RE: https://masto.free-dissociation.com/@kevinr/116722776919599573
queued for later: melanie is literally one of the best in the game
| Verified by | https://fedified.com |
| Web | https://cje.io |
| https://twitter.com/caseyjohnellis | |
| https://linkedin.com/in/caseyjohnellis | |
| Bluesky | caseyjohnellis.bsky.social |
RE: https://masto.free-dissociation.com/@kevinr/116722776919599573
queued for later: melanie is literally one of the best in the game

This week on #OpensourceSecurity I chat with @caseyjohnellis about vulnerability disclosure
This is a pretty hip topic right now, and on any list of the best in the business, Casey is at the top
I guarantee anyone who listens to this one will learn something useful
https://opensourcesecurity.io/2026/2026-05-vulnerability-disclosure-casey-ellis/

Josh talks to Casey Ellis about why vulnerability disclosure is so hard, and also so important. Casey is one of the best in this space having been a Bugcrowd founder. There are few people with more experience and insight into how a security vulnerability should be handled, and why the explosion of AI is making all this much harder than it’s ever been before. While finding vulnerabilities is easy, reporting them is still a lot of work. Casey is working on helping everyone better understand all this with his disclose.io project.
A new edition of my newsletter ~ this week in security ~ is now out, featuring: Canvas school login pages defaced; a new deepfake tech is alarmingly accurate, hackers used a screensaver file to hack SSL provider DigiCert, leaky vibe-coded apps, and a Verge reporter gets run over by a robot lawnmower — for journalism!
Read online: https://this.weekinsecurity.com/this-week-in-security-may-10-2026-edition/
Sign up/RSS and support the newsletter: https://this.weekinsecurity.com
"AI has also given people who have absolutely no idea what they're doing the ability to ascend the "Mount Stupid" section of the Dunning-Kruger curve in record time, and substantially lowered the barrier to entry for this particular behavior, which nets out to more people submitting more things. This isn't a linear problem, it's actually a compound one."
“We are going to crave more authentic in-person experiences as our online interactions are seemingly less authentic”
@thedarktangent utterly nailing it
I’ve a soft spot for researchers who revisit old problems and bugs and have another go. One of my top talks and research for this year by Yuqi Qui on DNS ECS bypasses, aka Rebirthday attack
Took a year worth of research to do. They spent a huge chunk of time perfecting their internet-wide scanning approach and working with vendors to get this resolved.
Super impressive stuff from Yuqi
NEW by me: Cloud app host Vercel says it was hacked and that some customers' data was taken.
Vercel blames an earlier breach at Context AI (*unrelated to OpenAI). Hackers allegedly used their access in March to hack a Vercel employee, who had linked a Context AI app to their work account.