From Facebook-phished to MVR Top 5 with Dhiral Patel
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Dhiral Patel, Senior Security Engineer at ZoomInfo and one of MSRC’s Most Valuable Researchers (MVR). Dhiral shares how a hacked Facebook account sparked his passion for ethical hacking. From web development to penetration testing, Dhiral has become a top bug hunter, landing multiple spots on the MSRC leaderboards. Dhiral reflects on his early MSRC submissions and lessons learned. He also discusses the importance of mastering web security basics, practicing on platforms like TryHackMe and Hack the Box, and staying connected with the bug bounty community.
In This Episode You Will Learn:
The importance of mastering web security basics before diving into bug bounty hunting
Why hands-on platforms like TryHackMe and Hack the Box are perfect for beginners
Dhiral’s journey from blogging to freelancing and security research
Some Questions We Ask:
How do you balance competition and collaboration in the bug bounty community?
Can you explain what clickjacking is and if it still works today?
Why did you start with Power BI, and how did it lead to your journey in security?
Resources:
View Dhiral Patel on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
--------
40:15
AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor to the Microsoft Security Research Center (MSRC) leaderboards and a Most Valuable Researcher. Tobias shares his journey from IT support to uncovering vulnerabilities in Microsoft products. He discusses his participation in the upcoming Zero Day Quest hacking challenge and breaks down a recent discovery involving Power Automate, where he identified a security flaw that could be exploited via malicious URLs. Tobias explains how developers can mitigate such risks and the importance of strong proof-of-concept submissions in security research.
In This Episode You Will Learn:
Researching vulnerabilities in Power Automate, Power Automate Desktop, and Azure
The importance of user prompts to prevent unintended application behavior
Key vulnerabilities Tobias looks for when researching Microsoft products
Some Questions We Ask:
Have you submitted any AI-related findings to Microsoft or other bug bounty programs?
How does the lack of visibility into AI models impact the research process?
Has your approach to security research changed when working with AI versus traditional systems?
Resources:
View Tobias Diehl on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
--------
35:25
Bug Hunting from the Beach with Brad Schlintz
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by Brad Schlintz, independent security researcher and bug bounty hunter. Brad shares how he transitioned from a decade-long career as a software engineer to hacking Microsoft products while traveling the world with his wife. He recounts his early days tinkering with RuneScape bots, his experience working in SharePoint and Azure at Microsoft, and the moment he first encountered a real-world cybersecurity incident. He also discusses his journey into ethical hacking and his qualification for the upcoming Zero Day Quest, showcasing how he turned bug hunting into a lifestyle that allows him to work from anywhere—including a stunning island in Brazil.
In This Episode You Will Learn:
How a single discovered bug can lead to finding multiple vulnerabilities in the same area
The importance of exploring app integrations when searching for security vulnerabilities
Why building on prior discoveries can make it easier to uncover more hidden security issues
Some Questions We Ask:
What guidance can you share with other researchers and hackers on how to find vulnerabilities?
Why did your background in software engineering help you in your bug bounty work?
How did you transition from working on the website incident to more full-time security research?
Resources:
View Brad Schlintz on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
--------
38:43
PoCs, Patching and Zero Day Quest Participation with Michael Gorelik
In this episode of The BlueHat Podcast, Nic and Wendy are joined by seasoned security researcher, and CTO of Morphisec, Michael Gorelik. Michael discusses his approach to security research, which often begins by exploring PoCs released by other researcher groups and continues through to the release and validation of – sometimes multiple rounds of – fixes. Michael also provides an overview of this BlueHat 2024 presentation from last October and discusses his upcoming participation in the Zero Day Quest Onsite Hacking Challenge.
In This Episode You Will Learn:
How Michael Gorelik transitioned from security researcher to company founder
Deeper motivations driving ethical hackers like Michael Gorelik beyond money
The importance of identifying incomplete security patches before attackers do
Some Questions We Ask:
What are you looking forward to with Zero Day Quest?
Did you have a moral dilemma about hacking when you were younger?
What was your experience like at Deutsche Telekom Laboratories?
Resources:
View Michael Gorelik on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
--------
46:25
Secret Herbs, Spices and Hacking Copilot Studio
In this episode of The BlueHat Podcast, host Nic Fillingham is joined by Scott Gorlick, Security Architect for Power Platform at Microsoft. Scott shares his unconventional journey into cybersecurity, from managing a KFC to driving big rigs before landing in tech. He dives into security research in Copilot Studio, discussing how AI models interact with security frameworks and how researchers can approach testing these systems. We also explore his recent training video on YouTube, which provides guidance for security researchers looking to engage with Microsoft’s bug bounty program.
In This Episode You Will Learn:
What Scott does to ensure Power Platform applications remain governable and secure
Why security and software quality go hand in hand in modern development.
How security researchers can explore vulnerabilities in Microsoft's low-code AI development platform
Some Questions We Ask:
What kinds of security issues should researchers focus on in Copilot Studio?
Can Copilot help researchers write better reports, especially in different languages?
How can researchers get access to Copilot Studio? Is there a free version?
Resources:
View Scott Gorlick on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Security Research in Copilot Studio Overview and Training on YouTube
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Since 2005, BlueHat has been where the security research community, and Microsoft, come together as peers; to debate, discuss, share, challenge, celebrate and learn. On The BlueHat Podcast, Microsoft and MSRC’s Nic Fillingham and Wendy Zenone will host conversations with researchers and industry leaders, both inside and outside of Microsoft, working to secure the planet’s technology and create a safer world for all.