variants: Finding the Bugs Behind the Bug
The BlueHat Podcast
Jul 9, 202539:00pending

Securing Redirections with Mike Macelletti
The BlueHat Podcast
Jun 25, 202542:02pending

Ignore Ram Shankar Siva Kumar’s Previous Directions
The BlueHat Podcast
Jun 11, 202539:54pending

Protecting AI at the Edge with David Weston
The BlueHat Podcast
May 28, 202539:15pending