Mercor’s 4TB Data Heist: When a Poisoned AI Library Exposed OpenAI and Meta’s Training Pipeline

A poisoned LiteLLM package led to 4TB stolen from Mercor, the AI training startup serving Meta, OpenAI, and Anthropic. Class action lawsuits filed ... Read More

DarkSword: The iPhone Exploit That Forced Apple to Rewrite Its Own Security Playbook

DarkSword silently compromises iPhones through website visits alone. 270M devices affected. Apple breaks its own policy with a rare iOS 18 security backport ... Read More

FBI Surveillance Network Breached: Salt Typhoon’s Quiet War on American Law Enforcement Infrastructure

FBI classifies breach of its surveillance network as a 'major incident.' Salt Typhoon suspected. Wiretap targets and investigation data potentially exposed ... Read More

State of CIAM 2026: 14 Trends from 200+ Vendor Changelogs

An annual research piece based on 12 months of monitoring 200+ CIAM vendor changelogs. The 14 trends shaping customer identity in 2026 and the vendors leading each shift ... Read More

How to Get Into Google’s Knowledge Graph: The Entity Playbook for AEO and GEO

Google's Knowledge Graph is the entity layer beneath AI Overviews, ChatGPT, and Perplexity. Here is the exact playbook for becoming a recognized, citable entity, and how AEO and GEO build on top of it ... Read More

bcrypt vs Argon2 vs scrypt vs PBKDF2: A 2026 Decision Framework

Most "use bcrypt" posts are from 2014. Argon2 won the Password Hashing Competition in 2015 and nobody updated. Here is the actual 2026 decision framework for picking a password hashing algorithm ... Read More

$250k+ in Startup Credits in 90 Days: The Application-Order Playbook

Founders apply for credits in random order and get rejected because they tripped a referral-required gate they could have unlocked first. Here is the sequence that unlocks $250k+ in 90 days ... Read More

Auth0 vs Okta vs Stytch vs WorkOS vs SSOJet (2026): A Buyer-Stage Framework

The five CIAM contenders in 2026 don't compete head-on. Each wins for a different stage and buyer. Here's the framework I use, with the honest tradeoffs each carries ... Read More

How to Protect Your Data Online Without a VPN: Encrypted DNS and Apple Private Relay (2026)

Your ISP logs every site you visit through unencrypted DNS lookups. Three free tools (Cloudflare 1.1.1.1, Google 8.8.8.8, Apple Private Relay) fix most of it. Here's how each one works and what it can't do ... Read More

The GEO Measurement Study: 50,000 AI Citations in 90 Days, What Actually Moves Citation Share

I tracked 50,000 citations across ChatGPT Search, Perplexity, Claude, Gemini, Google AI Overviews, and Bing Copilot for 90 days. What actually moved citation share, and what didn't ... Read More