archive
Archive
The Amended Linus's Law
Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.
Slopdemic, Not Vulnpocalypse (Yet)
I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching.
My Clanker Setup
A mate messaged me this week asking whether I'd ever written up my clanker setup — which harness I run, which models, what
AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.
There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&
The Hitchhiker's Guide to Vulnerability Disclosure in 2026
Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.
Coordinated, Until It Isn't
Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.
Auditing My 2026 Security Predictions: Five Months In
Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's
Thoughts on the #slopdemic
Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.
Continued Monitoring of the Situation
Week two of an AI-powered House Finch nest monitor: four model biases, a Wyze cam back from the dead, and a full pipeline rewrite before the eggs hatch.
"Monitoring the Situation" - The Internet of Birbs
Two pale-blue speckled eggs on the sunroom bookshelf turned into three cameras, an Unraid NAS, two AI models, and a journal that writes itself every morning. None of it had to be useful — it just had to be possible. Because joy.
Spicy Takes from my Aikido Security Podcast
Nine takes from my RSAC conversation with Mackenzie Jackson on Aikido's Secure Disclosure podcast — on bug bounty, AI slop, hack-back, vibe coding, and why the internet still working is a minor miracle.
Offense Scales with Compute. Defense Scales with Committees.
Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.
The Compliance Reckoning
AI makes security verification cheap, putting two decades of checkbox compliance, paper pentests, and audit theater under sudden economic pressure.
Bug Bounties in the Age of AI
As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.
The FCC Just Banned Every Foreign-Made Router
The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.
The White House AI Framework: What It Says, What It Doesn't, and Why the Gaps Matter More
The March 2026 White House AI policy framework analyzed: seven pillars, and why the AI security omissions matter more than what's actually in the document.
Vulnerability economics
The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.
No More Free-ish Bugs
The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.
Next things...
Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd.
Bugcrowd 2013 to 2025 — People and Places
A photo retrospective of Bugcrowd from 2013 to 2025 — the people, offices, and moments that built the security crowdsourcing category from a Sydney garage out.
For the Love of the Game: DistrictCon's Year 1 Junkyard
Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes exploit chain diagrams for all eleven talks.
2026 security predictions
2026 cybersecurity forecast: China's PLA centenary looms, AI turns anyone into a malware developer, and economic pressure pushes more people toward cybercrime. Shift-left finally start working—but only for modern code. The rest of the internet? A triage trash fire.
2025 security predictions retrospective
This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.
First Principles: Bad guys are humans, they're creative and driven, and they don't quit.
Here's the bigger question: If we do finally achieve 100% success in automating cyber defense, will the "bad guys" pack their stuff up and go home?
Hacker Summer Camp 2025 — People, Places, and Things
A little photo diary of Hacker Summer Camp 2025.
Founders Helping Founders: When Known Vulnerabilities are Life or Death
On today’s episode, Jon Sakoda speaks with Casey on the early economics of paying people to hack companies, criminal creativity, and why founders need to fix their known vulnerabilities.
Peace-time Cyber vs War-time Cyber
A long read on how cybersecurity doctrine built during 15 years of geopolitical peacetime is failing as nation-state actors abandon restraint and discretion.
What You Give Away Might Be Worth More Than What You Keep
The sticking point is the word "free". If you do happen to get stuck there (and a lot of things will push you in that direction), a lot of the magic in the decision math gets missed. Everything has a Give and a Get and, if you're doing it right, nothing is ever given away for free.
If a tech solution falls in the forest...
A solution disconnected from it's problem isn't actually solving anything.
What the Netflix ‘Zero Day’ series got right about incident response
That said, the widespread nature of the effects shown in the six-part series are definitely plausible. Industrial control systems and the infrastructure that supports them are riddled with zero-day vulnerabilities, alongside the more common "known, yet unpatched" n-day vulnerabilities.
Bug Bounties, The Wanted Poster For Ethical Hackers — Future Secured Episode 35
Crowdsourced security empowers ethical hackers to protect digital assets, reshaping cybersecurity. Casey Ellis encourages entrepreneurs to lead with resilience, delegate wisely, prioritize health, and embrace innovation amid chaos for lasting impact and scalable success.
The Original Bug Bounty: Alfred Hobbs and the Great Lock Controversy of 1851
Alfred Hobbs: The OG bug bounty hunter who cracked England’s ‘unpick-able’ locks. His breaker mindset exposed flaws, sparked innovation, and proved no system is perfect.
NEBULA:FOG:PRIME – AI x Security Panel Discussion
It was an privilege to participate on this panel at the NEBULA:FOG:PRIME AI x Security Hackathon event on the 25th of January.
A few security predictions for 2025
Security predictions for 2025: peacetime vs wartime cyber, hardware and IOT back in focus, AI as tool, target, and threat — and the slop firehose's arrival.
Some thoughts about Typhoons
What's the deal with Volt Typhoon, Salt Typhoon, and Flax Typhoon - and what do we need to do?
You're Soaking In It: Systemic Cyber Struggles
Chris Hughes, Wendy Nather, and Casey Ellis on systemic cyber struggles, the cybersecurity poverty line, and what regulation can actually shift the needle on.
Little update: “Rumors of my death have been greatly exaggerated”
It’s been just over three weeks since I randomly “let the Internet know” that I was heading in for unexpected heart surgery...
Builders and Breakers: Partnering for Secure Elections
In September 2023, the IT-ISAC Elections Industry SIG launched a first-of-its kind pilot program in which election technology providers gave security researchers access to modern voting technology under the principles of Coordinated Vulnerability Disclosure.
Bugs on a Plane: Implementing a Bug Bounty in an Airline IT/OT Environment
Bug bounty programs are a valuable tool for security efforts but only if they are correctly applied. This is particularly true for airlines who have to secure both the IT business systems and OT aircraft systems that enable the business to operate safely.
AI security: Tool, Target, Threat
The Tool/Target/Threat taxonomy for AI security — a shared vocabulary for the three orientations every conversation collapses without, built during EO 14110.
My office setup — Part 3 (US edition)
Optimizing my home office space for a work-from-home/hybrid setup became a bit of a hobby during the pandemic, and since returning to the USA from Australia in 2021 I've essentially replicated the successful aspects of the Sydney setup, with a few modifications.
DEF CON 31 Policy — All Your Vulns Are Belong to Terms and Conditions
DEF CON 31 Policy - All Your Vulns Are Belong to Terms and Conditions - DEF CON panel featuring David Rogers, Katie Trimble-Noble, Harley Geiger, and myself. Recorded on September 15, 2023 at DEF CON 31 in Las Vegas, Nevada.
The RSnake Show!
Recording this was a tonne of fun and we cover a LOT of ground - There's a general theme of system-level thinking, vulnerability and transparency, and the personal pursuit of potential through things like entrepreneurship. It's very much a backstory and #thoughtops conversation.
My #hackersummercamp 2023 moves
Here are my moves for #hackersummercamp 2023...
KEYNOTE: Release the Hounds, Part 2
Casey delivers "Release the Hounds, Part 2 - 11 Years Is A Long-Ass Time" as the keynote for BSides Knoxville on May 12th, 2023. This talk covers the history of vulnerability disclosure and crowdsourced security testing platforms, and dives into cybersecurity entrepreneurship.
Bugcrowd: 10 Years On, and Still Just Getting Started
On the 1st of September 2012 during a flight from Melbourne to Sydney, a series of ideas I’d been working on for a year or more coalesced with a bunch of conversations I’d just had, the lightbulb went off, and Bugcrowd was born.
#HSC2022 in Pics
A small selection of selfies and pics from #HSC2022. It was a good homecoming.
Where the bloody hell were you — The Great 2020 COVID Bug-In
During Hacker Summer Camp, I was asked "where do you, uh, live now and stuff" a lot. Forgive this slightly indulgent post, but I wanted to blog a little bit of our story, and some of the thinking that went into executing our trans-pacific COVID bug-in back in 2020.
9 Must-See Talks at #hackersummercamp 2022
Here's a list of the talks that I'm going to get myself along to at Blackhat and DEF CON this year, and why...
Digital and Personal Self-Care at #hackersummersamp — "New Normalish" Edition
I usually write a piece for first-timers and newbies on how to get the most out of Hacker Summer Camp and how to stay safe digitally and physically. This tradition began in the early days of Bugcrowd, when DEF CON was part of new-hire induction.
Two-thirds of ethical hackers considering bug bounty hunting as a full-time career
Casey Ellis, founder and CTO at Bugcrowd, said bug bounty hunters are ultimately entrepreneurs in their own right.
[TRANSCRIPT] Threats that may have gone unnoticed by organizations during the pandemic
Casey Ellis, the founder, chairman and CTO of Bugcrowd, told SC Media Senior Reporter Joe Uchill that companies should think about the various threat scenarios that emerged over the last year that they may have missed as employees return to the office environment.
[TRANSCRIPT] Threat hunting in the age of work-from-home
Casey Ellis, the founder, chairman and CTO of Bugcrowd, told SC Media Senior Reporter Joe Uchill that there’s always going to be corporate infrastructure that provides information for a threat hunter, such as VPN, antivirus, and endpoint detection and response.
IT Visionaries Podcast with Malcolm Harkness
On this roundtable episode of IT Visionaries, we explore the impact A.I. and technology are having on society and cybersecurity with Casey Ellis, the founder and CTO of Bugcrowd and Malcolm Harkins, a cybersecurity advisor, coach and board member.
The Bar Fight Risk Taxonomy
After hearing "vulnerability" and "threat" used interchangeably for a >9,000th time I decided to do something about it, and the Bar Fight Risk Taxonomy was born.
My "office" setup — Part 2
This is a follow up from https://cje.io/2021/03/28/my-office-setup which is worth reading first if you haven't yet... Everything in Part 1 is still in play - Part 2 talks through some optimizations and a couple of additions.
Bugcrowd at AusCERT2021
AusCERT 2021 was a hybrid conference this year, and one of the first Australian cybersecurity conferences to resume in real life after the onset of the COVID pandemic. I was there representing Bugcrowd across three (!) separate sessions.
The iOS FaceTime vulnerability: What it means and what you can do to protect yourself
Yesterday news broke that a bug in FaceTime that allows callers to listen to the audio of the person they are calling before that
How Governments are Running Effective Bug Bounty Programs
If you’re reading this article, statistically speaking your organization might be getting hacked. In the private sector, the Equifax hack and Intel’s
On disclosure, confidentiality, and norms…
A few weeks ago I was tagged by Art Manion of the CERT Coordination Center (CERT/CC) in a tweet asking about Bugcrowd’s
Election Security 2020: Don’t Let Disinformation Undermine Your Right to Vote
A tweet of a voting machine that “looks like” it’s infected by ransomware could be as effective at deterring voter turnout and confidence as the real deal, which is a cost-effective and asymmetric means to manipulate election results.
Titan Talks — Ep 2 — Casey John Ellis with @thecybermentor
I've watched Heath's journey as a education and community powerhouse, and more recently as an entrepreneur with tcm-sec with much interest and respect. We covered a lot of ground about entrepreneurship, founder DNA, competition, priorities, and the cybers all around.
On Project Zero's 90+30 vulnerability disclosure policy changes
Google is acknowledging the increasing prevalence of n-day exploitation in the wild, particularly over the past 18 months (e.g. the CISA/NSA memo) have taken their next step in refining how they strike balance between these forces.
Security Research and Disclosure: The Unauthorized Biography — Nullcon March 2021
Title: Security Research and Disclosure: The Unauthorized Biography | Casey John Ellis | Nullcon Conference March 2021
My "office" setup
As WFH was going from novel to normal, the thought occurred to me that "virtual semiotics" was quickly going to become a thing... The equivalent of the how to dress, where to sit, how to speak type advice executives get taught, but for a world which is virtual by default.
NIST: Vulnerability Disclosure as a Requirement for Every Organization
What is the NIST Cybersecurity Framework? The NIST Cybersecurity Framework is a set of policies meant to help the private sector in strengthening their
Responsible Disclosure Programs with Katie Moussouris & Casey Ellis | 401 Access Denied Ep. 22
Katie Moussouris, Founder & CEO of Luta Security and Casey Ellis, Founder & CTO of Bugcrowd join Joe and Mike to talk all things responsibility disclosure – the good, the bad, and the ugly.
Establishing asset ownership in vulnerability reporting
The thing I see people get wrong most frequently in vulnerability reporting is being able to answer the question of ownership and "where to report my findings." Here are some practical tips for establishing ownership and thereby identifying the appropriate coordinator to contact.
Modes of Public Vulnerability Disclosure
A proposed taxonomy... Discovery, Documentation, Distribution.
A thought re vulnerability research clustering
The fact that insecure software pipelines are exploitable feels a little like the idea that bugs exist in old F/OSS code, or that a chip design might not be 100% perfect. It's almost QED - but in the defensive realm, people weren't looking there.
Help! My Social Media has been hacked!
I know you do security stuff with computers and my Twitter/Facebook/Instagram/etc has been hacked! It's posting all kinds of strange stuff that isn't from me. What do I do to stop this???
Outrage is cheap
Outrage is cheap and of fleeting value. Introspection and change are expensive, precious, and resilient... and very easy to miss if everything is the other guy’s fault.
2020 Lernings for Make Benefit Glorious Year of 2021
My family and I are straight-up blessed with how we've fared this year, and I'm incredibly thankful for the myriad of people and things - but whichever way you cut it, 2020 was a dense and challenging year and not one I’d rush to repeat.
Van Buren v. United States — Oral Argument
The Supreme Court heard oral argument in Van Buren v. United States, a case concerning a statute of the Computer Fraud and Abuse Act (CFAA) and violations of terms of service agreements.
DEF CON endorsed by POTUS!
Great news everyone: After years of steady work and deliberate improvement of relationships and trust between the hacker community and government officials, we've made it to the apex of the American org chart!
Krebs Has A Posse
How the Pandemic is Reshaping the Bug Bounty Landscape
Bugcrowd Founder Casey Ellis talks about COVID-19’s impact on bug bounty hunters, bug bounty program adoption and more.
The Third-Quarter
"I'm exactly the same as I was nine months ago, but I'm also completely different."
VentureBeat: How ethical hackers are trying to protect the 2020 U.S. elections
“All software is vulnerable,” Bugcrowd CTO Casey Ellis said. “It just depends on how long you’re taking to look to find those vulnerabilities. Humans write code, and humans make mistakes.”
Data is the new oil: Breach edition
Data is the new oil... It spills everywhere, trashes the environment, and is impossible to clean up. Think before you store.
Cyber Talk Episode 14 w/ Pratik Dabhi
Cyber Talk EP14 - Casey Ellis talks about entrepreneurship, motivation, cybersecurity & @Bugcrowd
Vulnerability annihilation since 1851
"What Hobbs had in mind was not the usual cajoling of a provincial bank into an upgrade, but exposing weaknesses in the British Empire itself by revealing the faults of one of Day and Newell’s competitors."
Iowa launches vulnerability disclosure program for election-related sites
The State of Iowa has partnered with Bugcrowd to launch a vulnerability disclosure program on election infrastructure.
Information Asymmetry and the 1950s Nuclear Bounty
Props to Matt Ploessel for calling out this one... I'd not heard of a bounty around nuclear weapons until today.
Are you making a Walkman? Or an iPod?
When the walkman was introduced, it created a category. It's brand also became the term of description for that category.
NIST SP 800-53 R5 adds Vulnerability Disclosure Programs
NIST SP 800-53 Revision 5 is yet another step towards the legitimization of the Internet’s Immune System. Everyone who has worked on legitimizing the work of good-faith hackers for the past 30 years or more can feel encouraged by this release.
Quick note for mentees
Seasoned experts get as much out of the “feet on the street” insights and energy of younger mentee as the mentee gets from their wisdom of the mentor.
4 Questions for Leaders
I had a coach share this with me a little while back and it resonated - It's a valuable and simple framework, and a good set of questions to always be in a position to answer.
Techcrunch: Use ‘productive paranoia’ to build cybersecurity culture at your startup
At TechCrunch Early Stage, we asked Casey Ellis, founder, chairman and chief technology officer at Bugcrowd, to share his ideas for how startups can improve their security posture.
The Nth Country Experiment and Coincident Vulnerability Discovery
Nth Country Experiment - Nuclear MuseumCould any country with the right knowledge and technology build a nuclear bomb? From May 1964 to April 1967, the
Group Letter re IoT Cybersecurity Improvement Act (H.R. 1668)
We the undersigned cybersecurity companies and professionals write to express strong support for the IoT Cybersecurity Improvement Act (H.R. 1668). We respectfully urge you and your colleagues to support expedited passage of the bill before the end of the 116th Congress.
Public Comment from Casey Ellis, Bugcrowd re DRAFT BOD 20-01
Dear Director Krebs and CISA/DHS team, Thank you for the opportunity to comment on this Binding Operational Directive...
Forbes: Accelerating secure software development
7. Expect and plan for mistakes. Expect mistakes, and plan to capture and mitigate them quickly. After all, to err is human. Establishing a
NIST SP 800-53 R5 adds Vulnerability Disclosure Programs to Federal Security and Privacy Controls
Earlier this week, the National Institute of Science and Technology (NIST) released Revision 5 of NIST Special Publication (800–53) Guidelines Security and Privacy
DEF CON Black Hat 2020: Top 10 Tips
While it feels illegal to hang out with your friends right now, the pandemic is no match for the dedicated folks who unite for
Help! I've found a vulnerability. What now?
"You've just found a bug on a company's website. What are the first three to five things you'll try in order to establish contact with them?"
Disclose.io, VDP, Hackers, and voting
About 18 months ago, I sat in Capitol Hill with a bunch of other badasses including Matt Blaze, Kimber Dowsett, Jack Cable, Alexander Romero, Leonard Bailey, and others, and talked to voting machine manufacturers and US states.
WTF is happening on tcp:0? 2020 edition — Update 1
tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk…
WTF is going on with TCP:0?
tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk... Note: Never interact
WTF is happening on tcp:0? 2020 edition
tl;dr: 0.06% of the publicly-addressable IPv4 space is listening to and responding on TCP Port 0. Why? idk…
A few good cybersecurity companies
I spend a lot of time looking at cybersecurity solutions and companies, partly on request, and partly because it always fascinates me to see people are attempting to solve big problems.
On not being not-racist
An active problem needs an active opposing response, a passive response will always allow the aggressor to succeed in the end.
First principles
Simple is strong. Respect is key. Build it like you own it. Don’t be valuable, create value. Think like a hacker. 360-degree accountability.
Priority One: Insights into Submission and Payment Trends
2020: Chaos is a Ladder As 2020 comes to a close, I’ve started to see summaries of the year pop up, covering lessons
To err is human — Kerckhoffs' Principle in Software Transparency
Shannon and Kerckhoff were pioneers of disclosure thinking — They understood the concept of “build it like it’s broken”. This was especially true in WWII cryptography, but it’s becoming increasingly clear in its relevance to the 'peacetime' software that we use today.
Hacking styles
Broadly, there are two things that come into play when it comes to the style a person applies to hacking: The level of experience, and the overall wiring of the hacker.
A message to folks providing "free testing" at the moment
TLDR: If you’re performing any active, unsanctioned testing on healthcare systems: Please stop it. Don’t make their job any harder than it is right now.
COVID-19/Coronavirus — What are the bad guys up to?
As expected, the covid19 pandemic has out brought some of the Internet’s worst. I’ve been working with several groups to information share and fight back on this stuff, including the COVID-19 CTI Group.
Changes
You know that awkward thing at the moment when you see someone and go to shake their hand or hug them, then pull away…
The importance of delivering well
In general, people like to be think they have the ability to assess risk… you see it in kids jumping over puddles, you see
On #stopthespread and school closures
On the decision to keep schools open in Australia yesterday: It’s not that kids don’t catch covid. It seems that everyone catches
Tools for the WFH apocalypse
Well… It’s been an interesting couple of weeks. Viv, the kids, and I decided to bug out back to Australia last Thursday to
My moves for #rsac2020 & #bsidessf week
Deep breaths, because here we go again!!! The full list of Bugcrowd events can be found here… We’ve got a lot on this
Hacking Democracy On Securing an Election (Shmoocon 2020)
Democracy is the cornerstone of America’s Constitution, identity, and ideology, and this foundation was shaken during the 2016 Presidential Election.
Unity
Unity in a mediocre team > Division in a rock-star team. Driving unity through clear vision, careful hiring, and genuine care of a
Treasure
For where your treasure is, there will your heart be also. – Matthew 6:21 I believe in this as a universal truth. It’s
Founder motivations
A founder or category creator is driven by the delta between the full potential they see in the original concept, and where ever the
Crowdsourcing physics
Ok, time for some hard chats. I’m posting this following on from a series of conversations and reactions on Twitter and Slack/Discord,
Just decade things...
2000s – Possibility. 2010s – Impact. 2020s – Legacy.
The Future is Now: 2020 Cybersecurity Predictions
How is it 2020 already? We’re in the last month of the decade, and the year that has long held a “futurist bookmark”
The future is now: 2020 cybersecurity predictions
The year that has long held a “futurist bookmark” in people’s minds is now upon us. And while we may not have hoverboards and flying cars yet, our adoption, connectedness, and reliance on technology is accelerating faster than it ever has before.
Vulnerability value modifiers
There are a few globally and truly external modifiers to the marketplace-defined value of a vulnerability.
Upcoming talks
Here’s some of the talks and events I’ll be at over the next few months: Billington 10th Annual Cybersecurity Summit September 4-
My DEF CON/Vegas moves
It has been an amazing week so far, but as we drop from “suite and wingtips” mode to “hoodie and sneakers” mode I’d
Practical prepping for Hacker Summer Camp
Here are some last-minute security and general “staying vertical” notes I shared with a few folks who are headed to B-Sides/Diana/
7 Years and counting…
In 2012, Bugcrowd set out to create a radical cybersecurity advantage and level the playing field between attackers and defenders. As one of the
My moves during the RSAC/BSides SF circus
Quick post re where I’ll be speaking and attending while the infosec/cyberz are in town for RSA Conference and B-Sides: ps
Firing your clients
This concept is pushed pretty hard in Tim Ferriss’ book the 4-Hour Work Week as well… In a nutshell – you don’t want
Happy 6th Birthday @bugcrowd
6 years ago today I got off a plane armed with a bunch of notes. I’d spent a week meeting with pen-testing
Living intentionally
Happy New Year! Pretty much everyone I’ve spoken agrees on the same thing: 2017 was a turbulent, change-filled year packed with as
Thoughts on the vault7 CIA/Wikileaks disclosures
Wikileaks’ release of thousands of confidential CIA documents today is yet another demonstration of our just how vulnerable the cybersecurity domain is. Unless we
How to disrupt a sleepy incumbent
When building a product or company that’s designed to disrupt a sleepy incumbent there are four phases of typical interaction you’ll have with your future competition.
The three levels of input
A great tip one of our board members gave me a while back was that, as leadership and influence grow, it becomes increasingly important to make sure your team knows the type of input you’re giving them.
What a day! (Bugcrowd Series B)
So, Bugcrowd announced some pretty big news today… We closed our Series B financing of $15M, announced some amazing new partners in Salesforce and
On the U.S. Government and bug bounties
My favorite thing about going to conferences is establishing the underlying trends behind the questions I’m asked. We’re only half-way through
Repeat after me — I am not ashamed of sales and marketing!
I find that people are often ashamed, almost embarrassed to talk about sales and marketing. “Yeah, we’re going OK, we’re actually… kind
Bugcrowd's First Principles
About 12 months after Bugcrowd started, one of our team pulled me aside and made a suggestion that truly altered the course of the
3 years, 20,000 Security Researchers & 200 Clients later...
2012 was the year that almost every industry, banking, education, government, big tech and even security, was hacked. Many, if not all of these
Becoming CEO
The goal of a founder is to do everything. The goal of a CEO is to do nothing.
On Cogs and Levers (strength in diversity)
A dear friend of mine was a linesman with a national telco for 17 years. He drove all around Australia pulling copper. He’s
8,000 Miles + 1 Wife + 2 Kids + 1 Startup = ???
I remember when I first landed in Silicon Valley in April of 2013. Bugcrowd was 3 months old, and we’d seen enough early
disclose.io — Driving safety, simplicity, and standardization in vulnerability disclosure.
disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbour for good-faith security research. The project expands
Some Thoughts from pushstart’s Mentor Connect
Kim Heras and the Pushstart crew put on another Mentor Live event last night. Think speed dating for start-ups and mentors. I was
Your Idea Sucks
tl;dr: I love your idea. I want to hear about your idea. Please, do not interpret this post as me stifling your idea.
Bugcrowd — the Premier Crowdsourced Cybersecurity platform.
Bugcrowd is the premiere crowdsourced security platform. More enterprise organizations trust Bugcrowd’s Crowdcontrol platform to manage their bug bounty, vulnerability disclosure, and next-
Why the Smb Is Most at Risk from ms12-010
There’s a lot of hubbub going around about the recent vulnerability from Microsoft. It’s called MS12-020 and it affects the Remote
Rdpcheck Checks Your Network for the New Rdp Vulnerability
We’ve created a tool at RDPCheck to help you test your exposure to an attack from the outside on Microsoft’s recent MS12-
Using Viral Landing Pages to Go from 0 to 1500 Leads in 7 Days for $15
I was approached with a simple brief… The client, a start-up rookie trying to make a break from his 9-to-5 as
Mike Montiero – f*** you. Pay me.
Excuse the profanity, but this is really worth watching. [2011/03 Mike Monteiro F*** You. Pay Me.](http://vimeo.com/22053820) from San Francisco
Invention Is a flower, Innovation Is a Weed
“Here’s the difference between a visionary and an entrepreneur. Both have visions, which are a dime a dozen. But an entrepreneur has, in
What Is the Tall Poppy Group
If I’m really honest I’d have to say that I don’t really know what the Tall Poppy Group is yet. I
Myths from the Four Hour Work Week
Anyone who knows me, or has read more than a few posts on this blog, will know that I love Timothy Ferriss‘ book “The
Idea Validation — a Simple Framework
So you’ve had your light-bulb moment, there’s stars in your eyes and your new idea is making everything seem bright and
3 Questions to Ask Yourself Before You Start Up
1. What am I passionate about? 2. What am I really really really good at (another way to ask this – “What could I be
Goals for 2011
Here is the working list of goals for 2011… As is my custom there are only 5 goals, and they are more “set of
Skype Outage and Lessons on Bcp
As I post this, Skype is still down globally. There’s little doubt that Skype is the largest player in the VOIP and Internet
The 4 Minute Business Plan
OK, I admit it, I wrote the title like that just to suck you in… The truth is that 99% of entrepreneurs hate business
The Twitter Pitch
Being able to succinctly define and communicate what your business does is important for two reasons… 1. It helps you to define what the
6 Tips for Getting Paid on Time
One of the most difficult things any business owner faces is that murky and usually somewhat awkward period between invoicing and payment. I hear
The Return of the Blog
My two year old has this expression that she busts out whenever I’ve been away for too long – it’s goes “Daddy I
Crazy Not Stupid
One of the great things about young entrepreneurs is that they don’t know that something can’t be done. So they try something
Young and Stupid
One of the great things about young entrepreneurs is that they don’t know that something can’t be done. So they try something
What Makes a Good product?
For my money, a good business idea needs the following: 1. A problem (a.k.a. a need) 2. For that problem to be
The work/job/life Balance – an Idea on Enforcing Boundaries
One of the challenges us “part-time” entrepreneurs face is the creep of our “5 to 9″ (i.e. the side-projects) into our
Outsourcing — When to Remove Yourself from Your Own Life
This is an interesting way of looking at it… I’ll use hypothetical numbers for the illustration. This post is aimed at those thinking
Have Idea — Will Work for Equity
I’ve been meeting up with some very cool people of late. One person in particular got me to thinking about the idea of
Start something. today.
My dad has a saying that I love: “You can’t steer a parked car” You sort of can… turning the wheel is a
Juggling Dual Roles
This is one of my favourite blogs… This post talks about some of the things one needs to consider when working a part-time
Have idea. Will Work for equity.
I’ve been meeting up with some very cool people of late. One person in particular got me to thinking about the idea of
Life Is Learning
The single greatest personal skill in business is the ability to learn. The second greatest personal skill in business is to be able to
Outsourcing — Thinking Outside the Box
I love the book “The 4-hour Work Week”. A mate of mine just posted in his blog about the beginnings of his adventures
Keeping the Lights On
I’ve had moments over the past months, just like most other people I know, where I’ve “looked down” (i.e. think of
Picking an Idea
I often talk to people that are absolutely chomping at the bit to start their own business, and the number one pre-startup question
More on Skimming in Australia – Now an Official Epidemic
It turns out that a large percentage of recent fraud is being traced back to a single type of PIN pad: the Ingenico PX328.
Skype Controls 12% of All International Calls
This is a repost from http://www.strategyeye.com/articles/digitalmedia/id/24649416. Interesting to watch this progress – the take-up of anti-monopoly
What Are You Really Sharing
I’ve noticed a lot of people putting up quizzes on Facebook lately, I did one of my own as well (although I can’
umm, Excuse me… you’re Sitting on a goldmine.
I define the fundamental essence of business as this: Connecting low yield solutions to a high yield problems. In simpler terms, find something that
The M-word (...and it's friend the S-word)
I’m a solutions guy. I see a problem or a need and I come up with a way to fix it cost effectively
Thoughts on time management
It’s always interesting when things start to get a bit crazy. Here’s a couple of principals I use I manage my tasks
Taming the Hydra – Getting a handle on multiple business opportunities
Serial entrepreneurship, which is a fancy way of saying being a person who can’t really stop their brain from identifying new ideas and
...and so Begins the adventure.
Life is about learning and building. The Tall Poppy Group is a platform and a brand to learn and build.
Spinning plates — What do i do now?
People with an entrepreneurial mindset seasonally go through periods of massive inspiration, massive motivation, and often subsequently massive amounts of work. In these periods the ideas are flowing, the ways and means seem to be obvious and available.