Katie MoussourisAug 18, 20227 min readBug Bounty Evolution -- Not Your Grandson’s Bug BountyLearn about practical metrics to improve bug bounties and VDPs, non-exploitative hybrid labor models, hiring, & a sales referral bounty
Luta SecurityDec 14, 20213 min readVulnerability Disclosure Programs Done the Right WayThird-party vulnerability disclosure and bug bounty programs should never be the main path to discovering software insecurities.
Katie MoussourisApr 21, 20217 min readNew Clubhouse Security Vulnerabilities Could Happen to Any Growing Unicorn Luta's CEO hacked the Clubhouse app; vulns fixed now
Luta SecurityDec 17, 20203 min read2021 New Year’s Resolutions for VDPs & Bug BountiesMany of us kick off each new year enthusiastically brimming with more resolutions than a DNS server. We may resolve to get stronger, so...
Luta SecurityDec 16, 20204 min readFTC’s Settlement with ZoomIn November 2020, the Federal Trade Commission (FTC) announced a settlement with Zoom to reconcile the allegations that the company...
Luta SecuritySep 2, 20203 min readWho’s in the BBQ pit with USG?CISA and OMB published instructions for federal agencies on vuln disclosure programs. Sadly, the marching orders are all out of whack.