The HashWhales Dispatch

Software, security, and cloud news — summarized in plain language, with sources.

Progress Shuts Down ShareFile Access Amid Threat; Zero-Day Startup Founders Exposed as Felons

Two cybersecurity stories collide: a major file-sharing platform goes dark over a credible threat, while a zero-day broker is unmasked as a front run by convicted fraudsters.

Cloudflare Sharpens Cloud Cache Routing; AWS Adds OAuth to MCP Server

Two infrastructure updates aim to cut latency and simplify AI agent authentication for teams running workloads on major cloud platforms.

Laser Exploit Cracks Tangem Wallets; Felon-Run Startup Hawks Zero-Days

Two separate security stories expose hardware wallet vulnerabilities and a fraudulent offensive cybersecurity firm recruiting researchers to sell exploits.

GitHub Rethinks Copilot's Toolset After Better Tools Hurt Code Review

GitHub found that giving Copilot more powerful exploration tools degraded review quality—until it restructured agent workflows around pull request evidence.

Crypto Wallet Flaw 'Ill Bloom' Costs Users $3.1M; Zero-Day Firm Tied to Convicted Felons

A weak-randomness vulnerability is being actively exploited to empty crypto wallets, while a separate zero-day acquisition startup raises red flags over its founders' criminal histories.

AWS Adds OAuth to MCP Server While Cloudflare Pushes ML-DSA Now

Two major infrastructure moves this week signal a push toward standardized AI authentication and quantum-resistant security.

AWS Client VPN Lands in Four New Regions; Cloudflare Urges ML-DSA Now

AWS expands managed remote-access VPN coverage while Cloudflare argues enterprises should not wait for next-generation post-quantum signatures.

Ghost GitHub Accounts and Felon-Backed Zero-Day Firm Highlight Supply Chain Risks

Corporate GitHub infrastructure is being quietly mapped by attackers using aged dormant accounts, while a fraudulent cybersecurity startup with convicted felon leadership is courting zero-day sellers.

GitHub Resolved Ownership Gaps Across 14,000 Repos in 45 Days

GitHub's internal engineering team assigned validated owners to every active repository in under six weeks, then archived the remainder.

Cloudflare backs ML-DSA now as AWS opens free sandbox training

Cloudflare urges enterprises to adopt ML-DSA for post-quantum security today, while AWS removes account barriers for hands-on cloud learning.

AI Slashes Attack Timelines While a Fraudulent Zero-Day Broker Surfaces

Automated offensive AI now compresses multi-day intrusion campaigns into minutes, even as a convicted-felon-run startup attempts to buy zero-day vulnerabilities under a veneer of legitimacy.

Meta Opens Instagram Photos to AI Remixing; Cybersecurity Startup Tied to Convicted Felons

Two stories expose how trust is eroding at opposite ends of the security spectrum — one inside Big Tech, one inside a shadowy zero-day market.

Signal, not noise

Technology news translated into business decisions

The HashWhales Dispatch follows cybersecurity incidents, software releases, artificial intelligence, cloud infrastructure, and the policy changes that affect modern organizations. Each brief links to its original sources and explains why the development matters, without turning a press release into a prediction. The goal is to help owners and technical leaders decide what deserves attention now, what can wait, and what should change in their systems.

For deeper implementation guidance, visit our engineering insights. If a story raises a question about your own website, network, backups, or security posture, request a free technology risk review for a practical, company-specific next step.

Free AuditChat on WhatsApp