Microsoft has launched a new AI bounty program. This program is the result of investments and learnings from recent months, including an AI security research challenge and an update to Microsoft’s vulnerability severity classification for AI systems. Lynn Miyashita, a technical program manager with the Microsoft Security Response Center, shared this information.
The Microsoft AI bug bounty program
By infosecbulletin
/ Thursday , November 21 2024
Renowned cybersecurity researcher Jeremiah Fowler uncovered a non-password-protected database having over 1.1 million records linked to Conduitor Limited (Forces Penpals)....
Read More
By infosecbulletin
/ Wednesday , November 20 2024
Trend Micro released a security update for Deep Security 20 Agent Manual Scan Command Injection RCE Vulnerability (CVE-2024-51503) that resolves...
Read More
By infosecbulletin
/ Wednesday , November 20 2024
Apple released critical updates for its various products including for iOS, iPadOS, macOS, visionOS, and Safari to fix two zero-day...
Read More
By infosecbulletin
/ Tuesday , November 19 2024
Maxar Space Systems has verified a major data breach that exposed particular information of current and former workers. The breach...
Read More
By infosecbulletin
/ Tuesday , November 19 2024
A security vulnerability (CVE-2024-52308) in the GitHub Command Line Interface (CLI) could allow remote code execution on users' devices. With...
Read More
By infosecbulletin
/ Tuesday , November 19 2024
“Sarcoma” ransomware group attacked a well known Bangladeshi insurance company named "Popular life insurance company ltd". The threat actor keeps...
Read More
By infosecbulletin
/ Monday , November 18 2024
Bug Hunt 2024, one of the largest cyber security competitions and conferences in Bangladesh, was successfully held at the ICT...
Read More
By infosecbulletin
/ Saturday , November 16 2024
A serious security flaw has been found in some TP-Link routers, potentially enabling hackers to remotely access the affected devices.The...
Read More
By infosecbulletin
/ Saturday , November 16 2024
The Wall Street Journal reported on Friday citing people familiar with the matter that T-Mobile’s network was among the systems...
Read More
By infosecbulletin
/ Friday , November 15 2024
"Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall...
Read More
Microsoft wants bug hunters to test AI-powered Bing features on bing.com using a browser. They also want them to test Bing integration on Microsoft Edge, including Bing Chat for Enterprise. Additionally, they want testers to check the Bing integration in the iOS and Android versions of Microsoft Start and Skype mobile apps.
They should report vulnerabilities that could be exploited to:
* Manipulate the model’s response to individual inference requests, but do not modify the model itself (“inference manipulation”)
* Manipulate a model during the training phase (“model manipulation”)
* Infer information about the model’s training data, architecture and weights, or inference-time input data (“inferential information disclosure”)
* Influence/change Bing’s chat behavior in a way that impacts all other users
* Modify Bing’s chat behavior by adjusting client and/or server visible configuration
* Break Bing’s cross-conversation memory protections and history deletion
* Reveal Bing’s internal workings and prompts, decision making processes and confidential information
* Bypass Bing’s chat mode session limits and/or restrictions/rules
Click here to read more