GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

New Zero-Day Buying Startup Linked to Convicted Felons and Fake Intel Firms

A company offering millions for software exploits is reportedly headed by two men with histories of fraud, fabricated credentials, and shuttered AI lobbying schemes.

A newly launched offensive security startup has been courting researchers with large payouts for zero-day vulnerabilities in widely used software, the kind of business model that typically requires significant trust from both the security community and government buyers. But according to reporting from Krebs on Security, the people behind the venture have a track record that undercuts that trust considerably.

The founders are described as two individuals with prior felony convictions who have previously operated under assumed identities. Their earlier projects reportedly included at least one bogus intelligence-gathering firm and an AI-powered lobbying platform that quietly folded before facing scrutiny. Both men are also linked to far-right conspiracy circles, adding another layer of concern for anyone considering doing business with the new company.

Exploit brokering is a legitimate, if controversial, corner of the security industry, with legitimate firms and government agencies paying well for undisclosed vulnerabilities. But the space runs almost entirely on reputation and vetting, since buyers and sellers are trading in tools that can be weaponized. A startup fronted by people with a documented history of deception is a red flag that researchers and potential clients will want to take seriously before engaging.

Why it matters: Zero-day brokers sit at a uniquely sensitive point in the security ecosystem, where a lack of accountability can mean exploits end up in the hands of authoritarian governments, criminal groups, or worse. Researchers selling to unvetted buyers risk having their work used against the very users they meant to protect, and this case is a reminder that flashy funding and slick branding don't substitute for due diligence on who's actually running the show.

Sources: Krebs on Security