Katie Moussouris (she/her/she-hulk/she-ra)🌻
banner
k8em0.bsky.social
Katie Moussouris (she/her/she-hulk/she-ra)🌻
@k8em0.bsky.social
Founder & CEO LutaSecurity @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, 1/2 Greek all-American hacker
Ed is right about:
AI hype/bubble/can’t yet do what’s advertised

Ed fails to recognize: the market doesn’t give a fuck whether any of AIs promises are true - people are losing their jobs to hype

Give Ed’s annotation a read for reality checks on the facts, but don’t ignore the labor market quake
This piece is bullshit and rife with misinformation
bsky.app/profile/edzi...
Made an annotated version of "Something Big Is Coming" for all of you to enjoy. I hate this guy's writing so much
www.dropbox.com/scl/fi/qw6k5...
February 12, 2026 at 6:44 PM
“you deserve to hear this from someone who cares about you, not from a headline six months from now when it's too late to get ahead of it.”

Read this by @mattshumer.bsky.social because I care about you, even those of you I’ve never met.

We share the bond of humanity. 💞

shumer.dev/something-bi...
Something Big Is Happening
A personal note for non-tech friends and family on what AI is starting to change.
shumer.dev
February 12, 2026 at 4:08 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
February 6, 2026 at 3:59 PM
I’m so inspired by young people getting involved in their communities, running for office, & driving progressive change.

“Just do something & you’ll end up where you want to go.”
— Vivek Prakriya, Redmond City Councilmember & youngest elected in a city with over 75k residents in America

Go Vivek!
Vivek Prakriya is a Redmond City Councilman and the LD48 Democrats’ representative to King County Young Democrats.

We spoke with him about what motivated him to become politically active, and how young people can participate in politics.
#LD48Dems #WADems #KingCountyDemocrats #Democrats
February 2, 2026 at 1:30 AM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
The FBI was able to access Washington Post reporter Hannah Natanson's Signal messages because she used Signal on her work laptop. The laptop accepted Touch ID for authentication, meaning the agents were allowed to require her to unlock it. storage.courtlistener.com/recap/gov.us...
January 31, 2026 at 5:59 PM
Have we reached the stage of “many AIs make all bugs shallow”?
Great writeup on AI, open source, & bug bounties by @stanislavfort.bsky.social cofounder of AISLE.

“Mass adoption collapsed the median quality (“slop” killed bug bounty..) but.. raised the ceiling”

www.lesswrong.com/posts/7aJwgb...
AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty) — LessWrong
This is a partial follow-up to AISLE discovered three new OpenSSL vulnerabilities from October 2025. …
www.lesswrong.com
January 30, 2026 at 7:18 PM
Oh node! 😱 Low quality bug reports breaking another Open Source project. Trying to throttle the flood using a bug bounty platform reputation system & forking bug reporters with low signal score to…the OpenJS Foundation Slack?! Oh node indeed 😩
⚠️ The Node.js Project now requires a HackerOne Signal score of 1.0 or higher to submit vulnerability reports. This will help our team streamline reports and support effective security reviews.

nodejs.org/en/blog/anno...
Node.js — New HackerOne Signal Requirement for Vulnerability Reports
Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.
nodejs.org
January 23, 2026 at 12:38 AM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
You don’t have to run for office to help shape what happens next. 👀

Becoming a delegate is one of the easiest ways to show up, speak up, and help decide the future of our party. Self-nominate here: Tinyurl.com/26DemDelegate

LD 48 Dems need you. Yep, you. ✨

Sign up and get in the room. 💙🗳️
January 21, 2026 at 4:19 AM
AI was the accelerant on a perverse incentive fire sparked by bug bounty platforms that reward spray & pray. Both open source & orgs without dedicated vuln response teams get overloaded when they offer cash there. cURL is right to leave AI shark-infested waters to start fresh.
January 21, 2026 at 2:55 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
I think there is a discussion to be had here, but it shouldn't be taken out on people who are *using* AI.

we do need to have a reckoning about how UBI gets passed and funded, with taxation of the profits of those developing these labour-replacing/augmenting models. but yelling at users doesn't help
i think a core beef that i have with a lot of this "automation is bad" sentiment lately is that there is no inherent moral good in laboring

the story of humanity is one of invention, where we improve our conditions by building things that help us do more things more easily
I've been sitting with the discomfort here a bunch, and to me this is it, right? What is being suggested is that I engage in an act of self-flagellation (resolving thousands of lines of merge conflicts by hand) because the richest man in the world uses some of the same underlying tech to peddle CSAM
January 10, 2026 at 7:40 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
We’re mobilizing across the country this weekend to honor Renee Nicole Good, demand accountability for ICE’s killing of Renee, and make visible the human cost of ICE’s terror: docs.google.com/document/d/1...
January 9, 2026 at 3:11 AM
“Unbeknownst to Smith at the time, she had no right to vote… much less run for office. Though she was born in a U.S. territory, and has a U.S. passport and Social Security number, she is not a U.S. citizen.

American Samoa is the only US territory where people are born without automatic citizenship”
Eleven American Samoans in Alaska face serious prison time for voting in the only country they’ve ever known. Theirs is a wild story of colonialism, cops, “voter fraud” panic, small-town beef, and family. I spent months on this + am so glad to now be able to share it: boltsmag.org/prosecuted-f...
Americans by Name, Punished for Believing It - Bolts
In a small Alaska town, American Samoans face prosecution for voting in the only country they’ve ever known. They live in a limbo, created by colonial expansion, that now confuses even public official...
boltsmag.org
January 8, 2026 at 8:12 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
Puerto Rico enters the chat with a line forming behind it, including Guam, the US Virginia Islands, Guam, the Northern Marinara Islands....
KERNEN: Europeans are talking about it almost being like Vladimir Putin and Ukraine.

JEFF LANDRY: I disagree. When has the United States engaged in imperialism? Never. Europe has engaged in imperialism. The reason the Danish have Greenland is because of imperialism.
January 6, 2026 at 7:35 PM
“Why would free money make people work more? Because it takes money to make money. Basic income acts like venture capital for regular people.”
New article from me today about a centuries-old policy in Brazil that has a lot to tell us about just how high a universal basic income can be set at without seeing the effects on employment that so many people assume.
The 200-Year Experiment: How a 'Privileged' Basic Income in Brazil Proves We Can Afford to Be Universal
From $500 to $15,000 a Month: How Decades of Data Prove That an Unconditional Basic Income Guarantee Fuels Ambition Instead of Laziness
open.substack.com
January 6, 2026 at 4:28 PM
Happy #SouperBowlSundat to all who celebrate 🍲 🎉

www.eatingwell.com/recipe/26574...
(I used bone broth, doubled it & the & thickener, & added fresh thyme, kale 🥬, & salt)
December 28, 2025 at 9:43 PM
The ensloppification* of the internet continues, with VC backing

*/ht Cory Doctorow for “enshittification”
NEW: A hacker gained control of 1,100 mobile phones powering covert, AI-generated ads on TikTok. Then, he shared details of the operation with 404 Media.

A look inside how startup Doublespeed, which is backed by Andreessen Horowitz (a16z), is creating AI spam pages on TikTok to promote products.
Hack Reveals the a16z-Backed Phone Farm Flooding TikTok With AI Influencers
A hacker gained control of a 1,100 mobile phone farm powering covert, AI-generated ads on TikTok.
www.404media.co
December 17, 2025 at 6:26 PM
““UBI = a foundation…income is earned on top. A poverty-line UBI is not “the replacement paycheck for the post-work apocalypse.” .... It prevents the worst outcomes, stabilizes consumer demand, & gives ppl leverage to say no to exploitation”
New article from me in response to Eduardo Porter's article in The Guardian where he built a straw man of universal basic income to light on fire again, just as he did back in 2016, showing he's learned nothing new about UBI in a decade but is still happy to opine about it.
Eduardo Porter is Still Wrong About UBI and AI: A Response to The Guardian
Universal Basic Income Isn’t a Job Replacement Plan—It’s an AI Dividend and Stable Income Floor That Protects Work, Wages, and Democracy
open.substack.com
December 17, 2025 at 5:59 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
The "basic" in universal basic income does not mean low. It means basic as in base. Foundational. Primary. First. Basic income is an income floor. All other income adds to it. It's basic income because it's everyone starting income.
December 12, 2025 at 8:23 PM
Reposted by Katie Moussouris (she/her/she-hulk/she-ra)🌻
When it comes to developing skills through underground organizations, recent geopolitical issues have also helped muddy the waters of how some professionals think about ways to earn a living, said Casey Ellis, founder at @Bugcrowd.

www.dice.com/career-advic...
Dark Web, Underground Hiring Blurs Lines Between Legit and Illicit Work
Some skilled tech and cybersecurity pros are turning to underground forums for work, drawn by lucrative but illegal opportunities. Experts caution that these jobs blur the line between legitimate and…
m.cje.io
December 12, 2025 at 12:27 AM
We’ve seen other orgs attempt 3rd party bug bounties, thinking it will help their ecosystem become safer. Inevitably, the safety of software depends more on the maturity of the org producing it than how many bugs are reported to it. Bug foie gras isn’t the safest path to maturity
When I started Microsoft Vuln Research in 2008, we found out just how few orgs were ready for vuln disclosure. When I started Microsoft’s 1st bug bounty in 2013, I never imagined it would grow to paying for 3rd party bugs. I hope the 3rd parties were warned & OSS gets tested patches supplied to them
As announced by Tom Gallagher, VP of Engineering, MSRC, on stage at Black Hat EU, we’re evolving our bug bounty program. Now, high-severity vulnerabilities that directly impact Microsoft online services are eligible for bounty awards, whether the code is Microsoft-owned, third-party, or open source.
December 11, 2025 at 6:42 PM
When I started Microsoft Vuln Research in 2008, we found out just how few orgs were ready for vuln disclosure. When I started Microsoft’s 1st bug bounty in 2013, I never imagined it would grow to paying for 3rd party bugs. I hope the 3rd parties were warned & OSS gets tested patches supplied to them
As announced by Tom Gallagher, VP of Engineering, MSRC, on stage at Black Hat EU, we’re evolving our bug bounty program. Now, high-severity vulnerabilities that directly impact Microsoft online services are eligible for bounty awards, whether the code is Microsoft-owned, third-party, or open source.
December 11, 2025 at 6:24 PM
I spoke with @billgoodwin.bsky.social of @computerweekly.bsky.social on NDA bug bounties failing to increase security & effects of gov disclosure requirements on nat security, plus how AI threatens the future human expert pipeline & why UBI may be our best bet
www.computerweekly.com/news/3666362...
Why bug bounty schemes have not led to secure software | Computer Weekly
Computer Weekly speaks to Kate Moussouris, security entrepreneur and bug bounty pioneer, about the life of security researchers, bug bounties and the artificial intelligence (AI) revolution.
www.computerweekly.com
December 9, 2025 at 2:11 PM
“AI is helping to identify over 70% of targets. Sometimes AI is hallucinating targets. So we always need humans in the loop.” - Heli Tiirmaa-Klaar in her SANS CyberThreat keynote “Cyber war by proxy: What Ukraine teaches us about
defense coalitions and digital policy at scale”
December 4, 2025 at 10:30 AM