Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.
Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.
In this episode:
Casey's path from building Bugcrowd to advising, investing, and policy work
Why more practitioners need to get involved in policy, and why law is just code
The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
AI lowering the bar for a broader, less predictable pool of threat actors
Daniel Stenberg, curl, and maintainers below the security poverty line
The lightning rod vs. rockets distinction between VDPs and bug bounties
The pentest market correction underway from AI pricing pressure
Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io
Chapters:
0:00 Intro and Casey's background 2:56 Why practitioners belong in policy 6:22 The slopdemic vs. the vulnpocalypse 9:40 AI lowering the bar for threat actors 11:47 Open source, curl, and the security poverty line 15:37 VDP vs. bug bounty readiness 19:20 The pentest market correction 24:20 What breaks first in vulnerability management 27:20 Hack-back and non-cooperative defense 28:43 A near-term playbook for security leaders 31:40 CFAA, SRLDF, and disclose.io
Podden och tillhörande omslagsbild på den här sidan tillhör
Chris Hughes. Innehållet i podden är skapat av Chris Hughes och inte av,
eller tillsammans med, Poddtoppen.