Skip to content
← home
Casey Ellis

Casey Ellis

Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.

Thinking

We don't have a slop problem.

The real security problem isn't AI slop — it's that vulnerability research and the broader industry can't prioritize what actually matters in the noise.

24 Apr 2026 · 1 min read
Thinking

Build the tooling. Don't be the tooling.

The AI move in vulnerability research isn't prompting from scratch every run — it's using AI to build deterministic scanners, fuzzers, and analysis pipelines.

22 Apr 2026 · 1 min read
Security

Offense Scales with Compute. Defense Scales with Committees.

Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.

08 Apr 2026 · 11 min read
Security

Why Security Teams Gaslight Hackers: Disclosure Reality

The cybersecurity industry has a dirty secret: security teams are systematically dismissing legitimate vulnerability reports from ethical hackers. In a recent episode of Hackers

02 Apr 2026 · 2 min read
Thinking

The Compliance Reckoning

AI makes security verification cheap, putting two decades of checkbox compliance, paper pentests, and audit theater under sudden economic pressure.

28 Mar 2026 · 4 min read
Security

Bug Bounties in the Age of AI

As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.

27 Mar 2026 · 4 min read
Security

The FCC Just Banned Every Foreign-Made Router

The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.

24 Mar 2026 · 3 min read
Policy

The White House AI Framework: What It Says, What It Doesn't, and Why the Gaps Matter More

The March 2026 White House AI policy framework analyzed: seven pillars, and why the AI security omissions matter more than what's actually in the document.

23 Mar 2026 · 7 min read
Security

Vulnerability economics

The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.

22 Mar 2026 · 1 min read
Security

I Made AI Clones of Me and Matt Devost Argue About Exploit Stockpiling. They Agreed on a Framework.

Matt Devost and I have been circling the same set of questions for years: should governments stockpile zero-days? When does offense help defense?

02 Mar 2026 · 4 min read
Policy

No More Free-ish Bugs

The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.

12 Feb 2026 · 1 min read
Building

Next things...

Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd.

11 Feb 2026 · 2 min read