[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMeBQ3epYvnuBwVMULIemEgc4bYvzlYiN8cM2Gyit_s4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"98cab6f3-1c5d-41d6-bdb1-0f2a3173db55","convicted-fraudsters-launch-offensive-cyber-startup-buying-zero-days","c6d2c6fb-b72b-4711-ad18-b48bb0f1e5c6","Convicted Fraudsters Launch Offensive Cyber Startup Buying Zero-Days","IRIS C2, a newly formed cybersecurity startup run by individuals with documented histories of fraud, disinformation, and criminal conviction, is openly soliciting zero-day vulnerabilities for significant payouts — raising serious concerns about the responsible disclosure ecosystem and the weaponization of offensive research. The root issue is a failure of the cybersecurity industry and regulatory bodies to vet who can operate as legitimate vulnerability brokers, creating a supply chain risk where exploits could flow to bad actors under a veneer of corporate legitimacy. This matters because zero-days acquired by untrustworthy brokers can end up in the hands of threat actors, nation-states, or criminal enterprises, bypassing established responsible disclosure norms. Organizations and independent researchers must exercise extreme due diligence before engaging with any vulnerability acquisition program, as the provenance and end-use of exploits directly impacts global cybersecurity posture.","**Immediate actions:**\n- Vet any vulnerability broker or bug bounty program against public records, legal history, and industry reputation before submitting research.\n- Alert internal security and legal teams when researchers or employees are approached by unverified or suspicious zero-day acquisition programs.\n\n**Long-term improvements:**\n- Establish a formal policy requiring due diligence checks on all third-party vendors and partners operating in offensive security or vulnerability markets.\n- Advocate for and comply with industry-standard responsible disclosure frameworks (e.g., ISO\u002FIEC 29147) to ensure exploits reach legitimate, accountable parties.\n- Engage with government and regulatory bodies to push for licensing or registration requirements for commercial vulnerability brokers.\n\n**Detection & awareness measures:**\n- Train security researchers and staff to recognize red flags of fraudulent or legally compromised cybersecurity entities.\n- Monitor threat intelligence feeds for intelligence on rogue brokers or newly emerged offensive cyber firms with questionable backgrounds.\n- Report suspicious vulnerability acquisition solicitations to relevant authorities such as CISA or the FBI's Internet Crime Complaint Center (IC3).",[12,13,14,15,16,17,18,19,20],"NIST CSF ID.SC-2: Suppliers and third-party partners are identified and prioritized","NIST CSF ID.SC-4: Suppliers and third-party partners are routinely assessed","CIS Control 15: Service Provider Management","CIS Control 17: Security Skills and Training","ISO\u002FIEC 29147: Vulnerability Disclosure","ISO\u002FIEC 30111: Vulnerability Handling Processes","GDPR Article 32: Security of Processing (data shared with rogue brokers)","NIST SP 800-161: Cyber Supply Chain Risk Management","FTC Act Section 5: Unfair or Deceptive Acts (relevant to fraudulent business practices)","published","2026-07-08T14:20:26.562588+00:00","2026-07-08T14:20:26.417+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F07\u002Ffelons-fraudsters-flog-offensive-cybersecurity-startup\u002F","felons-fraudsters-flog-offensive-cybersecurity-startup-11d200","Felons, Fraudsters Flog Offensive Cybersecurity Startup",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]