Skip to content

the #thoughtops blog

security | ai | technology | policy | startups

Founder of Bugcrowd & disclose.io, pioneer of crowdsourced security as-a-service, principal of Tall Poppy Group. Sharp takes on breaking things, building things, fixing things, and the economics in between.

Featured

Latest

All →
Ghostbusters still, captioned: Human sacrifice. Dogs and cats living together. Mass hysteria.
Security

Wake Me After the Vulnpocalypse

AI industrialized the discovery of vulnerabilities, not the exploitation of them, and that distinction is the whole argument. What we have is a slopdemic. The fragility was always there, and the real exposure is the gap between instant discovery and human-speed remediation.

04 Aug 2026 · 3 min read

My moves for Hacker Summer Camp 2026

...and away we go! Here's (roughly) what I'll be up to this week: Monday BSides Las Vegas for the I Am The

03 Aug 2026 · 3 min read
Learn

Hacker Summer Camp Tips and Tricks

As I've been thinking about Hacker Summer Camp (aka Blackhat, BSides Las Vegas, DEF CON, and all of the associated and adjacent cons and Vegas things) this year, it occurred to me that there are going to a LOT of new founders and operators roaming the desert this year.

29 Jul 2026 · 3 min read
Casey Ellis on stage at SOURCE Boston 2014, next to a slide asking "So how do you get more eyes on security bugs?"
Security

The Amended Linus's Law

Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.

13 Jul 2026 · 5 min read
Security

Slopdemic, Not Vulnpocalypse (Yet)

I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching. It was

05 Jul 2026 · 2 min read
Johnny Five from Short Circuit rendered as an Obama 'Hope' campaign poster, captioned NO DISASSEMBLE
Building

My Clanker Setup

A mate messaged me this week asking whether I'd ever written up my clanker setup — which harness I run, which models, what hardware, and

05 Jul 2026 · 7 min read
Security

AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.

There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we'd

29 Jun 2026 · 4 min read
Casey Ellis on VulnCheck Threat Con One — vulnerability disclosure post-Mythos
Thinking

The Hitchhiker's Guide to Vulnerability Disclosure in 2026

Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.

17 May 2026 · 13 min read
Policy

Coordinated, Until It Isn't

Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.

17 May 2026 · 9 min read
Security

Auditing My 2026 Security Predictions: Five Months In

Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's time to

15 May 2026 · 7 min read
Security

Thoughts on the #slopdemic

Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.

04 May 2026 · 2 min read
Personal

Continued Monitoring of the Situation

Week two of an AI-powered House Finch nest monitor: four model biases, a Wyze cam back from the dead, and a full pipeline rewrite before the eggs hatch.

03 May 2026 · 14 min read

Hot Takes

All →