w/ Casey Ellis, Founder, Bugcrowd
Casey Ellis, founder of Bugcrowd, joins the show to talk about the evolution of bug bounty, how hackers went from outsiders to strategic assets, and why AI-generated bug reports are putting pressure on security teams. We also get into VDPs vs public bounties, pentesting, vulnerability economics, and where security research is headed over the next five years. Chapters 00:00:00 From hacker roots to Bugcrowd 00:03:03 Why Casey Ellis started Bugcrowd 00:06:30 How bug bounty became mainstream security 00:07:20 AI slop and the bug bounty triage problem 00:10:20 VDP vs paid bug bounty: when to use each 00:16:28 Can AI help fix vulnerability triage? 00:23:04 Will AI replace pentesting and hackers? 00:26:31 The future of bug bounty and security research 00:30:22 Would you rather game
Tell us who, why, and how to reach them. We read every submission.