
Black Hat 2026: Why Threat Researchers Are Hoarding Zero-Days
Is the AI "vulnpocalypse" already here? According to Casey Ellis, Founder of Bugcrowd and pioneer of Disclose.io, we aren't quite in an apocalypse yet, we're actually in a "slopdemic." The cost of discovering vulnerabilities has plummeted, flooding bug bounty and SOC triage queues with low-quality, noisy submissions. Because these queues are so overwhelmed, many highly skilled researchers are simply hoarding zero-days because reporting them has become too difficult. In this episode, Ashish sits down with Casey to unpack the major themes and mindset shifts from RSA and Black Hat 2026. Casey breaks down how AI is shrinking the OODA loop for defenders, forcing the industry to adopt a true "assume breach" mentality and reconsider deception technology to frustrate active adversaries. They also explore the risks of non-technical employees "vibe coding" corporate applications and why CISOs must get hands-on with AI tools at home if they want to understand the risks their workforce is taking. Questions asked: (00:00) Introduction to Offensive AI and Black Hat 2026(02:00) Casey Ellis’s Background (Bugcrowd, Disclose.io)(04:00) Major Themes from RSA and Black Hat 2026(09:00) The Impact of Mythos and Daybreak on Security Awareness(12:30) Why Threat Researchers Are Hoarding Zero-Days(14:00) The "Slopdemic" vs. The "Vulnpocalypse"(17:30) Managing Noisy Bug Bounty Queues and Risk Models(20:00) The Futility of Export Controls on Frontier Models(25:00) Point-and-Pwn vs. Building Complex Attack Graphs(29:30) The Defender’s Dilemma and the Shrinking OODA Loop(34:00) Shadow AI and the Risks of Non-Technical "Vibe Coding"(38:30) Why CISOs Need Hands-On Experience with AI Tools(45:30) The Resurgence of Deception Technology Resources spoken about during the episode: Casey's Blog