GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

New Zero-Day Buying Startup Linked to Convicted Felons and Fake Intel Firms

A company offering millions for software exploits is reportedly headed by two men with histories of fraud, fabricated credentials, and shuttered AI lobbying schemes.

A newly launched offensive security startup has been courting researchers with large payouts for zero-day vulnerabilities in widely used software, the kind of business model that typically requires significant trust from both the security community and government buyers. But according to reporting from Krebs on Security, the people behind the venture have a track record that undercuts that trust considerably.

The founders are described as two individuals with prior felony convictions who have previously operated under assumed identities. Their earlier projects reportedly included at least one bogus intelligence-gathering firm and an AI-powered lobbying platform that quietly folded before facing scrutiny. Both men are also linked to far-right conspiracy circles, adding another layer of concern for anyone considering doing business with the new company.

Exploit brokering is a legitimate, if controversial, corner of the security industry, with legitimate firms and government agencies paying well for undisclosed vulnerabilities. But the space runs almost entirely on reputation and vetting, since buyers and sellers are trading in tools that can be weaponized. A startup fronted by people with a documented history of deception is a red flag that researchers and potential clients will want to take seriously before engaging.

Why it matters: Zero-day brokers sit at a uniquely sensitive point in the security ecosystem, where a lack of accountability can mean exploits end up in the hands of authoritarian governments, criminal groups, or worse. Researchers selling to unvetted buyers risk having their work used against the very users they meant to protect, and this case is a reminder that flashy funding and slick branding don't substitute for due diligence on who's actually running the show.

Sources: Krebs on Security