Skip to content
← home
Casey Ellis

Casey Ellis

Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.

Learn

Hacker Summer Camp Tips and Tricks

As I've been thinking about Hacker Summer Camp (aka Blackhat, BSides Las Vegas, DEF CON, and all of the associated and adjacent cons and Vegas things) this year, it occurred to me that there are going to a LOT of new founders and operators roaming the desert this year.

29 Jul 2026 · 3 min read
Casey Ellis on stage at SOURCE Boston 2014, next to a slide asking "So how do you get more eyes on security bugs?"
Security

The Amended Linus's Law

Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.

13 Jul 2026 · 5 min read
Hot Takes

You get to choose your hard

Being known for what you're against is easy. Being known for what you're for is hard. You get to choose

10 Jul 2026 · 1 min read
Hot Takes

It's con season

It's con season — Black Hat, DEF CON, and the summer security-conference circuit are nearly here. The best research of the year

09 Jul 2026 · 1 min read
Hot Takes

Find it and fix it

A fun exercise: run various models against deliberately vulnerable apps, and eval them on their ability to identify the vulns and effectively patch them

08 Jul 2026 · 1 min read
Hot Takes

Prompt-injection bumper stickers

Prompt injection is climbing out of the chat box and into the physical world. Print an adversarial instruction big enough for a camera to

07 Jul 2026 · 1 min read
Hot Takes

Words mean things

If the AI era teaches you anything, let it be the lesson that words mean things.

06 Jul 2026 · 1 min read
Security

Slopdemic, Not Vulnpocalypse (Yet)

I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching.

05 Jul 2026 · 2 min read
Johnny Five from Short Circuit rendered as an Obama 'Hope' campaign poster, captioned NO DISASSEMBLE
Building

My Clanker Setup

A mate messaged me this week asking whether I'd ever written up my clanker setup — which harness I run, which models, what

05 Jul 2026 · 7 min read
Security

AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.

There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&

29 Jun 2026 · 4 min read
Casey Ellis on VulnCheck Threat Con One — vulnerability disclosure post-Mythos
Thinking

The Hitchhiker's Guide to Vulnerability Disclosure in 2026

Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.

17 May 2026 · 13 min read
Policy

Coordinated, Until It Isn't

Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.

17 May 2026 · 9 min read