Skip to content

More posts

All →
Security

AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.

There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we'd

29 Jun 2026 · 4 min read
Casey Ellis on VulnCheck Threat Con One — vulnerability disclosure post-Mythos
Thinking

The Hitchhiker's Guide to Bug Bounty and Vulnerability Disclosure in 2026

Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.

17 May 2026 · 13 min read
Policy

Coordinated, Until It Isn't

Everyone has a take on Moksha's 89-vuln XAPI drop. Almost everyone misses the same thing: it wasn't one decision, it was four: go public, go Day-0, withhold patches from Citrix, lean into the "shittrix" frame. Coordinated disclosure runs on goodwill, and the goodwill runs out sometimes.

17 May 2026 · 9 min read
Security

Auditing My 2026 Security Predictions: Five Months In

Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's time to

15 May 2026 · 7 min read
Security

Thoughts on the #slopdemic

Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.

04 May 2026 · 2 min read
Thinking

The "irrational asymmetry" in threat behavior

We've traditionally thought about defense through the lens of a financially motivated attacker or a nation state — predictable rewards. Open it to everyone and

04 May 2026 · 1 min read
Personal

Continued Monitoring of the Situation

Week two of an AI-powered House Finch nest monitor: four model biases, a Wyze cam back from the dead, and a full pipeline rewrite before the eggs hatch.

03 May 2026 · 14 min read
Thinking

The top five turtles in a stack of 50

AI defense and code review get the funding, but hospitals still run XP and Ivanti falls over weekly. The security industry is ignoring 45 of its 50 turtles.

02 May 2026 · 1 min read
Thinking

Cryptographically enforced disclosure

A speculative proposal: cryptographically enforced vulnerability disclosure using a drand-triggered dead-man switch to make CVD fallback dates unbreakable.

01 May 2026 · 1 min read
Security

Peacetime cyber versus wartime cyber

Cyber defense doctrine was built during 15 years of peacetime; the transition to wartime and austerity demands a rewrite of what we accept as polite.

30 Apr 2026 · 1 min read
Three pale-blue speckled House Finch eggs nestled in a cup of dried grass on a sunroom bookshelf
Personal

"Monitoring the Situation" - The Internet of Birbs

Two pale-blue speckled eggs on the sunroom bookshelf turned into three cameras, an Unraid NAS, two AI models, and a journal that writes itself every morning. None of it had to be useful — it just had to be possible. Because joy.

29 Apr 2026 · 7 min read
Security

AI isn't the problem — asymmetry is

AI isn't the security problem — it widens the asymmetry between vulnerability discovery and remediation, putting attack capability in many more hands.

27 Apr 2026 · 1 min read