







Since CDK discovered the breach and shut off systems on June 19, chaos has ensued at many of the roughly 15,000 car dealerships that it counts as clients.
How a 40-Minute Window Brought Down a $10 Billion AI Startup: The Mercor Data Breach, Explained
A poisoned open-source package, a credential-stealing payload, and 4 terabytes of stolen data here’s what every AI company needs to learn…

Mercor Data Breach | What You Need to Know
A massive data breach at AI startup Mercor exposes risks in AI supply chains, third-party tools, and data governance. Here’s what security teams need to know.

AI Agent Executes 'First' End-To-End Ransomware Attack - Slashdot
Sysdig says it has documented the first ransomware attack carried out end to end by an AI agent, which autonomously exploited exposed systems, stole credentials, established persistence, compromised a production database, and destroyed data. The research team named the attacker "JadePuffer" and said...


What Happened to HackerOne?
The rise and fall of the largest bug bounty platform in the world

Bug bounty businesses bombarded with AI slop
Never-ending" AI slop strains corporate hacking reward schemes.

Hacking Capitalism | A Guide To Exploiting The Tech Industry
This is an independently published book about modeling the tech industry as a system. Particularly this book will model computers, humans, and money and their subsequent relationships. Understand the alarming state of the tech industry for better or for worse.

Hackathon on Decentralised Media - TEP (Trusted European Platforms) Bluesky, Nostr · Luma
Every year, thousands of developers of free and open-source software from all over the world gather at FOSDEM. For two weeks around this event – from the 26th…
Mercor, a $10 billion AI startup, confirms it was caught up in a major security incident | Fortune
The high-flying startup that provides AI training data to OpenAI, Anthropic, and Meta confirms it was hit by a “supply-chain attack.”

The $11 Billion Marketplace Enabling the Crypto Scam Economy
Deepfake scam services. Victim data. Electrified shackles for human trafficking. Crypto tracing firm Elliptic found all were available for sale on an online marketplace linked to Cambodia’s ruling family.

“Claude Mythos doesn’t just find vulnerabilities - it exploits them” | Ctech
Anthropic restricts access to its most powerful AI model to around 40 companies, including Apple, Google, Microsoft, Amazon, Nvidia, Palo Alto Networks and CrowdStrike, as part of a $100 million cybersecurity initiative aimed at using the system to detect and patch critical software flaws before similar capabilities spread more widely across the ecosystem.

Dark Code
A few months ago, a founder I know had a data leak that took his security team four days to understand.

Politically Connected Crypto Project Pursued Resort With Alleged Scam Syndicate Figures
AB is a little-known blockchain network that recently partnered with the Trump family’s crypto firm. But one of the projects it has promoted — a proposed crypto technology resort in Southeast Asia — involved people sanctioned by the U.S. last year for ties to the Prince Group, an alleged multibillion-dollar fraud...

Five US tech giants' hidden debts soar to $1.65tn on opaque AI funding
Data center leases, GPU supply contracts raise liabilities at Meta, Oracle, Nikkei study shows

AI Companies Are Trying to Hide a Staggering Amount of Debt
AI companies are pouring tens of billions of dollars into enormous data centers. They're being built on top of a mountain of hidden debt.

The hacker crackdown: law and disorder on the electronic frontier
A journalist investigates the past, present, and future…
