RSSAmplifier

Blog

caseyjohnellis

security | ai | technology | policy | startups

cje.ioRSS feed ↗15 posts

Latest posts

Notes from Hacker Summer Camp 2026

I've been trying to compiled a raft of notes and thoughts into a post, but I'm thinking that the ol' bullet-point dump is going to be the way to go here...

Non-Cooperative Defense and Impermissive Access

wp2shell handed the quiet policy debate about non-cooperative defense its first civilian-scale live-fire exercise.

Wake Me After the Vulnpocalypse

AI industrialized the discovery of vulnerabilities, not the exploitation of them, and that distinction is the whole argument. What we have is a slopdemic. The fragility was always there, and the real exposure is the gap between instant discovery and human-speed remediation.

My moves for Hacker Summer Camp 2026

...and away we go! Here's (roughly) what I'll be up to this week: Monday BSides Las Vegas for the I Am The Cavalry and [un]prompted Tracks. There are a tonne of great talks, including the Monday Keynote from Leonard Bailey talking through how our community

Hacker Summer Camp Tips and Tricks

As I've been thinking about Hacker Summer Camp (aka Blackhat, BSides Las Vegas, DEF CON, and all of the associated and adjacent cons and Vegas things) this year, it occurred to me that there are going to a LOT of new founders and operators roaming the desert this year.

The Amended Linus's Law

Marcus Hutchins says LLMs just killed "many eyes make all bugs shallow." He's half-right. Linus's Law was never wrong, it was incomplete: the missing variable is incentive, and AI just gave it teeth on both sides.

You get to choose your hard

Being known for what you're against is easy. Being known for what you're for is hard. You get to choose your hard.

It's con season

It's con season — Black Hat, DEF CON, and the summer security-conference circuit are nearly here. The best research of the year is about to hit the stage — and some of it will be met with a legal threat instead of a thank-you. Facing legal

Find it and fix it

A fun exercise: run various models against deliberately vulnerable apps, and eval them on their ability to identify the vulns and effectively patch them — without degrading app functionality. Finding is only half the job.

Prompt-injection bumper stickers

Prompt injection is climbing out of the chat box and into the physical world. Print an adversarial instruction big enough for a camera to read — on a t-shirt, a billboard, a bumper sticker — and any AI perceiving the world through that lens might follow it as a

Words mean things

If the AI era teaches you anything, let it be the lesson that words mean things.

Slopdemic, Not Vulnpocalypse (Yet)

I joined Sherrod DeGrippo on the Microsoft Threat Intelligence Podcast this week to talk about how AI is reshaping vulnerability research, disclosure, and patching. It was her first video episode, and it turned into one of those conversations that wanders the whole landscape: triage load, disclosure timelines, vibe crime, chaotic

My Clanker Setup

A mate messaged me this week asking whether I'd ever written up my clanker setup: which harness I run, which models, what hardware, and whether I'd gone full Hermes or full OpenClaw. I started typing a reply, watched it turn into an essay, and decided it

AI Didn't Break Vulnerability Disclosure. It Exposed What Was Already Broken.

There's a sentence I keep coming back to from a conversation Josh Bressers and I had recently on Open Source Security : we'd already gotten pretty bad at the intake side of vulnerability disclosure, and then we multiplied the discovery and fix sides by ten. That'

The Hitchhiker's Guide to Bug Bounty and Vulnerability Disclosure in 2026

Post-Mythos vulnerability disclosure: a 2026 field guide for vendors and researchers on AI-era bug bounties, slop triage, and rebuilding ecosystem norms.