User Avatar
sheriff

u/m

Building a Startup Ecosystem
Entrepreneur
India
Joined Feb 03, 2025
Admin
2.1k Karma
5 Followers
15 Following
u/m m · 2 hr ago

Apple announced that Tim Cook will become executive chairman of Apple’s board of directors and John Ternus, senior vice president of Hardware Engineering, will become Apple’s next chief executive officer effective on September 1, 2026.

Cook will continue in his role as CEO through the summer as he works closely with Ternus on a smooth transition. As executive chairman, Cook will assist with certain aspects of the company, including engaging with policymakers around the world.

Arthur Levinson, who has been Apple’s non-executive chairman for the past 15 years, will become its lead independent director on September 1, 2026. Ternus will join the board of directors, also effective September 1, 2026.

Ternus joined Apple’s product design team in 2001 and became a vice president of Hardware Engineering in 2013. He joined the executive team in 2021 as senior vice president of Hardware Engineering. Throughout his tenure at Apple, Ternus has overseen hardware engineering work on a variety of groundbreaking products across every category. He was instrumental in the introduction of multiple new product lines, including iPad and AirPods, as well as many generations of products across iPhone, Mac, and Apple Watch.

Source: Apple

2

u/m m · 16 hr ago

A user was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account.

They accessed another user's profile, listed their public projects, and downloaded the source code of an admin panel for Connected Women in AI, a real danish nonprofit. the project was last edited 10 days ago. the developer has 3,703 edits this year. this is not abandoned. this is active.

They extracted the database credentials from the source code and queried it. got back real names, real companies, real linkedin profiles. speakers from Accenture Denmark and Copenhagen Business School. not test data. not "John Doe". real people at real companies who have no idea their information is exposed.

Lovable patched this for new projects. they never patched it for existing ones.

A project created in April 2026 returns 403 forbidden. The same developer's older project, actively edited 10 days ago, returns 200 OK with the full source tree. same API. Same endpoint. same free account. same session. one is protected. the other is wide open.

The first hackerone report was filed March 3, 2026. Lovable marked it triaged, then they shipped ownership checks for new projects and left every existing project exposed. 48 days later nothing has changed. He also claims that every conversation you have with lovable's AI is stored and readable through the same bug.

Source: weezerOSINT

2

u/m m · 16 hr ago

A threat actor has listed their customers' data, source code, databases, and keys up for sale.

A security incident has been identified that involved unauthorized access to certain internal Vercel systems. Customers Vercel credentials were compromised.

As per Vercel, the incident originated with a compromise of Context.ai, a third-party AI tool used by a Vercel employee. The attacker used that access to take over the employee's Vercel Google Workspace account, which enabled them to gain access to some Vercel environments and environment variables that were not marked as “sensitive.”

Source: Vercel

2






u/m m · 4 d ago

Cal AI was removed because it used Stripe (via Link) for subscriptions instead of Apple's in-app purchase system.

The payment sheet showed "Pay another way" routing to external billing, which violates Apple's guidelines (3.1.1) for digital goods/subscriptions. Publicly highlighting the higher ARPU setup drew Apple's attention, leading to the takedown. It should be back after they fix it.

3



u/m m · 5 d ago

A peer-reviewed CMU study (ICSE 2026) found 6 million fake stars across 18,617 repositories using 301,000 accounts - with AI/LLM repos the largest non-malicious category.

The definitive account comes from a peer-reviewed study presented at ICSE 2026 by researchers at Carnegie Mellon University, North Carolina State University, and Socket. Their tool, StarScout, analyzed 20 terabytes of GitHub metadata - 6.7 billion events and 326 million stars from 2019 to 2024 - and identified approximately 6 million suspected fake stars distributed across 18,617 repositories by roughly 301,000 accounts.

The problem accelerated dramatically in 2024. By July, 16.66% of all repositories with 50 or more stars were involved in fake star campaigns - up from near-zero before 2022. The researchers' detection proved accurate: 90.42% of flagged repositories and 57.07% of flagged accounts had been deleted as of January 2025, confirming GitHub itself recognized these as illegitimate.

Key Points:

  • Stars sell for $0.03 to $0.85 each on at least a dozen websites, Fiverr gigs, and Telegram channels - no dark web required
  • VCs explicitly use stars as sourcing signals: Redpoint found the median star count at seed is 2,850, and firms run automated scrapers to find fast-growing repos
  • An analysis sampling 150 profiles per repo across 20 projects and found repos where 36-76% of stargazers have zero followers and fork-to-star ratios 10x below organic baselines
  • The FTC's 2024 rule banning fake social influence metrics carries penalties of $53,088 per violation - and the SEC has already charged startup founders for inflating traction metrics during fundraising

Source: Awesome Agents

3







u/m m · 10 d ago

Nandan Reddy, co-founder of Swiggy is leaving the company and is also stepping down from the board.

Swiggy is bringing in CFO Rahul Bothra and co-founder Phani Kishan to the board as additional directors.

Reddy is expected to launch a new startup.

Group CEO Sriharsha Majety is now the only member of the founding trio still at the company. In 2013, they started logistics tech startup Bundl which became Swiggy in 2014.

CTO and co-founder Rahul Jaimini had left in 2020 for ed-tech startup Pesto.

Source: The Arc

4