//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...
Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker
Katie Moussouris (she/her/she-hulk/she-ra)🌻









Loading...
MSN reporting on Microsoft’s smooth moves on Vulnerability Disclosure features quotes from me and @doublepulsar.com www.msn.com/en-us/news/i...
I’ve seen the paper. It’s not a jailbreak. It was Defense Oriented Prompting (DOP) - a capability defenders need. My thoughts about the hasty Export Controls that made Anthropic halt access to Fable. If national defense is the goal, this is an own goal against us www.wsj.com/tech/ai/anth...
More of my thoughts on the public vulnerability disclosure fight Microsoft picked with the researcher Nightmare Eclipse in this piece by @mattkapko.com for @cyberscoop.bsky.social . @andrewmorr.is of @greynoise.io Intelligence shares perspective too. cyberscoop.com/microsoft-co...
17d
4d
12d
This tshirt I made for Symantec Vulnerability Research, a program predating Google Project Zero by nearly a decade where we’d discover, report, & disclose vulnerabilities we found in other people’s software, is 20 years old. Still holds true: Don’t hate the Finder, hate the vuln
Cheers 🍻 to the unfinished mission. #l0phtDay
Not that ‘responsible’ disclosure shit again 🙄 No vendor uses that term unless they want to call someone irresponsible. Even if someone drops 0day, patch & move on. Going after a researcher is a great way to turn 1 bad relationship into many terrible relationships.
Dropping 0day isn’t the worst thing a researcher can do. It’s not ideal, but at least orgs can take steps to mitigate. Non disclosure is far worse. What drives researchers toward non disclosure? Threats from vendors. Researchers aren’t criminals unless their crime is curiosity.