Casey Ellis
Hacker Summer Camp Tips and Tricks
As I've been thinking about Hacker Summer Camp (aka Blackhat, BSides Las Vegas, DEF CON, and all of the associated and adjacent cons and Vegas things) this year, it occurred to me that there are going to a LOT of new founders and operators roaming the desert this year.
The Amended Linus's Law
Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.
You get to choose your hard
Being known for what you're against is easy. Being known for what you're for is hard. You get to choose
It's con season
It's con season — Black Hat, DEF CON, and the summer security-conference circuit are nearly here. The best research of the year
Find it and fix it
A fun exercise: run various models against deliberately vulnerable apps, and eval them on their ability to identify the vulns and effectively patch them
Prompt-injection bumper stickers
Prompt injection is climbing out of the chat box and into the physical world. Print an adversarial instruction big enough for a camera to
Words mean things
If the AI era teaches you anything, let it be the lesson that words mean things.
Slopdemic, Not Vulnpocalypse (Yet)
I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching.
My Clanker Setup
A mate messaged me this week asking whether I'd ever written up my clanker setup — which harness I run, which models, what
AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.
There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&
The Hitchhiker's Guide to Vulnerability Disclosure in 2026
Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.
Coordinated, Until It Isn't
Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.