2K Followers
635 Following
403 Posts
founder @Bugcrowd && co-founder @disclose_io || dad x 2, hacker, entrepreneur, executive, advisor || عصا موسى || #w00w00
Verified byhttps://fedified.com
Webhttps://cje.io
Twitterhttps://twitter.com/caseyjohnellis
LinkedInhttps://linkedin.com/in/caseyjohnellis
Blueskycaseyjohnellis.bsky.social

RE: https://masto.free-dissociation.com/@kevinr/116722776919599573

queued for later: melanie is literally one of the best in the game

Beavis and Butt-Head Become A.I. Tech Bros | Animated

YouTube

This week on #OpensourceSecurity I chat with @caseyjohnellis about vulnerability disclosure

This is a pretty hip topic right now, and on any list of the best in the business, Casey is at the top

I guarantee anyone who listens to this one will learn something useful

https://opensourcesecurity.io/2026/2026-05-vulnerability-disclosure-casey-ellis/

Vulnerability disclosure with Casey Ellis

Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight into how a security vulnerability should be handled, and why the explosion of AI is making all this much harder than it’s ever been before. While finding vulnerabilities is easy, reporting them is still a lot of work. Casey is working on helping everyone better understand all this with his disclose.io project.

Open Source Security

A new edition of my newsletter ~ this week in security ~ is now out, featuring: Canvas school login pages defaced; a new deepfake tech is alarmingly accurate, hackers used a screensaver file to hack SSL provider DigiCert, leaky vibe-coded apps, and a Verge reporter gets run over by a robot lawnmower — for journalism!

Read online: https://this.weekinsecurity.com/this-week-in-security-may-10-2026-edition/

Sign up/RSS and support the newsletter: https://this.weekinsecurity.com

this week in security — may 10 2026 edition

Instructure hacked and Canvas defaced, CopyFail bug under attack, Daemon Tools backdoored, AI vibe coding apps exposing data, U.S. states shared sensitive data with ad-tech giants, mass tech layoffs, and more.

~this week in security~

"AI has also given people who have absolutely no idea what they're doing the ability to ascend the "Mount Stupid" section of the Dunning-Kruger curve in record time, and substantially lowered the barrier to entry for this particular behavior, which nets out to more people submitting more things. This isn't a linear problem, it's actually a compound one."

https://cje.io/2026/05/04/thoughts-on-the-slopdemic/

#vulnpocalypse #slopdemic #flameswelcome

Thoughts on the #slopdemic

Move over #vulnpocalypse — there's a new term we need to talk about: the #slopdemic. AI didn't invent low-quality vuln reports, but it just turbocharged them, and F/OSS is drowning.

caseyjohnellis
happy friday

“We are going to crave more authentic in-person experiences as our online interactions are seemingly less authentic”

@thedarktangent utterly nailing it

I’ve a soft spot for researchers who revisit old problems and bugs and have another go. One of my top talks and research for this year by Yuqi Qui on DNS ECS bypasses, aka Rebirthday attack

Took a year worth of research to do. They spent a huge chunk of time perfecting their internet-wide scanning approach and working with vendors to get this resolved.

Super impressive stuff from Yuqi

NEW by me: Cloud app host Vercel says it was hacked and that some customers' data was taken.

Vercel blames an earlier breach at Context AI (*unrelated to OpenAI). Hackers allegedly used their access in March to hack a Vercel employee, who had linked a Context AI app to their work account.

https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai

App host Vercel says it was hacked and customer data stolen | TechCrunch

Vercel blamed its breach on an earlier hack at Context AI, which allowed hackers to hijack a Vercel employee's account to steal customer data.

TechCrunch