Bug bounties under NDA are not the answer to your security woes with hackers. Hear from our CEO @k8em0 on that & other insights on how AI is changing cybersecurity & how UBI might heal a broken labor market in her interview with @Williamrt for @ComputerWeekly
I spoke with @Williamrt of @ComputerWeekly on NDA bug bounties failing to increase security & the effects of gov disclosure requirements on national security, plus how AI threatens the human expert labor pipeline of tomorrow & why UBI may be our best bet
. @CurrentJen tops the list of people who have enabled me to grow as a person & professional. She’s the best person to strategically work towards company goals while effortlessly handling the gnarliest security crisis comms. Hire Jen Wood if you “take security very seriously.”
🎤 Keynote Announcement 🎤
We're excited to announce Katie Moussouris (@k8em0) as keynote speaker for No Hat 2025!
Founder/CEO of @LutaSecurity, leading voice in vuln disclosure & bug bounties. Seen at Black Hat, DEF CON, RSA now live in Bergamo, Italy on Oct 18th!
#nohat2025
You shouldn't have a #bugbounty program if you’re unwilling to fix your internal processes to handle the intake, have context-aware triage, and deploy comprehensive fixes of reported vulnerabilities. Contact @LutaSecurity today to learn more or get help! https://t.co/eMzCitQore
Do you need a security maturity assessment or an audit for your #bugbounty program? Hire @LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure and handling processes. #DontLetTheBugsPileUp#FixYourBrokenProcess https://t.co/lPLvOcUTDC
Are the unpatched bugs piling up within your organization? @LutaSecurity can help fix your broken vuln management & improve your security ROI. Contact us today! #DontLetTheBugsPileUp#FixYourBrokenProcess https://t.co/BCJ8p2jv8M
When I testified before US Congress about the Uber data breach when they misused their bug bounty program to pay off data thieves, I didn’t think I would have to update my core guidance to include this:
Don’t let extortionists set your bounty reward price.
Coinbase was *right* not to pay extortion, but putting up a “reward pool” for the same $20M amount is ultimately going to lead future criminals to groom more minors to commit crimes & turn them in to reap the rewards.
Defense cannot pay the same as offense or you create perverse incentives.
In this case, it’s just adding steps to exploit a company for huge sums, not an effective deterrent.
It’s tempting to flex with huge rewards, but the disruption to criminals is negligible & ultimately increases the cost to protect customers.
Cryptocurrency exchanges & others should consult with us on complex situations like this.
You know where to find us:
@LutaSecurity
#Cryptocurrency Exchanges—Do you need a security maturity assessment? Do you need an audit for your #bugbounty program? Hire @LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. #crypto https://t.co/lPLvOcUTDC
Does your organization need a security maturity assessment and roadmap for improving its security posture? @LutaSecurity can help you find emerging threats before your adversaries do. Contact us today! https://t.co/BCJ8p2jv8M #DontLetTheBugsPileUp#FixYourBrokenProcess
Check out the latest episode of @hackersonrocks featuring @LutaSecurity CEO @k8em0 discussing the Pall Mall Process, vuln disclosure, the researcher community, and more. https://t.co/0YT3xOoWRa
As cyber adversaries become more adept at exploiting weaknesses, organizations must prioritize maturity, so having a partner like @LutaSecurity is vital to your comprehensive #security strategy. Learn more at: https://t.co/uV6k2Im1G9
Are the unpatched bugs piling up within your organization? @LutaSecurity can help fix your broken vuln management & improve your security ROI. Contact us today! #DontLetTheBugsPileUp#FixYourBrokenProcess https://t.co/BCJ8p2jv8M