tag
#learn
Processing experience into insight - retrospectives, lessons
Hacker Summer Camp Tips and Tricks
As I've been thinking about Hacker Summer Camp (aka Blackhat, BSides Las Vegas, DEF CON, and all of the associated and adjacent cons and Vegas things) this year, it occurred to me that there are going to a LOT of new founders and operators roaming the desert this year.
AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.
There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&
Auditing My 2026 Security Predictions: Five Months In
Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's
Thoughts on the #slopdemic
Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.
Offense Scales with Compute. Defense Scales with Committees.
Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.
Why Security Teams Gaslight Hackers: Disclosure Reality
The cybersecurity industry has a dirty secret: security teams are systematically dismissing legitimate vulnerability reports from ethical hackers. In a recent episode of Hackers
Bug Bounties in the Age of AI
As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.
The White House AI Framework: What It Says, What It Doesn't, and Why the Gaps Matter More
The March 2026 White House AI policy framework analyzed: seven pillars, and why the AI security omissions matter more than what's actually in the document.
No More Free-ish Bugs
The line between bug bounty programs and vulnerability disclosure programs has blurred — and why pretending Red Bull and t-shirts count as a bounty hurts everyone.
2026 security predictions
2026 cybersecurity forecast: China's PLA centenary looms, AI turns anyone into a malware developer, and economic pressure pushes more people toward cybercrime. Shift-left finally start working—but only for modern code. The rest of the internet? A triage trash fire.
2025 security predictions retrospective
This time of year, everywhere you see, security guys like me are sharing our hot takes for the year ahead. However, reflecting on the past year is equally important. I like to see how my previous predictions held up and how things actually played out.
First Principles: Bad guys are humans, they're creative and driven, and they don't quit.
Here's the bigger question: If we do finally achieve 100% success in automating cyber defense, will the "bad guys" pack their stuff up and go home?