AI NewsAnother customer of troubled startup Delve suffered a big security incident

Another customer of troubled startup Delve suffered a big security incident

10:10 PM IST · April 23, 2026

Another customer of troubled startup Delve suffered a big security incident

The story of embattled compliance startup Delve keeps hitting twists and turns. TechCrunch has confirmed that Delve was the compliance company that performed the security certifications for Context AI, the AI agent training startup that last week disclosed a security incident whichled to a data breach at popular app and website hosting giant Vercel. On the other hand, Lovable, which had its own security incident, is no longer a Delve customer. To recap: Last month, Delve came under fire when an anonymous whistleblower alleged thatthe startup was faking customer dataand using rubber-stamping auditors in its compliance and certifications processes. Delve has denied those allegations. Soon afterwards, hackers attackedone of Delve’s security certification customers, LiteLLM, and planted malware in its open source code. After the incident, LiteLLM told TechCrunch it was dumping Delve and getting re-certified. Delve was alsoaccused of taking an open source tooland passing it off as its own work without proper license attribution. The startup’s reputation grew shaky, promptingY Combinator, where Delve graduated from, to sever ties. Fast-forward to last weekend, Vercel said hackers hadbreached its internal systems and accessed some customer data. The company said hackers broke in after an employee downloaded an app made by Context AI and connected that app to Vercel’s corporate account hosted by Google. The hackers abused that employee’s access to their Google account to break into some of Vercel’s internal systems. After Context AI was named in the Vercel attack, Gergely Orosz, author of the engineering newsletter The Pragmatic Engineer, saidin a post on Xthat Delve was the company that handled Context AI’s security certification. Context AI has now confirmed to TechCrunch that it did use Delve, but it has since ditched the startup and is in the process of getting re-certified. “Yes, Context was previously a Delve customer,” a spokesperson for Context AI told TechCrunch. “Following the reporting surrounding Delve in March, we transitioned our compliance program to Vanta and engaged Insight Assurance, an independent audit firm, to conduct new examinations. As part of the re-examination, we began updating our public materials, and we’ll share the new attestation when it is complete,” the spokesperson added. Security certifications on their own don’t stop security issues. They are intended to verify that a company has policies and processes in place to hinder attacks and reduce the likelihood of customer data being compromised. Case in point: Lovable was a Delve customer, butafter the whistleblower’s allegations came out,the vibe-coding platform said it had ditched the startup back in late 2025. The company has already re-completed one security certification, and is in process of redoing others, it said. Still, Lovable onMonday admittedthat it had inadvertently shared access to customer chat data publicly. The company also said it had dismissed vulnerability reports that alerted the company to the problem months earlier. Lovable apologized for initially denying there was a data breach, though it said the issue was caused by a configuration error, rather than a hack. There’s even weirder news swirling around Delve. The anonymous whistleblower, DeepDelver, haspublished another postalleging Delve was denying refunds to customers, but still took its team of more than 20 people to an offsite meeting in Hawaii between April 15 and April 19. The whistleblower shared some compelling receipts with TechCrunch that lend credence to the alleged Hawaii trip, but TechCrunch could not confirm other claims. After publication, Delve declined comment.

read more

Latest AI News

View All News →
Databricks Has a ‘Too Much Opportunity Problem’ in India

Databricks Has a ‘Too Much Opportunity Problem’ in India

For companies like Databricks, the country is becoming the next frontier of scale, experimentation, and eventually, product definition.

1 hour ago

View

Laid-off Oracle workers tried to negotiate better severance. Oracle said no.

Laid-off Oracle workers tried to negotiate better severance. Oracle said no.

As was widely reported, Oracleaxed an estimated 20,000 to 30,000 peoplevia email on March 31. One of the employees cut that day told TechCrunch about the experience: “I had, like, this weird feeling in my stomach. I went to go sign into the VPN, and the VPN was like, ‘this user doesn’t exist anymore.’ Then I called my friend, and I was like, ‘Hey, can you see me in Slack?’ And she said, ‘No, your account’s been deactivated.’” The person soon received an email stating their role was terminated immediately. The severance offer arrived a few days later. But Oracle’s terms would quickly become a point of contention — and some laid-off employees would push back. Oracle offered fairly standard Corporate America terms to laid off employees. In exchange for signing a release waiving their right to sue, employees received four weeks of pay for the first year, plus one additional week per year of service, capped at 26 weeks. The company was also paying for one month of COBRA insurance. The catch: Although stock compensation often makes up a good chunk of a tech worker’s pay, particularly at Oracle, the company did not accelerate soon-to-vest RSUs. Any shares that hadn’t vested by the termination date were forfeited. That held true even for stock granted as retention incentives or in place of salary increases tied to promotions. One long-tenured employee lost $1 million in stock that was just four months from vesting; RSUs made up about 70% of his compensation,Time reported. Some employees also discovered that if they were classified as remote workers by the company, and didn’t work in a state with stronger worker provisions like California or New York, the company said they didn’t qualify for WARN Act protections. TheWARN Act is a lawthat requires companies conducting mass layoffs to give employees two months notice prior to letting them go. It’s triggered when 50 or more people are impacted at one location. By classifying employees as remote workers, the minimum location requirements can be sidestepped. Some people were unaware they were classified as remote workers, because they were near an office and worked on a hybrid schedule. Even if they were covered by the WARN Act, this did not necessarily extend severance, the former Oracle employee said. That’s because Oracle included the two-months’ WARN notice pay in its existing calculation of four-weeks, plus one week per year. For a short time, a group of employees tried to negotiate en masse with Oracle, according to a letter seen by TechCrunch. At least90 people signed a public petitionurging the database and cloud computing giant to match the terms of other big tech companies conducting mass layoffs in the name of AI. For instance, Meta’s severance package, according to an email published by Business Insider, started at 16 weeks of base pay, plus two weeks for every year of employment and covered COBRA for 18 months. Microsoft, which extended voluntary retirement offers to long-serving employees, provided accelerated stock vesting, a minimum of eight weeks’ pay, and an additional one to two weeks for every six months of service, depending on rank, theSeattle Times reported. And Cloudflare, which just cut 20% of its employees,offered lump sum severancethat was the equivalent of base pay through the end of 2026, plus healthcare coverage through the end of the year, and accelerated vesting of stock through August 15. So if an employee was close to obtaining another tranche, they will get it. Oracle declined to negotiate, according to an email seen by TechCrunch. It was a take-it-or-leave scenario, the employee said. When asked about its severance terms, classifying employees as remote, and the failed attempt by employees to negotiate more, Oracle declined to comment. Such a reaction from the company isn’t a surprise, not even to those who hoped to negotiate. But it does underscore that for all the theoretical high pay (often via stocks) and perks that tech workers enjoy when it’s an employees’ market, they have very few protections in place when it isn’t.

9 hours ago

View

Cloudflare says AI made 1,100 jobs obsolete, even as revenue hit a record high

Cloudflare says AI made 1,100 jobs obsolete, even as revenue hit a record high

Cloudflare on Thursday joined a growing list of tech companies — including Meta, Microsoft, and Amazon — that have reported increased revenue alongside massive layoffs, attributing both trends to their use of AI. Cloudflare, which provides internet security and performance services to millions of websites worldwide, announced it was cutting its workforce by approximately 20%, which equates to 1,100 people, it said as part of its first quarter 2026 earnings report on Thursday. “We’ve never done something like this in Cloudflare’s history,” co-founder and CEO Matthew PrincesaidThursday on the quarterly conference call, marking the first mass layoff in the company’s 16-year history. The company is cutting people from all teams and geographies except for salespeople who carry revenue quotas, CFO Thomas Seifert detailed on the call. The news of the workforce cuts came as the companyreportedquarterly revenues of $639.8 million, a 34% year-over-year increase and the highest single quarter in the company’s history. However, this was coupled with a loss of $62.0 million compared with losing $53.2 million in the year-ago quarter. That widening loss, even as revenue surged, highlights a familiar paradox in Cloudflare’s story: the company is growing fast but has yet to turn a consistent profit. But the loss was a smaller percentage of revenue, and the quarter was coupled with a lot of other positive indicators. For instance, Cloudflare reported that it had over $2.5 billion in “remaining performance obligations,” a year-over-year growth of 34%. RPO is the favorite metric these days to indicate revenue under contract but not yet delivered. Hence, Prince insisted, the 20% cuts were not to reduce expenses but were strictly because of its use of AI. “Today’s actions are not a cost-cutting exercise or an assessment of individuals’ performance; they are about Cloudflare defining how a world-class, high-growth company operates and creates value in the agentic AI era,” Prince and Cloudflare co-founder and president, Michelle Zatlyn,wrotein a related blog post about the layoffs. Prince acknowledged on the call that even though Cloudflare has been selling AI-powered products, it was at first cautious about adopting AI itself. “Internally, the tipping point was last November. At that point, across our teams, we began to see massive productivity gains, team members that were two, 10, even 100 times more productive than they had been before. It was like going from a manual to an electric screwdriver,” he described. “Cloudflare’s usage of AI has increased by more than 600% in the last three months alone,” he added. Prince highlighted the internal use of AI coding, saying that virtually the entire R&D team is now using the company’s own Workers platform — a tool that lets developers build and run software directly on Cloudflare’s global network — including its vibe coding feature. He also noted that 100% of the code produced this way and deployed for use in Cloudflare’s products is “now reviewed by autonomous AI agents.” But it’s not just developers who are using AI internally, he said. “Employees across the company from engineering to HR to finance to marketing run thousands of AI agent sessions each day to get their work done.” As a result, these highly productive, AI-powered employees require fewer support staff, he argued. “A lot of the support people that provide support behind them, those roles aren’t going to be the roles that, you know, drive companies going forward,” Prince said. Interestingly, Prince says that Cloudflare “will continue to hire people, and we’ll continue to invest in them because the people that are embracing these tools are just so much more productive than we’d ever seen before. I would guess that in 2027 we’ll have more employees than we did at any point in 2026.” Cloudflare said it ended its first quarter before layoffs with a headcount of about 5,500. The pattern Prince described — deploying AI gains as justification for workforce reductions even during a period of strong revenue growth — is fast becoming a familiar script across the tech industry. Whether it reflects true structural transformation or acts as convenient cover for cost discipline is a question that investors and employees will be wrestling with for some time to come. When asked by an analyst on the call why the company needed to cut so deeply after such a good quarter, Prince said, “Just because you’re fit doesn’t mean you can’t get fitter.”

13 hours ago

View

Intel’s comeback story is even wilder than it seems

Intel’s comeback story is even wilder than it seems

Bloomberg has adeep divethis week into how Intel CEO Lip-Bu Tan is trying to rescue one of Silicon Valley’s most storied, and stumbling, chipmakers. It’s worth a read, but it actually undersells the most jaw-dropping part of the story: Intel’s stock has risen a stunning 490% over the past year, a bet by Wall Street that may be running well ahead of the company’s actual turnaround. Tan, who took over inMarch of last year, has spent much of his first year schmoozing rather than restructuring — locking in asweetheart dealwith the U.S. government (now Intel’s third-largest shareholder), cozying up to Elon Musk on afactory partnership, and reportedly landing preliminary manufacturing agreements with both Apple and Tesla. The fundamentals are still messy. Intel’s chip yields lag well behind industry leader TSMC, and employees tell Bloomberg that Tan has been light on specifics internally, with some teams adjusting missed deadlines rather than recovering from them. But investors are betting big on the bigger picture. Whether the execution follows is the multi-billion-dollar question.

13 hours ago

View