Connect with us
DAPA Banner
DAPA Coin
DAPA
COIN PAYMENT ASSET
PRIVACY · BLOCKDAG · HOMOMORPHIC ENCRYPTION · RUST
ElGamal Encrypted MINE DAPA
🚫 GENESIS SOLD OUT
DAPAPAY COMING

Tech

FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

Published

on

Fortinet

A newly discovered data leak dubbed “FortiBleed” has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.

The exposed data was first discovered by security researcher Bob Diachenko, who says he found a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords.

According to screenshots and information shared by Diachenko, the database contains entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and many others. 

image

“Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action,” Diachenko posted on LinkedIn.

“Thousands of top vendors instances are listed in the files like this (see screenshot). This one alone has 21,634 domain names – from Chevron to Fortinet itself. All – with potentially working passwords to the FortiGate appliances obtained through various menas.”

Advertisement

The exposed data also included comments listing each organization’s industry, revenue, and number of employees, likely for planning attacks.

Fortinet credentials found on an exposed server
Fortinet credentials found on an exposed server
Source: Diachenko

Diachenko later shared additional information that claimed the operation was conducted by a Russian-speaking multi-operator threat group that harvested credentials for FortiGate SSL VPN devices.

According to Diachenko’s investigation, the attackers allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and an additional 2.1 billion attempts against 163,650 Microsoft SQL Server systems.

He further claimed the threat actors intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used the recovered credentials to move laterally into internal Active Directory environments.

Diachenko told BleepingComputer he obtained these details after analyzing additional files inadvertently exposed on the same server.

Advertisement

“They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc,” Diachenko explained.

The researcher also stated that multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. 

Threat intelligence company Hudson Rock has since published its own analysis of the exposed data after receiving the dataset from Diachenko. The company described the collection as one of the largest known troves of compromised Fortinet-related credentials.

According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. 

Advertisement

The company says the attackers maintained detailed logs of successful compromises and assembled a database containing verified credentials for organizations across nearly every major industry sector. 

Among the organizations Hudson Rock says appear in the dataset are Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. 

The company also released statistics showing that the highest number of affected devices was in India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates.

The most common sectors for the listed companies are telecommunications, IT services, financial services, government organizations, healthcare providers, educational institutions, and manufacturing.

Advertisement

One strange aspect of the leak is that many of the exposed credentials were long, complex passwords that would ordinarily be considered difficult to crack.

Believed to be extracted from Fortinet configs

Cybersecurity researcher Kevin Beaumont independently reviewed portions of the exposed data and told BleepingComputer that some of the credentials are authentic.

“I have been able to confirm the authenticity of some of the admin logins and passwords – this looks like a real dump,” Beaumont said.

After further review of the data shared by Hudson Rock, Beaumont published additional findings indicating that the dataset contains credentials for roughly 75,000 Fortinet devices, most of which remain online.

Advertisement

According to Beaumont, the data appears to have originated from exported Fortinet configurations because it contains information, including email addresses, that is typically only accessible through configs.

He also said the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak, further indicating that this is a more recent and larger collection of compromised devices.

Beaumont said he verified that multiple organizations listed in the dataset were using valid credentials and observed that many affected devices were running relatively recent FortiOS versions.

“The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data,” Beaumont wrote.

Advertisement

Based on network data from Shodan, Beaumont says the leak contains approximately half of all internet-accessible Fortinet firewalls and said that a majority of the affected devices expose their FortiGate management interfaces directly to the internet.

The source of the configuration data remains unknown, with it unclear whether it was stolen through previously disclosed Fortinet vulnerabilities, a newly discovered flaw, or another method. Neither Diachenko, Hudson Rock, nor Beaumont have identified how the configuration data was originally obtained.

Hudson Rock has created a free FortiBleed lookup tool to check if your organization is impacted.

Organizations in the dataset should immediately rotate passwords associated with Fortinet VPN and administrative interfaces, enforce MFA, examine gateway logs for suspicious activity, and monitor for exposed employee credentials.

Advertisement

BleepingComputer contacted Fortinet regarding the exposed dataset and will update this article if we receive a response.


article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech

A New Middle Class of Content Creators Is Quietly Quitting the 9-to-5

Published

on

“The rise of TikTok, Instagram Reels and Amazon storefronts has created a new kind of white-collar exit strategy,” reports Bloomberg. Workers ditch office jobs not to become celebrities, necessarily, “but to piece together an income online through brand deals, affiliate links and highly personal videos documenting everyday life.”

In many cases, the followers necessary to sustain a living are smaller (and more attainable) than people might assume. A small but loyal audience can now generate enough income to rival a midlevel salary. Welcome to the middle-class creator economy. Last year, 25-year-old Abi Platock balanced a corporate marketing job in New York while posting online in her spare time. She built her audience by posting one or two videos a day, offering career advice, beauty tips and daily vlogs. “I signed my first brand deal in the four-figure range, and for me that was just such a big eye-opening moment,” Platock says of her partnership with deodorant brand Secret. She had 8,000 followers on TikTok at the time. “You can totally make it work without having hundreds of thousands of followers.” Platock, who now has roughly 25,000 followers across platforms, has signed about $25,000 in brand deals so far this year and expects her annual creator income to reach around $50,000 by yearend.

Her experience reflects a broader shift in advertising. Brands are increasingly moving money toward so-called microinfluencers — smaller online personalities who have less than 100,000 followers. “They are hiring a bunch of microcreators at scale instead of hiring a handful of macrocreators for what could potentially be the same cost,” says Ali Grant, co-chief executive officer of the Digital Department, a creator management company. And they perform where it matters most: engagement. An engagement rate of 3% is considered strong, and some microinfluencers exceed 10%, Grant says of the closely watched metric that tracks how often followers interact with content through likes, comments, shares and saves. Microinfluencers average a 3.2% engagement rate, almost triple the 1.1% rate for macroinfluencers (more than 1 million followers), according to growth marketing agency ATTN… A TikTok partnership with a creator who has around 50,000 followers can run a brand more than $3,500 for a single post, Grant says; with 10 times the followers, that fee might just triple, to around $10,000….

The influencer marketing economy ballooned to a projected $33 billion in 2025 up from $1.7 billion in 2015. The segment gained momentum after the COVID-19 pandemic, as dissatisfaction with traditional work pushed many to reconsider conventional career paths, says Brooke Duffy, a professor of communications at Cornell University. “They realized the trade-offs in terms of the investments of time, energy and human capital were not necessarily worth sacrificing so much of one’s personal self for,” she says. Success online can bring greater freedom — and even higher pay than many traditional office jobs, which have a median US salary of $69,000, according to Glassdoor. But the middle-class hustle still requires constant effort to maintain. The career has no promise of lifetime longevity. And unlike traditional workers, creators have no predictable paycheck or job protections, making career stability elusive. Roughly 57% of 3,000 surveyed full-time creators earn below a living wage from content creation, according to a report last year from Influencer Marketing Hub. Income from social media can fluctuate wildly from month to month, driven by shifts in algorithms, sponsorship cycles and platform trends.

Advertisement

“You could have a month where you make zero dollars, or you could have a month where you make $10,000,” Platock says.
The article cites Gallup Poll data released last year that found employee engagement in the U.S. had fallen to its lowest level in a decade [with engagement defined as “the psychological attachment workers have to their work/team/employer]. “Among the hardest-hit groups were Generation Z and workers in finance and technology. Broader workplace challenges, including rapid organizational change, hybrid and remote work transitions, and rising employee expectations are considered drivers of the overall trend.”

“For many workers, influencing can seem like a better deal; flexible schedules and independence wrapped in a veneer of creativity and fun. Almost 60% of Gen Zers say they’d become an influencer if given the opportunity, according to a 2023 survey from Morning Consult.”

Source link

Advertisement
Continue Reading

Tech

How to get the best deal on AppleCare One

Published

on

Previously exclusively in the US, AppleCare One is now launching in the UK, France, Germany, and Australia, with Apple’s best insurance deal for users with multiple devices — as long as you’re careful in selecting what’s covered.

A year after it launched in the US, AppleCare One is expanding outside of the US. It’s only going to four more countries, and they’re countries you’d expect it to launch in, but that’s a start.

“At Apple, we’re focused on creating and delivering exceptional experiences,” Bob Borchers, Apple’s vice president of Worldwide Product Marketing, said in a statement to AppleInsider. “With AppleCare One, customers in the UK can now enjoy the trusted protection of AppleCare+ in a way that’s simpler and more flexible than ever before — one plan, one price, and the peace of mind that comes with knowing all their eligible products can be covered.”

Full details of the terms, conditions and all pricing have yet to be published, but based on the details provided by Apple UK, the program will cost around the same as it does in the US. It will also offer the same befits, which are:

Advertisement
  • Up to three products covered
  • Theft and Loss Coverage (for iPhone, iPad, and Apple Watch)
  • Unlimited repairs for accidental damage
  • Free battery replacement
  • Priority access to Apple support

There are limits in that, for instance, AppleCare One users may only make up to three claims of theft or loss per year. But then there are also extra benefits in that iPad accidental damage from handling (ADH) coverage can include an associated Apple Pencil or Apple-branded iPad keyboard.

Who this does and does not work for

Users who have any single device, such as one iPhone or one iPad, should not take up the new AppleCare One option. They should use AppleCare+, which Apple has also improved.

That AppleCare+ plan used to only feature theft and loss coverage for the iPhone, but it now extends this to the iPad and Apple Watch. AppleCare+ prices vary depending on the model of device, but for example the monthly cost in the US at time of writing is:

  • iPhone: from $9.99 to $13.99
  • iPad: from $5.49 to $11.49
  • Mac: from $3.99 to $17.99
  • Apple Watch: from $2.99 to $5.99
  • Apple Vision Pro: $19.99

Each of these comes with an annual version which is roughly equivalent to 10 months at the monthly rate. Note that AppleCare+ only allows annual payment for insuring displays, Apple TV, HomePod, or AirPods.

Those items can, though, be paid for monthly via the new AppleCare One. Again, non-US details will not be fully available until AppleCare One launches on August 4, but the US version does allow adding headphones, for example.

Nonetheless, users who want to insure single devices get no financial benefit from the new AppleCare One. Users who have two devices will definitely benefit if those devices include the Apple Vision Pro.

Advertisement

Covering the Apple Vision Pro by itself with AppleCare+ is exactly the same price as covering it via AppleCare One. So that would be like getting coverage for a second and even third device for free.

Devil in the details

There are ways in which AppleCare One’s coverage of three devices is more than the price of insuring them each with a separate AppleCare+ plan. It depends on if the devices include a Mac, which on its own ranges from $3.99 per month for a Mac mini, to $17.99 per month for a Mac Pro.

Or with the iPhone, the separate monthly cost is $9.99 for an iPhone 17e, rising to $13.99 for an iPhone Air, iPhone 17 Pro, or iPhone 17 Pro Max.

It naturally gets more complicated if you have both an iPhone and a Mac in the equation. For example, if the three devices to be insured consist of an iPhone 17e, Mac mini, and an Apple Watch SE, the total individual cost is $16.97 where AppleCare One is $19.99 and you shouldn’t go near it.

Advertisement

But then if the devices are, say, an iPhone 17 Pro Max, an M5 13-inch iPad Pro, and a Mac Studio, you’d save a startling $12.48 per month by going to AppleCare One. In that case, that’s a hell of a deal.

That’s if you stick to just the basic AppleCare One and its coverage of three devices. It’s possible to add a fourth or any number of more devices, for $5.99 per month each.

Do that by adding, say, an Apple Vision Pro to the example with the iPhone 17 Pro max, 13-inch iPad Pro, Mac Studio and your monthly cost goes up to $25.99. The cost of doing these separately is more than double at $57.46.

One more huge benefit

Not long ago, all of this comparison of coverage costs would be moot because you were limited to which devices could get any AppleCare. It was typically a new device, or a device bought in the last 60 days.

Advertisement

Now with AppleCare One, the coverage is not only cheaper for most people in most circumstances, it is broader. Instead of solely being for new devices, AppleCare One can potentially be used for Apple devices that are up to four years old.

Those devices have to be in good condition, and during online registration users are prompted through questions regarding potential damage. It’s also possible that Apple will require the device to be brought to a store for a visual inspection.

If a user is starting with a new device, then instructions for signing up to AppleCare One will be displayed in Settings. Otherwise it can be done via the Apple website using the user’s Apple Account.

Those users who already have AppleCare plans will be able to switch to AppleCare One. Apple says that their existing plans will be cancelled and a new AppleCare One plan put in place.

Advertisement

Apple’s best deal

As long as you check out the pricing differences between AppleCare+ and AppleCare One, this new program can represent a very significant saving. So it’s unquestionably worth examining the details once Apple has published them for the UK, France, Germany, and Australia, on August 4, 2026.

Note, though, that the US service had some teething problems with eligible devices not always being displayed. If that happens again with the new countries, there are steps you can take to get the correct coverage.

Source link

Advertisement
Continue Reading

Tech

Google goes it alone with a new cybercrime crew taxonomy

Published

on

Security

So much for Microsoft and CrowdStrike’s plans for consistent names across the industry

Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names.

The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG).

Advertisement

Now that two have become one, Google reckons they need consistent naming conventions to describe cybercrime crews.

The result is a two-word schema in which the first word “is a unique and memorable term chosen to represent the specific actor.” If security folk have already applied a particular moniker Google will use it, otherwise it will randomly generate a word “to remove bias.”

Google says the second word “categorizes threat clusters by motivation, attribution, or activity type based on which category we consider to be most important for defense and response strategies.”

More on that later.

Advertisement

Google has decided on the following names:

  • CASTLE to describe crews from the People’s Republic of China

  • ION for threats from Iran

  • NEPTUNE for North Korean attackers

  • RELIC for Russians

  • COMET for cybercrims who aren’t backed by a state

Google’s post notes that other infosec industry players have developed their own schemas for describing threat actors and says the web giant is therefore “intentionally seeking to keep this system as simple as possible to streamline operations and facilitate mapping to other naming taxonomies.”

That’s an odd position, given that in 2025 Microsoft and CrowdStrike tried to spark an industry-wide effort to apply consistent names to threat actors. As we noted at the time, the existence of multiple naming schemas means that researchers often refer to the same group by ten different names. Researchers use the names Seashell Blizzard, IRIDIUM, VOODOO BEAR, BE2, UAC-0113, Blue Echidna, PHANTOM, BlackEnergy Lite, and APT44 to refer to the same entity – Russia’s Military Intelligence Unit 74455.

With most orgs using multiple security tools and therefore receiving threat intelligence security info from many vendors, users must try to understand which crews they’re trying to defend against.

Advertisement

At the time, sources told us Google and Mandiant were keen to adopt the Microsoft-led scheme.

Google’s new announcement suggest the relationship either wasn’t consummated or didn’t last.

Back to the issue of possible bias, as in 2024 China’s National Computer Virus Emergency Response Center (CVERC) complained that western companies choose names like “Typhoon,” “Panda,” or “Dragon” to describe Chinese cybercrime groups.

CVERC suggested names that reflect English language idioms, such as “Hurricane” or “Koala” are more appropriate.

Advertisement

For what it’s worth, “Koala” is a word from the language spoken by the Darug people, the indigenous tribe who lived around Sydney, Australia, prior to British colonization. Koalas are utterly supine creatures that sleep 18 to 22 hours a day, and a mention of the marsupials may therefore not spur defenders to action, even if the creatures’ habits do perhaps describe the behavior of some sleeper malware. ®

Source link

Continue Reading

Tech

Scanwheel: A Pocket-Sized POV TV

Published

on

Scanwheel

When you hear the word TV, you probably think of a big LED screen, maybe even the old CRT TVs, but in either case it’s something large and fairly complicated. However, thanks to the persistence of vision, it doesn’t have to be. In this handheld-sized project from [Ancient], the Scanwheel is born, a miniature mechanical TV that uses a spinning disk and some LEDs to produce an image.

The electronics of the Scanwheel are pretty straightforward. The smarts come from a Raspberry Pi Pico, an A4988 motor driver, a couple of LEDs, and a small 21-02485 stepper motor. The Raspberry Pi Pico is used to command the motor speed as well as coordinate the LEDs to turn on at the right time. The case is 3D printed; the base includes space for the various support electronics as well as some small light baffles to ensure the LEDs don’t bleed over outside their intended area. The top of the case is a disk that includes 20 small holes spaced evenly around the perimeter at varying heights, allowing light to only leave the disk when one of these holes is in front of the LEDs.

When you put all these pieces together, spin the motor up to roughly 900 RPM, and turn the LEDs on in a precise order, you end up with a really cool result: a miniature TV. And due to the five different LEDs in this build, you actually have a color 20×20 pixel display in the center and, on either side of that, two more 20×20 black-and-white displays capable of showing different images. Thanks [Ancient] for sharing this awesome build that takes advantage of the persistence of vision effect to create a unique display. Be sure to check out the video below as well as the instructions on how to build your own. And if you enjoy this sort of thing, check out some of our other persistence-of-vision projects as well.

Source link

Advertisement
Continue Reading

Tech

Yeast Turns Sugar Into Liquid Power in a Paintball Bottle

Published

on

Fermentation Filling High Pressure CO2 Bottles
Yeast spends its days chewing through sugar and splitting the leftovers into alcohol and carbon dioxide. Most people chasing homemade ethanol treat the second half of that reaction as pure waste and let the gas drift away. One maker decided the gas was too useful to ignore and set out to trap every molecule, dry it, chill it, and pack it into the same kind of high-pressure bottles that drive paintball markers and soda siphons.



The numbers appear almost too clean, since 4 kilograms of ordinary sugar dissolved in 14 liters of water already gives a solution that is nearly 22% sugar. If the yeast performs its job and converts everything, the process should result in little more than 2 kg of CO2. That’s enough liquid to fill nearly four 20-ounce paintball cylinders. The problem is that the gas comes out of the fermenter wet and diluted, making the first job (gathering it) difficult, as does maintaining the pressure up and preventing air from entering the system.

Sale


Airmoto Tire Inflator Portable Air Compressor for Cars, Bikes and Bicycles
  • QUICK & ACCURATE: Built with the highest quality materials, Airmoto is a portable tire inflator for car, trucks, SUVs, motorcycles, and bicycles…
  • AUTO SHUT OFF: Use the “+” and “-” control buttons on the Airmoto to easily select your desired pressure, simply connect the air hose to your…
  • MAIN HIGHLIGHTS: Easily change between PSI, kPa, BAR, and KG/CM pressure units with a push of a button; Easy to read large LCD; Digital Tire Pressure…

A 5-gallon water jug serves as a fermentation tank. The carbon dioxide is routed out via an airlock tube and into a recycled water-filter canister. The works is stuffed with silica-gel beads, which reduces moisture slightly, but we later discovered that the dew point remains too high, causing ice to form inside the valves. The next step is to transfer the gas to a beach ball. It takes a few days, but the ball eventually fills up with hundreds of gallons of CO2. It serves the purpose of providing some extra room to keep the pressure near the proper level while the yeast is still active.

Advertisement

Fermentation Filling High Pressure CO2 Bottles
The major issue is turning the squishy substance into liquid. At room temperature, the CO2 must be compressed to roughly 64bar before it can condensate. The problem is that standard shop compressors can only reach a fraction of that capacity. The solution is to simply leave it in the air box. To cool a copper coil, a DIY system makes use of propylene as a refrigerant. This lowers the temperature to roughly -33 degrees Celsius and reduces the condensation pressure to about 13 bar absolute, which is well within the capabilities of a severely modified oil-less air compressor with its over-pressure cut-out switch disabled.

Fermentation Filling High Pressure CO2 Bottles
That copper coil is a 2-inch pipe, approximately 2 feet long, with a thinner copper coil within to convey the propylene. The CO2 from the beach ball enters at the top, meets the chilly surface, and condenses into a liquid that gathers at the bottom. A second coil (the same as the first) is housed in a 96% ethanol-lined thermos. A paintball tank sits in that bath, keeping the metal cool. Once some liquid has accumulated in the coil, a valve opens and the liquid flows into the chilled tank.

Fermentation Filling High Pressure CO2 Bottles
An typical oil-free compressor can move the gas, but only at a very sluggish rate; at 17 bar, it moves like a snail. Switching to a refrigerated compressor provides the necessary pressure, 400 psi or greater, and reduces fill time to 10 or 15 minutes. But now we have a new problem: oil separation. Any lubricant that gets into the tank degrades the purity. Then there’s water, which still freezes inside the tank valve while we pump it out, and this can jam the nozzle until the metal heats up again.

Fermentation Filling High Pressure CO2 Bottles
After filling the bottle to capacity, the scales read 1312 grams with the valve still connected. When the contents were drained, 974 grams remained, indicating that 338 grams of liquid carbon dioxide had been trapped inside. The container wasn’t even full to the brim, but that liquid was unmistakable, and when that valve was opened quickly, the temperature of the tank dropped to the point where it iced over. If you discharge it completely and quickly, you could bring it down to the temperature of dry ice.

Fermentation Filling High Pressure CO2 Bottles
That small charge of ours already has some substantial practical power behind it. By connecting it to a short-stroke pneumatic actuator, he was able to elevate the back end of a full-size pickup approximately 200 millimeters off the ground. The same gas, linked to a vane motor, was able to power a small generator for a few minutes, but you can probably predict where this is going: the intense chill that comes in as the liquid boils away causes the pressure to drop and the motor to turn off.
[Source]

Source link

Continue Reading

Tech

Most accelerators make startups worse. What do the good ones do?

Published

on

Every accelerator makes a version of the same offer: capital, mentorship, a network, three months of support, and materially better odds of survival. Evidence suggests that little of it actually works.

In April, Youn Baek and Deepak Hegde of NYU Stern published a working paper through the National Bureau of Economic Research examining nearly 750,000 American startups across 329 programs. Between 60 and 80 percent of accelerators, they found, leave the companies that join them worse off than if they had never applied. A smaller group does the opposite, raising funding, growth and exit rates by a wide margin. Among them, Y Combinator, Techstars and Endless Frontier Labs.

The study establishes which programs work, but it does not explain why. For that, we asked founder and product-market fit expert Yann Goarin.

Goarin spent a decade at Google and YouTube, where he launched more than twenty products in Europe and the United States, and has since led product and marketing at several venture-backed startups. He founded Zag Labs in 2023, an advisory firm that has helped more than a hundred early-stage companies go to market and accelerate their path to product-market fit. He developed the “PMF System”, a method that treats product-market fit as a problem-solving process rather than an event or a vibe. He is currently Founder in Residence at AAXIS, where he leads the enterprise technology firm’s venture-building work. He also mentors and judges at five accelerator programs across the US (Techstars, gener8tor, FoundersBoost, Expert Dojo, and USC’s Iovine and Young Academy), which gives him a unique perspective on how different programs support their founders.

Advertisement

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

Most accelerators take equity in exchange for a check and three months of support, and their return depends on whether a few companies in each cohort raise at scale or exit. What they offer founders is leverage in several forms: capital, introductions to investors and customers, brand recognition, and knowledge.

Like top universities, the best accelerators attract and select the best founders. Even so, the odds of success are very low. Building a category-defining, venture-backed company is incredibly difficult, and luck and timing decide a great deal of it. But it is not magic. There is a method to the madness, and that method, Goarin claims, is either not taught or not taught well.

Advertisement

Research shows that knowledge is the form of leverage that appears to matter most. Susan Cohen, Benjamin Hallen and Christopher Bingham, who spent years studying the original American accelerator programs, found that where accelerators do improve their companies, the primary driver is what those companies learned inside them. But it is also the hardest to scale.

Goarin remembers one client engagement, a seed-stage AI startup that had built a video production platform. Its founders had come through one of the world’s most selective accelerators. It raised $4 million and within twelve months passed $1.2 million in annual recurring revenue. However, churn was running above 30 percent. The response was to sell harder and build faster, adding features as customers asked for them, and investors supported that on the view that revenue was the number that mattered most.

What the founders failed to realize was that the three segments they were selling to (small marketing agencies, independent video creators, and boutique production companies) were not a cohesive market. While they appeared to need faster and cheaper video production, they differed in how much video they produced, how polished it had to be, how it fit in their workflow, and where it was distributed. The product tried to stretch across all three, and served none of them well. Customers left faster than sales could replace them. After cutting half the team and pivoting, they failed to secure a bridge round and ran out of runway.

Goarin came in near the end, too late to change the outcome. “I assumed that founders coming out of a program like that would be better at testing their assumptions and diagnosing their issues. I was wrong. They were just as clueless as most of the others I advise.”

Advertisement

Around that time he started mentoring at Techstars. That’s where he saw an opportunity to address the problem at scale. From inside a program, it becomes clear how knowledge actually reaches founders, and what never does.

The programs that do teach tend to teach in fragments: a product expert teaches product, a sales executive covers sales, someone who has raised four rounds helps with fundraising. Founders are expected to assemble them into a working company. Most fail. There is something odd in that, viewed from outside. Accelerators and venture funds spend enormous effort on selection, screening thousands of applicants to find the few worth backing, and then just hope they figure it out.

What goes untaught is product-market fit itself, i.e., the correct assembly of these fragmented pieces that ultimately leads to widespread demand for something people badly need, delivered profitably every time. There are two reasons it does not appear on syllabuses. Product-market fit is not understood as a discipline in its own right, so there is no settled body of practice to teach from. And the mentorship model recruits subject matter experts by function, so PMF, which sits between and over the functions, isn’t owned by anybody. Until now.

What Goarin teaches in these programs runs end-to-end, and his objective is straightforward: avoid building something nobody wants.

Advertisement

“Accelerators give founders access and funding, and of course that matters,” says Goarin. “But where they can have an even bigger impact is teaching first-time founders to operate like second-time founders. That means going beyond the surface-level material and breaking down the mechanics of startups.”

User experience went through the same thing. Usability testing, information architecture and interaction design were practiced separately for years before the field recognized them as one discipline and created roles for people who worked across all of them. Naming it is what made it possible to teach.

The case for teaching product-market fit as its own subject is getting stronger. As technology levels the playing field on building and execution, what separates companies is judgment: Is this problem worth solving? Is this the right customer segment? Can I deliver my solution repeatably and profitably? Is it time to pivot? None of those questions can be answered well without knowing what to look at, and that is what Goarin focuses on.

“In the early days only three things matter,” Goarin claims. “Speed of learning, speed of decision-making, speed of execution. A startup is a learning machine before it is anything else, and learning is the part founders struggle with the most. Building is fast and cheap now, so the temptation is to ship something and see if it sticks. But that’s how you end up with a product in search of a problem. That’s how you end up in pivot hell.”

Advertisement

His work has been expanding. He was a Lead Mentor at Techstars for the Spring 2025 and Spring 2026 cohorts and a judge in Mentor Magic, the program’s week of back-to-back mentoring and evaluation sessions. He has advised two gener8tor cohorts and judged USC’s Venture Showcase. He is in discussions with other top programs in the United States and Europe.

Top accelerator entry requirements have been rising. Joshua Lu, who runs Speedrun, told TechCrunch this year that because AI has made building and testing so much faster, the program now expects market validation or early traction before it will admit a company. That created a new market of programs beneath the accelerators. The best of them are focusing on education, and have invested accordingly. FoundersBoost, one of the world’s best pre-accelerators, brought Goarin in to strengthen its programming and asked him to teach its last two cohorts.

The gap is about to matter more. AI is accelerating a trend already underway, in which smaller and smaller teams, working alongside swarms of agents, can perform like much larger companies. That does not reduce the value of knowing what to build. Rather, it concentrates it. Judgment, pattern recognition, knowing what to focus on and when, the confidence to make a decision and move: these have always been the unfair advantage, but are ever more critical in the AI age.

“Fundraising used to be something most founders didn’t understand,” says Goarin. “Now every program teaches it. Product-market fit is more complex, but it is a subject, and I expect it will be taught the same way before long.”

Advertisement

Baek and Hegde could not say what separates the accelerators that work from the ones that do not. If the answer is what they teach, the programs that work it out first will be the ones worth applying to.

Source link

Advertisement
Continue Reading

Tech

TP-Link Tapo C660 Kit review: a bang-for-your-buck 4K security camera with local storage

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

TP-Link Tapo C660 Kit: One-minute review

The TP-Link Tapo C660 Kit is a feature-packed 4K outdoor security camera that delivers many of the perks usually reserved for pricier models, including solar charging, pan-and-tilt coverage, color night vision and local microSD storage.

That last feature means you won’t need to pay for a subscription for video playback and download, but there are still some great (but non-essential) features in the paid Tapocare subscription, especially if you plan to expand your home’s security with more than a single camera.

Advertisement

Source link

Advertisement
Continue Reading

Tech

Man gets six years for hacking 750 women’s Snapchat accounts

Published

on

Snapchat

An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online.

After being charged in December, 26-year-old defendant Kyle Svara admitted in February to having used various social engineering tactics to phish Snapchat access codes from over 750 women.

Between May 2020 and February 2021, he targeted more than 4,500 victims while posing as a representative of Snap Inc and using anonymized phone numbers.

image

After stealing the victims’ credentials, Svara accessed approximately 517 women’s Snapchat accounts without permission to download nude or semi-nude photos and activated two-factor authentication to lock them out of the compromised accounts.

Svara phishing Snapchat access codes
Svara phishing Snapchat access codes (Justice Department)

The investigators also found that Svara distributed child sexual abuse material (CSAM), finding approximately 530 images and 600 videos depicting CSAM in his Mega account.

“When Svara was interviewed by investigators, he falsely stated that he did not know anything about hacking Snapchat,” the Justice Department said in February.

Advertisement

“Additionally, he falsely stated that had no interest in child pornography and had never actively sought out or accessed child sexual abuse material (CSAM). Contrary to these statements, the defendant collected, distributed and solicited CSAM.”

According to court documents, he also advertised his “services” online, trading the stolen images, offering to “get into girls snap accounts,” and asking potential clients to reach out through the Kik encrypted messaging app.

Svara offering to hack Snapchat accounts
Svara offering to hack Snapchat accounts (Justice Department)

​Steve Waithe, a former Northeastern University track and field coach and one of his clients, hired Svara to hack the Snapchat accounts of students at Northeastern and members of the women’s track and field and soccer teams.

After being found guilty of targeting at least 128 women and stealing thousands of explicit photos from more than 100 women, Waithe was sentenced in March 2024 to five years in prison for cyber fraud, cyberstalking, and sextortion.

Between paid hacking jobs, Svara also independently hacked into the accounts of many women in Plainfield, Illinois (including neighbors, family friends, classmates, his own personal friends), as well as students at Colby College in Waterville, Maine.

Advertisement

article image

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Source link

Continue Reading

Tech

Some Kids Will Never Think AI Is Cool

Published

on

Forget cheating on homework and chatbot friends. Some kids are getting in on a new AI trend: thinking it sucks.

In the four years since chatbots went mainstream, and their marketing campaigns went into overdrive, young people have grown increasingly skeptical of the hype around LLMs. Yes, many of them still use the tech for school assignments and companionship, but according to market research firm YPulse, 37 percent of teens aged 13 to 17 cringe when they see AI content like music and videos, and more than half worry about misinformation and deepfakes.

The polling on youthful AI attitudes shows a great deal of contradiction. Adoption rates are high, with a majority of America’s teens reporting they use chatbots, but enthusiasm is mixed. A recent Pew Research report found that while many teens think AI will be good for them personally, over a fourth of their cohort believe AI will have a negative impact on society in the next 20 years, citing job loss, the decline of critical thinking skills, and environmental impacts as concerns.

Young people typically adopt new consumer technology eagerly, but Melanie Green, a communications professor at the University at Buffalo, says AI is different. This time, the moral panic isn’t coming from older generations—in fact, kids are turned off by the way AI is being pushed on them by adults and tech corporations. They’re also, Green says, “acutely aware that whatever disruption happens, their generation is going to be bearing the brunt of it.”

Advertisement

Ergo, the eye-rolls. On Bluesky, parents bond over their kids’ distrust of AI, with many claiming that their children come home saying “that’s AI” to mean “that’s BS.” On Reddit, educators share that students—even those who use AI—worry about its consequences and can’t stand the art it produces. WIRED spoke to young people, their parents, and their teachers to find out why some kids don’t want to be on the AI bandwagon.

Source link

Continue Reading

Tech

SpaceX just about nails Starship test flight 13

Published

on

science

Super Heavy booster had a super heavy landing, but other reusability tech did the trick

The 13th flight of SpaceX’s Starship made it off the launchpad on Friday and ticked off just about everything on the company’s to-do list.

After delays and engine replacements, Elon Musk’s colosso-launcher took to the skies at beer-o’clock on Friday evening – 5:51PM Texas time.

Advertisement

One hour, five minutes and 21 seconds later, Starship made a controlled splashdown in the Indian Ocean, where it floated after landing.

SpaceX says it was able to gather critical data on the performance of Starship’s heatshield, and that the craft made “a dynamic banking move to mimic the trajectory that future missions returning to Starbase will fly.”

Gathering data on Starship’s heatshield performance will help SpaceX ensure the craft is re-usable. Simulating missions that land at Starbase, SpaceX’s Texas home, builds toward future missions that launch and land at the same facility, speeding turnarounds for re-usable hardware.

The test flight also saw SpaceX test a new routine for de-orbiting the Super Heavy booster used to hoist Starship into space. “The booster successfully completed the high thrust portion of the boostback burn with all 33 engines, the first time with a Super Heavy V3, before ending the burn early,” SpaceX said. “It attempted to relight its engines for the landing burn, with a subset successfully igniting before experiencing a hard splashdown in the Gulf.”

Advertisement

That part of the mission didn’t go perfectly, as SpaceX hoped for a softer landing and more engines lighting to make it possible.

Once Super Heavy and Starship separated, the latter vehicle used its six Raptor engines to reach desired speed and orbit. It then deployed 20 Starlink V3 satellites. SpaceX crew verified the sats worked and half a dozen of them got a look at Starship’s heatshield. While the satellites were functional, SpaceX did not intend them to form part of the Starlink constellation and allowed them to re-enter Earth’s atmosphere. Or as the company’s mission report put it, the satellites “demised upon reentry approximately 20 minutes after deployment.”

Starship performed one more trick on its way back to Earth, by starting one of its Raptor engines while coasting through space. The success of that test again demonstrated tech that will be needed for future missions, in this case flights that push Starship into sustainable orbit – or allow it to reach a trajectory capable of reaching the Moon, as NASA envisages will be the case for future Artemis missions that land humans on Earth’s permanent natural satellite.

SpaceX boss Elon Musk said he hopes the next Starship test flight will see the Super Heavy booster caught by robot arms at Starbase, another step towards improved reusability and turnaround times between flights. ®

Advertisement

 

Source link

Continue Reading

Trending

Copyright © 2025