AI, Bug Bounties & the Vulnerability "Slopdemic"
Échec de l'ajout au panier.
Échec de l'ajout à la liste d'envies.
Échec de la suppression de la liste d’envies.
Échec du suivi du balado
Ne plus suivre le balado a échoué
-
Narrateur(s):
-
Auteur(s):
Bugcrowd founder Casey Ellis joins me to dig into what AI is actually doing to bug bounties, vulnerability discovery, and open source security. We get into his "slopdemic" framing, the curl bug bounty saga, VDP readiness, the pentest market correction, and where security research policy heads next.
Casey Ellis is the founder of Bugcrowd, co-founder of disclose.io, and a board member of the Security Research Legal Defense Fund. These days he advises and invests through Tall Poppy Group and works at the intersection of security, AI, and policy. His argument is that the vulnpocalypse was already here, and AI has made the cost of both finding and reporting vulnerabilities collapse at the same time.
In this episode:
- Casey's path from building Bugcrowd to advising, investing, and policy work
- Why more practitioners need to get involved in policy, and why law is just code
- The slopdemic vs. the vulnpocalypse, and what actually changed in submissions
- AI lowering the bar for a broader, less predictable pool of threat actors
- Daniel Stenberg, curl, and maintainers below the security poverty line
- The lightning rod vs. rockets distinction between VDPs and bug bounties
- The pentest market correction underway from AI pricing pressure
- Collapsing OODA loops, hack-back, CFAA reform, SRLDF, and disclose.io
Chapters:
0:00 Intro and Casey's background
2:56 Why practitioners belong in policy
6:22 The slopdemic vs. the vulnpocalypse
9:40 AI lowering the bar for threat actors
11:47 Open source, curl, and the security poverty line
15:37 VDP vs. bug bounty readiness
19:20 The pentest market correction
24:20 What breaks first in vulnerability management
27:20 Hack-back and non-cooperative defense
28:43 A near-term playbook for security leaders
31:40 CFAA, SRLDF, and disclose.io
Connect with Casey:
LinkedIn: https://www.linkedin.com/in/caseyjohnellis
Blog: https://cje.io
disclose.io: https://disclose.io
Bugcrowd: https://www.bugcrowd.com
Resilient Cyber: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.