MyDr Breach: Five Leaks, One Missing Disclosure Channel
Poland's MyDr leak, Change Healthcare, Salesloft Drift, Free Mobile and Tea share one trait: nobody outside had a supported way to report a flaw.
Hiring strategies, product updates, and engineering insights.
Poland's MyDr leak, Change Healthcare, Salesloft Drift, Free Mobile and Tea share one trait: nobody outside had a supported way to report a flaw.
Job scams made candidates distrust real recruiters too. Here's the data, and the trust infrastructure that proves your outreach is legit, not a scam.
Microsoft threatened a researcher with criminal charges, then backtracked in days. Here's how safe harbor in your vulnerability disclosure policy prevents that.
The Mercor breach exposed 4TB of candidate SSNs, passports, and video interviews. Here is why your ATS is a prime target and the privacy-by-design controls that shrink the blast radius.
From 11 September 2026, the EU Cyber Resilience Act forces software vendors to run coordinated vulnerability disclosure and report exploited bugs to ENISA on a 24-hour clock.
HackerOne cut Internet Bug Bounty rewards up to 89% on work already done. Here's how to set bug bounty tiers that survive AI slop without betraying researchers.
curl, HackerOne, and Nextcloud all buckled under AI-generated bug bounty slop in 2026. Here's the triage playbook that keeps a VDP alive under volume.
The North Korean IT worker scheme nets an estimated $250M-$600M a year by placing fake remote hires inside U.S. companies. Here's how to catch them at intake.
Researchers don't drop zero-days because they're hostile. They publish after slow acks, silent fixes, and severity downgrades. Keep them coordinating with you.
Displaying items 1-9 of 11 in total