Skip to content
← home

archive

Archive

182 posts
Casey Ellis on stage at SOURCE Boston 2014, next to a slide asking "So how do you get more eyes on security bugs?"
Security

The Amended Linus's Law

Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.

13 Jul 2026 · 5 min read
Security

Slopdemic, Not Vulnpocalypse (Yet)

I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching.

05 Jul 2026 · 2 min read
Johnny Five from Short Circuit rendered as an Obama 'Hope' campaign poster, captioned NO DISASSEMBLE
Building

My Clanker Setup

A mate messaged me this week asking whether I'd ever written up my clanker setup — which harness I run, which models, what

05 Jul 2026 · 7 min read
Security

AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.

There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&

29 Jun 2026 · 4 min read
Casey Ellis on VulnCheck Threat Con One — vulnerability disclosure post-Mythos
Thinking

The Hitchhiker's Guide to Vulnerability Disclosure in 2026

Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.

17 May 2026 · 13 min read
Policy

Coordinated, Until It Isn't

Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.

17 May 2026 · 9 min read
Security

Auditing My 2026 Security Predictions: Five Months In

Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's

15 May 2026 · 7 min read
Security

Thoughts on the #slopdemic

Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.

04 May 2026 · 2 min read
Personal

Continued Monitoring of the Situation

Week two of an AI-powered House Finch nest monitor: four model biases, a Wyze cam back from the dead, and a full pipeline rewrite before the eggs hatch.

03 May 2026 · 14 min read
Three pale-blue speckled House Finch eggs nestled in a cup of dried grass on a sunroom bookshelf
Personal

"Monitoring the Situation" - The Internet of Birbs

Two pale-blue speckled eggs on the sunroom bookshelf turned into three cameras, an Unraid NAS, two AI models, and a journal that writes itself every morning. None of it had to be useful — it just had to be possible. Because joy.

29 Apr 2026 · 7 min read
Security

Spicy Takes from my Aikido Security Podcast

Nine takes from my RSAC conversation with Mackenzie Jackson on Aikido's Secure Disclosure podcast — on bug bounty, AI slop, hack-back, vibe coding, and why the internet still working is a minor miracle.

24 Apr 2026 · 5 min read
Security

Offense Scales with Compute. Defense Scales with Committees.

Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.

08 Apr 2026 · 11 min read
Thinking

The Compliance Reckoning

AI makes security verification cheap, putting two decades of checkbox compliance, paper pentests, and audit theater under sudden economic pressure.

28 Mar 2026 · 4 min read
Security

Bug Bounties in the Age of AI

As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.

27 Mar 2026 · 4 min read
Security

The FCC Just Banned Every Foreign-Made Router

The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.

24 Mar 2026 · 3 min read
Policy

The White House AI Framework: What It Says, What It Doesn't, and Why the Gaps Matter More

The March 2026 White House AI policy framework analyzed: seven pillars, and why the AI security omissions matter more than what's actually in the document.

23 Mar 2026 · 7 min read
Security

Vulnerability economics

The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.

22 Mar 2026 · 1 min read
Policy

No More Free-ish Bugs

The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.

12 Feb 2026 · 1 min read
Building

Next things...

Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd.

11 Feb 2026 · 2 min read
Building

Bugcrowd 2013 to 2025 — People and Places

A photo retrospective of Bugcrowd from 2013 to 2025 — the people, offices, and moments that built the security crowdsourcing category from a Sydney garage out.

09 Feb 2026 · 4 min read
Security

For the Love of the Game: DistrictCon's Year 1 Junkyard

Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes exploit chain diagrams for all eleven talks.

07 Feb 2026 · 9 min read
Thinking

2026 security predictions

2026 cybersecurity forecast: China's PLA centenary looms, AI turns anyone into a malware developer, and economic pressure pushes more people toward cybercrime. Shift-left finally start working—but only for modern code. The rest of the internet? A triage trash fire.

26 Dec 2025 · 5 min read
Thinking

2025 security predictions retrospective

This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.

16 Dec 2025 · 6 min read
Thinking

First Principles: Bad guys are humans, they're creative and driven, and they don't quit.

Here's the bigger question: If we do finally achieve 100% success in automating cyber defense, will the "bad guys" pack their stuff up and go home?

26 Nov 2025 · 2 min read
Personal

Hacker Summer Camp 2025 — People, Places, and Things

A little photo diary of Hacker Summer Camp 2025.

15 Aug 2025 · 3 min read
Thinking

Founders Helping Founders: When Known Vulnerabilities are Life or Death

On today’s episode, Jon Sakoda speaks with Casey on the early economics of paying people to hack companies, criminal creativity, and why founders need to fix their known vulnerabilities.

13 Aug 2025 · 2 min read
Thinking

Peace-time Cyber vs War-time Cyber

A long read on how cybersecurity doctrine built during 15 years of geopolitical peacetime is failing as nation-state actors abandon restraint and discretion.

02 Jul 2025 · 5 min read
Building

What You Give Away Might Be Worth More Than What You Keep

The sticking point is the word "free". If you do happen to get stuck there (and a lot of things will push you in that direction), a lot of the magic in the decision math gets missed. Everything has a Give and a Get and, if you're doing it right, nothing is ever given away for free.

27 May 2025 · 1 min read
Building

If a tech solution falls in the forest...

A solution disconnected from it's problem isn't actually solving anything.

27 May 2025 · 1 min read
Security

What the Netflix ‘Zero Day’ series got right about incident response

That said, the widespread nature of the effects shown in the six-part series are definitely plausible. Industrial control systems and the infrastructure that supports them are riddled with zero-day vulnerabilities, alongside the more common "known, yet unpatched" n-day vulnerabilities.

18 May 2025 · 4 min read
Security

Bug Bounties, The Wanted Poster For Ethical Hackers — Future Secured Episode 35

Crowdsourced security empowers ethical hackers to protect digital assets, reshaping cybersecurity. Casey Ellis encourages entrepreneurs to lead with resilience, delegate wisely, prioritize health, and embrace innovation amid chaos for lasting impact and scalable success.

05 May 2025 · 4 min read
Security

The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851

Alfred Hobbs: The OG bug bounty hunter who cracked England’s ‘unpick-able’ locks. His breaker mindset exposed flaws, sparked innovation, and proved no system is perfect.

07 Mar 2025 · 5 min read
Security

NEBULA:FOG:PRIME – AI x Security Panel Discussion

It was an privilege to participate on this panel at the NEBULA:FOG:PRIME AI x Security Hackathon event on the 25th of January.

13 Feb 2025 · 1 min read
Security

A few security predictions for 2025

Security predictions for 2025: peacetime vs wartime cyber, hardware and IOT back in focus, AI as tool, target, and threat — and the slop firehose's arrival.

17 Dec 2024 · 2 min read
Security

Some thoughts about Typhoons

What's the deal with Volt Typhoon, Salt Typhoon, and Flax Typhoon - and what do we need to do?

12 Dec 2024 · 3 min read
Security

You're Soaking In It: Systemic Cyber Struggles

Chris Hughes, Wendy Nather, and Casey Ellis on systemic cyber struggles, the cybersecurity poverty line, and what regulation can actually shift the needle on.

14 Nov 2024 · 1 min read
Personal

Little update: “Rumors of my death have been greatly exaggerated”

It’s been just over three weeks since I randomly “let the Internet know” that I was heading in for unexpected heart surgery...

21 Jul 2024 · 5 min read
Policy

Builders and Breakers: Partnering for Secure Elections

In September 2023, the IT-ISAC Elections Industry SIG launched a first-of-its kind pilot program in which election technology providers gave security researchers access to modern voting technology under the principles of Coordinated Vulnerability Disclosure.

13 Jun 2024 · 6 min read
Security

Bugs on a Plane: Implementing a Bug Bounty in an Airline IT/OT Environment

Bug bounty programs are a valuable tool for security efforts but only if they are correctly applied. This is particularly true for airlines who have to secure both the IT business systems and OT aircraft systems that enable the business to operate safely.

13 Jun 2024 · 6 min read
Teach

AI security: Tool, Target, Threat

The Tool/Target/Threat taxonomy for AI security — a shared vocabulary for the three orientations every conversation collapses without, built during EO 14110.

04 Apr 2024 · 4 min read
Personal

My office setup — Part 3 (US edition)

Optimizing my home office space for a work-from-home/hybrid setup became a bit of a hobby during the pandemic, and since returning to the USA from Australia in 2021 I've essentially replicated the successful aspects of the Sydney setup, with a few modifications.

18 Sep 2023 · 3 min read
Policy

DEF CON 31 Policy — All Your Vulns Are Belong to Terms and Conditions

DEF CON 31 Policy - All Your Vulns Are Belong to Terms and Conditions - DEF CON panel featuring David Rogers, Katie Trimble-Noble, Harley Geiger, and myself. Recorded on September 15, 2023 at DEF CON 31 in Las Vegas, Nevada.

17 Sep 2023 · 34 min read
Security

The RSnake Show!

Recording this was a tonne of fun and we cover a LOT of ground - There's a general theme of system-level thinking, vulnerability and transparency, and the personal pursuit of potential through things like entrepreneurship. It's very much a backstory and #thoughtops conversation.

24 Aug 2023 · 2 min read
Building

My #hackersummercamp 2023 moves

Here are my moves for #hackersummercamp 2023...

08 Aug 2023 · 1 min read
Thinking

KEYNOTE: Release the Hounds, Part 2

Casey delivers "Release the Hounds, Part 2 - 11 Years Is A Long-Ass Time" as the keynote for BSides Knoxville on May 12th, 2023. This talk covers the history of vulnerability disclosure and crowdsourced security testing platforms, and dives into cybersecurity entrepreneurship.

22 Jun 2023 · 1 min read
Building

Bugcrowd: 10 Years On, and Still Just Getting Started

On the 1st of September 2012 during a flight from Melbourne to Sydney, a series of ideas I’d been working on for a year or more coalesced with a bunch of conversations I’d just had, the lightbulb went off, and Bugcrowd was born.

01 Sep 2022 · 4 min read
Building

#HSC2022 in Pics

A small selection of selfies and pics from #HSC2022. It was a good homecoming.

21 Aug 2022 · 5 min read
Security

Where the bloody hell were you — The Great 2020 COVID Bug-In

During Hacker Summer Camp, I was asked "where do you, uh, live now and stuff" a lot. Forgive this slightly indulgent post, but I wanted to blog a little bit of our story, and some of the thinking that went into executing our trans-pacific COVID bug-in back in 2020.

20 Aug 2022 · 9 min read
Security

9 Must-See Talks at #hackersummercamp 2022

Here's a list of the talks that I'm going to get myself along to at Blackhat and DEF CON this year, and why...

04 Aug 2022 · 3 min read
Security

Digital and Personal Self-Care at #hackersummersamp — "New Normalish" Edition

I usually write a piece for first-timers and newbies on how to get the most out of Hacker Summer Camp and how to stay safe digitally and physically. This tradition began in the early days of Bugcrowd, when DEF CON was part of new-hire induction.

28 Jul 2022 · 6 min read
Security

Two-thirds of ethical hackers considering bug bounty hunting as a full-time career

Casey Ellis, founder and CTO at Bugcrowd, said bug bounty hunters are ultimately entrepreneurs in their own right.

30 May 2022 · 1 min read
Security

[TRANSCRIPT] Threats that may have gone unnoticed by organizations during the pandemic

Casey Ellis, the founder, chairman and CTO of Bugcrowd, told SC Media Senior Reporter Joe Uchill that companies should think about the various threat scenarios that emerged over the last year that they may have missed as employees return to the office environment.

20 Aug 2021 · 2 min read
Security

[TRANSCRIPT] Threat hunting in the age of work-from-home

Casey Ellis, the founder, chairman and CTO of Bugcrowd, told SC Media Senior Reporter Joe Uchill that there’s always going to be corporate infrastructure that provides information for a threat hunter, such as VPN, antivirus, and endpoint detection and response.

20 Aug 2021 · 2 min read
Security

IT Visionaries Podcast with Malcolm Harkness

On this roundtable episode of IT Visionaries, we explore the impact A.I. and technology are having on society and cybersecurity with Casey Ellis, the founder and CTO of Bugcrowd and Malcolm Harkins, a cybersecurity advisor, coach and board member.

06 Jul 2021 · 36 min read
Security

The Bar Fight Risk Taxonomy

After hearing "vulnerability" and "threat" used interchangeably for a >9,000th time I decided to do something about it, and the Bar Fight Risk Taxonomy was born.

26 Jun 2021 · 4 min read
Building

My "office" setup — Part 2

This is a follow up from https://cje.io/2021/03/28/my-office-setup which is worth reading first if you haven't yet... Everything in Part 1 is still in play - Part 2 talks through some optimizations and a couple of additions.

22 May 2021 · 4 min read
Building

Bugcrowd at AusCERT2021

AusCERT 2021 was a hybrid conference this year, and one of the first Australian cybersecurity conferences to resume in real life after the onset of the COVID pandemic. I was there representing Bugcrowd across three (!) separate sessions.

19 May 2021 · 1 min read
Policy

The iOS FaceTime vulnerability: What it means and what you can do to protect yourself

Yesterday news broke that a bug in FaceTime that allows callers to listen to the audio of the person they are calling before that

16 May 2021 · 3 min read
Policy

How Governments are Running Effective Bug Bounty Programs

If you’re reading this article, statistically speaking your organization might be getting hacked. In the private sector, the Equifax hack and Intel’s

16 May 2021 · 2 min read
Building

On disclosure, confidentiality, and norms…

A few weeks ago I was tagged by Art Manion of the CERT Coordination Center (CERT/CC) in a tweet asking about Bugcrowd’s

16 May 2021 · 3 min read
Policy

Election Security 2020: Don’t Let Disinformation Undermine Your Right to Vote

A tweet of a voting machine that “looks like” it’s infected by ransomware could be as effective at deterring voter turnout and confidence as the real deal, which is a cost-effective and asymmetric means to manipulate election results.

16 May 2021 · 2 min read
Building

Titan Talks — Ep 2 — Casey John Ellis with @thecybermentor

I've watched Heath's journey as a education and community powerhouse, and more recently as an entrepreneur with tcm-sec with much interest and respect. We covered a lot of ground about entrepreneurship, founder DNA, competition, priorities, and the cybers all around.

10 May 2021 · 54 min read
Security

On Project Zero's 90+30 vulnerability disclosure policy changes

Google is acknowledging the increasing prevalence of n-day exploitation in the wild, particularly over the past 18 months (e.g. the CISA/NSA memo) have taken their next step in refining how they strike balance between these forces.

08 May 2021 · 4 min read
Security

Security Research and Disclosure: The Unauthorized Biography — Nullcon March 2021

Title: Security Research and Disclosure: The Unauthorized Biography | Casey John Ellis | Nullcon Conference March 2021

16 Apr 2021 · 31 min read
Personal

My "office" setup

As WFH was going from novel to normal, the thought occurred to me that "virtual semiotics" was quickly going to become a thing... The equivalent of the how to dress, where to sit, how to speak type advice executives get taught, but for a world which is virtual by default.

28 Mar 2021 · 9 min read
Policy

NIST: Vulnerability Disclosure as a Requirement for Every Organization

What is the NIST Cybersecurity  Framework? The NIST Cybersecurity Framework is a set of policies meant to help the private sector in strengthening their

08 Mar 2021 · 2 min read
Policy

Responsible Disclosure Programs with Katie Moussouris & Casey Ellis | 401 Access Denied Ep. 22

Katie Moussouris, Founder & CEO of Luta Security and Casey Ellis, Founder & CTO of Bugcrowd join Joe and Mike to talk all things responsibility disclosure – the good, the bad, and the ugly.

26 Feb 2021 · 59 min read
Policy

Establishing asset ownership in vulnerability reporting

The thing I see people get wrong most frequently in vulnerability reporting is being able to answer the question of ownership and "where to report my findings." Here are some practical tips for establishing ownership and thereby identifying the appropriate coordinator to contact.

22 Feb 2021 · 3 min read
Policy

Modes of Public Vulnerability Disclosure

A proposed taxonomy... Discovery, Documentation, Distribution.

20 Feb 2021 · 3 min read
Security

A thought re vulnerability research clustering

The fact that insecure software pipelines are exploitable feels a little like the idea that bugs exist in old F/OSS code, or that a chip design might not be 100% perfect. It's almost QED - but in the defensive realm, people weren't looking there.

10 Feb 2021 · 3 min read
Security

Help! My Social Media has been hacked!

I know you do security stuff with computers and my Twitter/Facebook/Instagram/etc has been hacked! It's posting all kinds of strange stuff that isn't from me. What do I do to stop this???

11 Jan 2021 · 7 min read
Personal

Outrage is cheap

Outrage is cheap and of fleeting value. Introspection and change are expensive, precious, and resilient... and very easy to miss if everything is the other guy’s fault.

09 Jan 2021 · 2 min read
Personal

2020 Lernings for Make Benefit Glorious Year of 2021

My family and I are straight-up blessed with how we've fared this year, and I'm incredibly thankful for the myriad of people and things - but whichever way you cut it, 2020 was a dense and challenging year and not one I’d rush to repeat.

31 Dec 2020 · 1 min read
Security

Van Buren v. United States — Oral Argument

The Supreme Court heard oral argument in Van Buren v. United States, a case concerning a statute of the Computer Fraud and Abuse Act (CFAA) and violations of terms of service agreements.

01 Dec 2020 · 41 min read
Policy

DEF CON endorsed by POTUS!

Great news everyone: After years of steady work and deliberate improvement of relationships and trust between the hacker community and government officials, we've made it to the apex of the American org chart!

14 Nov 2020 · 6 min read
Security

Krebs Has A Posse

14 Nov 2020 · 1 min read
Building

How the Pandemic is Reshaping the Bug Bounty Landscape

Bugcrowd Founder Casey Ellis talks about COVID-19’s impact on bug bounty hunters, bug bounty program adoption and more.

28 Oct 2020 · 2 min read
Personal

The Third-Quarter

"I'm exactly the same as I was nine months ago, but I'm also completely different."

25 Oct 2020 · 1 min read
Policy

VentureBeat: How ethical hackers are trying to protect the 2020 U.S. elections

“All software is vulnerable,” Bugcrowd CTO Casey Ellis said. “It just depends on how long you’re taking to look to find those vulnerabilities. Humans write code, and humans make mistakes.”

23 Oct 2020 · 1 min read
Thinking

Data is the new oil: Breach edition

Data is the new oil... It spills everywhere, trashes the environment, and is impossible to clean up. Think before you store.

07 Oct 2020 ·
Building

Cyber Talk Episode 14 w/ Pratik Dabhi

Cyber Talk EP14 - Casey Ellis talks about entrepreneurship, motivation, cybersecurity & @Bugcrowd

06 Oct 2020 · 15 min read
Security

Vulnerability annihilation since 1851

"What Hobbs had in mind was not the usual cajoling of a provincial bank into an upgrade, but exposing weaknesses in the British Empire itself by revealing the faults of one of Day and Newell’s competitors."

05 Oct 2020 · 1 min read
Policy

Iowa launches vulnerability disclosure program for election-related sites

The State of Iowa has partnered with Bugcrowd to launch a vulnerability disclosure program on election infrastructure.

01 Oct 2020 · 1 min read
Security

Information Asymmetry and the 1950s Nuclear Bounty

Props to Matt Ploessel for calling out this one... I'd not heard of a bounty around nuclear weapons until today.

29 Sep 2020 · 3 min read
Security

Are you making a Walkman? Or an iPod?

When the walkman was introduced, it created a category. It's brand also became the term of description for that category.

29 Sep 2020 · 3 min read
Building

NIST SP 800-53 R5 adds Vulnerability Disclosure Programs

NIST SP 800-53 Revision 5 is yet another step towards the legitimization of the Internet’s Immune System. Everyone who has worked on legitimizing the work of good-faith hackers for the past 30 years or more can feel encouraged by this release.

28 Sep 2020 · 4 min read
Personal

Quick note for mentees

Seasoned experts get as much out of the “feet on the street” insights and energy of younger mentee as the mentee gets from their wisdom of the mentor.

22 Sep 2020 · 1 min read
Personal

4 Questions for Leaders

I had a coach share this with me a little while back and it resonated - It's a valuable and simple framework, and a good set of questions to always be in a position to answer.

15 Sep 2020 · 1 min read
Building

Techcrunch: Use ‘productive paranoia’ to build cybersecurity culture at your startup

At TechCrunch Early Stage, we asked Casey Ellis, founder, chairman and chief technology officer at Bugcrowd, to share his ideas for how startups can improve their security posture.

11 Sep 2020 · 6 min read
Security

The Nth Country Experiment and Coincident Vulnerability Discovery

Nth Country Experiment - Nuclear MuseumCould any country with the right knowledge and technology build a nuclear bomb? From May 1964 to April 1967, the

31 Aug 2020 · 1 min read
Policy

Group Letter re IoT Cybersecurity Improvement Act (H.R. 1668)

We the undersigned cybersecurity companies and professionals write to express strong support for the IoT Cybersecurity Improvement Act (H.R. 1668). We respectfully urge you and your colleagues to support expedited passage of the bill before the end of the 116th Congress.

29 Aug 2020 · 1 min read
Building

Public Comment from Casey Ellis, Bugcrowd re DRAFT BOD 20-01

Dear Director Krebs and CISA/DHS team, Thank you for the opportunity to comment on this Binding Operational Directive...

27 Aug 2020 · 6 min read
Security

Forbes: Accelerating secure software development

7. Expect and plan for mistakes. Expect mistakes, and plan to capture and mitigate them quickly. After all, to err is human. Establishing a

09 Aug 2020 · 1 min read
Policy

NIST SP 800-53 R5 adds Vulnerability Disclosure Programs to Federal Security and Privacy Controls

Earlier this week, the National Institute of Science and Technology (NIST) released Revision 5 of NIST Special Publication (800–53) Guidelines Security and Privacy

07 Aug 2020 · 4 min read
Security

DEF CON Black Hat 2020: Top 10 Tips

While it feels illegal to hang out with your friends right now, the pandemic is no match for the dedicated folks who unite for

06 Aug 2020 · 3 min read
Policy

Help! I've found a vulnerability. What now?

"You've just found a bug on a company's website. What are the first three to five things you'll try in order to establish contact with them?"

04 Aug 2020 · 1 min read
Policy

Disclose.io, VDP, Hackers, and voting

About 18 months ago, I sat in Capitol Hill with a bunch of other badasses including Matt Blaze, Kimber Dowsett, Jack Cable, Alexander Romero, Leonard Bailey, and others, and talked to voting machine manufacturers and US states.

04 Aug 2020 · 2 min read
Security

WTF is happening on tcp:0? 2020 edition — Update 1

tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk…

03 Aug 2020 · 1 min read
Security

WTF is going on with TCP:0?

tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk... Note: Never interact

30 Jul 2020 · 3 min read
Building

WTF is happening on tcp:0? 2020 edition

tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk…

29 Jul 2020 · 3 min read
Security

A few good cybersecurity companies

I spend a lot of time looking at cybersecurity solutions and companies, partly on request, and partly because it always fascinates me to see people are attempting to solve big problems.

17 Jul 2020 · 4 min read
Personal

On not being not-racist

An active problem needs an active opposing response, a passive response will always allow the aggressor to succeed in the end.

08 Jun 2020 · 2 min read
Building

First principles

Simple is strong. Respect is key. Build it like you own it. Don’t be valuable, create value. Think like a hacker. 360-degree accountability.

26 May 2020 · 1 min read
Security

Priority One: Insights into Submission and Payment Trends

2020: Chaos is a Ladder As 2020 comes to a close, I’ve started to see summaries of the year pop up, covering lessons

16 May 2020 · 3 min read
Security

To err is human — Kerckhoffs' Principle in Software Transparency

Shannon and Kerckhoff were pioneers of disclosure thinking — They understood the concept of “build it like it’s broken”. This was especially true in WWII cryptography, but it’s becoming increasingly clear in its relevance to the 'peacetime' software that we use today.

08 Apr 2020 · 2 min read
Security

Hacking styles

Broadly, there are two things that come into play when it comes to the style a person applies to hacking: The level of experience, and the overall wiring of the hacker.

29 Mar 2020 · 1 min read
Security

A message to folks providing "free testing" at the moment

TLDR: If you’re performing any active, unsanctioned testing on healthcare systems: Please stop it. Don’t make their job any harder than it is right now.

28 Mar 2020 · 1 min read
Security

COVID-19/Coronavirus — What are the bad guys up to?

As expected, the covid19 pandemic has out brought some of the Internet’s worst. I’ve been working with several groups to information share and fight back on this stuff, including the COVID-19 CTI Group.

28 Mar 2020 · 2 min read
Security

Changes

You know that awkward thing at the moment when you see someone and go to shake their hand or hug them, then pull away…

23 Mar 2020 · 1 min read
Security

The importance of delivering well

In general, people like to be think they have the ability to assess risk… you see it in kids jumping over puddles, you see

23 Mar 2020 · 1 min read
Security

On #stopthespread and school closures

On the decision to keep schools open in Australia yesterday: It’s not that kids don’t catch covid. It seems that everyone catches

22 Mar 2020 · 3 min read
Security

Tools for the WFH apocalypse

Well… It’s been an interesting couple of weeks. Viv, the kids, and I decided to bug out back to Australia last Thursday to

20 Mar 2020 · 4 min read
Building

My moves for #rsac2020 & #bsidessf week

Deep breaths, because here we go again!!! The full list of Bugcrowd events can be found here… We’ve got a lot on this

22 Feb 2020 · 2 min read
Policy

Hacking Democracy On Securing an Election (Shmoocon 2020)

Democracy is the cornerstone of America’s Constitution, identity, and ideology, and this foundation was shaken during the 2016 Presidential Election.

01 Feb 2020 · 31 min read
Building

Unity

Unity in a mediocre team > Division in a rock-star team. Driving unity through clear vision, careful hiring, and genuine care of a

23 Jan 2020 · 1 min read
Personal

Treasure

For where your treasure is, there will your heart be also. – Matthew 6:21 I believe in this as a universal truth. It’s

10 Jan 2020 · 1 min read
Building

Founder motivations

A founder or category creator is driven by the delta between the full potential they see in the original concept, and where ever the

08 Jan 2020 · 1 min read
Policy

Crowdsourcing physics

Ok, time for some hard chats. I’m posting this following on from a series of conversations and reactions on Twitter and Slack/Discord,

02 Jan 2020 · 4 min read
Personal

Just decade things...

2000s – Possibility. 2010s – Impact. 2020s – Legacy.

01 Jan 2020 · 1 min read
Security

The Future is Now: 2020 Cybersecurity Predictions

How is it 2020 already? We’re in the last month of the decade, and the year that has long held a “futurist bookmark”

31 Dec 2019 · 3 min read
Security

The future is now: 2020 cybersecurity predictions

The year that has long held a “futurist bookmark” in people’s minds is now upon us. And while we may not have hoverboards and flying cars yet, our adoption, connectedness, and reliance on technology is accelerating faster than it ever has before.

18 Dec 2019 · 3 min read
Security

Vulnerability value modifiers

There are a few globally and truly external modifiers to the marketplace-defined value of a vulnerability.

30 Aug 2019 · 1 min read
Security

Upcoming talks

Here’s some of the talks and events I’ll be at over the next few months: Billington 10th Annual Cybersecurity Summit September 4-

14 Aug 2019 · 1 min read

My DEF CON/Vegas moves

It has been an amazing week so far, but as we drop from “suite and wingtips” mode to “hoodie and sneakers” mode I’d

08 Aug 2019 · 1 min read
Security

Practical prepping for Hacker Summer Camp

Here are some last-minute security and general “staying vertical” notes I shared with a few folks who are headed to B-Sides/Diana/

31 Jul 2019 · 3 min read
Security

7 Years and counting…

In 2012, Bugcrowd set out to create a radical cybersecurity advantage and level the playing field between attackers and defenders. As one of the

16 May 2019 · 1 min read
Security

My moves during the RSAC/BSides SF circus

Quick post re where I’ll be speaking and attending while the infosec/cyberz are in town for RSA Conference and B-Sides: ps

02 Mar 2019 · 1 min read
Building

Firing your clients

This concept is pushed pretty hard in Tim Ferriss’ book the 4-Hour Work Week as well… In a nutshell – you don’t want

17 Jan 2019 · 1 min read

Happy 6th Birthday @bugcrowd

6 years ago today I got off a plane armed with a bunch of notes. I’d spent a week meeting with pen-testing

01 Sep 2018 · 1 min read
leadership

Living intentionally

Happy New Year! Pretty much everyone I’ve spoken agrees on the same thing: 2017 was a turbulent, change-filled year packed with as

01 Jan 2018 · 1 min read
vulnerability-disclosure

Thoughts on the vault7 CIA/Wikileaks disclosures

Wikileaks’ release of thousands of confidential CIA documents today is yet another demonstration of our just how vulnerable the cybersecurity domain is. Unless we

07 Mar 2017 · 2 min read
Building

How to disrupt a sleepy incumbent

When building a product or company that’s designed to disrupt a sleepy incumbent there are four phases of typical interaction you’ll have with your future competition.

23 Jun 2016 · 1 min read
leadership

The three levels of input

A great tip one of our board members gave me a while back was that, as leadership and influence grow, it becomes increasingly important to make sure your team knows the type of input you’re giving them.

31 May 2016 · 1 min read
Building

What a day! (Bugcrowd Series B)

So, Bugcrowd announced some pretty big news today… We closed our Series B financing of $15M, announced some amazing new partners in Salesforce and

20 Apr 2016 · 1 min read
vulnerability-disclosure

On the U.S. Government and bug bounties

My favorite thing about going to conferences is establishing the underlying trends behind the questions I’m asked. We’re only half-way through

06 Mar 2016 · 3 min read
Building

Repeat after me — I am not ashamed of sales and marketing!

I find that people are often ashamed, almost embarrassed to talk about sales and marketing. “Yeah, we’re going OK, we’re actually… kind

26 Jan 2016 · 1 min read
Building

Bugcrowd's First Principles

About 12 months after Bugcrowd started, one of our team pulled me aside and made a suggestion that truly altered the course of the

31 Dec 2015 · 3 min read
Security

3 years, 20,000 Security Researchers & 200 Clients later...

2012 was the year that almost every industry, banking, education, government, big tech and even security, was hacked. Many, if not all of these

08 Oct 2015 · 3 min read
leadership

Becoming CEO

The goal of a founder is to do everything. The goal of a CEO is to do nothing.

30 Sep 2015 · 1 min read
Building

On Cogs and Levers (strength in diversity)

A dear friend of mine was a linesman with a national telco for 17 years. He drove all around Australia pulling copper. He’s

16 Mar 2015 · 1 min read
Building

8,000 Miles + 1 Wife + 2 Kids + 1 Startup = ???

I remember when I first landed in Silicon Valley in April of 2013. Bugcrowd was 3 months old, and we’d seen enough early

15 Mar 2015 · 3 min read
vulnerability-disclosure

disclose.io — Driving safety, simplicity, and standardization in vulnerability disclosure.

disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research. The project expands

22 Jul 2014 · 1 min read
Building

Some Thoughts from pushstart’s Mentor Connect

Kim Heras and the Pushstart crew put on another Mentor Live event last night. Think speed dating for start-ups and mentors. I was

15 Dec 2012 · 3 min read
Building

Your Idea Sucks

tl;dr: I love your idea. I want to hear about your idea. Please, do not interpret this post as me stifling your idea.

24 Sep 2012 · 2 min read
Security

Bugcrowd — the Premier Crowdsourced Cybersecurity platform.

Bugcrowd is the premiere crowdsourced security platform. More enterprise organizations trust Bugcrowd’s Crowdcontrol platform to manage their bug bounty, vulnerability disclosure, and next-

31 Aug 2012 · 1 min read
Security

Why the Smb Is Most at Risk from ms12-010

There’s a lot of hubbub going around about the recent vulnerability from Microsoft. It’s called MS12-020 and it affects the Remote

18 Mar 2012 · 5 min read
Security

Rdpcheck Checks Your Network for the New Rdp Vulnerability

We’ve created a tool at RDPCheck to help you test your exposure to an attack from the outside on Microsoft’s recent MS12-

05 Mar 2012 · 1 min read
Building

Using Viral Landing Pages to Go from 0 to 1500 Leads in 7 Days for $15

I was approached with a simple brief… The client, a start-up rookie trying to make a break from his 9-to-5 as

28 Dec 2011 · 2 min read
Building

Mike Montiero – f*** you. Pay me.

Excuse the profanity, but this is really worth watching. [2011/03 Mike Monteiro F*** You. Pay Me.](http://vimeo.com/22053820) from San Francisco

14 Nov 2011 · 1 min read
Building

Invention Is a flower, Innovation Is a Weed

“Here’s the difference between a visionary and an entrepreneur. Both have visions, which are a dime a dozen. But an entrepreneur has, in

17 Oct 2011 · 1 min read
Building

What Is the Tall Poppy Group

If I’m really honest I’d have to say that I don’t really know what the Tall Poppy Group is yet. I

25 Sep 2011 · 1 min read
Building

Myths from the Four Hour Work Week

Anyone who knows me, or has read more than a few posts on this blog, will know that I love Timothy Ferriss‘ book “The

30 Mar 2011 · 4 min read
Building

Idea Validation — a Simple Framework

So you’ve had your light-bulb moment, there’s stars in your eyes and your new idea is making everything seem bright and

21 Mar 2011 · 1 min read
Building

3 Questions to Ask Yourself Before You Start Up

1. What am I passionate about? 2. What am I really really really good at (another way to ask this – “What could I be

20 Jan 2011 · 1 min read
Building

Goals for 2011

Here is the working list of goals for 2011… As is my custom there are only 5 goals, and they are more “set of

30 Dec 2010 · 1 min read
Building

Skype Outage and Lessons on Bcp

As I post this, Skype is still down globally. There’s little doubt that Skype is the largest player in the VOIP and Internet

09 Dec 2010 · 2 min read
Building

The 4 Minute Business Plan

OK, I admit it, I wrote the title like that just to suck you in… The truth is that 99% of entrepreneurs hate business

01 Dec 2010 · 2 min read
Building

The Twitter Pitch

Being able to succinctly define and communicate what your business does is important for two reasons… 1. It helps you to define what the

01 Dec 2010 · 1 min read
Building

6 Tips for Getting Paid on Time

One of the most difficult things any business owner faces is that murky and usually somewhat awkward period between invoicing and payment. I hear

11 Oct 2010 · 2 min read
Building

The Return of the Blog

My two year old has this expression that she busts out whenever I’ve been away for too long – it’s goes “Daddy I

22 Aug 2010 · 1 min read
Building

Crazy Not Stupid

One of the great things about young entrepreneurs is that they don’t know that something can’t be done. So they try something

26 Jun 2010 · 1 min read
Building

Young and Stupid

One of the great things about young entrepreneurs is that they don’t know that something can’t be done. So they try something

25 Jun 2010 · 1 min read
Building

What Makes a Good product?

For my money, a good business idea needs the following: 1. A problem (a.k.a. a need) 2. For that problem to be

29 Mar 2010 · 1 min read
Building

The work/job/life Balance – an Idea on Enforcing Boundaries

One of the challenges us “part-time” entrepreneurs face is the creep of our “5 to 9″ (i.e. the side-projects) into our

22 Mar 2010 · 2 min read
Building

Outsourcing — When to Remove Yourself from Your Own Life

This is an interesting way of looking at it… I’ll use hypothetical numbers for the illustration. This post is aimed at those thinking

20 Mar 2010 · 2 min read
Building

Have Idea — Will Work for Equity

I’ve been meeting up with some very cool people of late. One person in particular got me to thinking about the idea of

17 Mar 2010 · 1 min read
Building

Start something. today.

My dad has a saying that I love: “You can’t steer a parked car” You sort of can… turning the wheel is a

17 Mar 2010 · 1 min read
Building

Juggling Dual Roles

This is one of my favourite blogs… This post talks about some of the things one needs to consider when working a part-time

16 Mar 2010 · 1 min read
Building

Have idea. Will Work for equity.

I’ve been meeting up with some very cool people of late. One person in particular got me to thinking about the idea of

08 Mar 2010 · 1 min read
Thinking

Life Is Learning

The single greatest personal skill in business is the ability to learn. The second greatest personal skill in business is to be able to

06 Mar 2010 · 1 min read
Building

Outsourcing — Thinking Outside the Box

I love the book “The 4-hour Work Week”. A mate of mine just posted in his blog about the beginnings of his adventures

13 Feb 2010 · 2 min read
leadership

Keeping the Lights On

I’ve had moments over the past months, just like most other people I know, where I’ve “looked down” (i.e. think of

27 Jan 2010 · 2 min read
Building

Picking an Idea

I often talk to people that are absolutely chomping at the bit to start their own business, and the number one pre-startup question

25 Jan 2010 · 3 min read
Security

More on Skimming in Australia – Now an Official Epidemic

It turns out that a large percentage of recent fraud is being traced back to a single type of PIN pad: the Ingenico PX328.

21 Jan 2010 · 3 min read
Building

Skype Controls 12% of All International Calls

This is a repost from http://www.strategyeye.com/articles/digitalmedia/id/24649416. Interesting to watch this progress – the take-up of anti-monopoly

19 Jan 2010 · 1 min read
Security

What Are You Really Sharing

I’ve noticed a lot of people putting up quizzes on Facebook lately, I did one of my own as well (although I can’

17 Jan 2010 · 2 min read
Building

umm, Excuse me… you’re Sitting on a goldmine.

I define the fundamental essence of business as this: Connecting low yield solutions to a high yield problems. In simpler terms, find something that

13 Jan 2010 · 2 min read
Building

The M-word (...and it's friend the S-word)

I’m a solutions guy. I see a problem or a need and I come up with a way to fix it cost effectively

22 Nov 2009 · 2 min read
Building

Thoughts on time management

It’s always interesting when things start to get a bit crazy. Here’s a couple of principals I use I manage my tasks

05 Nov 2009 · 2 min read
Building

Taming the Hydra – Getting a handle on multiple business opportunities

Serial entrepreneurship, which is a fancy way of saying being a person who can’t really stop their brain from identifying new ideas and

29 Oct 2009 · 2 min read
Building

...and so Begins the adventure.

Life is about learning and building. The Tall Poppy Group is a platform and a brand to learn and build.

26 Oct 2009 · 1 min read
Building

Spinning plates — What do i do now?

People with an entrepreneurial mindset seasonally go through periods of massive inspiration, massive motivation, and often subsequently massive amounts of work. In these periods the ideas are flowing, the ways and means seem to be obvious and available.

15 Oct 2008 · 3 min read