Exposed: Shady Startup Buying Software Vulnerabilities Run by Convicted Felons
Investigative reporting from Krebs on Security has revealed that a company offering large payouts for previously unknown software vulnerabilities (known as zero-days) is being run by individuals with a troubling history. The founders are described as far-right conspiracy theorists and convicted felons who previously operated fake intelligence companies and an AI-based lobbying platform under assumed identities.
Zero-day vulnerabilities are highly valuable because they can be exploited before software vendors even know they exist, making them attractive to both defenders and attackers. Legitimate vulnerability research and acquisition firms exist to help improve security, but the credibility and intentions of the buyers matter greatly — vulnerabilities sold to bad actors, or handled irresponsibly, can end up weaponised against businesses, governments, and critical infrastructure.
This case is a reminder that the market for security vulnerabilities is not always transparent, and that not every company claiming to work in "offensive security" operates with ethical or accountable practices. Businesses and security researchers should be cautious about who they engage with when reporting or selling vulnerability information.