Black Hat 2026: Why Threat Researchers Are Hoarding Zero-Days | Casey Ellis, Bugcrowd

View Show Notes and Transcript

Is the AI "vulnpocalypse" already here? According to Casey Ellis, Founder of Bugcrowd and pioneer of Disclose.io, we aren't quite in an apocalypse yet, we're actually in a "slopdemic." The cost of discovering vulnerabilities has plummeted, flooding bug bounty and SOC triage queues with low-quality, noisy submissions. Because these queues are so overwhelmed, many highly skilled researchers are simply hoarding zero-days because reporting them has become too difficult.

In this episode, Ashish sits down with Casey to unpack the major themes and mindset shifts from RSA and Black Hat 2026. Casey breaks down how AI is shrinking the OODA loop for defenders, forcing the industry to adopt a true "assume breach" mentality and reconsider deception technology to frustrate active adversaries. They also explore the risks of non-technical employees "vibe coding" corporate applications and why CISOs must get hands-on with AI tools at home if they want to understand the risks their workforce is taking.  

Questions asked:
00:00 Introduction to Offensive AI and Black Hat 2026
02:00 Casey Ellis’s Background (Bugcrowd, Disclose.io)
04:00 Major Themes from RSA and Black Hat 2026
09:00 The Impact of Mythos and Daybreak on Security Awareness
12:30 Why Threat Researchers Are Hoarding Zero-Days
14:00 The "Slopdemic" vs. The "Vulnpocalypse"
17:30 Managing Noisy Bug Bounty Queues and Risk Models
20:00 The Futility of Export Controls on Frontier Models
25:00 Point-and-Pwn vs. Building Complex Attack Graphs
29:30 The Defender’s Dilemma and the Shrinking OODA Loop
34:00 Shadow AI and the Risks of Non-Technical "Vibe Coding"
38:30 Why CISOs Need Hands-On Experience with AI Tools
45:30 The Resurgence of Deception Technology

Ashish Rajan: [00:00:00] I'm there.

Casey Ellis: Yep. All right.

Ashish Rajan: Hello, welcome to another episode of Ask Katie podcast. I've got Casey with me, a long-term friend. Man, thanks so much for coming in and filling in for Caleb.

Casey Ellis: Thanks for having me, man.

Ashish Rajan: I mean, maybe just for the audience who may not have been familiar with your work in the past, if you can share a bit about yourself, your professional background as well, man.

Casey Ellis: Yeah, sure. Uh, geez. Um, I was born at a young age, is generally how I start that one. Uh, now look, I've, I've been in security really since, since high school, sort of old school hacking days, um, transitioned across into the practitioner side pretty much straight away, um, and then worked on the tools for, for a chunk of time before I cut, cut across into the solutions architecture and kind of more businessy end of things.

Casey Ellis: Um, then I got it in my head I wanted to be an entrepreneur, so, so kind of broke bad at that point. Um, and, you know, long story short, that, that led to me starting a company called Bugcrowd back in, uh, 2012 was when we kind of kicked off working on that. Yeah, Bugcrowd didn't invent vulnerability disclosure or bug bounty programs, but we did sort of [00:01:00] pioneer this idea of putting a platform in between the research community and all the people that kind of need their help.

Casey Ellis: So that escalated. Um- ... and, you know, Yeah ... in the, in the middle of all of that, uh, got pretty involved in, in policy as well. So the other, the other thing that I, I work on a ton these days is a thing called the disclose.io project, and that's really about, you know, normalizing, uh, security reporting, um, safe harbor on the legal side, and then the infrastructure to actually support it across the internet.

Casey Ellis: 'Cause as we, uh, as we turn everything up to 11, there's a, there's definitely a growing need to do that. So that's the, that's the short version.

Ashish Rajan: Fair. And I mean, and, um, not, not that it was... The accent doesn't give it away, but you're definitely Australian. But it just happened to be the Americanism hasn't got caught up to you yet.

Casey Ellis: It's, it's definitely rounded off. It's funny 'cause when I, when I spend time in Australia, and if I do something like this, I'll listen back to myself and I'm like, "Oh, there it is." You can kind of hear the- ... the twang sort of build back up. So it's, it's curved off over the years talking to Americans. Um, I actually [00:02:00] live in the Bay Area, uh- Yeah

Casey Ellis: but still have, you know, deep roots back home as well.

Ashish Rajan: Yeah. Fair. Uh, and maybe, uh, ta-talking about deep roots as well, one of the things that has been core to our cybersecurity ecosystem has been the Black Hat conference and RSA Conference. Obviously- Yes ... we're, we're all attending those conferences to get to know what the, the top of mind things for CISOs and practitioners are.

Ashish Rajan: Uh, but I'm curious because I think you and I have both seen RSA and Black Hat. Was there an obvious theme in terms of whether it was related to the AI mi- Uh, well, I, I was, I already said AI. I should not have started with AI, but I already said AI. So- Great ... let's just say, what were the themes that came across, uh, that RSA and Black Hat that stood out for you, obviously seeing both the, both the conferences?

Casey Ellis: Yeah. Look, I, I mean, the theme, the theme through both was definitely, you know, AI kind of as a standalone thing that we're all trying to wrap our heads around. I, I think this year, and it, it actually applies in a lot of ways to BSides Las [00:03:00] Vegas, um, DEF CON, and some of the more call it skeptical and, and like practitioner heavy cons as well, we've kind of all reached a point where it's like, "Yeah, this is a real thing."

Casey Ellis: Um- Yeah. 'Cause I do, I do feel like the, um, the security industry just in general, I mean, we've got an, uh, you know, a natural allergy to hype and, and the hype cycle around AI I think turned a lot of people off. Um, I do think that hype cycle was real and there was a lot of stuff about it that was kind of annoying, but at the same time it's like, no, this is a real, this is a real thing that's gonna eventually touch and change everything.

Casey Ellis: So I feel like this year between RSA and BlackHat, like everyone's basically on that same page. Um, you know, I think there's definitely a difference between how, how vendors are talking about things, um, and how the, how the practitioners are talking about things. Um, you know, CISOs all the, all the way down and even like policy folk all the way down, you know, the vendor halls like, "Here's this new solution that solves absolutely everything 'cause we've got AI to do that now."

Casey Ellis: [00:04:00] And like the reality of that on the coal face is maybe not quite as, um rose-colored as it, as it might get presented, not to put too fine a point on it. And there are- Yeah ... vendors that are actually trying to do this really well, too. So, like massive shout out- Yeah ... to those folk. But I think just as a general observation, there's a lot of, um, there's a lot of sort of shouting over the top of each other about how, you know, agentic your thing is and, and that's kind of the main selling point at this point, which- Yeah

Casey Ellis: to me kind of misses the mark, but it's definitely a common theme.

Ashish Rajan: Um- Yeah. I think that I, I

Casey Ellis: agree- One, one thing I would say really... Sorry, go ahead.

Ashish Rajan: No, no, no. Yeah, I'll let you finish the thought. Sorry.

Casey Ellis: Yeah, last, last thing is, like, I do think, um, you know, the, the big thing that, about BlackHat this year, um, just was the way, I mean, like, literally the entire Mandalay was, was booked out.

Casey Ellis: Uh, and I think it's, you know, it's the first year I've seen them actually do that. So, so the, the whole kind of opportunity for, for hallway con and [00:05:00] community and, and the, and the kind of stuff that a lot of us actually attend BlackHat for, you know, alongside the talks and the booths and all that kind of stuff, there really wasn't a lot of opportunity for that in the venue.

Casey Ellis: So I feel like sort of BlackHat's trying to be more like RSA in terms of commercializing the conference itself, and maybe they jumped the shark a little bit on that side. Yeah. I heard, I heard that from a lot of other people as well, but that was, that was definitely a difference between the two.

Ashish Rajan: I think a worthwhile calling out to what you said.

Ashish Rajan: I think, uh, the events that I hosted for the book launch that I had was all- Yeah ... either in Venetian, Cosmopolitan, definitely not in the Mandalay Hotel, which is- Right ... I mean, just the venue technically, but everyone had, was traveling between hotels just to, uh, for, for to what you said, uh, 'cause everything was booked out for- Yeah

Ashish Rajan: whatever event. So you almost were running out of places to have hallway conversations, and everyone just talking, or at least there's like a mob of people walking i- together. Yeah. Um, I, I was going to say the something that I thought was interesting and in terms of conversations that I had, was from a RSA perspective, I noticed that there's a, there was this...

Ashish Rajan: If[00:06:00]

Ashish Rajan: you were, if I were to step like a 10,000 feet view of RSA, the conversations that were there, there was a lot of focus on visibility, shadow AI.

Casey Ellis: Hmm.

Ashish Rajan: Uh, AI agents were kind of sprinkling, but there was sprinkles of, "Hey, we can do SOC automation in terms of product ecosystem." In terms of CISOs and practitioners, I felt they were still trying to get their head around, and if anyone who had not given Uh, even a remote serious thought to AI and how that would, what that would mean, uh, they had, were still on that cusp of, "Oh shit, I need to kind of at least get a handle of this because people are moving forward."

Casey Ellis: Yeah.

Ashish Rajan: And fast-forward to BlackHat, which technically is, like, less than six months, I guess, between RSA, I found that many people had focused on the whole coding agent pieces. Right. Yeah. Uh, then they had conversations around the... They were a lot more mature in terms of, "Hey, we need to have an agent policy."

Casey Ellis: Yeah.

Ashish Rajan: Agent, uh, the AI governance conversations were a lot more mature. People were talking a lot more about how can I automate my SOC, [00:07:00] my GRC. And bug bounty, which is kinda, I know your wheelhouse, like you, you've kind of clearly have spent a lot of time in there as well. Sure. There's a lot more conversation around how, and maybe because of the Mythos effect in between as well.

Ashish Rajan: Yeah. There's a lot more conversation around, oh, what does it mean for runtime? What does it mean for how hackers would misuse the technology, even if it's open source? It, did anything that... I, I mean, I, obviously this is what I noticed, but I'm just curious if any of those, uh-

Casey Ellis: That's a, that's a heck of a laundry list I can kind of agree with, with basically all of that.

Casey Ellis: Um, yeah. Look, I, I think, um, it was funny 'cause I wrote, I wrote a blog post just before RSA, um, talking about, you know, where I kind of predicted Uh, agentic AI, you know, like the intersection between that and, and offensive security. Um, whether it's, you know, the good version of it or the, or the attacker version of it, kind of where all of that's gonna go.

Casey Ellis: And just calling out really [00:08:00] based on, you know, my experience of like hacking the internet at scale for the last 15 years, it's like we're actually still in a pretty bad spot when it, when it comes to- Mm ... you know, vulnerabilities and opportunities, and that's not necessarily a, a concept that's well, well understood, or where it's understood, it's not necessarily talked about or accepted.

Casey Ellis: And then literally two weeks later, Mythos drops. Um, and I think that was, that was really useful as a... Like to me, that was almost like a, you know, a Snowden moment in terms of like everyone suddenly thinking about this cybersecurity thing all at once. Um- Yeah ... I think, you know, Mythos and Daybreak kind of did that, you know, right across the board in terms of AI's ability to, to, you know, speed up finding things.

Casey Ellis: But to me, like the underlying thing is like, no, there's a lot to find. We're actually still pretty bad- Yeah ... at a lot of this stuff. And, and if attackers are sufficiently resourced and motivated, they'll, they'll, you know, nature finds a way in a, in a lot of ways. Yeah. So I think that was a, that was a way more, um, it was kind of [00:09:00] more of a given, I guess, at BlackHat.

Casey Ellis: Like I f- I felt like that conversation at RSA, I had to do some, I had to put some sort of evangelistic weight behind it. Um- Oh, right, right, right ... I didn't, I didn't, I didn't really need to do that at BlackHat.

Ashish Rajan: Was there something that, in terms of all the conversations you had with the bug bounty folks and others in- Hmm

Ashish Rajan: the offensive security side, do you f- was there... I, I guess where I'm going with this is that I'm curious in terms of the usage of AI in that ecosystem as well.

Casey Ellis: Sure.

Ashish Rajan: That's usually the people who are in a way driving the automated pen testing, the- Yeah ... runtime assessment, like all the, insert the, to your point, the laundry list of things that can happen on the right-hand side of the SDLC.

Ashish Rajan: Um, was there any theme that stood out there in terms of their maturity or what you saw in terms of, uh, how the- Yeah,

Casey Ellis: no. Y- yeah. Um, and, and probably, you know, the way I'd phrase that is that like I've been... It's, like bug bounty to me is sort of one expression of this, that people have gotten used to kind of typecasting into like web [00:10:00] vulnerabilities, uh, that you can see from the outside.

Casey Ellis: Um- Yeah ... my angle on, on offensive security is it's the entire spectrum. It's not just that. So when I'm talking- Yeah, of course. Yeah, yeah ... to people about the role that AI plays, it's, it's across that entire spectrum, not just the web part. Um-

Ashish Rajan: Yeah ...

Casey Ellis: but you know, what, what I'd say is that like it's, it's a pretty broad, it's a pretty broad spectrum of Of, I guess, responses to it.

Casey Ellis: Like, everyone's using AI in some way to, to improve. You know, AI as a tool, like it's reducing the time to effectiveness. Like, everyone's pretty much on that boat at this point. And for the better part, that's been true, I'd say, for two or three years now. Um-

Ashish Rajan: Yeah ...

Casey Ellis: it's just now that you can kind of talk about it and people don't think you're trying to, you know, shill OpenAI or Anthropic in the process.

Casey Ellis: It's like, "Oh, that's actually a real thing." Um, so there's definitely that. Um, I do think that there's a, you know, there's a lot of uncertainty. Like, I heard a lot of folk talking about, um, you know, if my special [00:11:00] thing's all of a sudden getting commoditized by technology, then what does that mean for me in the future from a career standpoint?

Casey Ellis: All that kind of stuff. There's a lot of that. In, in, in the same way that I think there is in a lot of different industries right now, but that was sort of like a bit of a light bulb moment for, for parts of the community that, that are concerned about that. Um, and yeah, probably the last thing I'd say there, and this is, this is, uh, like a big takeaway, is that a lot of people are just sitting on zero-day now.

Casey Ellis: 'Cause, 'cause the, you know, the, the thing is that like triage queues right across the board, not just vulnerability intake from the outside world, but like the SOC queues, the... Like, everything's just gotten dialed up from a noise standpoint over the past, you know, 12 to 18 months at, at the very least.

Ashish Rajan: Right.

Casey Ellis: Um, and that's causing lag. So if you're, if you're on the outside trying to help, you know, be it in context of a bug bounty program through like a HackerOne, a Bugcrowd, whoever, doing it directly, or you're just trying to report a vulnerability to get it fixed- Yeah ... [00:12:00] that's actually pretty hard to do right now.

Casey Ellis: So, um- Wow ... a lot of folk are just basically not hoarding zero-day for like, you know, they're, they're not like thinking about breaking bad or doing whatever. It's just too hard, so they're just sort of sitting on it.

Ashish Rajan: So do you find that the vo- it's an interesting thing, right? Because it-

Casey Ellis: Yeah, it is ...

Ashish Rajan: a lot of

Casey Ellis: that,

Ashish Rajan: uh, 'cause is the volume AI slop?

Ashish Rajan: 'Cause obviously- No ... you can, I'll, I'll put some color to this as well, because you know how- Mm-hmm ... you and I have seen this world where the whole ecosystem of, "Hey, I have a disclosure program," came in also from the fact that I'm sure, as I say this, most people relate to this, we get emails saying, "Hey, I have a zero day I've identified.

Ashish Rajan: I have a whatever. Pay me $5,000, $10,000," or whatever. Yeah. Big,

Casey Ellis: big bounty and extortion, all that kind of stuff. Yeah.

Ashish Rajan: Yeah. Yeah. So is this like a volume of that has increased, or is it legit, or it's just disappearing-

Casey Ellis: This is the problem ... maybe because there's so many- It's actually, it's actually both. It's actually both.

Casey Ellis: So, so what's, what's happened is the cost of discovery, uh, or like the cost of getting to a point [00:13:00] of discovery and a, a point of weaponization to where you can create impact has gone down. Yeah. Especially for competent operators, but like right across the board as well for the more trivial types of vulnerabilities.

Casey Ellis: Um, so there's that. Then, like, the, the you must be this tall to ride bar has gone down, so there's- Mm ... more people jumping in and actually doing that. And at the same time, the cost of actually writing a submission and sending it has gone down as well. So you've got, like, this increase in noise, this increase in opportunism.

Casey Ellis: Um, I think a lot of it actually is people that aren't necessarily trying to be extortionate or anything like that. They're just like a 3 out of 10 for usefulness and like an 11 out of 10 for enthusiasm, and they've got new toys, right? And that's always been a thing. Like, we've seen that, you know, versions of that the entire lifespan of, of, of Bugcrowd.

Casey Ellis: That's not... That's what the community just does community things, and you gotta figure out what to do with that. Um- Yeah ... but the problem is if that noise level gets up too high, you end up in [00:14:00] a position where you're spending so much time dealing with it that you miss the stuff that actually matters in the process, and the volume of that is going up at the same time.

Ashish Rajan: Yeah. Yeah. I think 'cause, uh, I was on a, I was on a call with a CISO and I think I re- I remember telling him, uh, kind of similar vein around volume of, uh, notifications coming in has increased, but I think, uh, they were almost at the point where if, if the email had something to do with remotely, "I have found something," without any evidence, it's ignored instantly.

Ashish Rajan: Yeah. Even though it may be a genuine one, 'cause obviously, understandably so, you don't put all the information in the first email for clear- clearly, but then they said the volume was so high that they were choosing to just ignore the ones that were coming with not much evidence, just say, "Hey, pay me money," or even the fact that I have found something legit, and it's usually people who are finding success from, I reach out to, say, Casey, who's working for a company, and-

Casey Ellis: Yeah

Ashish Rajan: I reach out to them personally and go, "Hey, I, I think I've found something here with probably you guys should fix kind of." Is, is that... H- Have you found a better way? [00:15:00] Uh, 'cause obv- that obviously is an extreme scenario.

Casey Ellis: Yeah, just turn everything off and go back to the abacus, I think is probably

Ashish Rajan: the solution.

Ashish Rajan: I feel like just turn it off and hopefully I'll just reach out to the right person, yeah.

Casey Ellis: Uh, look, yeah, in, in terms, in terms of better ways, um- There is, there is definitely, there is definitely an element like of researcher education around this, like helping people, you know, get more efficient, I guess, at, at, at delivering their point when they're trying to- Yeah

Casey Ellis: to submit a vulnerability report. Um, again, that's something that, you know, we've always tried to do, that I've always tried to do in, in a, in a Bugcrowd context 'cause that's always been a need, but now that need's kind of on, on, you know, a lot of Adderall, um, and moving at a million miles an hour. So, so like there's definitely an increased need for that on the, on the community side just in general.

Casey Ellis: I, I think, um, downstream, you know, when, when I'm talking to, to companies about how to think about this, [00:16:00] like you've, you've got to make sure... To me, the biggest thing is making sure that your policies and, and kind of your expectation setting to the outside world is really clear. Um- Mm. 'Cause, uh, you know, if you do that, then you can end up in a position where if there's a disagreement at some point, you can just point to the thing that you've already said, and oftentimes that helps to, to deescalate.

Casey Ellis: Um, and there's a lot of need for that right now. Um, the other is just understanding what your risk model is. You know, like, uh, like the big thing, this is probably the other big observation from, from RSAN BlackHat, is this whole concept of like vulnerability management sort of being, you know, a bit of a fool's errand if your goal is to make sure that everything's fixed.

Casey Ellis: It's like we're not gonna get around to all of it. There's too much. Like we've got to actually think about, you know, what, what our threat model is, what are we trying to prevent, like what kind of attackers are we expecting, like what's their level of like economically rational motivation to do the thing?

Casey Ellis: How do we sort of reverse out the things that are most [00:17:00]important and make sure that we're not missing that stuff if it comes in on the queue, and then kind of work, work backwards from that instead of trying to eat the whole elephant and figure out which part was best.

Ashish Rajan: Yeah. And I, I think too, uh, there's a few things to, to what you said as well, right?

Ashish Rajan: Do pe- did you find people even understand how to measure risk that AI is bringing? 'Cause I know the... And I don't know if you noticed this thing in the work you've been doing or at least the conversation you've been having across America, but I definitely found that between the con- conversation that I have in America versus Europe and UK, Europe and UK have kind of doubled down on the whole Mythos readiness assessment.

Casey Ellis: Right.

Ashish Rajan: And the big four companies keep selling them the idea, they pay, pay six figures just to get that assessment, and you're like, "Eh, I don't think you need this." But it's like, um- Mm ... and I guess goes back to the maturity of these things as well. Was there a more, more of a Uh, a mindset of that, um, hey, Mythos is actually bad, or was it Mythos is actually good for the [00:18:00]industry?

Ashish Rajan: 'Cause I, I'm curious also because to your point, there's the community perspective- Mm ... and then there is the reality of if this hits all the vulnerabilities we spoke about earlier, which we could never patch before AI, but now we are with Mythos. Uh, what was

Casey Ellis: your sentiment around that? Yeah, and, and now more people are capable of doing that potentially, so we can't necessarily predict intent in the same way.

Ashish Rajan: Yeah. Yeah. Um,

Casey Ellis: I think- In general, the US is a little ways behind on that, frankly. Like a, a l- a lot of the thinking on that stuff is very reactive. Like even, even talking about it as a Mythos problem, to me, kind of misses the point a little bit because like I'd, I've seen... Literally, I've seen people do this type of stuff with, with open weight models and with- Yeah

Casey Ellis: with unrestrained, um, frontier models for the last three and a half to four years. Like this is not a new, it's not a new thing. Yeah. It's just that everyone's talking about it all at the same time now. Yeah. Um, so there's that. Like it's not sort of... Like this [00:19:00] didn't suddenly happen. We just all suddenly started talking about it, and I don't think that necessarily registers with, with folk.

Casey Ellis: Um, but I also think that, um, you know, I was in DC actually at the White House like the w- the week that the, the export control stuff happened. Um- Oh,

Ashish Rajan: yeah. Yeah ...

Casey Ellis: and you know, like without going too far off piste, um, I do think a part of that reaction was a whole bunch of policymakers suddenly realizing that this is possible in the first place.

Ashish Rajan: Yeah. Yeah.

Casey Ellis: If that makes sense. Um- Yeah ... and, and in reality, a lot of people have been trying to say that and, and kind of get them onto that page for a while, but this was kind of their moment where they're like, "Oh, it's real." So, so there's this sort of reaction that happens to that. Um, and that's been I think that's driven a lot of, um, a lot of thinking around how this is gonna get solved in ways that I actually don't think are necessarily correct, if that makes sense.

Casey Ellis: You're not gonna export control your way to, to, to a safer [00:20:00] security. It's one... safer security state, you know, internet wide. Um-

Ashish Rajan: Yeah ...

Casey Ellis: you know, at the same time as I think kind of unleashing this stuff wholesale across the internet's gonna cause some pretty serious bumps in the night. Um, that's gonna happen anyway 'cause the frontier stuff's trailing, you know, three to six months behind, and- Yeah

Casey Ellis: everyone's getting their hands on that nowadays. Yeah. So it's, it's one of those ones where it's like w- we don't really... I think we keep on, in general, talking about this sort of problem space as though we've got the ability to control it, whereas in reality we actually kind of don't. Like we can- Yeah. ... we can control what attackers will be capable of when they show up with these tools.

Casey Ellis: Um- Yeah ... to treat it as a thing where we can tell the internet like, "No, don't do that, please," and have it. Yeah. Like if that's... Historically, you know, I've, I've... Especially doing the bug bounty and the vulnerability disclosure thing for so long, like i- if there's one thing I've learned is that that, that does not work.

Casey Ellis: Like the internet isn't listening. And- ... I think it doesn't work the way you want it to work, the way you want. Right? [00:21:00]

Ashish Rajan: Yeah. I, I think, uh, someone said this, I can't remember the name of the person, but, uh, at BlackHat someone said, uh, "Mythos is the worst of the AI model today." compared to what we will see in the future.

Casey Ellis: Yeah, I

Ashish Rajan: agree with that. 'Cause you almost look at this going, we- we are com- we're talking so much about Mythos and everything else around it, but i- and as much as I appreciate the marketing behind it, now my parents know what I finally do and what my book was about, so great from that perspective. It has been really useful for

Casey Ellis: that.

Casey Ellis: Like the m- like the marketing problem and actually driving awareness around this, I think that's a, that's an underrated problem to solve that it did actually solve in some ways. But sorry, I cut you off there.

Ashish Rajan: No, no, no, but you're, you're right, 'cause it, it definitely made everyone know what cybersecurity is, know what Mythos is.

Ashish Rajan: It was there everywhere. And great job on that. So keeping that marketing thing aside, I definitely found that- Um, what people kind of took away from the fact that it-- this is, since this is, like, the worst model that we can get today, and the future models are, are [00:22:00] gonna be better, and I think, uh, there was another argument about the fact that, oh, it's gonna cost me $10,000 to find that 23-year-old vulnerability.

Ashish Rajan: But then to the counterargument to that someone- It goes down ...called out was the fact that today, when a frontier model goes through one of those benchmarks that people look at, if you compare the f- the first few models to the models that are being used today, the amount of tokens used is actually far less.

Ashish Rajan: Yeah. Which means it's actually costing you, I mean, way considerably less than what it used to to run it on a benchmark. Which means this 23-year-old vulnerability which is costing $10,000 today would be probably 1,000, 100. Would you pay for that? I mean, compared to what you can find in your organization?

Casey Ellis: Yeah. Well, that's, that's one side of the question. The other side of the question is what would, what would an attacker pay for it, um- Ooh ...in reality? That's a good point. And this, and this, and this, by the way, is, is why I roll my eyes when people say bug bounty is dead, 'cause I'm like- ...if, if you think that's true, then you, [00:23:00] you don't un- actually understand what, what a bounty is.

Casey Ellis: To me, it's a function of the fact that, like, every vulnerability and every chain of impact that can be created has- Yeah ...some sort of value to it- Yeah. Yeah ...to someone, and it- Yeah ...the whole thing kind of functions as a marketplace. That, that value might be zero, legitimately, or it could be really- Yeah ...high.

Casey Ellis: You've got to actually figure out what that is and make sure that you're getting information to the right place. So yeah, it's, it's one of those things where, I mean, you know, again, like this, this little guy behind me is, like, tearing apart firmware with, with, you know, 27 billion parameter models and a harness that's actually optimized for that particular task, and it's a- Yeah ...it's effective, right?

Casey Ellis: So it's- Yeah ...it's not like I don't need Mythos or a frontier class model with all the context memory and all those other things to actually do that. It's just more for me actually knowing the thing that I wanna do from a research and an output standpoint and optimizing AI pipelines to achieve that outcome.

Casey Ellis: Um, you know, there's, again, like, that's been a thing now [00:24:00] for three or four years amongst a lot of the, the true VR and offensive community and, and- Yeah ...you know, the frontier version of it is just, it's sort of put it on easy mode 'cause you can just throw something up into Daybreak or Mythos and say, "Hey, pone this thing," and it'll come out with something that, you know, mostly works.

Ashish Rajan: Yeah. And to, to your point, what's the, the-- what, I think what, what you said earlier, which was really interesting, that you have to be this yay high to ride, take the ride. Like, well, as a script kiddie who may be watching and listening or maybe looking at these conversations like, oh, Mythos probably is not accessible today, but it would be on an open source, open weight model soon.

Ashish Rajan: Mm. So it's only a matter of time. Is the skill set for the end tr- uh, and going back using that same analogy a bit further Is the bar to entry to find vulnerabilities low for everyone? Is that just a theme that you saw? And when I say everyone, obviously I'll put a asterisk in. And obviously not non-technical people, I'll keep them aside for a second.

Ashish Rajan: Mm. But if I was... I, I'm a, I'm a [00:25:00] recovering malware an-an-analysis person. I tried that for one hot minute and I gave up very quickly. Right. And I, I was, I've been told multiple times by people that I should pick up that skill set again 'cause I'll find it way more easier. And I, I wonder how much truth is there to that, uh, especially after we've had the BlackHat conversations as well.

Casey Ellis: Yeah. Um, that's a great, that's a great question. I think on the, on the offensive side, you know, there is definitely a difference between vulnerability discovery and, and like exploitation. Um- Yeah ... and, and, you know, this is actually, you know, when I say like the vuln apocalypse isn't here yet, like we're in the slopdemic right now, that's a part of what I mean.

Casey Ellis: 'Cause like folk can find, it is easy to find, like that's a symptom of v- of, of vulnerability. I'm gonna test that and prove that it's real. Job done, right? Like that part- Yeah ... is actually pretty easy, but attackers and exploits don't function as a list. They function as a graph that has a starting point and [00:26:00] an impact endpoint.

Ashish Rajan: Mm.

Casey Ellis: Um, and usually what it comes down to is that traversing that graph is, is very much up to the skill and, and the context of the operator. Um, so yeah, I d- I, I think, you know, if you're talking about just point and pwn, um, you can definitely do that and, and have like simpler issues fall out, I think, in a bug bounty context and even in like a, you know, adversarial attacker context.

Casey Ellis: The challenge you're gonna have with that type of thing these days is that it's contested. Like it's actually really easy to find that, so you're gonna dupe out if you're a bounty hunter or end up, you know, bumping into a competing adversary if you're an actual bad guy. Um- Mm ... you know, when it comes to doing things that are more sophisticated, um, I do think it's, it's really, um...

Casey Ellis: You know, I, like I, I, since I picked up, you know, put the suit on and started doing like the business thing, I've tried to keep some of my skills up from the old days, but like the older I get, the better I was. Like what I've found [00:27:00] personally is being able to jump in and actually steer these models towards an outcome with more of like a product management level understanding of how this all works in context that I'm not as familiar with or a bit rusty on.

Casey Ellis: Like that works really well. Like I can guide stuff to an outcome 'cause I understand how the operator mindset works, um, even if- Yeah ... I don't necessarily understand the bits and bytes of how to actually do it myself. So people that have that kind of knowledge or that kind of intelligence, I think they can become really, really effective with this.

Casey Ellis: Like the folks that are doing like true VR, like the scary stuff, they've just upleveled their game, you know, 10 to 100X because they're not, they're not like delegating their intelligence to the model. They're using it as this like- super partner, like, you know, what's the word? Um, the wingman type thing.

Ashish Rajan: Oh, yeah. I mean, glad you didn't say co-pilot. That would've just been

Casey Ellis: I was, we're trying not to say co-pilot, so I had to find

Ashish Rajan: another word. I know. It's like, you know those words that I... It's been butchered so much, you almost [00:28:00] feel like, it- it's like I need to come up with a better word than a co-pilot, 'cause they just have done, not done justice to that word.

Ashish Rajan: But-

Casey Ellis: Yeah, like loyal, loyal wingman, I, is, is-

Ashish Rajan: Yeah, yeah, yeah ... a good

Casey Ellis: approach. That's, that's actually a better word.

Ashish Rajan: Loyal wingman or woman who doesn't leave you anywhere. Uh, and-

Casey Ellis: It's a military hardware term, but I think it actually kind of applies a lot to this type of thing, so yeah.

Ashish Rajan: 100%. And I, I think you've kind of touched on what I think based on what we are seeing, at least what you saw and what I saw, um, it definitely seems like a theme that the offensive side has definitely leveled up quite a bit in terms of- Mm

Ashish Rajan: I guess between RSA now, there's people obviously, uh, being able to use much more of their, uh, understanding of how this operator model works to, to, to go a large extent. I'm, I'm curious more from, um, the security practitioner eq- like the de- defense side as well, how are you seeing them address some of these?

Ashish Rajan: Like, we spoke about the, we are not even at the wonderful, wonderful, I can't even say that, but essentially- Wonderful ... vulnerability apocalypse. I'm gonna use the full word. Yeah. Yeah. Uh, [00:29:00] the, we're not even the, uh, at the apocalypse yet. However- Yeah ... it, and we're all getting the volume of increase in reports coming out from external sources, internal sources.

Ashish Rajan: The AppSec pipeline seems to be quite full because there's a lot more code being created-

Casey Ellis: Yeah ...

Ashish Rajan: uh, than it was before 'cause everyone's using code- coding agents. The, the cloud bill, uh, uh, if I, it feels like, or at least to me, it felt like everyone I spoke to, they all said there's a huge volume everywhere across security.

Ashish Rajan: And- Right ... I'm curious if you kind of saw something similar and was there things that you noticed that people, were someone doing better or you heard stories that were, uh, people could maybe learn something from as well?

Casey Ellis: Yeah. No, for sure. Um, I, yes, 100%. A- and, and, you know, I kind of mentioned that a little bit earlier was the, with the observations from RSA, there was definitely more of that this year.

Casey Ellis: Like, everyone's kind of- Yeah ... strained, really is what it comes down to. Um, I think the, like, the folk [00:30:00] You know, something that I started talking about probably two years ago is that, you know, like the defender's dilemma always was a real thing. I feel like the, the thing that we've transitioned into now is that no one's really able to argue with that anymore.

Casey Ellis: Mm. 'Cause like I, I do think, you know, there was-- It's up for healthy debate in a lot of ways, but to me, that's an economics problem that you either understand or you don't, right? I, I feel like- Yeah ... AI has kind of highlighted the fact that that's a real thing. Um, you know, something that I was talking about a while back is the idea that like we're used to this sort of attacker-defender innovation like cycle time in, in- Yeah

Casey Ellis: in the cybersecurity industry, and what AI does is that it squishes that like OODA loop to the point where, you know, maybe we're not gonna fit into it for too much longer. So at that point, we've got to think about like how are we actually changing the game here? Like how do we, um, how do we impose cost on attackers?

Casey Ellis: How do we, you know, think very carefully about like detection, [00:31:00] you know, ejection, recovery, like all those different things. Moving into a, into an assume breach posture. Mm. Continuing to work on prevention and defense. I'm not saying give up on that necessarily, but it's like, okay, this is, like this is gonna fail at some point, so like how do we, how do we actually, you know, in a resilient and an antifragile way prepare for that?

Casey Ellis: Um- Yeah. I think the folk that, that I feel are most on top of this are the ones that are kind of leaning into that mode of thinking. I know the labs are definitely putting a ton of work into thinking through how to, how to support the industry-

Ashish Rajan: Yeah ...

Casey Ellis: in, in doing that- Yeah ... in general. And, and it's still the-- I don't feel like there are necessarily clear answers to a lot of those questions just yet.

Casey Ellis: But like that to me is sort of the set of the sail at this point.

Ashish Rajan: Yeah, yeah. And I think well put together because I think, um, I, I agree on frontier models trying to make some impact there because they realize they can't do this on their own.

Casey Ellis: Yeah.

Ashish Rajan: Um, we had a conversation, and I think it's gonna come out soon, which is a state of AI security conversation.

Ashish Rajan: We had the OpenAI folks-- Oh, [00:32:00] actually Clint Gibler, I don't know if you know him already, so- Oh, cool. Yeah,

Casey Ellis: I know Clint. Yeah.

Ashish Rajan: Yeah, he works for OpenAI now. So, um, him, uh, we had Forrester analyst Ali Melhan. We spoke about, it's kind of funny enough, the same theme as to why our frontier model is now suddenly, uh, partnering with all these cybersecurity companies or Accentures of the world, or KPMG, whatever other cons- insert consulting company, the big ones.

Casey Ellis: Yeah.

Ashish Rajan: You-- One thing that I definitely found, and I love the, the dilemma conversation as well because, um, uh, and, and this is a theme that I saw, uh, which I definitely know people are seeing it, but it was very interesting to kind of-- The dilemma kind of amplifies a bit more because these days, if you used to work for a bank which has been there for 10, 15, 20, maybe 40 years, they've gone through the transition from your da-data centers to cloud, now going from cloud to

Casey Ellis: AI.

Ashish Rajan: Yep. There are essentially three kinds of applications that I found that most people were talking about. One was the fully AI native application. Now, and now there that, there are not that many in there, and a lot [00:33:00] primarily are startups, I wanna say, or they are companies that are just ve- uh, they've been broken out of the traditional company.

Ashish Rajan: I think, uh, there's a few examples in Australia and the US for this as well, where, uh, companies have branched out going, "Hey, we are too rigid to change- Yeah ... why don't we just start this side company?" Yeah. Uh, and that's like first bucket of defense that people are

Casey Ellis: looking at how

Ashish Rajan: do we- It's, it's like

Casey Ellis: we-- like a digital transformation, um, in-

Ashish Rajan: Yeah, yeah.

Ashish Rajan: Literally

Casey Ellis: same thing ... same, same sort of thing, but for AI. Yeah.

Ashish Rajan: Yeah, yeah. And that's, that's like my-- I'm looking at this as my first bucket of defense, where a lot of people have gone down that path where how do I do security AI native way? Yeah. And then the second one was the AI bolt-on, as I like to call it, where, hey, I'm a traditional enterprise, but I have my developers using coding agents producing more code.

Ashish Rajan: I'm, uh, uh, basically putting pressure through the neck of every employee that I can find, "Hey, use more AI, use more AI, but security, you have a $200 per month budget." Like, like do, do whatever you can- It's done ... but it's [00:34:00] $200. So there is, there is that as the, the sec- so there is a dilemma more also in the context of they've been given access to AI- And whereas to what we've been talking about so far, the attacker is willing to pay $10,000 for a bounty, uh, or for, for a vulnerability

Ashish Rajan: And then there is a, the third theme, which is kind of, uh, kind of in that shadow AI bucket as well, which is the whole wipe coding becoming a norm.

Casey Ellis: Yeah.

Ashish Rajan: Especially in the AI forward companies where the non-technical people have started, uh, doing, um, building applications, pushing code into GitHub, and- Yeah

Ashish Rajan: ties in really nicely to what you just said a- about the assume breach mentality. Yeah. Which traditionally used to have the lens of that, "Hey, it's the technical people." Now it's like, fuck- Yeah. Now it's never technical ... it's like everyone in the organization. yeah. Yeah, yeah. It's like even the... I mean, it's no longer the CEO is gonna click on a phishing link, but my Bob in accounting is gonna build an app just because he's being put pressure on by the boss to use more AI.

Ashish Rajan: So he's like- Yeah ... "Okay, I'm gonna- Yeah ... use another application and build one application for [00:35:00] myself and te- show it to my boss, 'Hey, this is what I made with AI. Look at my productivity.'" I don't know. It, it, I feel like it... Do you-- Is, has there been a theme like that as well that came out for you in terms of how people are using AI, and has that changed in organizations?

Casey Ellis: So, so, uh, the, the Bob from accounting example, like I'm, I'm close with the, uh, the folk that run the, the NOC and the SOC at, at BlackHat.

Ashish Rajan: Oh,

Casey Ellis: yeah. And, and, and at DEF CON as well. And, um, there were, there were a couple of things that they saw. Like, one of them was they were actually seeing zero day across the wire, which is not normally something that happens at that conference 'cause-

Ashish Rajan: Oh, wow.

Ashish Rajan: At

Casey Ellis: BlackHat? ... if you're sitting on... Yeah. If you're sitting on something, like you know that if you shoot it across the network at BlackHat, it's gonna get caught. So like- Yeah ... traditionally folk with that kind of tradecraft would just kind of keep it to themselves at that particular event. And that shifted this year, I think, because you've got folks that have capability but don't necessarily understand that, that tradecraft component.

Casey Ellis: So that was, that was one. But then the other two, which sort of goes more to what- [00:36:00] you're talking about is that, like, port 3000 was pretty wild. You've got- ... you know, folk that have vibe coded Yeah, yeah, yeah. And they've forgotten to not bind it to, to, to any, any and, um, you know, there, there were people that were sort of sitting around waiting for that to happen.

Casey Ellis: So there's, there was some interesting action on that side. And then the idea of, like, Bob from accounting who's, you know, vibe coded up, um, or someone from the sales team, or, like, people that are just there to do work, right? And they've, you know, what they're doing is actually kind of a good thing. They, they've- Yeah

Casey Ellis: they've kind of used AI to try to make themselves more efficient at their job. But in the process, they're sending, you know, like prospect lists in clear text and, like, just all sorts of silly shit like that. So- Yeah ... so, like, that's a real, that is 100% a real thing. Um, on the, the first version that you said, like, when we got, you know, one of the early aspects of the, the, the bug bounty story, um, [00:37:00] was when we, um, you know, started working with, with the Pentagon on, on, on Hack the Pentagon.

Casey Ellis: Um and, you know, HackerOne got the initial thing and then it kind of blew out, but the part that's not necessarily talked about as much is that, you know, we were actually working with, with them in the setup process of all of that. And, and the way that that happened, that kind of goes to what you're talking about, is it was through a group called the United States Digital Services Group, which was effectively the digital transformation arm for the DoD.

Casey Ellis: Right. So it was literally what you're just talking about. It's like we are big and old and slow and, like, organiz- It's not even our fault necessarily. We might want to improve and innovate, but organizational inertia means it's gonna be really hard, so we need this group that's, like, literally their job to disrupt the way that we think- Yeah

Casey Ellis: within the organization. Yeah. And that was, that was how that all kind of got moving, um, when it came to introducing hackers into, into the Pentagon [00:38:00] at that point in time. Yeah. So, like, I think that's gonna be the right model for most larger organizations at this point, just because this is moving really quickly and there's, there's an urgency to it.

Casey Ellis: Um, the other thing I would say real quick on that is that um, I do spend a lot of time, like a lot of the conversations that I have with senior leaders in particular, um, you know, they, they aren't necessarily aware of what AI can be used for defensively or even from like a build standpoint because corporate policy has been like, "Don't use this stuff."

Casey Ellis: Right? Mm-hmm. Like the reality is that people are just gonna use it anyway at this point. Yeah. I think like relying on policy to prevent, that's probably not the best defensive, you know, thinking at this point. Um, but then if you've got leadership that's not necessarily aware of the art of the possible, then you're gonna end up with this pretty big gap between the folk leading the business and, and what your workforce is actually [00:39:00] doing.

Casey Ellis: So- Yeah ... what I've, what I've been encouraging, you know, senior leaders to do is like just use this stuff at home. Like figure it out. Yeah. Like, yeah, like get a harness, like just play with it. Figure out what you can use AI for to, to automate, you know, stuff that you're trying to do around the house. Like think about your own like home network security if you want to, or whatever it is.

Casey Ellis: Yeah,

Ashish Rajan: yeah.

Casey Ellis: Um, actually get hands-on tools with, with using this stuff in an applied way, and make sure you're at least comfortable with that. 'Cause if you're not, you're gonna end up with this huge gap between, you know, your like office and your employees, and that's gonna create this massive internal threat problem basically at that point in time.

Ashish Rajan: Yeah. And I, I think it's worthwhile calling out, you don't have to be really technical. I know- No ... you and I maybe come from a bias of being technical first, but- Agreed ... you don't have to be technical to kind of walk that path, even if you're a non-technical CISO.

Casey Ellis: Yeah. Yeah. I mean, it, it, this is designed, like the stuff is designed for that.

Casey Ellis: Like you [00:40:00] said before, it's, it's like, it's a massive level up if you are technical, but it's designed for people that aren't technical to start to do-

Ashish Rajan: Yeah ...

Casey Ellis: more technical things. Yeah. Um, and yeah, like, like you said, it's not about necessarily being an expert. Like the, the advice I give is just get comfortable with it.

Casey Ellis: Just be- Yeah ... in a position where you can have a conversation and, and you're not like you know, thinking the other person's talking about science fiction or something that- Mm-hmm ... is gonna happen, you know, three years into the future. It's like if you- Yeah ... still think AI is stupid because it said that there was seven Rs in the word strawberry three years ago, like you're doing it wrong at this point.

Ashish Rajan: Yeah. But I, I think the, the way I've been explaining to a lot of people is the fact that, uh, I, I use iPhone as an example. It was the first smart- well, but okay, I'm not gonna claim the first smartphone, but it was one of the f- b- popular, uh, smartphones, uh, that got- As far as the market is concerned, yeah.

Ashish Rajan: Yeah, as far as the mar- as far as the market is concerned. But I think- I,

Casey Ellis: I'm sure there's some Canadians that are gonna get pretty mad about that, but that's

Ashish Rajan: okay. Yeah. But the, the reason I exam- use the iPhone example is that it's been decades of iPhone being [00:41:00] out. Mm. And I, even today, as no mat- no matter how technical I am, I'm pretty sure I'm just using 10 to 20% of what the actual capability of an iPhone is, just because I chose to be comfortable with how an iPhone works.

Casey Ellis: Yeah.

Ashish Rajan: And I think that's what we are asking people to get to.

Casey Ellis: Yes.

Ashish Rajan: You don't have to be like, "Oh, I know the ins and outs of every AI and LLM. I'm a data scientist or whatever." Yep. Just enough to make it usable for things you want.

Casey Ellis: Yeah. Yes, 100%. Um, I, I think, I think that's right, and that's, that sort of thinking was the kind of thinking that enabled BYOD.

Casey Ellis: Yeah. 'Cause that, that used to be a dirty word way back in the day, and all of a sudden it became normal. And like everyone who was behind the curve on that had to play catch up at that point. Like this is- Yeah ... another iteration of a similar sort of phase shift, I think, in, in how we do a lot of stuff. I mean, the other side of it, you know, the other sort of suggestion, and this is something that I've actually been doing a lot, is like literally getting with friends, um, and saying, "Hey, like you're building a thing or you run a small business or whatever [00:42:00] else, like how, you know, how can we find ways to, to use AI to make life suck less in the places where it sucks, and actually- Yeah.

Casey Ellis: Yeah ... enable you to do more of what you're, like, uniquely good at or what you're trying to do as a- Yeah ... as a business or an operator. And just, like, it's valuable for them, but for me, like, the, the act of, like, repeating that kind of translation process is actually something that keeps me sharp on that side of things as well.

Casey Ellis: So, I think that's a really-- that's just a useful... And it's kinda fun, do you know what I mean? Like- Yeah. No, for sure ... being able to build silly crap is, you know, you can, you can just do things now in that sense, and I think for, for folks that are in a leadership position to actually have their hands on the keyboard with some of this stuff, I think is really important.

Ashish Rajan: Yeah. Dig, dig into the curiosity mindset that we always had. Yeah. You just need to dig back into it.

Casey Ellis: Exactly.

Ashish Rajan: Uh, it, it's, uh, it's funny, kind of similar reason why, um... So, we've been running these free sessions on a fortnightly basis called AI Security Lab. Kind of to what you said, there's an obvious gap even [00:43:00] in BlackHat, the conversations were, "I don't know what security workflows to start with," or...

Ashish Rajan: So, we've had people from Snap, Adobe, I think we've got SpaceX coming in.

Casey Ellis: Nice.

Ashish Rajan: The, the whole idea has been it's a free session for one and a half hour. Someone just shows you a workflow from end to end. Hey, this-- I think the first one was about how do I do authentication for multiple, uh, when I'm using a multi-AI agent chain.

Ashish Rajan: Yeah. The second one was about how to build an AI harness that you can use with security.

Casey Ellis: Right. Like,

Ashish Rajan: I mean, there's plenty of ideas. Just, you can obviously make your own, but, um, AI Security Lab if you are interested. But, uh, the thing that you mentioned earlier- Yeah ... uh, which I would like to go back to, is the gap that you've n- I'm curious because you've been on the operative seat as well as on the founding seat as well.

Ashish Rajan: I'm curious, what is the gap that you are noticing in this ecosystem today that not many people either are talking about or it is not being covered?

Casey Ellis: Uh, on the, on the operator side, you mean?

Ashish Rajan: Uh, I mean, even from a product perspective. Could be any, any- Oh. Just pick [00:44:00] any side you like. Mm-hmm. I'm just curious as to overall, considering you talk to both sides like me, I'm just curious-

Ashish Rajan: Yeah ... as to what are you finding as gaps.

Casey Ellis: I think, yeah, um, uh, look, probably the biggest thing is that there's just a, a, a norm, like, like, a vast spread of, of, um- You know, understanding of the art of the possible, like acceptance of, of the technology and, and kind of, you know, even thinking about like where is this actually gonna fit into things into the future.

Casey Ellis: Um- Mm. ... the spread of that is just insane. Like it, it, it goes from people that are like, you know, fully, I hate the term AI or AGI pilled, um, but like- Yeah, it's A-

Ashish Rajan: AGI pilled. That was-- Actually, that was one theme as well. No one was saying AI pilled. Everyone said AGI pilled at BlackHat.

Casey Ellis: Yeah. Yeah. And it's, uh, that's a...

Casey Ellis: I can get on a long re- To me, like the whole thing is like, no, I'm human pilled, I'm not AGI pilled. Yeah, yeah. Like I believe in, I believe in AI being as transformative as, as, you know, like [00:45:00] the internet in like 1998 kind of thing. Yeah. Like I, I believe that part. Um- Yep ... but the whole idea of like it being, you know, the purpose of all of it, I, I don't buy into that bit.

Casey Ellis: Um, yeah, like the whole idea of like folks that fully, fully kind of accept the fact that this is a phase shift in technology and they're really leaning into that and they're thinking about it through that lens, you know, today and when it comes to seeing around corners, like that's, that's to me like right up the sophisticated end.

Casey Ellis: And then you've got folks that are like, you know, what I said just before, like it told me that there were seven Rs in the word strawberry one time, so I think this whole thing's BS. Um, you know, uh, like that spread is so obvious I think at this point in time. And, and like what it does is it creates all of these potential impedance mismatches, um, you know, for, for an operator, right?

Casey Ellis: You've got different levels of technical nativity inside an organization, and as a leader, like you've got to make your own decisions around where you think this is gonna go and then try to bring everyone else up to [00:46:00] speed with that. And I think that's, that job's actually getting harder and harder as, as time goes by, 'cause that spread to me feels like it's getting broader, right?

Casey Ellis: Mm. Um, so that's probably, that's a, that's a big one on the operator side. On the, on the vendor side, like I do think, I mean, I'm, I'm in like regroup, you know, and, uh, and think about startup mode, so I, I can ideate on this, but there's some stuff I have to keep in the pocket a little bit. But I think in- Fair

Casey Ellis: I think in terms of like the problems that we're solving, um, you know, like the whole f- like there's so many agentic pen test vendors, you know, on the floor at BlackHat, for example, and it's like the pen testing was effective to a certain point before we turbocharged it and made it available 24/7 and got robots to do it.

Casey Ellis: Like now we're just sort of dialing up the same thing that has been somewhat effective, but I wouldn't say super effective [00:47:00] in terms of the overall risk posture of organizations over the years and just doing more of it because that's kind of what the market says we should do. Um, basically inverting that thinking and seeing what falls out is, is kind of- Yeah

Casey Ellis: you know, a lot of what I've been doing. And, and I do think about it in terms of like, what are the bad guys up to? How do we reduce, you know, or how do we increase the cost of attack, um, in ways that are rational, um, you know, legal obviously, all that kind of stuff. But how do we think about it more as a, you know, the entire reason we're doing this is to basically frustrate an active adversary.

Casey Ellis: Yeah. So like how do we How do we... Like, have we-- Where are the places that we've forgotten that, and, and how do we actually start to think about solutions that sort of orient themselves in that, in that direction? 'Cause, like, app sec's awesome, shift left's awesome. Like, those things are all good and important from a resilience standpoint.

Casey Ellis: Yeah. Um, but when you come back to the fundamental of why we're doing this in the first place, it's because of the [00:48:00] bad guy. So all right, now what? Um- Yeah. I think that's a, that's a thing that I see some, like, a small number of vendors really leaning into. Like, deception tech, I think, is gonna have a really good time over the next period because- Yeah, yeah,

Ashish Rajan: yeah

Casey Ellis: like, shout out to Haroon and, and those guys who've been, like, literally just quietly grinding away on that as a, as a good solution for, you know, 12 or 13 years, and all of a sudden everyone's like, "Oh, crap, we don't know what our agents are doing." Um, that's-

Ashish Rajan: Yeah. I mean, it's actually AI deception companies quite a bit.

Ashish Rajan: I think we spoke to Tracebit recently, but yeah, to your point, deception is fin-finally finding its limelight moment. It

Casey Ellis: was always a good solution, but now it's sort of an obviously good solution, I

Ashish Rajan: think. Y-yeah, 'cause I mean, it used to be hard to justify why do we have this thing which never lights up?

Casey Ellis: Yeah.

Ashish Rajan: Like what's the point of the thing that it never lights up? Yeah. Isn't there a... I mean, and obviously we can go... Dude, I, I, I'm just conscious that, uh, I only had you for an hour, so I don't wanna make... I respect your time for this as [00:49:00] well. Um- No,

Casey Ellis: I appreciate the time. We could probably

Ashish Rajan: ramble on

Casey Ellis: this for a long time, but yeah.

Ashish Rajan: Yeah, no, I, I'm... We could have gone for an hour, but I, I- No worries at all. Wh-where can people find more about what you're working on and connect with you on all these things and-

Casey Ellis: Yeah, for sure.

Ashish Rajan: No, look- I'm looking forward, obviously, more episodes, but where can people connect with you?

Casey Ellis: I appreciate that. Um, so yeah, I, I write stuff at, uh, cje.io.

Casey Ellis: That's probably the main kind of presence that I have on, on the internet. Uh, the disclose.io project is at disclose.io. Um-

Ashish Rajan: Yep ...

Casey Ellis: you know, check out Bugcrowd as well. Uh, those are probably the three main places to go, to go looking and, you know, I'm always ranting on LinkedIn and X, Twitter, all those different things.

Casey Ellis: So, you know, if you wanna find me, I'm not that hard to find.

Ashish Rajan: Uh, I will, uh, put those links under the show notes as well. But dude, thank you so much for coming on the show. Appreciate it. I really appreciate this.

Casey Ellis: Great to chat. Cheers, Ashish. All right. All right. Thanks everyone. See you next time.

No items found.
More Videos