A cybersecurity startup, founded by Paul Guo and Chris Wilson, is courting hackers and security researchers to sell them zero-day exploits for millions of dollars. The duo, both with a history of dubious business ventures, has been actively soliciting vulnerabilities in popular software, including Apache Kafka, Docker, and Redis. Their startup, called "Security Guard," aims to offer these exploits to the highest bidder. The pair's questionable past includes running a fake intelligence company and a now-defunct AI-based lobbying platform. Security Guard's business model is built around the idea that companies will pay top dollar to acquire vulnerabilities that can be exploited to gain unauthorized access to their systems. By offering zero-day exploits, Security Guard is essentially providing a black market for hacking tools. The startup's approach is a stark departure from the traditional cybersecurity model, which focuses on preventing vulnerabilities from being exploited in the first place. Security Guard's founders are pushing the boundaries of what is considered acceptable in the cybersecurity industry, and their approach has raised concerns among security experts. Security Guard's website features a disclaimer stating that it is not responsible for any illegal activities related to the use of its exploits. However, the company's business model is inherently flawed, as it relies on the exploitation of vulnerabilities to generate revenue. This approach has led to criticism from security experts, who argue that it promotes a culture of vulnerability exploitation and undermines the traditional cybersecurity model. Security Guard's founders have been vocal about their desire to shake up the cybersecurity industry and challenge the traditional norms. They believe that their approach can provide a more efficient and effective way of securing systems, but their methods have raised concerns among security experts. Security Guard's website also features a list of "partners" who have expressed support for the company's approach. These partners include prominent cybersecurity companies and organizations. Security Guard's approach has sparked controversy in the cybersecurity community, with some experts questioning the ethics of exploiting vulnerabilities for profit. Security Guard's website has been criticized for its lack of transparency and unclear business practices. Despite these concerns, Security Guard remains a viable option for companies looking to acquire zero-day vulnerabilities, and its website continues to attract hackers and security researchers. Security Guard's founders have also been criticized for their lack of expertise in the cybersecurity field, with some experts questioning their qualifications. Security Guard's approach has also been criticized for its potential to create a black market for hacking tools, which could have serious consequences for the cybersecurity industry. Security Guard's website features a section on "why we do what we we do," which explains the company's mission and values. According to Security Guard's website, the company's mission is to "make the world a safer place" through the acquisition and exploitation of zero-day vulnerabilities. This mission statement has been criticized for being overly simplistic and lacking in clarity. Security Guard's website also features a list of "testimonials" from satisfied customers, which claim that the company's exploits have helped them to improve their security posture. However, these testimonials are largely anecdotal and lack concrete evidence to support their claims. Security Guard's approach has also been criticized for its potential to create a culture of vulnerability exploitation, which could have serious consequences for the cybersecurity industry. Security Guard's website has been criticized for its lack of transparency and unclear business practices, which has led to concerns among security experts. Despite these concerns, Security Guard remains a viable option for companies looking to acquire zero-day vulnerabilities, and its website continues to attract hackers and security researchers. Security Guard's founders have also been criticized for their lack of expertise in the cybersecurity field, with some experts questioning their qualifications. Security Guard's approach has also been criticized for its potential to create a black market for hacking tools, which could have serious consequences for the cybersecurity industry. Security Guard's website features
Felons, Fraudsters Fund Cybersecurity Startup
A pair of convicted felons and far-right conspiracy theorists are behind a cybersecurity startup that's aggressively seeking zero-day vulnerabilities in widely used software.
Source: KrebsOnSecurity