Mercor’s 4TB Data Heist: When a Poisoned AI Library Exposed OpenAI and Meta’s Training Pipeline
A poisoned LiteLLM package led to 4TB stolen from Mercor, the AI training startup serving Meta, OpenAI, and Anthropic. Class action lawsuits filed ... Read More
DarkSword: The iPhone Exploit That Forced Apple to Rewrite Its Own Security Playbook
DarkSword silently compromises iPhones through website visits alone. 270M devices affected. Apple breaks its own policy with a rare iOS 18 security backport ... Read More
FBI Surveillance Network Breached: Salt Typhoon’s Quiet War on American Law Enforcement Infrastructure
FBI classifies breach of its surveillance network as a 'major incident.' Salt Typhoon suspected. Wiretap targets and investigation data potentially exposed ... Read More
State of CIAM 2026: 14 Trends from 200+ Vendor Changelogs
An annual research piece based on 12 months of monitoring 200+ CIAM vendor changelogs. The 14 trends shaping customer identity in 2026 and the vendors leading each shift ... Read More
How to Get Into Google’s Knowledge Graph: The Entity Playbook for AEO and GEO
Google's Knowledge Graph is the entity layer beneath AI Overviews, ChatGPT, and Perplexity. Here is the exact playbook for becoming a recognized, citable entity, and how AEO and GEO build on top of it ... Read More
bcrypt vs Argon2 vs scrypt vs PBKDF2: A 2026 Decision Framework
Most "use bcrypt" posts are from 2014. Argon2 won the Password Hashing Competition in 2015 and nobody updated. Here is the actual 2026 decision framework for picking a password hashing algorithm ... Read More
$250k+ in Startup Credits in 90 Days: The Application-Order Playbook
Founders apply for credits in random order and get rejected because they tripped a referral-required gate they could have unlocked first. Here is the sequence that unlocks $250k+ in 90 days ... Read More
Auth0 vs Okta vs Stytch vs WorkOS vs SSOJet (2026): A Buyer-Stage Framework
The five CIAM contenders in 2026 don't compete head-on. Each wins for a different stage and buyer. Here's the framework I use, with the honest tradeoffs each carries ... Read More
How to Protect Your Data Online Without a VPN: Encrypted DNS and Apple Private Relay (2026)
Your ISP logs every site you visit through unencrypted DNS lookups. Three free tools (Cloudflare 1.1.1.1, Google 8.8.8.8, Apple Private Relay) fix most of it. Here's how each one works and what it can't do ... Read More
The GEO Measurement Study: 50,000 AI Citations in 90 Days, What Actually Moves Citation Share
I tracked 50,000 citations across ChatGPT Search, Perplexity, Claude, Gemini, Google AI Overviews, and Bing Copilot for 90 days. What actually moved citation share, and what didn't ... Read More

