Skip to content

More posts

All →
Thinking

The Compliance Reckoning

AI makes security verification cheap, putting two decades of checkbox compliance, paper pentests, and audit theater under sudden economic pressure.

28 Mar 2026 · 4 min read
Security

Bug Bounties in the Age of AI

As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.

27 Mar 2026 · 4 min read
Security

The FCC Just Banned Every Foreign-Made Router

The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.

24 Mar 2026 · 3 min read
Policy

The White House AI Framework: What It Says, What It Doesn't, and Why the Gaps Matter More

The March 2026 White House AI policy framework analyzed: seven pillars, and why the AI security omissions matter more than what's actually in the document.

23 Mar 2026 · 7 min read
Security

Vulnerability economics

The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.

22 Mar 2026 · 1 min read
Policy

No More Free-ish Bugs

The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.

12 Feb 2026 · 1 min read
Building

Next things...

Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd.

11 Feb 2026 · 2 min read
Building

Bugcrowd 2013 to 2025 — People and Places

A photo retrospective of Bugcrowd from 2013 to 2025 — the people, offices, and moments that built the security crowdsourcing category from a Sydney garage out.

09 Feb 2026 · 4 min read
Security

For the Love of the Game: DistrictCon's Year 1 Junkyard

Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes exploit chain diagrams for all eleven talks.

07 Feb 2026 · 9 min read
Thinking

2026 security predictions

2026 cybersecurity forecast: China's PLA centenary looms, AI turns anyone into a malware developer, and economic pressure pushes more people toward cybercrime. Shift-left finally start working—but only for modern code. The rest of the internet? A triage trash fire.

26 Dec 2025 · 5 min read
Thinking

2025 security predictions retrospective

This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.

16 Dec 2025 · 6 min read
Thinking

First Principles: Bad guys are humans, they're creative and driven, and they don't quit.

Here's the bigger question: If we do finally achieve 100% success in automating cyber defense, will the "bad guys" pack their stuff up and go home?

26 Nov 2025 · 2 min read