
Desired Effect Launches First Vuln/Exploit Ethical Market - Brings Defenders to the Pre-Attack Buying Pool, Strips Attackers of Cheap Exploits and First-Mover Edge
SAN FRANCISCO & BALTIMORE--(BUSINESS WIRE)-- Desired Effect, the first ethical market vulnerability management exchange that disrupts the cybercrime supply chain and offers pre-attack exploit intelligence, has launched the Desired Effect Marketplace, which lets organizations and independent researchers legitimately and legally transact for zero day exploits that impact any organization or business. The Desired Effect Marketplace gives defenders true, immediate, pre-attack zero day insight, offers independent researchers better compensation and recognition for their work, and drives up the cost of the adversary's critical tooling by breaking up their current monopoly on access to exploits.
We deliver disruptively superior intelligence feeds by getting closer to the source. We elicit/leverage cutting-edge research by providing a platform for researchers to ethically sell exploits to vetted buyers – stripping attackers of first-mover advantage
Share
Desired Effect is emerging from stealth for the RSA Conference 2025, and is now successfully analyzing content and processing transactions between independent researchers and early customers.
Desired Effect CEO and Founder Evan Dornbush, a former NSA cybersecurity professional and successful entrepreneur, said: 'We deliver disruptively superior intelligence feeds because we get closer to the source. We elicit and leverage cutting-edge research by providing a platform for researchers to ethically sell exploits to vetted buyers.
'By offering an efficient, transparent marketplace, we normalize the buying and selling of zero day exploits, which has until now taken place in disparate and opaque markets at a disadvantage to everyone except the attackers.'
The Desired Effect Edge
Desired Effect lets subscribers acquire deep, real-time research data on future zero day exploits tailored to their unique tech stack - data that highlights the precise technology at risk and enables immediate protective action. Further, for the first time in a commercial offering, once vetted they can also choose to buy the exploits from the researchers, either alone, or in crowdsourced pools. Defenders can then take immediate protective action. Cybersecurity researchers can use the Desired Effect Marketplace to gain access to an ethical marketplace that lets them derive both recognition and compensation levels that honor and reflect their contributions to the community.
Attackers are stripped of both the perpetual first-mover advantages they've enjoyed and the extremely low acquisition and operating costs that have allowed them to amass fortunes through theft.
One investor says, 'Cyber threat intelligence (CTI) and vulnerability management are focused on understanding and mitigating potential IT risks by sharing past and present threat behavior. Desired Effect lets organizations understand pre-emergent threats – reframing these cybersecurity categories.'
How Desired Effect's Marketplace Works
For Defenders: Desired Effect gives defenders access to zero day vulnerability data and exploit products tailored to their unique tech stack, via its early-warning Cyber Threat Intelligence feed powered by an exploit marketplace unique in the industry. It elicits and leverages cutting-edge research by providing a platform for researchers to ethically sell exploits to vetted buyers, who can either purchase the exploit intellectual property outright, or crowdsource with others to outpace adversary budgets.
For Independent Researchers: The Desired Effect Marketplace opens an important new pathway to compensate and recognize independent cybersecurity researchers for the outsized impact their discoveries and contributions have on the security postures of the organizations they assist, and our collective societal defense. Unlike current avenues, researchers set their own terms to include price, acceptable buyer demographics, optional public recognition for the finding, and IP assignment.
For Vendors: A downstream benefit of the Desired Effect Marketplace is that defenders can alert technology vendors to vulnerabilities and issues with their products far earlier in the cycle, enabling faster fixes. Vendors are also invited to become subscribers to gain timelier awareness of vulnerabilities and their potential for exploitation.
For Attackers: It doesn't.
Customer and Investor Comments:
Dornbush also shared enthusiastic feedback and results achieved by beta customers, such as one of the big four accounting firms, a bank holding company with more than $200 billion in held assets, and a cryptocurrency exchange.
One customer says: 'The pain of threat intel is that it's damn near impossible to make operational. When you get something from Desired Effect, you know it's actionable, not academic.'
Another says: 'Your marriage of market data and the capability of the exploit against a customer's unique environment is a special and valuable offering.'
Dornbush added: 'Over the last decade, exploits have been readily available, cheaply and without competition, in sketchy shadow markets, allowing criminals with marginal skill and budget to amass fortunes using cheap exploits, putting both defenders and researchers at a disadvantage. The Desired Effect Marketplace upends that dynamic by allowing those most likely affected by exploits - i.e. the defenders – to achieve the earliest threat intelligence possible, while bringing researchers out of the shadows and into fairer compensation and well-deserved recognition.'
To learn more about Desired Effect membership plans, visit: http://www.desiredeffect.io
About Desired Effect
Desired Effect provides all members with the earliest possible warning of vulnerabilities that could impact business operations via the technology they use, and the option to remove exploits from circulation. It provides researchers with the world's first open, ethical marketplace.
Desired Effect normalizes the research, discovery and procurement of zero day exploit data and if desired, the exploits themselves. It provides legitimate and legal means for researchers and defender organizations to transact and work together. Go to www.desiredeffect.io for more information.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Business Wire
18 minutes ago
- Business Wire
MangoBoost Sets New Benchmark for Multi-Node LLM Training on AMD GPUs in MLPerf Training v5.0
BELLEVUE, Wash.--(BUSINESS WIRE)--MangoBoost, a provider of cutting-edge system solutions for maximizing compute efficiency and scalability, has validated the scalability and efficiency of large-scale AI training on AMD Instinct™ MI300X GPUs through its MLPerf Training v5.0 submission. Tailored for enterprise data centers prioritizing performance, flexibility, and cost-efficiency, this milestone demonstrates that state-of-the-art LLM training is now viable beyond traditional vendor-locked GPU platforms. This showcases how the AMD Instinct™ MI300X GPUs and ROCm™ software stack synergize with MangoBoost's LLMBoost™ AI Enterprise software and GPUBoost™ RoCEv2 NIC. Share Using 32 AMD Instinct™ MI300X GPUs across four nodes, MangoBoost fine-tuned the Llama2-70B-LoRA model in just 10.91 minutes, setting the fastest multi-node MLPerf benchmark on AMD GPUs to date. The system achieved near-linear scaling efficiency (95–100%), proving that MangoBoost's stack can support practical and scalable LLM training in production environments. Scalability and Efficiency for Enterprise Data Centers The result showcases more than just benchmark success—it underscores how enterprises can reliably scale LLM training across clusters without network bottlenecks or rigid infrastructure dependencies. Mango LLMBoost™: A full-featured MLOps software platform for large language models, supporting model parallelism, automatic tuning, batch scheduling, and advanced memory management. Mango GPUBoost™ RoCEv2 RDMA: Inter-GPU communication hardware optimized for low-latency, high-throughput node-to-node communication, sustaining line-rate performance across thousands of concurrent QPs. These technologies together deliver predictable and efficient multi-node training, ideal for organizations operating their own AI infrastructure or deploying on public cloud. Industry-First MLPerf Training on AMD MI300X GPUs This is the first-ever MLPerf Training submission on AMD GPUs spanning multiple nodes. MangoBoost's platform demonstrated robust performance with a 4-node, 32-GPU cluster and confirmed compatibility with additional model sizes and structures—including Llama2-7B and Llama3.1-8B—in internal benchmarks. These results validate the generalizability of MangoBoost's platform beyond benchmarks to diverse production-scale use cases. " I'm excited to see MangoBoost's first MLPerf Training results, pairing their LLMBoost AI Enterprise MLOps software with their RoCEv2-based GPUBoost DPU hardware to unlock the full power of AMD GPUs, demonstrated by their scalable performance from a single-node MI300X to 2- and 4-node MI300X results on Llama2-70B LoRA. Their results underscore that a well-optimized software stack is critical to fully harness the capabilities of modern AI accelerators." — David Kanter, Founder, Head of MLPerf, MLCommons Vendor-Neutral AI Infrastructure Enabled by AMD Collaboration The achievement was made possible through deep collaboration with AMD and seamless integration with the ROCm™ software ecosystem, enabling full utilization of MI300X's compute, memory bandwidth, and capacity. Enterprises are now empowered to choose infrastructure based on business needs—not vendor constraints. " We congratulate MangoBoost on their MLPerf 5.0 training results on AMD GPUs and are excited to continue our collaboration with them to unleash the full power of AMD GPUs. In this MLPerf Training submission, MangoBoost has achieved a key milestone in demonstrating training results on AMD GPUs across 4 nodes (32 GPUs). This showcases how the AMD Instinct™ MI300X GPUs and ROCm™ software stack synergize with MangoBoost's LLMBoost™ AI Enterprise software and GPUBoost™ RoCEv2 NIC." — Meena Arunachalam, Fellow, AI Performance Design Engineering, AMD "At MangoBoost, we've shown that software-hardware co-optimization enables scalable, efficient LLM training without vendor lock-in. Our MLPerf result is a key milestone proving our technology is ready for enterprise-scale AI training with superior efficiency and flexibility," said CEO Jangwoo Kim. MangoBoost continues to develop innovations in communication optimization, hybrid parallelism, topology-aware scheduling, and domain-specific acceleration to further scale performance in distributed AI workloads. About MangoBoost MangoBoost is a provider of cutting-edge, full-stack system solutions for maximizing compute efficiency and scalability. At the heart of the solutions is the MangoBoost Data Processing Unit (DPU), which ensures full compatibility with general-purpose GPUs, accelerators, and storage devices, enabling cost-efficient, standardized AI infrastructure. Founded in 2022 on a decade of research, MangoBoost is rapidly expanding its operations in the U.S., Canada, and Korea.
Yahoo
23 minutes ago
- Yahoo
QPS Celebrates 30th Anniversary
NEWARK, Del., June 04, 2025--(BUSINESS WIRE)--QPS Holdings, LLC (QPS), an award-winning contract research organization (CRO) focused on bioanalytics and clinical trials, is celebrating its 30-year anniversary in 2025. Founded by Dr. Benjamin Chien in 1995 to provide high-quality bioanalytical liquid chromatography with tandem mass spectrometry (LC-MS/MS) contract services, QPS is now recognized as a global leader in contract research. Over the past 30 years, the company has grown from a single office in Delaware, USA to a widely respected, global, full-service CRO with 8 locations spread across the US, EU, Asia, India and Australia, a clinical trial network of over 700 sites and an increased focus on leveraging the power of AI to accelerate clinical trials. Over the years, QPS has grown from a small molecule bioanalysis shop of three people to a global CRO with more than 1,200 employees. "30 years is a major milestone for QPS and I couldn't be more proud of the hard-working and innovative people who choose to work at QPS. They are the backbone of the company, and I am very grateful for their valuable contributions," said founder and CEO of QPS, Dr. Benjamin Chien. "Through QPS, the pharmaceutical and biotechnology industries have access to dedicated, focused scientific expertise across the drug development spectrum. In facilities around the world, QPS has assembled best-in-class instruments, platforms, people and processes required to conduct the studies necessary to support client drug discovery and development programs focused on obesity, type 2 diabetes, oncology, CNS diseases, cell and gene therapy, and more," said Dr. Chien. Since its humble beginnings, QPS has expanded its service options, to include pharmacology, DMPK, toxicology, bioanalysis, translational medicine, leukopaks, PBMCs, cell therapy products, clinical trials, central lab services, and a full range of clinical research services. QPS is known for high-quality data, technical expertise, delivery of promised study timelines, collaborative solutions, and customer-focused strategies. Going forward, QPS plans to continue delivering custom-built research services that accelerate pharmaceutical breakthroughs across the globe. ABOUT QPS HOLDINGS, LLC QPS is a global, full-service, GLP/GCP-compliant contract research organization (CRO) delivering the highest grade of discovery, bioanalysis, preclinical and clinical drug development services. Since 1995, QPS has grown from a small bioanalysis shop into a full-service CRO with 1,200+ employees in the US, Europe, Asia and Australia. Today, QPS offers expanded pharmaceutical contract R&D services with special expertise in pharmacology, DMPK, toxicology, bioanalysis, translational medicine, leukopaks, PBMCs and cell therapy products, clinical trials, and clinical research services. An award-winning leader focused on bioanalysis and clinical trials, QPS is known for proven quality standards, technical expertise, a flexible approach to research, client satisfaction, and turnkey laboratories and facilities. Through continual enhancements in capacities and resources, QPS stands tall in its commitment to delivering superior quality, skilled performance and trusted service to its valued customers. For more information, visit or email info@ View source version on Contacts QPS CONTACT: Name: Gabrielle PastorePhone: 1-302-635-4290Email: Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data
Yahoo
28 minutes ago
- Yahoo
RSA Announces New Windows Desktop Login and Entra ID Passwordless Solutions
LAS VEGAS, June 04, 2025--(BUSINESS WIRE)--RSA, the security-first identity leader, announced new innovations that expand RSA's complete passwordless solutions, including support for Microsoft Entra ID-joined desktops and legacy, RADIUS-based environments at Identiverse today. These innovations help organizations accelerate deployment of phishing-resistant passwordless solutions across their entire environment, reducing risks, modernizing authentication, and driving efficiency. Available as part of RSA® ID Plus, the only complete passwordless identity security platform, new passwordless features include: Passwordless support for Windows Desktop Login and Entra ID: ID Plus now supports mobile passkeys and QR codes to complete Windows log-in. ID Plus will add Entra ID support in July. One-step enrollment process: Starting in July, users will be able to enroll new RSA mobile passkeys and other RSA MFA methods via a one-step enrollment process that eliminates delays and reduces help desk support costs. Code matching for RADIUS: Organizations operating in RADIUS environments can now deploy code matching to reduce the risk of prompt bombing and ensure legacy architecture stays operational. These new passwordless enhancements are fortified by deep security innovations that extend organizations' defenses and protect against post-passwordless threats. The newly-announced RSA Help Desk Live Verify (patent pending), only available through ID Plus, uses passwordless bi-directional identity verification to stop help desk scams like the recent attacks on Marks & Spencer, Christian Dior, Co-Op, and MGM Resorts. RSA Mobile Lock secures the authentication process itself by scanning devices for app tampering, malware, sideloading, jailbreaking, and AiTM attacks. "Not all passwordless is created equal: government agencies, finance, energy and healthcare providers, and other security-first organizations need a passwordless solution for all users, environments, and devices," said RSA CEO Rohit Ghai. "Moreover, to defend against emerging threats, organizations must integrate passwordless into an identity security platform that provides full visibility into user access while constantly assessing identity security posture. Cyberattacks start wherever organizations' security capabilities end, which is why high-security organizations rely on RSA for a complete identity security platform that stops phishing, malware help desk scams, ransomware, and other attacks before they start." Identiverse attendees are invited to demo these new solutions at booth #342. Resources: Book a meeting with RSA at Identiverse RSA Governance & Lifecycle Advanced Dashboards solution brief RSA passwordless solution brief RSA Mobile Lock data sheet Try RSA ID Plus About RSA RSA provides mission-critical cybersecurity solutions that protect the world's most security-sensitive organizations. The RSA Unified Identity Platform provides true passwordless identity security, risk-based access, automated identity intelligence, and comprehensive identity governance across cloud, hybrid, and on-premises environments. More than 9,000 high-security organizations trust RSA to manage more than 60 million identities, detect threats, secure access, and enable compliance. For additional information, visit our website to contact sales, find a partner, or learn more about RSA. View source version on Contacts teamrsa@