:

CYBERSECURITY STARTUP RUN BY CONVICTED FELONS

SECURITY DESK1 MIN READ
WED, JUL 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A vulnerability acquisition startup offering millions for zero-day exploits is operated by convicted felons with ties to far-right conspiracy theories, according to reports. The founders previously ran fake intelligence companies and an AI lobbying platform under assumed identities.

The startup sources security vulnerabilities in widely-used software, a practice that exists in a gray area of the cybersecurity industry. However, the backgrounds of its operators raise significant concerns about how acquired vulnerabilities might be used. The founders' prior ventures operated under false identities and included entities misrepresenting themselves as intelligence agencies. Their involvement in conspiracy theory circles adds another layer of scrutiny to the operation. Zero-day vulnerability markets have drawn regulatory attention in recent years, with policymakers debating whether such transactions should be restricted or regulated. The U.S. government has expressed concerns about exploits potentially reaching malicious actors. The startup's operational status and any regulatory response remain unclear at this time.

■ SOURCES

Krebs on Security

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Top Chinese military strategists have published analyses detailing artificial intelligence's role in accelerating command decision-making. The writings offer insight into Beijing's military modernization efforts.

1H AGOAI Desk

Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI models to generate exploit code and scan networks, according to Taiwanese cybersecurity firm TeamT5.

1H AGOAI Desk

AliExpress deployed an outdated browser fingerprinting technique using ultrasonic frequencies to identify and track users. Security researchers discovered the e-commerce platform embedding inaudible sounds in web pages to create unique device signatures.

2H AGOIndustry Desk

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass network protections and expose devices on private networks to the internet. The flaw affects routers deployed by multiple U.S. broadband providers.

13H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.