Connect with us

Tech

Now Rippling is counter suing tiny startup Runlayer

Published

on

HR startup Rippling filed a lawsuit Monday accusing MCP gateway startup Runlayer of infringing on three of its patents, according to the lawsuit seen by TechCrunch.

The filing comes after Runlayer sued the HR startup last month, accusing it of breach of contract and stealing its product ideas.

It’s the latest saga between the two companies after Rippling spent nearly a year testing the startup’s MCP product. The two companies never agreed on a price, and the trial never turned into a paid contract. Instead, Rippling built its own MCP server, and will soon offer it as a product that competes with Runlayer. (Rippling often turns its internally used tech into products, like its recently released AI Spend Console.)

Their battle serves as a warning of how the relationship between customers and startups can devolve in this AI-powered age of fast product building.

Runlayer, which launched its product about a year ago, bundles an MCP gateway with cybersecurity features like threat detection. MCP is an open standard that allows AI agents to connect with data and software systems needed to work independently.

Runlayer has raised a total of $42 million and was founded by third-time founder Andrew Berman. (His previous companies were baby-monitor maker Nanit and an AI video conferencing tool, Vowel, that sold to Zapier in 2024). Rippling became one of Runlayer’s earliest potential customers trialing its software.

The most dramatic detail in the lawsuit is Runlayer’s claim that a Rippling employee reached out to Berman to warn him that his employer was building a “copy” of Runlayer’s product. A Rippling spokesperson tells TechCrunch that its employee has since revised that view.

On Rippling’s side, perhaps the most dramatic claim is that it informed Runlayer of the patents it believed Runlayer had infringed soon after the startup filed its lawsuit.

One might infer that the suit is intended as leverage to bring Runlayer to the settlement table. Indeed, that’s how Runlayer views it.

“This is a desperate, retaliatory ploy to distract from the fact Rippling misappropriated our proprietary technology. We clearly have a standout AI product that has nothing to do with these patents. No attempt to bully or distract will prevent us from protecting our IP and continuing to innovate and create the best product for our fast-growing customer base,” Berman said in a written statement.

Rippling loves a good fighting-words statement too. Its spokesperson told TechCrunch: “It takes a certain boldness to accuse a competitor of violating intellectual property laws while infringing on that competitor’s inventions. But that’s exactly what Runlayer has done here. Rippling’s lawsuit calls out Runlayer’s hypocrisy. Having manufactured claims against Rippling to distract from its business failures, it now has to face a lawsuit for repeatedly copying Rippling’s inventions in building its own products.”

Now it’s up to the courts to unwind who did what to whom, unless the parties settle. But these dueling cases still serve as a buyer- and seller-beware warning. With AI advances, enterprises have never before been more empowered to build tech in-house. Yet they still may put a startup through its paces before choosing that option.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

UK Manufacturers Face Growing Cyber Supply Chain Risk

Published

on

Nearly a third of UK manufacturers say they or a company in their supply chain experienced a cyber incident in the past year, while only half have a response plan in place.

The new findings put supplier exposure alongside direct attacks as a manufacturing risk. A compromised supplier can interrupt production even when the manufacturer itself is not the initial target.

Supply-chain incidents are disrupting production

The Guardian reported that a Make UK survey found 30% of manufacturers had experienced a cyber incident either directly or through their supply chain during the previous 12 months. Among manufacturers affected through their supply chains, about 30% reported delayed customer deliveries or cuts to output, while almost a quarter reported supplier delays or shortages of components and materials.

The UK government’s Cyber Security Breaches Survey provides a broader benchmark. It found 43% of UK businesses identified a breach or attack in the past year, while only 25% had a formal incident-response plan. Those figures cover businesses across the economy and are not a direct manufacturing comparison.

Jaguar Land Rover shows how quickly a cyber incident can move from IT disruption into production. JLR shut down global systems after discovering an attack in late August 2025 and began a phased manufacturing restart on October 8. Production returned to normal levels by mid-November, and JLR recorded £196 million in cyber-related costs in its second fiscal quarter.

The Cyber Monitoring Centre separately estimated the wider UK financial impact at £1.9 billion across more than 5,000 organizations, including disruption to JLR’s multi-tier manufacturing supply chain and downstream businesses.

For manufacturers, supply-chain breaches require more than vendor questionnaires. Teams need to know which suppliers can reach production-critical systems, which dependencies could stop output, and how quickly alternatives could be activated.

Response plans need to cover the factory floor

The UK’s Cyber Resilience Pledge makes board responsibility and stronger supply-chain security core commitments. Its requirements include auditing Cyber Essentials coverage across supply chains and taking a risk-based approach to supplier requirements.

For manufacturers, that means mapping supplier access, testing escalation paths, and making sure incident-response plans cover production recovery as well as data and systems.

Security teams should also verify where operational technology connects to enterprise networks and which third parties can reach those environments. A factory restart can involve production scheduling, logistics, supplier systems, and the controlled return of equipment, not just restoring files.

The practical question is straightforward: Which supplier or system failure could stop production, and has the response plan actually been tested against that scenario?

Also read: Researchers found 77 counterfeit Open VSX extensions that collected developer and CI/CD data, exposing another route for supply-chain compromise.

>

Continue Reading

Tech

Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers

Published

on

Klaviyo has fixed a website configuration bug that may have exposed new customers’ sign-up data, including passwords, to third-party trackers embedded on its site.

The company says fewer than 200 people are known to have been affected based on its readily available active logs. That figure is not a final total, because Klaviyo has not said how far back those logs extend or exactly how long the misconfiguration remained live.

What the Klaviyo sign-up bug may have exposed

TechCrunch reported that security researcher Sam Jadali, co-founder of Melurna, found the Klaviyo sign-up form was misconfigured from at least February 2024 through November 2025 and possibly longer. Melurna’s testing found that sign-up data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X.

The information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. The reporting describes a browser-side data exposure involving trackers, not evidence that attackers breached Klaviyo’s customer database.

Klaviyo attributed the bug to an “application configuration issue” and said it notified the people it identified as affected. The company did not tell TechCrunch how far back its active logs go, meaning the fewer-than-200 figure cannot be treated as the total number affected across the full period identified by Melurna.

The reporting concerns Klaviyo’s own account-registration form, rather than consumer sign-up forms run by retailers using the platform. For businesses whose credentials may have been exposed, the immediate concern is account takeover, particularly when a password was reused or MFA was not enabled.

What Klaviyo customers and IT teams should do now

Anyone who created a Klaviyo account during the reported window should change the password. If the same credential was used elsewhere, reset those accounts too because password reuse can enable credential-stuffing attacks.

Teams should use a password manager to generate unique credentials and review whether MFA is enabled. Klaviyo’s account-security guidance recommends both unique passwords and MFA.

Organizations should also review third-party scripts on registration and login pages and verify that sensitive fields are excluded from analytics and advertising data flows.

Klaviyo’s Activity Log gives administrators a searchable record of edits and other account changes, but it covers activity inside an account rather than data sent from the public registration page.

Until Klaviyo discloses its log-retention window or a complete incident timeline, fewer than 200 people are currently known to be affected while the full scope remains unresolved.

Also read: Fake The Odyssey downloads are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

>

Continue Reading

Tech

Google co-founder Sergey Brin has now spent $100 million to fight the billionaire tax

Published

on

Google co-founder Sergey Brin has donated another $20 million to Build a Better California, an organization advocating against California’s proposed billionaire tax, according to a new filing. That means that the world’s fourth-richest man, whose net worth hovers around $267 billion, has now spent more than $100 million to avoid an estimated $13.3 billion tax payment.

California’s Prop 40, known as the billionaire tax, would impose a one-time 5% tax on the net worth of around 200 billionaires that live in the state. The windfall from this proposed tax would mostly go toward funding California’s healthcare programs. The state’s Medicaid program alone could lose up to $30 billion in federal funding once Trump’s budget cuts take effect next year.

Brin isn’t the only tech mogul seeking ways to avoid such a tax. It’s no coincidence that Meta founder Mark Zuckerberg reportedly bought a $170 million mansion near Miami this year. Former Uber CEO Travis Kalanick, venture capitalist Peter Thiel, and Brin’s fellow Google co-founder Larry Page have also left the state.

Prop 40 has also generated dissent from Governor Gavin Newsom (D-CA), who is concerned about the economic impact of these billionaires and their businesses fleeing California. Instead, Newsom has called for a “national billionaires’ tax.”

“Today, the office worker can shoulder a higher tax rate than the heiress,” Newsom noted in a blog post. “We should end the ‘tax-free lifestyle loan,’ the gimmick that lets the ultra-wealthy borrow against their stock portfolios while reporting no taxable income.”

Californians will vote on Prop 40 in November. The organization that Brin is funding has proposed opposing ballot measures that, if passed, could effectively block Prop 40 by limiting the introduction of new taxes.

Meanwhile, Nvidia co-founder and unlikely working class hero Jensen Huang says he’s “perfectly fine” paying the tax.

“I have not even thought about it once,” Huang, who would owe around $8 billion in taxes, said in a January interview with Bloomberg. “We chose to live in Silicon Valley, and whatever taxes they would like to apply, so be it. I’m perfectly fine with it.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.