← All organizations

Crowdsourced cybersecurity and AI security testing

Bugcrowd; Carnegie Mellon University

Bugcrowd provides a cybersecurity platform that connects security teams with hackers to find and address vulnerabilities. Its Bug Bounty offering supports continuous vulnerability hunting with payment for results, while vulnerability disclosure programs help organizations receive, prioritize, and remediate submissions. Penetration testing supports compliance work, and red teaming simulates real-world threats. Together, these services give organizations access to security expertise beyond their internal teams.

Founder Casey Ellis launched Bugcrowd and its first bug bounty programs in 2012; Dave Gerry is CEO. Bugcrowd acquired Mayhem Security in 2025, adding autonomous code and API testing capabilities. Mayhem’s research lineage includes its 2016 DARPA Cyber Grand Challenge win with a system that discovered, diagnosed, and repaired software flaws. Carnegie Mellon University is a separate institution: Mayhem originated with its researchers, and Bugcrowd’s Chief AI and Science Officer, David Brumley, is a Carnegie Mellon professor.

That acquisition also underpins Bugcrowd’s Reinforcement Learning Environments, which let AI developers train agents to find, exploit, and fix vulnerabilities in real software with scored feedback. Launched in 2026, the offering uses environments derived exclusively from open-source software. Beyond AI model development, Bugcrowd serves corporate and government security programs: in 2024, the company reported more than 1,200 customers, including OpenAI, Google, T-Mobile, and the U.S. Defense Department’s Chief Digital and Artificial Intelligence Office.

www.bugcrowd.com

1 talk

Newest first

1 speaker at AIE

Affiliations reflect their AIE appearances, not necessarily current employment.

Messages from the stage

Grading discoveries without rewarding shortcuts

Brumley emphasizes deterministic grading instead of LLM judges and audit tasks that assess multiple vulnerabilities. Reward hacking and evaluating newly discovered vulnerabilities remain challenges for this approach.

Affiliations reflect each recorded session, not necessarily current employment.

Company sources · checked 2026-08-28