tag
#security
The technical heart: vulnerability research, disclosure, threat analysis, the craft of finding and fixing
Wake Me After the Vulnpocalypse
AI industrialized the discovery of vulnerabilities, not the exploitation of them, and that distinction is the whole argument. What we have is a slopdemic. The fragility was always there, and the real exposure is the gap between instant discovery and human-speed remediation.
The Amended Linus's Law
Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.
Slopdemic, Not Vulnpocalypse (Yet)
I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching.
AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.
There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security: we&
The Hitchhiker's Guide to Vulnerability Disclosure in 2026
Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.
Auditing My 2026 Security Predictions: Five Months In
Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's
Thoughts on the #slopdemic
Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.
The "irrational asymmetry" in threat behavior
We've traditionally thought about defense through the lens of a financially motivated attacker or a nation state — predictable rewards. Open it to
The top five turtles in a stack of 50
AI defense and code review get the funding, but hospitals still run XP and Ivanti falls over weekly. The security industry is ignoring 45 of its 50 turtles.
Cryptographically enforced disclosure
A speculative proposal: cryptographically enforced vulnerability disclosure using a drand-triggered dead-man switch to make CVD fallback dates unbreakable.
Peacetime cyber versus wartime cyber
Cyber defense doctrine was built during 15 years of peacetime; the transition to wartime and austerity demands a rewrite of what we accept as polite.
AI isn't the problem — asymmetry is
AI isn't the security problem — it widens the asymmetry between vulnerability discovery and remediation, putting attack capability in many more hands.