Skip to content

More posts

All →
Security

I Made AI Clones of Me and Matt Devost Argue About Exploit Stockpiling. They Agreed on a Framework.

Matt Devost and I have been circling the same set of questions for years: should governments stockpile zero-days? When does offense help defense? Where does

02 Mar 2026 · 4 min read
Policy

No More Free-ish Bugs

The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.

12 Feb 2026 · 1 min read
Building

Next things...

Last Saturday Jan 31 was my last day "inside the tent" at Bugcrowd.

11 Feb 2026 · 2 min read
Building

Bugcrowd 2013 to 2025 — People and Places

A photo retrospective of Bugcrowd from 2013 to 2025 — the people, offices, and moments that built the security crowdsourcing category from a Sydney garage out.

09 Feb 2026 · 4 min read
Security

For the Love of the Game: DistrictCon's Year 1 Junkyard

Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes exploit chain diagrams for all eleven talks.

07 Feb 2026 · 9 min read
Thinking

2026 security predictions

2026 cybersecurity forecast: China's PLA centenary looms, AI turns anyone into a malware developer, and economic pressure pushes more people toward cybercrime. Shift-left finally start working—but only for modern code. The rest of the internet? A triage trash fire.

26 Dec 2025 · 5 min read
Thinking

2025 security predictions retrospective

This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.

16 Dec 2025 · 6 min read
Thinking

First Principles: Bad guys are humans, they're creative and driven, and they don't quit.

Here's the bigger question: If we do finally achieve 100% success in automating cyber defense, will the "bad guys" pack their stuff up and go home?

26 Nov 2025 · 2 min read
Personal

Hacker Summer Camp 2025 — People, Places, and Things

A little photo diary of Hacker Summer Camp 2025.

15 Aug 2025 · 3 min read
Thinking

Founders Helping Founders: When Known Vulnerabilities are Life or Death

On today’s episode, Jon Sakoda speaks with Casey on the early economics of paying people to hack companies, criminal creativity, and why founders need to fix their known vulnerabilities.

13 Aug 2025 · 2 min read
Thinking

Peace-time Cyber vs War-time Cyber

A long read on how cybersecurity doctrine built during 15 years of geopolitical peacetime is failing as nation-state actors abandon restraint and discretion.

02 Jul 2025 · 5 min read
Building

What You Give Away Might Be Worth More Than What You Keep

The sticking point is the word "free". If you do happen to get stuck there (and a lot of things will push you in that direction), a lot of the magic in the decision math gets missed. Everything has a Give and a Get and, if you're doing it right, nothing is ever given away for free.

27 May 2025 · 1 min read