@LutaSecurityi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
#1 process planning partners for vuln disclosure & bug bounties. More bugs won't help you fix a broken process! Stop premature bountification.
United States
Joined April 2016
- Tweets502
- Following88
- Followers5.6K
- Likes473
Pinned Tweet
This Hacker Is Trying to Close the Gender Pay Gap in Cybersecurity vice.com/en/article/xgyvza/t… via @motherboard & featuring @LutaSecurity CEO @k8em0
Bug bounties under NDA are not the answer to your security woes with hackers. Hear from our CEO @k8em0 on that & other insights on how AI is changing cybersecurity & how UBI might heal a broken labor market in her interview with @Williamrt for @ComputerWeekly
I spoke with @Williamrt of @ComputerWeekly on NDA bug bounties failing to increase security & the effects of gov disclosure requirements on national security, plus how AI threatens the human expert labor pipeline of tomorrow & why UBI may be our best bet
@LutaSecurity is proud to be a returning sponsor for @SentinelOne @labscon_io 🌺
September 17-20, 2025
labscon.io/
Luta Security retweeted
🎤 Speaking at #BindingHookLive: @k8em0, founder and CEO of @LutaSecurity. 📩 Request your invite: bindinghooklive.com
Luta Security retweeted
. @CurrentJen tops the list of people who have enabled me to grow as a person & professional. She’s the best person to strategically work towards company goals while effortlessly handling the gnarliest security crisis comms. Hire Jen Wood if you “take security very seriously.”
After five incredible years at @LutaSecurity, I’ll be moving on at the end of the month and looking for a new senior communications leadership role within the cybersecurity industry. For more info about my background, please read: tinyurl.com/yeyw4xb6. Thanks!
Luta Security retweeted
🎤 Keynote Announcement 🎤
We're excited to announce Katie Moussouris (@k8em0) as keynote speaker for No Hat 2025!
Founder/CEO of @LutaSecurity, leading voice in vuln disclosure & bug bounties. Seen at Black Hat, DEF CON, RSA now live in Bergamo, Italy on Oct 18th!
#nohat2025
You shouldn't have a #bugbounty program if you’re unwilling to fix your internal processes to handle the intake, have context-aware triage, and deploy comprehensive fixes of reported vulnerabilities. Contact @LutaSecurity today to learn more or get help! lutasecurity.com/post/vulner…
Need help managing your #VDP or #BugBounty Program? @LutaSecurity has the right solution to fit your needs and budget. #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/bug-bounty-…
Includes comments from @LutaSecurity CEO @k8em0
NIST's 'LEV' Equation to Determine Likelihood a Bug Was Exploited: bit.ly/3ZnWmVa by Alexander Culafi #DRTheEdge
Do you need a #security maturity assessment or an audit for your #bugbounty program? Hire @LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/bug-bounty-…
Do you need a security maturity assessment or an audit for your #bugbounty program? Hire @LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure and handling processes. #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/bug-bounty-…
Are the unpatched bugs piling up within your organization? @LutaSecurity can help fix your broken vuln management & improve your security ROI. Contact us today! #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/solutions
Contact @LutaSecurity today for a #security maturity audit and roadmap for building or fixing your organization’s #vulnerability handling processes. #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/solutions
Luta Security retweeted
When I testified before US Congress about the Uber data breach when they misused their bug bounty program to pay off data thieves, I didn’t think I would have to update my core guidance to include this:
Don’t let extortionists set your bounty reward price.
Coinbase was *right* not to pay extortion, but putting up a “reward pool” for the same $20M amount is ultimately going to lead future criminals to groom more minors to commit crimes & turn them in to reap the rewards.
Defense cannot pay the same as offense or you create perverse incentives.
In this case, it’s just adding steps to exploit a company for huge sums, not an effective deterrent.
It’s tempting to flex with huge rewards, but the disruption to criminals is negligible & ultimately increases the cost to protect customers.
Cryptocurrency exchanges & others should consult with us on complex situations like this.
You know where to find us:
@LutaSecurity
Cyber criminals bribed and recruited rogue overseas support agents to pull personal data on <1% of Coinbase MTUs. No passwords, private keys, or funds were exposed. Prime accounts are untouched. We will reimburse impacted customers. More here: coinbase.com/blog/protecting…
#Cryptocurrency Exchanges—Do you need a security maturity assessment? Do you need an audit for your #bugbounty program? Hire @LutaSecurity—the only company led by a co-author of the international standards on vuln disclosure & handling processes. #crypto lutasecurity.com/bug-bounty-…
Are the bugs piling up from your #VDP or #bugbounty program? @LutaSecurity can help clean out your backlog & fix your processes. Contact us today! #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/bug-bounty-…
Does your organization need a security maturity assessment and roadmap for improving its security posture? @LutaSecurity can help you find emerging threats before your adversaries do. Contact us today! lutasecurity.com/solutions #DontLetTheBugsPileUp #FixYourBrokenProcess
Check out the latest episode of @hackersonrocks featuring @LutaSecurity CEO @k8em0 discussing the Pall Mall Process, vuln disclosure, the researcher community, and more. youtube.com/watch?v=3wLRrVTx…
As cyber adversaries become more adept at exploiting weaknesses, organizations must prioritize maturity, so having a partner like @LutaSecurity is vital to your comprehensive #security strategy. Learn more at: lutasecurity.com/post/buildi…
Need a bug bounty program audit? Get it from the international standards co-author @LutaSecurity's CEO & founder @k8em0 #DontLetTheBugsPileUp #FixYourBrokenProcess
lutasecurity.com/bug-bounty-…
Are the unpatched bugs piling up within your organization? @LutaSecurity can help fix your broken vuln management & improve your security ROI. Contact us today! #DontLetTheBugsPileUp #FixYourBrokenProcess lutasecurity.com/solutions