Google announced that it helped take down NetNut, a 2 million strong malicious residential proxy network. The incident highlights the growing risks posed by residential proxy networks that quietly conscript consumer devices into services used by cybercriminals and nation-state actors alike.
A simple website flaw exposed members, political profiles, login tokens, and dating data from Peter Thiel ‘s secretive Dialog network.
Dialog, a private invitation-only organization cofounded in 2006 by billionaire tech investor Peter Thiel, has spent two decades refusing to disclose its membership. That position became harder to maintain last week when Swiss hacktivist maia arson crimew, known for exposing the US government’s No Fly List, found an open directory embedded in the source code of dialog.org that was visible to anyone who viewed the page. WIRED independently verified the contents and obtained the registration list for Dialog’s 2026 retreat, scheduled for August 12-16 near Dublin, Ireland.
“A trove of internal records from a secret society for powerful figures in US politics, finance, and tech was left exposed online, WIRED has confirmed, naming participants in its events and revealing sensitive personal details they were assured would stay private.” reported Wired. “The group, called Dialog, is a private, invitation-only organization cofounded in 2006 by the billionaire tech investor Peter Thiel. It convenes US officials, foreign government figures, and Silicon Valley executives at off-the-record annual retreats.”
The 2026 list names 222 registrants, 87 of them first-time attendees. Others have histories stretching back more than a decade, a handful to the founding itself. None used a government email address, placing their attendance outside public records laws.
The roster is not a list of adjacent power. It’s power in direct regulatory relationship with itself. Treasury Secretary Scott Bessent appears alongside Auren Hoffman, Dialog’s chairman, who founded location-data broker SafeGraph and identity-resolution firm LiveRamp. Senator Ted Cruz, who chairs the committee overseeing the FTC and its data-privacy authority, is listed in the same directory. Palantir cofounder Joe Lonsdale, whose software runs case management for ICE and data fusion for the Pentagon, appears alongside Army Secretary Dan Driscoll and Representative Jim Himes, ranking member of the House Intelligence Committee, which oversees agencies Palantir contracts with.
Forbes confirmed additional members including investor Marc Andreessen and investor and former Facebook board member Jim Breyer.
General Alexus Grynkewich, NATO’s supreme allied commander Europe and head of US European Command, is recorded as having attended Dialog gatherings since 2021.
The session agenda for the 2026 retreat includes “Navigating WWIII,” “Battlefield Technologies,” “Bring Back Nuclear,” and “Build-a-Cult,” the last moderated by the founder of the Christian networking site Pray.com. There’s also “How’s Your Sex Life?” which presumably has a different moderator.
“The website directory names sitting Trump administration officials, two US senators, six members of the Paypal Mafia, a former Middle East chief of intelligence, and a sitting ambassador to the United States, along with the founders and directors of many of the country’s largest surveillance, data-broker, and advertising-data companies.” Wired continues.
The leaked registration list adds names not in the public directory of 113: Randy Kroszner, former Federal Reserve governor now on the Bank of England’s Financial Policy Committee; Jonathan Greenblatt, CEO of the Anti-Defamation League; Ryan Stowers, executive director of the Charles Koch Foundation; Roger Myerson, Nobel laureate economist; and a cluster of Google and Google DeepMind executives including Tom Lue, who leads global affairs for the frontier AI division.
The data breach is structurally embarrassing because it was entirely avoidable. The directory was served to any visitor who viewed the page’s source code. A separate Dialog page at app.dialog.org presents a sign-in screen with no terms of service, no indication the application is restricted, and no invitation requirement. The records sat in Airtable, a commercial database, and included for each participant their membership status, every retreat attended, biography, home city, and a private access token functioning as a login credential.
Dialog also runs a matchmaking service. Its registration form asks whether participants are “looking for love” and offers to include single respondents in “future matchmaking.” A separate site at dating.dialog.org hosts an app pitched as “meaningful connections for exceptional people.” The form also collects each registrant’s political leaning, which Dialog promised would never be shared.
“That data, and the matchmaking responses, were exposed in the leak.” concludes Wired.
The data collected by Dialog could be valuable for criminals or intelligence agencies because it reveals personal vulnerabilities, relationship status, political views, and access to influential networks. Such information can support targeted phishing, social engineering, honey-trap operations, blackmail, or influence campaigns. The risk is amplified because participants are often members of the global elite, making them attractive intelligence targets. Many may be highly accomplished in their fields but still willing to share sensitive personal details in trusted environments, creating opportunities for manipulation and exploitation.
An internal guide for event moderators, also found in the exposed directory, instructs them to remind participants that everything is off the record, keep comments concise and “nonobvious,” and model brief introductions to “avoid status signaling” in a room full of senators, dignitaries, and tycoons. The discipline imposed on members apparently didn’t extend to basic website security.
The cryptocurrency market witnessed another major security breach this week after the MAPO token collapsed by 96% following an exploit tied to the Butter Network cross-chain bridge. The incident resulted in the unauthorized minting of a quadrillion MAPO tokens, flooding the market with a supply vastly larger than the legitimate circulating amount and causing severe disruption across decentralized finance ecosystems connected to ETH and other blockchains.According to blockchain security researchers, the exploit enabled the attacker to generate tens of thousands of times more MAPO tokens than the official supply. As panic selling intensified, the price of the Map Protocol token dropped from nearly $0.003 to around $0.0001 within hours, based on market tracking data from CoinGecko.
Attacker Drains ETH From Liquidity Pools
The attack primarily targeted the Butter Network bridge infrastructure, a cross-chain protocol associated with Map Protocol. Security platform Blockaid reported that the exploiter used a newly created externally-owned account (EOA) to offload approximately one billion MAPO tokens into decentralized exchanges.During the process, the attacker reportedly drained nearly 52 ETH from Uniswap liquidity pools, an amount valued at roughly $180,000 at the time of the incident. Despite the liquidation of a portion of tokens, blockchain analysts noted that the attacker still retained close to a trillion MAPO tokens.Those remaining holdings continue to create risks for additional liquidity pools and potential exchange listings linked to the Map Protocol token ecosystem. The sudden flood of tokens severely impacted market confidence and highlighted ongoing vulnerabilities within cross-chain bridge infrastructure.
MAPO Exploit Adds to Growing List of DeFi Attacks
The exploit comes during an already damaging month for decentralized finance projects. Reports indicate that at least 18 DeFi and blockchain protocols have been compromised in recent weeks.Among the affected projects are THORChain, Verus Protocol, Transit Finance, TrustedVolumes, Ekubo, Echo Protocol, and RetoSwap.The repeated attacks have intensified concerns surrounding interoperability protocols, especially those handling assets across ETH, Bitcoin, and other blockchain ecosystems. Cross-chain bridges remain frequent targets because of the complexity involved in validating transactions between multiple networks.
Map Protocol Pauses Mainnet Operations
In response to the breach, Map Protocol confirmed that the vulnerability originated in the Solidity contract layer. The project announced that it had paused its mainnet and initiated a migration process while the investigation continues.Butter Network also suspended ButterSwap operations, although the team stated that user funds were not directly at risk.In its latest statement, the Map Protocol team said it would announce a new contract address and later conduct an asset snapshot. The project added that “any remaining tokens held by attacker-controlled addresses will be fully invalidated and will not be included in any future snapshot or conversion process.”Blockchain data further revealed that approximately one billion MAPO tokens were transferred to Uniswap shortly after the quadrillion-token mint occurred.
How the MAPO Mint Exploit Happened
Security researchers later outlined how the attack unfolded. According to Blockaid, the attacker initially submitted a legitimate oracle multisig-signed message before deploying a malicious smart contract at a carefully chosen address.The exploiter then resent a modified “retry” message that appeared identical in transaction hash but had actually been manipulated. Because the cross-chain bridge incorrectly verified the altered message as authentic, the system approved the minting of the massive MAPO supply.Researchers stressed that no private keys were stolen and no light clients were compromised during the attack. Instead, the incident was described as a “classic Solidity vulnerability involving multiple dynamic fields.”The exploit once again demonstrated how weaknesses in smart contract validation can place both MAPO and ETH liquidity ecosystems at risk.
As API and AI adoption grows across the Middle East, so do the expectations around how data is handled. For many organizations operating in this region, it’s not just about securing applications. It’s about doing it in a way that keeps data in-country and aligned with local requirements. Today, we’re introducing the Wallarm Middle East [...]
What happened A ransomware attack on Sandhills Medical Foundation, a Federally Qualified Community Health Center in McBee, South Carolina, is now the subject of a class action investigation, nearly a year after the incident was first discovered. Sandhills Medical discovered the ransomware attack on May 8, 2025. A forensic investigation determined that an unauthorized third […]
What happened CTM360 researchers have uncovered a large-scale fraud operation using Telegram’s Mini App feature to run cryptocurrency scams, impersonate major brands, and distribute Android malware. The platform behind the operation, dubbed FEMITBOT based on a string found in API responses, uses Telegram bots and embedded Mini Apps to create convincing app-like experiences within the […]
What happened Frost Bank, San Antonio’s largest bank, is facing two proposed class-action lawsuits following a cyberattack attributed to the Everest ransomware group that allegedly exposed the sensitive personal data of an estimated 109,000 customers. The bank has not publicly confirmed the scope of the breach or reported it to the Texas Attorney General’s Office, […]
What happened A cybersecurity incident in late April 2026 targeted Sistemi Informativi, an Italian company wholly owned by IBM Italy that provides IT infrastructure management for public agencies and key private sector organizations. IBM confirmed the breach through an official statement, acknowledging it had identified and contained a cybersecurity incident and activated incident response protocols […]
What happened Cyberthint analysts have documented a structural shift in how cyberattacks are conducted, with threat actors now using artificial intelligence to discover and exploit zero-day vulnerabilities in minutes rather than months. The firm identified this transition in late 2024, noting that AI is operating not just as a research assistant but as an active […]
What happened A faulty Microsoft Defender antimalware signature update released around April 30, 2026, caused widespread false positive alerts by incorrectly flagging two legitimate DigiCert root certificates as high-severity malware. The detection, labeled Trojan:Win32/Cerdigent.A!dha, identified registry entries belonging to DigiCert Assured ID Root CA and DigiCert Trusted Root G4 as threats and automatically quarantined them […]
The cyber threat outlooks from CIOs and CISOs at the NASCIO Midyear Conference in Philadelphia ranged from the good to the bad to the ugly — with AI front and center.
Security leadership is often associated with emerging threats and advanced technologies, but much of the role comes down to disciplined execution, thoughtful decision-making, and balancing protection with business continuity. In CISO Diaries, we speak with leading CISOs around the world to understand what the role actually looks like beyond frameworks and incident headlines, how security […]
What happened A supply chain attack campaign attributed to TeamPCP, dubbed Mini Shai-Hulud, has compromised packages across the PyPI, NPM, and PHP ecosystems over a two-day period, affecting over 1,800 developer repositories containing stolen credentials. The campaign was first identified on April 29 when malicious versions of four SAP NPM packages were caught delivering information-stealing […]
What happened A third iteration of the ConsentFix attack technique has been circulating on hacker forums, introducing automation and scalability to a method that abuses Microsoft Azure’s OAuth2 authorization code flow to hijack accounts without passwords and despite multi-factor authentication being enabled. The original ConsentFix was documented by Push Security in December 2025 as an […]
What happened The FBI issued a public service announcement on April 30, 2026, warning the US transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025. That represents a 60% increase over the prior year. Confirmed cargo theft […]
What happened Instructure, the company behind the Canvas learning management system, has disclosed that it recently suffered a cybersecurity incident perpetrated by a criminal threat actor and is now investigating its scope with the help of outside forensics experts. The disclosure was made by Chief Security Officer Steve Proud, who committed to transparency as the […]
What happened Congress approved a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act on Thursday, hours before the program was set to lapse, pushing the next deadline to June 12. President Trump is expected to sign the legislation before the midnight deadline. The path to the extension was complicated. The day prior, […]