Press
Uncle Sam Seeks Private Hackers to Disrupt Criminal Networks
The White House, in a major expansion of how it works with the private sector, has launched a program to engage private cybersecurity firms to conduct cyber
To get in touch about speaking at your event, email [email protected]
Media Packet · Press
853 items
853 items
Press
Microsoft announced it will not pursue legal action against security researchers following public criticism, according to Windows Central. Casey Ellis contributed to the discussion around responsible disclosure practices and the importance of constructive collaboration between software vendors and the security research community.
Press
Dark Reading published an article examining legal threats and industry backlash following a Microsoft zero-day vulnerability disclosure. Casey Ellis commented on the broader implications of how security researchers and coordinated disclosure practices navigate legal risks and responsible vulnerability reporting in the current threat landscape.
Press
A LinkedIn post from Casey Ellis examines emerging trends in vulnerability reporting and security disclosure practices. Ellis proposes new terminology to describe the proliferation of low-quality vulnerability reports and discusses patterns he has observed throughout his career in the field.
Press
Dice Insights published a 2026 guide on what cybersecurity hiring managers seek in candidates, drawing on interviews with CISOs and security leaders. Casey Ellis contributes insights on the skills, certifications, and professional qualities that help cybersecurity professionals stand out in the current job market.
Press
The Rip Current published an article examining governance and oversight of advanced AI capabilities and their potential economic impact. Casey Ellis contributes perspective on decision-making processes around transformative AI systems and the balance between industry self-regulation and institutional oversight.
Press
CyberScoop published an article examining how cybersecurity leaders interpret findings from the Claude Mythos AI cybersecurity threat report. Casey Ellis contributed perspective on how defenders assess the tool's potential hacking capabilities and implications for security strategy.
Press
An AOL article examines how artificial intelligence capabilities could shift the balance toward attackers in cybersecurity. Casey Ellis, co-founder of Bugcrowd, discusses the potential security risks and timeline for when advanced AI tools might become broadly accessible to malicious actors.
Press
NBC News published an article titled "Vulnpocalypse: What happens when AI gives hackers a superweapon" examining concerns about advanced AI models and cybersecurity risks. Casey Ellis is featured discussing the implications of AI capabilities for vulnerability research and the security landscape.
Press
CSO Online published an article on preparing security operations centers for agentic AI. Ellis discusses governance frameworks, playbook updates, and organizational readiness measures that security leaders should implement as AI systems take on greater autonomy in SOC environments.
Press
SafetyDetectives published an article examining overlooked cybersecurity threats and defense strategies. Casey Ellis contributed expert perspective on risks that receive less attention than major threats like ransomware and nation-state attacks.
Press
tl;dr sec published an issue on February 19, 2026 covering Claude Code power user techniques, threat actor tracking on GitHub, and open source AI-powered pentesting tools. The newsletter mentioned Casey Ellis stepping away from Bugcrowd, where he had served as co-founder and chief executive.
Press
SecurityWeek's Cyber Insights 2026 report examines cyberwar trends and escalating nation-state threats in the coming year. Casey Ellis provides analysis on the geopolitical dimensions of cyber operations and their impact on critical infrastructure security and private sector defense strategies.
Press
Dark Reading published an article on Chinese electric buses triggering an Australian government review. Casey Ellis is quoted discussing cybersecurity risks associated with the vehicles and their potential vulnerabilities to foreign interference.
Press
Security Boulevard published an article examining the recruitment of teenagers into hacking groups and efforts to counter this trend. Casey Ellis discusses the challenge of redirecting young people's skills toward ethical hacking and cybersecurity careers rather than malicious activities.
Press
Casey Ellis published a 2026 cybersecurity predictions article on his site examining anticipated threats including China's military milestones, AI-enabled malware development, and economic drivers of cybercrime. The piece forecasts that shift-left security approaches will gain traction for modern code while legacy systems face mounting vulnerability challenges.
Press
An article from Firstpost examines misinformation circulating on social media about the Bondi Beach attack and the importance of critical evaluation of online claims. Casey Ellis is quoted discussing how to assess information reliability and avoid spreading unverified narratives during crisis events.
Press
A Bugcrowd Blog post published December 17, 2025, features predictions from Bugcrowd executives and security researchers about cybersecurity trends in 2026. Casey Ellis contributes his outlook on evolving attack methods, AI innovation, and emerging security challenges for the year ahead.
Press
The Sydney Morning Herald published an article examining misinformation spread on social media following the Bondi shooting incident. Casey Ellis is quoted discussing how AI systems and social platforms can amplify false narratives, including fabricated hero accounts, during crisis events.
Press
Security Boulevard reported on December 11, 2025, that attackers worldwide including nation-state groups and cybercriminals are exploiting the React2Shell vulnerability across multiple attack vectors. Casey Ellis contributed analysis on the severity and exploitation patterns of the flaw and the range of threat actors leveraging it.
Press
Dice Insights published an article examining how skilled technology and cybersecurity professionals are increasingly turning to dark web forums for work opportunities that blur legitimate and illicit boundaries. Casey Ellis cautions that participation in such underground hiring carries significant risks for both employers and individual practitioners engaging in these activities.
Press
Hackread published a December 2025 report on North Korean hackers deploying EtherRAT malware through React2Shell exploits. The article documents the technical details and threat actors behind the campaign without attribution to Casey Ellis.
Press
ReversingLabs published a blog post examining five ways artificial intelligence will transform security operations centers. Casey Ellis contributes perspectives on how AI can reduce alert fatigue and automate repetitive manual workflows in SOC environments.
Press
An SC Media article examines Oracle EBS exploitation tactics that parallel those used in the Clop ransomware group's MOVEit and GoAnywhere attacks. Casey Ellis discusses how these supply chain vulnerabilities represent a persistent threat pattern and the importance of rapid patching and vulnerability disclosure practices.
Press
Dark Reading published "With Friends Like These: China Spies on Russian IT Orgs," covering espionage activity targeting Russian IT organizations. Casey Ellis is quoted in the article providing analysis on the geopolitical implications and technical indicators of the surveillance campaign.
Press
An opinion piece published on Yahoo News examines teenage hackers who compromised an educational technology company serving thousands of U.S. school districts. Casey Ellis argues that channeling young hackers' skills toward legitimate security work and community protection is more productive than punishment alone.
Press
The 74 Million published an opinion piece arguing that teenagers with hacking skills should receive training and compensation to defend systems against cyber attacks. Casey Ellis contends that structured programs can redirect adolescent technical talent toward protecting communities rather than targeting them.