@LutaSecurity

#1 process planning partners for vuln disclosure & bug bounties. More bugs won't help you fix a broken process! Stop premature bountification.

United States
Joined April 2016
Bug bounties under NDA are not the answer to your security woes with hackers. Hear from our CEO @k8em0 on that & other insights on how AI is changing cybersecurity & how UBI might heal a broken labor market in her interview with @Williamrt for @ComputerWeekly
I spoke with @Williamrt of @ComputerWeekly on NDA bug bounties failing to increase security & the effects of gov disclosure requirements on national security, plus how AI threatens the human expert labor pipeline of tomorrow & why UBI may be our best bet
1
2
898
@LutaSecurity is proud to be a returning sponsor for @SentinelOne @labscon_io 🌺 September 17-20, 2025 labscon.io/
2
1
4
2,513
Luta Security retweeted
🎤 Speaking at #BindingHookLive: @k8em0, founder and CEO of @LutaSecurity. 📩 Request your invite: bindinghooklive.com
4
5
1,493
. @CurrentJen tops the list of people who have enabled me to grow as a person & professional. She’s the best person to strategically work towards company goals while effortlessly handling the gnarliest security crisis comms. Hire Jen Wood if you “take security very seriously.”
After five incredible years at @LutaSecurity, I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!
1
8
22
6,042
Luta Security retweeted
🎤 Keynote Announcement 🎤 We're excited to announce Katie Moussouris (@k8em0) as keynote speaker for No Hat 2025! Founder/CEO of @LutaSecurity, leading voice in vuln disclosure & bug bounties. Seen at Black Hat, DEF CON, RSA now live in Bergamo, Italy on Oct 18th! #nohat2025
4
21
1,851
When I testified before US Congress about the Uber data breach when they misused their bug bounty program to pay off data thieves, I didn’t think I would have to update my core guidance to include this: Don’t let extortionists set your bounty reward price. Coinbase was *right* not to pay extortion, but putting up a “reward pool” for the same $20M amount is ultimately going to lead future criminals to groom more minors to commit crimes & turn them in to reap the rewards. Defense cannot pay the same as offense or you create perverse incentives. In this case, it’s just adding steps to exploit a company for huge sums, not an effective deterrent. It’s tempting to flex with huge rewards, but the disruption to criminals is negligible & ultimately increases the cost to protect customers. Cryptocurrency exchanges & others should consult with us on complex situations like this. You know where to find us: @LutaSecurity
Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on <1% of Coinbase MTUs. No passwords, private keys, or funds were exposed. Prime accounts are untouched. We will reimburse impacted customers. More here: coinbase.com/blog/protecting…
2
6
29
3,310