Securing a DoD Contractor: Strix Finds Zero Tenant Isolation Exposing Military Training Data — 197 Points on HN
Strix / Hacker News·medium signal
Security firm Strix published a detailed writeup of discovering a multi-tenant authorization vulnerability in a DoD-backed startup, with zero tenant isolation that exposed military training data across organizations. The responsible disclosure timeline took five months. The post hit 197 points and 81 comments on HN, with practitioners discussing the broader pattern of SaaS companies serving defense customers without adequate tenant isolation. The story arrives as the FY2026 NDAA mandates new CMMC-style AI security frameworks for DoD contractors.