Skip to content
← home

tag

#security

103 posts

The technical heart: vulnerability research, disclosure, threat analysis, the craft of finding and fixing

Security

Mythos feels a lot like Snowden

Mythos is to vulnerability awareness what Snowden was to surveillance: the moment the zeitgeist finally caught up to what insiders already knew.

26 Apr 2026 · 1 min read
Hot Takes

Security-focussed test/fix is basically “sparkling QA”

A short reaction to Firefox's claim that AI-found defects are finite: security-focused test-and-fix is basically QA wearing a fancier hat.

25 Apr 2026 · 1 min read
Security

Spicy Takes from my Aikido Security Podcast

Nine takes from my RSAC conversation with Mackenzie Jackson on Aikido's Secure Disclosure podcast — on bug bounty, AI slop, hack-back, vibe coding, and why the internet still working is a minor miracle.

24 Apr 2026 · 5 min read
Security

Offense Scales with Compute. Defense Scales with Committees.

Why AI is widening the attacker-defender gap faster than anything we've built to close it — and what that actually means for the next decade of security.

08 Apr 2026 · 11 min read
Security

Why Security Teams Gaslight Hackers: Disclosure Reality

The cybersecurity industry has a dirty secret: security teams are systematically dismissing legitimate vulnerability reports from ethical hackers. In a recent episode of Hackers

02 Apr 2026 · 2 min read
Security

Bug Bounties in the Age of AI

As AI accelerates the offense-defense asymmetry, bug bounties and vulnerability disclosure remain essential. Casey Ellis on the future of bug bounties, the evolving threat landscape, and how disclose.io and the SRLDF protect the researchers keeping us safe.

27 Mar 2026 · 4 min read
Security

The FCC Just Banned Every Foreign-Made Router

The FCC added every foreign-made consumer router to the Covered List — a March 2026 supply-chain action that goes far beyond previous adversary-nation bans.

24 Mar 2026 · 3 min read
Security

Vulnerability economics

The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.

22 Mar 2026 · 1 min read
Security

I Made AI Clones of Me and Matt Devost Argue About Exploit Stockpiling. They Agreed on a Framework.

Matt Devost and I have been circling the same set of questions for years: should governments stockpile zero-days? When does offense help defense?

02 Mar 2026 · 4 min read
Security

For the Love of the Game: DistrictCon's Year 1 Junkyard

Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes exploit chain diagrams for all eleven talks.

07 Feb 2026 · 9 min read
Security

What the Netflix ‘Zero Day’ series got right about incident response

That said, the widespread nature of the effects shown in the six-part series are definitely plausible. Industrial control systems and the infrastructure that supports them are riddled with zero-day vulnerabilities, alongside the more common "known, yet unpatched" n-day vulnerabilities.

18 May 2025 · 4 min read
Security

Bug Bounties, The Wanted Poster For Ethical Hackers — Future Secured Episode 35

Crowdsourced security empowers ethical hackers to protect digital assets, reshaping cybersecurity. Casey Ellis encourages entrepreneurs to lead with resilience, delegate wisely, prioritize health, and embrace innovation amid chaos for lasting impact and scalable success.

05 May 2025 · 4 min read