Bug bounties in the age of AI

In this session, Tod Beardsley (runZero) and Casey Ellis (Bugcrowd) explore the evolving role of bug bounties in a world increasingly shaped by artificial intelligence. Ellis explains that while AI has lower the barrier for entry for both offensive and defensive players, the fundamental spy versus spy dynamic remains, with human intent and agility still being the primary drivers of security research. The conversation touches on the "defender's dilemma," where attackers can iterate quickly and risk failure without major consequences, while defenders must secure entire environments and face severe operational impact if their automated "agents" cause a production outage.

The discussion shifts to the intrinsic value of vulnerability research and the importance of standardizing disclosure practices across the internet. Ellis highlights his work with disclose.io, a project aimed at making vulnerability disclosure "suck less" by providing standardized legal boilerplate and a vendor-agnostic database of disclosure policies. He notes that while some organizations have reached a maturity model where they actively encourage and protect researchers, many still rely on compliance-driven box-ticking exercises that do little to actually reduce risk in a meaningful way.

Meet Our Speakers

todb

VP of Security Research, runZero

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
The infinite eye: How AI threat intelligence gives defenders an asymmetric edge
Tod Beardsley, HD Moore, and Jonathan Cran discuss how AI-powered threat intelligence is providing defenders with a much-needed advantage.
Podcasts
Perimeters and pathways: Protecting the complete attack surface
Tod Beardsley, Jared Atkinson, Zakir Durumeric, and HD Moore discuss the perimeters and pathways that connect internal networks to the global...
Podcasts
The network edge: EOL and exploitation
Tod Beardsley is joined by Kimber Duke & Patrick Garrity of VulnCheck to discuss the critical intersection of EOL hardware and cybersecurity...
Podcasts
Mute the sirens: Prioritizing vulnerability noise
In this session, Tod Beardsley and Mark Lambert discuss the escalating challenge of managing vulnerability noise in the era of AI.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.