Sam Bowne 

1.4K Followers
735 Following
30K Posts
Instructor at CCSF, corporate trainer for Infosec Decoded.
websitehttps://samsclass.info
Elon Musk insists banks working on SpaceX IPO must buy Grok subscriptions
Some banks "agreed to spend tens of millions on the chatbot," NYT reports.
https://arstechnica.com/tech-policy/2026/04/elon-musk-insists-banks-working-on-spacex-ipo-must-buy-grok-subscriptions/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk
https://www.wired.com/story/meta-pauses-work-with-mercor-after-data-breach-puts-ai-industry-secrets-at-risk/
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Major AI labs are investigating a security incident that impacted Mercor, a leading data vendor. The incident could have exposed key data about how they train AI models.

WIRED

Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year.

https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/

Device code phishing attacks surge 37x as new kits spread online

Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year.

BleepingComputer
Better To Die In Iran

YouTube

Node.js pauses bug bounty program after a funding lapse

They were sponsored by IBB, a program funded by Microsoft, Meta, Adobe, and a bunch of other tech giants

Unclear what happened there

https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties

Node.js — Security Bug Bounty Program Paused Due to Loss of Funding

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

Squiblydoo has released the CertGraveyard, a centralized place to document the abuse of code-signing certificates

https://certgraveyard.org/

https://squiblydoo.blog/2026/04/01/the-certgraveyard/

The Cert Graveyard

Perplexity's "Incognito Mode" is a "sham," lawsuit says
Google, Meta, and Perplexity accused of sharing millions of chats to increase ad revenue.
https://arstechnica.com/tech-policy/2026/04/perplexitys-incognito-mode-is-a-sham-lawsuit-says/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
SpaceX claims Amazon Leo launches could crash into Starlink satellites
Amazon denies violation, says SpaceX caused conflict by lowering Starlink satellites.
https://arstechnica.com/tech-policy/2026/04/spacex-claims-amazon-leo-launches-could-crash-into-starlink-satellites/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
3D Print-blocking laws hand monopolistic power to manufacturers and can criminalize open source alternatives. We need to reject these onerous restraints on creation. https://www.eff.org/deeplinks/2026/04/print-blocking-anti-consumer-permission-print-part-1
Print Blocking is Anti-Consumer - Permission to Print Part 1

When legislators give companies an excuse to write untouchable code, it’s a disaster for everyone. This time, 3D printers are in the crosshairs across a growing number of states. Even if you’ve never used one, you’ve benefited from the open commons these devices have created—which is now under threat. We need to roundly reject these onerous restraints on creation.

Electronic Frontier Foundation
Some GWU students to pay over $98,000 for 2026-27 year, estimate shows https://archive.is/UkPqL