"You know who will be hiring juniors again? Bad guys."
Casey Ellis founded Bugcrowd and launched the first bug bounty programs on it back in 2012, pioneering crowdsourced security as a service. He co-founded disclose.io, sits on the Black Hat and DEF CON Policy review boards, and now runs Tall Poppy Group, angel investing and advising the next generation of security startups.
Fresh off a week at Black Hat, B-Sides, and DEF CON, Casey joins Aaron for a wide-ranging conversation about what he actually heard on the ground — and why the mood at each of those three conferences was completely different.
We get into the "slopdemic" (Casey's term for AI-generated vulnerability reports drowning the ecosystem), why he's "human pilled" rather than AGI pilled, and his read on the White House memorandum he's calling the privateering order — what it actually authorizes, and who's really going to use it. Plus: why pen test firms are about to have a very hard time defending their value, why every company already has a vulnerability disclosure program whether they know it or not, and the hygiene fundamentals that still contain the blast radius when everything else fails.
The last stretch is the one worth staying for — a genuinely urgent case for why the industry's "we're never hiring juniors again" moment is a gift to the people recruiting them instead.
Guest: Casey Ellis, founder of Bugcrowd and disclose.io, principal of Tall Poppy Group. Find him on LinkedIn.
⏱️ CHAPTERS
00:00 Intro
02:35 Coming out of Black Hat, B-Sides, and DEF CON
06:33 Why DEF CON was allergic to the AI hype
09:35 Hybrid conflict is already here
10:53 Royalty in the palace, villagers at the gate
12:16 Security below the poverty line
13:14 "I'm not AGI pilled. I'm human pilled."
14:51 Do stupid things faster with more energy
19:04 What people get wrong about AI and exploitation
21:43 The slopdemic and the vulnpocalypse
25:07 What it takes before anything actually changes
28:48 Nobody is coming to save you
33:02 What actually works if you start from scratch today
37:34 Why pen test is in for a ride
39:13 Hygiene, blast radius, and the boring basics
43:31 The privateering memorandum
48:26 Who's actually waiting to hack back?
51:24 What to tell a 22-year-old today
53:21 It's really easy to do crime
55:08 Community, disclose.io, and knowledge transfer
58:01 The industry needs to give back
60:45 "Who will be hiring juniors again? Bad guys."
61:11 Tall Poppy Group and where to find Casey
#cybersecurity #infosec #AI #bugbounty #DEFCON