Luta Security

504 posts

Luta Security banner
Luta Security

Luta Security

@LutaSecurity

#1 process planning partners for vuln disclosure & bug bounties. More bugs won't help you fix a broken process! Stop premature bountification.

United States Katılım Nisan 2016
89 Takip Edilen5.6K Takipçiler
Luta Security
Luta Security@LutaSecurity·
Bug bounties under NDA are not the answer to your security woes with hackers. Hear from our CEO @k8em0 on that & other insights on how AI is changing cybersecurity & how UBI might heal a broken labor market in her interview with @Williamrt for @ComputerWeekly
Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷@k8em0

I spoke with @Williamrt of @ComputerWeekly on NDA bug bounties failing to increase security & the effects of gov disclosure requirements on national security, plus how AI threatens the human expert labor pipeline of tomorrow & why UBI may be our best bet

English
0
1
2
338
Luta Security retweetledi
Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷
. @CurrentJen tops the list of people who have enabled me to grow as a person & professional. She’s the best person to strategically work towards company goals while effortlessly handling the gnarliest security crisis comms. Hire Jen Wood if you “take security very seriously.”
Jennifer Wood@CurrentJen

After five incredible years at @LutaSecurity, I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!

English
1
8
24
6K
Luta Security retweetledi
No Hat Con
No Hat Con@nohatcon·
🎤 Keynote Announcement 🎤 We're excited to announce Katie Moussouris (@k8em0) as keynote speaker for No Hat 2025! Founder/CEO of @LutaSecurity, leading voice in vuln disclosure & bug bounties. Seen at Black Hat, DEF CON, RSA now live in Bergamo, Italy on Oct 18th! #nohat2025
English
0
4
21
1.8K
Luta Security retweetledi
Katie🌻Moussouris (she/her/she-ra/she-hulk) 🪷
When I testified before US Congress about the Uber data breach when they misused their bug bounty program to pay off data thieves, I didn’t think I would have to update my core guidance to include this: Don’t let extortionists set your bounty reward price. Coinbase was *right* not to pay extortion, but putting up a “reward pool” for the same $20M amount is ultimately going to lead future criminals to groom more minors to commit crimes & turn them in to reap the rewards. Defense cannot pay the same as offense or you create perverse incentives. In this case, it’s just adding steps to exploit a company for huge sums, not an effective deterrent. It’s tempting to flex with huge rewards, but the disruption to criminals is negligible & ultimately increases the cost to protect customers. Cryptocurrency exchanges & others should consult with us on complex situations like this. You know where to find us: @LutaSecurity
Coinbase 🛡️@coinbase

Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on <1% of Coinbase MTUs. No passwords, private keys, or funds were exposed. Prime accounts are untouched. We will reimburse impacted customers. More here: coinbase.com/blog/protectin…

English
2
6
29
3.3K