Prince Baruwala
I write and edit Root Notes, from India. The site covers security — breaches, exploited vulnerabilities, the tooling attackers use — alongside AI, infrastructure and the companies building both.
How I work
Every piece starts at the primary source: the vendor advisory, the research write-up, the regulator's document, the filing. Where reporting is the only source, it is named as such. Quotations are kept short and few, and the rest is paraphrased with attribution, so a reader can tell what a company said from what I concluded.
Each article ends with what is not established — the attribution nobody has confirmed, the number two sources disagree about, the question the research leaves open. That section exists because a story that only lists what is known reads as more certain than it is. The full method is in the editorial policy.
Corrections and contact
If something here is wrong, tell me and I will fix it: hello@rootnotes.in. How corrections are handled is set out in the editorial policy.
Recent articles
- Bitget lost about 388 million dollars, and the way in was the security product — 2026-10-01
- France's tax agency learned of the theft from the thief, seven weeks after it started — 2026-10-01
- The malicious GPT sat on chatgpt.com, the ad was bought on Google, and the victim pasted the command themselves — 2026-10-01
- OpenAI says it cancelled a finished model over its own safety tests, and published none of the numbers — 2026-10-01
- The Zimbra flaw arrives as an email, and what it takes is the pair of keys that make passwords beside the point — 2026-10-01
- 101 npm packages stole nothing. They signed the developer's WhatsApp account up to a channel — 2026-10-01
- One hex-encoded letter walks past Cisco SD-WAN Manager's login, and it is already being used — 2026-10-01
- The CPU forgets the code and remembers where it jumped. That is enough to read the root hash — 2026-10-01
- The agent could not attach a screenshot to a pull request, so it published one. Then 13,000 of them — 2026-10-01
- Zscaler counts 275% more ransomware and 3% fewer named victims. Those are two different things being counted — 2026-10-01
The rest are in the archive.