Archive for June 23, 2026

Tata investigates breach claims involving Apple and Tesla

Posted in Commentary with tags on June 23, 2026 by itnerd

Tata has apparently been pwned and the victims are Apple and Tesla.

The individual claimed to have stolen approximately 730,000 files, including engineering documents, presentations, spreadsheets, and other internal records associated with Tata Electronics’ manufacturing operations. The alleged breach comes months after Tata Electronics disclosed a separate cyber incident that temporarily disrupted some IT systems. 

Tata Electronics is a key supplier within the global electronics supply chain, producing components and assembling products for major technology companies including being one of Apple’s most significant manufacturing partners outside of China, accounting for roughly a third of its iPhone production in India.

John Strand, Owner, Black Hills Information Security, Inc.:

   “Whenever a breach becomes public because stolen data appears on the dark web, it raises a larger question: how many similar operations, especially those conducted by nation-state-level adversaries, are still operating undetected? The attacks that make the news deserve attention, but the greater concern is the reuse and evolution of the same tactics, tools, and infrastructure across campaigns that never become visible.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:

   “Apple escaped supplier concentration in China and recreated it in India under one corporate roof. A third of India’s iPhone output, one conglomerate. Single point of failure, different mailing address.

   “Vendor cybersecurity review has to cover the whole corporate family. Second cyber incident at Tata Electronics in months. TCS and JLR were hit by different attackers in the past year. Subsidiaries share IT vendors and security culture, so a breach at one should trigger immediate review of every entity holding sensitive client IP.

   “When you hand trade secrets to a contract manufacturer, the cybersecurity terms in that vendor agreement need to reflect what’s being transferred. Continuous monitoring, audit rights, and breach notification requirements should be baseline for a supplier holding IP at this sensitivity level. A questionnaire at onboarding doesn’t cut it. 630 gigabytes on a leak site shows what happens when vendor oversight doesn’t match the exposure.”

John Carberry, Solution Sleuth, Xcape, Inc. adds this:

   “This breach underscores a critical distortion in enterprise risk management where the actual containment of a data exposure plays second fiddle to managing the commercial boundaries of the cyber insurance policy. While the immediate operational crisis centers on leaked schematics for Apple and Tesla, the true systemic damage occurs when organizations prioritize check-the-box compliance to preserve underwriting limits rather than addressing the root cause of third-party aggregation risk.”

   “Critical Takeaways

  • Enterprise security teams must shift from static vendor compliance questionnaires to continuous, automated data lineage tracking across all external manufacturing partners.
  • Risk officers must audit existing cyber insurance policies to ensure coverage limits explicitly account for interconnected, multi-party supply chain liabilities rather than localized infrastructure losses.
  • Access architectures governing joint-venture environments must enforce strict zero-trust isolation to prevent lateral movement from compromised sub-contractor networks.

   “Look on the bright side: your competitors will finally find out how much it actually costs to manufacture your products.”

I think its a safe bet that if Apple and Tesla do not get the answers that they are looking for, that their contract manufacturing will be someplace else shortly.

Klue says hackers stole credential from 2022 that led to pwnage

Posted in Commentary with tags on June 23, 2026 by itnerd

Klue disclosed a cybersecurity incident affecting hundreds of customers including Recorded FutureTaniumHackerOneKudelski Security,Insurity, and Huntress, after attackers gained unauthorized access to data stored within the company’s environment. That you know. But you may not know is that the company may have used a credential that dates back to 2022:

Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal reams of data from its corporate customers, including several cybersecurity companies.

The new detail suggests that Klue may have had years to decommission the credential that was used for the pilot, raising questions about the company’s security posture and what actions it could have taken to prevent the breaches of its customers’ data.

Sunil Gottumukkala, CEO, Averlon had this to say:

   “This is the same pattern we saw with the Salesloft Drift attack, where stolen OAuth tokens were used to pull data from Salesforce and Google Workspace. This method is becoming the dominant way data leaves the enterprise: not through your perimeter, but through an approved SaaS integration.

   “A compromised legacy credential at Klue gave attackers OAuth tokens into hundreds of customers’ Salesforce instances, which they used to impersonate the app and exfiltrate competitive intelligence and customer data. Your security is now only as strong as the third-party apps you have granted standing access to your CRM, and most teams don’t actively track those integrations.

   “The immediate work is to inventory every OAuth integration into your SaaS, revoke what you don’t need, scope what you keep, and watch for anomalous token activity. And since the stolen data includes contact and sales detail, expect targeted phishing next. Warn your customers and employees before the attacker reaches them.”


John Strand, Owner, 
Black Hills Information Security, Inc. provided this comment:

   “This is just a preview of the coming SaaS apocalypse. As AI accelerates offensive cyber operations across threat actors, from nation-states to militias, the risk is no longer limited to organizations building new AI-driven SaaS applications. Attackers are increasingly turning existing SaaS platforms into centralized points of failure, allowing them to exploit multiple customers simultaneously.”

Denis Calderone, CTO, Suzu Labs added this comment:

   “Three Salesforce OAuth supply chain attacks in under a year, from two different threat actors, using the same playbook. Salesloft, Gainsight, and now Klue. Icarus is a brand-new extortion group, active since late April, and they executed the exact same technique that ShinyHunters ran through Gainsight back in November. Compromise the integration vendor, harvest OAuth tokens, query the Salesforce REST API with automated scripts, exfiltrate CRM data in bulk. At this point we have to accept that this particular attack pattern has been successfully commoditized.”

   “What’s got our attention is how many security vendors are on the victim list. Huntress, Recorded Future, Tanium, HackerOne, Kudelski Security, Snyk, Jamf. The data sitting in their Salesforce instances includes competitive battlecards, pricing strategy, customer contacts, deal sizes, and sales communications. We expect to see some highly targeted spear-phishing campaigns as a result of this data.  The attacker has access to real data that only an insider would know.

   “We feel it important to highlight the root cause here. Huntress traced initial access back to a single credential Klue created for a prototype third-party integration they never actually deployed. One forgotten API key got the attacker into Klue’s backend. From there, they pushed a malicious code update that harvested the OAuth tokens of all connected customers at once. So one dormant credential that nobody remembered existed opened the door to 300 organizations’ CRM environments in a single operation.

   “If you’re a Klue customer, rotate every OAuth token tied to that integration, and don’t limit yourself to Salesforce. Klue also integrated with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. The confirmed bulk exfiltration targeted Salesforce, but the token harvest covered all connected platforms.

   “If Klue had an OAuth connection into your Slack, your Google Drive, or anything else, treat those tokens as compromised and rotate them now. Every org needs to audit connected apps for dormant integration credentials and building automated alerts on abnormal API query volume from third-party services. If a connected app that normally syncs a few hundred records starts pulling thousands of queries in minutes, that’s your early warning.”

Damon Small, Board of Directors, Xcape, Inc. said this:

   “This third-party compromise highlights a severe operational risk where specialized business platforms become aggregate targets for corporate espionage, exposing the strategic playbooks of the cybersecurity sector itself. By exploiting Salesforce-linked integrations, attackers bypassed external perimeters to directly access sensitive competitive analysis, product intelligence, and customer data.

   “For security executives, this incident demonstrates that non-core software vendors often possess highly privileged pathways into primary data repositories. To contain this exposure, organizations must immediately catalog all API and OAuth integrations connected to their central Customer Relationship Management systems. Teams should prioritize revoking obsolete or over-privileged third-party tokens, implementing strict scoping boundaries on automated data access, and establishing anomaly detection baselines for bulk data exports conducted by integrated applications.

   “Critical Takeaways

  • Security leaders must immediately audit and inventory all active OAuth tokens and connected applications within their Customer Relationship Management environments to identify over-privileged third-party access.
  • Organizations should enforce strict data scoping and API restriction policies to limit the volume of proprietary competitive intelligence and customer telemetry accessible by integrated platforms.
  • Security operations teams need to establish baseline detection rules specifically tailored to identify anomalous, high-volume data exports or API queries originating from external business applications.

   “It is tough to sell threat visibility to your customers when your own corporate battlecards are exposed because you did not have a Klue.”

I guess that it is far past time for you to audit your environment to ensure that you’re not the next Klue. Because it is much easier to not be the next Klue that it is for me to write about you.

OpenAI’s GPT-5.5-Cyber expansion reflects AI’s shift from finding vulnerabilities to fixing vulnerabilities

Posted in Commentary with tags on June 23, 2026 by itnerd

OpenAI’s expansion of Daybreak with GPT-5.5-Cyber is another sign that leading AI companies are investing heavily in cybersecurity-focused models and programs.

For years, finding serious vulnerabilities required rare expertise, time, and deep familiarity with complex systems. Now, models can navigate large codebases, reason through attack paths, validate hypotheses, and surface security issues that might otherwise stay hidden. Defenders absolutely need access to these capabilities, and also need tools to fix what we can now find, before attackers do.

Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix. We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction.

While much of the attention around AI has focused on offensive risks, announcements like this reflect growing demand for tools that can help defenders analyze vulnerabilities, support security research, and respond to threats more efficiently. As these capabilities continue to improve, the focus will increasingly shift from what AI can find to how effectively organizations can act on those findings.

Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment:

“OpenAI’s GPT‑5.5‑Cyber and ‘Patch the Planet’ underline a new reality: AI is now accelerating both vulnerability discovery and exploitation on timelines measured in days or even hours, not weeks. That’s welcome support for overburdened maintainers who need help finding and patching flaws across massive codebases and critical open‑source projects, but it also means organizations must assume that any internet‑facing weakness will be identified and weaponized very quickly.

To keep pace, enterprises need faster, AI‑assisted discovery and patching baked into their software development lifecycle—not treated as periodic clean‑up work after headlines hit. Just as importantly, even aggressive patching won’t be enough on its own. As models get better at navigating production environments, organizations will need stronger, data‑centric controls across email, SaaS, collaboration tools, and AI systems so that when a vulnerability is inevitably missed or exploited, the blast radius for sensitive data is tightly contained and core business operations remain resilient.”

Yusif Mukhtarov, Lead Data Scientist, Polygraf AI, Polygraf AI follows with this:

“We’ve reached the point in time where every major AI lab is now shipping its own cybersecurity model (Anthropic with Mythos, OpenAI with GPT-5.5-Cyber). They’re all coming from the same idea: finding vulnerabilities wasn’t the hardest part. The top models are clustered within a few points of each other, all on the high end of 80%. When everyone can find the bugs, finding bugs stops being the differentiator. The bottleneck today is validation, triage, patch dev – basically the parts that still run on human time.

That’s why Patch the Planet exists. Frontier models are drowning (cURL, Python, and the Go) projects in findings faster than volunteer maintainers can act on them, and they have to partner with those projects’ maintainers. A model surfacing a 23 year old problem is impressive, but every finding still needs a human to verify it, write the fix, and ship it without breaking the millions of systems depending on that code. In this case, patching scales with people and discovery with compute.

What I wouldn’t agree with is saying that this is a defensive win. The ability to generate a patch can also be used to generate an exploit. Offense in this case has the structural edge – a defender has to validate, test, and deploy across a fragmented install base, an attacker just needs the exploit to work once.  That imbalance is the problem of this moment, and no model release closes it.”

The one thing that I see as a problem is that more advanced AI models are turbocharging bad actors’ abilities to take advantage of security vulnerabilities, forcing the industry to plug the holes almost as soon as they are discovered. That however isn’t a bad thing as far as I am concerned.

Check Point to Embed OpenAI Frontier Cyber Capabilities into Check Point Security Products 

Posted in Commentary with tags on June 23, 2026 by itnerd

Check Point today announced the use of OpenAI’s frontier cyber capabilities into its customer-facing defenses. Through the OpenAI Daybreak Cyber Partner Program, open to only a select group of security vendors, Check Point can embed OpenAI models directly into the products, workflows, and managed services its customers rely on. 

It marks a meaningful shift, from using these models internally to embedding them directly inside the defenses that protect customers, carrying the safety controls, abuse-prevention standards, and scoped outputs that enterprise security demands. The aim is to sharpen threat prevention, faster remediation, and stronger security operations, delivered through the products and services customers already rely on. 

The threat landscape is being shaped by AI. Threat actors are using it to move faster, craft more convincing attacks, and find weaknesses at scale. Defenders need equivalent or stronger capabilities, delivered safely and within clear boundaries. The quality of the models powering defensive workflows has become a strategic variable, not a technical detail. 

Through this expanded partnership, Check Point is identifying the defensive security workflows and solutions where OpenAI’s trusted access for cyber models, paired with the right safeguards, can deliver measurable customer value.  

Check Point and OpenAI are working together to help define the standards for using trusted access frontier AI responsibly in security, building protections against misuse and the controls to catch and stop it. The rollout is deliberately gradual: it begins with carefully controlled defensive uses and widens only as those protections prove themselves. This disciplined approach reflects how Check Point brings AI into its platform across the board, with the rigor and responsibility enterprise security demands. 

Claude Reports Major Outage Across Multiple Models 

Posted in Commentary with tags on June 23, 2026 by itnerd

You may have noticed that Claude AI has had an outage today. 9to5Google reports the following:

Anthropic says it is aware of an outage and has rolled out a fix as recent as 10:53 a.m. ET. The company’s server status website indicates an issue affecting multiple models occurred at 10:19 a.m. ET.

The status update doesn’t detail which models were affected, though attempts to get a response from Sonnet and Opus returned nothing. Those models seem to be the most commonly used, especially as Fable 5 was recently pulled from user access.

The current outage did, however, affect those models across all platforms except for Claude for Government. That includes claude.ai, Claude Console, Claude Code, and Claude API. The total outage time comes close to an hour and stands out as one of the largest outages to hit Anthropic within the past 60 days.

Commenting on this news is Jamie Beckland, Chief Product Officer at APIContext

“Ready or not, AI inference is now production infrastructure. Enterprises are no longer using these systems only for experiments or side projects. They are putting AI into customer support, coding workflows, analytics, operations and decision support. When an inference endpoint slows down, throws errors or goes unavailable, that can now break a real business process.

Enterprises must run AI with the same discipline they apply to payments, cloud, APIs and other critical services. That means continuously monitoring inference endpoints for latency, error rates, model availability, response quality and regional performance. It also means having a tested failover plan before the outage happens.

Applications with one model provider hardcoded create a single point of failure. A more resilient approach is to design AI systems with fallback models, backup providers, graceful degradation and clear routing rules. Not every task needs the same model. If the primary model is unavailable, some workloads can move to another frontier model, some can fall back to a smaller model, and some should pause rather than return a bad answer.

Six months ago, these tools were enterprise experiments. Now, AI resilience is part of operational resilience.”

If you rely on AI as part of your business, then you need to plan for downtime. Why? Downtime is part of the game and you need to be prepared for it or bad things will happen.

TELUS named one of the world’s most sustainable companies

Posted in Commentary with tags on June 23, 2026 by itnerd

TELUS is grateful to have been recognized among the world’s sustainability leaders after being named to TIME Magazine’s World’s Most Sustainable Companies list and earning third place on Corporate Knights’ Best 50 Corporate Citizens ranking. The recognition reflects more than 25 years of integrating environmental stewardship, innovation and social purpose into the company’s core business strategy..

TIME Magazine and Corporate Knights evaluate thousands of companies across sustainable revenue, governance, emissions, innovation, transparency and social impact, making these among the world’s most respected sustainability benchmarks.

This recognition builds on TELUS’ exceptional track record of sustainability leadership, including earning inclusion in Newsweek’s World’s Greenest Companies, receiving a Schneider Electric Sustainability Impact Award for excellence in strategy, digitization, and decarbonization, and being listed on the Dow Jones Best-in-Class Indices for 25 consecutive years, a feat unmatched by any other North American telecommunications company, and inclusion in Corporate Knights’ Global 100 Most Sustainable Corporations.

Driven by its leadership in social capitalism, TELUS has made significant progress on its commitments to ambitious science-based greenhouse gas emission reduction targets, and is continuing to implement sustainable practices across its business including:

  • The achievement of its 2030 climate target of 46% reduction in Scope 1 and 2 emissions five years ahead of schedule
  • Launching its Climate Transition Framework to map its journey to net zero by 2040
  • Avoiding more than 1.4 million tonnes of CO₂e emissions through customer use of TELUS-enabled digital solutions
  • Continuing the expansion of digital health, smart energy, IoT, and precision agriculture technologies
  • Facilitating the ongoing retirement of copper infrastructure in favor of more energy-efficient fibre networks
  • 96% of its electricity – globally – comes from renewable or low-emitting sources
  • 26 million trees planted with our customers and partners, supporting ecosystem restoration across over 16,000 hectares of land
  • 18 million devices diverted from landfills and the launch of a new reuse and recycle program

Sustainable business practices continue to strengthen TELUS’ operational resilience, improve network efficiency, reduce emissions and create long-term value for customers, communities and shareholders.

To learn more about TELUS’ commitment to social capitalism and sustainability, visit telus.com/sustainability.

Peer Software Launches Latest Version of PeerGFS with Major Performance Gains and Enhanced Edge Data Management

Posted in Commentary with tags on June 23, 2026 by itnerd

Peer Software today announced PeerGFS v6.4, the latest version of its Global File Service platform. The new release delivers significant advancements in performance, scalability and operational flexibility for organizations managing large-scale environments and globally distributed file infrastructure.

Today’s enterprises, particularly in the semiconductor, healthcare and life sciences, AI/ML and other data-intensive industries, are facing exponential growth in data driven events and increasingly complex application workloads. As a result, organizations are distributing workloads across multiple locations, dynamically pursuing available compute resources, and leveraging cloud elasticity to scale capacity on demand.

PeerGFS v6.4 is purpose-built to meet this challenge, enabling seamless data orchestration and synchronization across on-premises and cloud infrastructure, so teams can move faster and operate at hyperscale without sacrificing cost efficiency or productivity.

PeerGFS v6.4 delivers broad performance advancements for real-time file synchronization and scheduled replication for large data sets, including:

  • Greatly improved performance for both scheduled scan and real-time replication for SMB and NFS workloads
  • Enhanced resilience for large file transfer resumption on connectivity breaks across distributed sites
  • Upgraded auditing of configuration and management activity
  • Improved performance, reliability, and manageability of edge data management in distributed and bandwidth-constrained environments.

Active exploitation of Gravity SMTP flaw exposes hidden WordPress risk

Posted in Commentary with tags on June 23, 2026 by itnerd

Attackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin that can expose sensitive system information, including API keys, OAuth tokens, plugin inventories, and server configuration details without authentication. While the flaw does not directly enable remote code execution, it highlights a persistent security challenge in the WordPress ecosystem: information disclosure vulnerabilities are often underestimated until attackers use the exposed data for reconnaissance, credential theft, and follow-on attacks.

You can get an overview here: CVE-2026-4020: Gravity SMTP WordPress Plugin Exploited

Gidi Cohen, CEO & Co-founder, Bonfy.AI had this comment

“The active exploitation of the Gravity SMTP vulnerability (CVE‑2026‑4020) to steal API keys, secrets, and full system details from WordPress sites shows how even minor plugins now sit on the front line of enterprise data exposure. An unauthenticated REST endpoint returning configuration data, plugin inventories, and third‑party email credentials gives attackers both the ability to impersonate a brand and high‑quality reconnaissance for chaining additional exploits.

Updating to version 2.1.5 and rotating exposed keys is critical, but this incident reflects a broader problem: a growing web of plugins, SaaS connectors, and AI‑enabled services moving sensitive content with limited content‑level governance. Modern data security strategies increasingly need to treat every outbound channel as a high‑risk path requiring consistent, contextual, content‑aware controls and to provide unified visibility into how unstructured data moves across websites, SaaS apps, collaboration tools, and AI systems.”

Vusal Shahbazzade, Lead Edge Deployment Engineer, Polygraf AI follows with this:

“What’s interesting about CVE-2026-4020 is not a severity score (5.3 is medium), but it gives to an attacker. It includes a REST endpoint that that authenticates nobody and returns the site’s full system report (PHP version, server paths, active plugins, database details, configured API keys). It’s not the medium level problem in practice, because that data opens many other doors – everything shown in clean JSON, no skill required to read it. On top of it 17 million blocked attempts are people building a map.

This bug lives in a shared configuration library bundled into the plugin, an endpoint that registered itself as public without anyone explicitly deciding it should be. It’s a convenience feature in a dependency exposed one by default, and it inherited the trust of the plugin it shipped inside. Teams would beed to audit every endpoint a dependency registers, rather than assuming they’re safe, otherwise low-CVSS bugs will keep doing high-CVSS damage.”

If I were you, either update this plugin to version 2.1.5 or discontinue its use. Either way, you’ll be doing yourself a favour.

CData Launches Connect AI Developer Edition, Python SDK, and CLI

Posted in Commentary with tags on June 23, 2026 by itnerd

CData Software today launched three products for developers building AI applications on enterprise data: Connect AI Developer Edition (free), the CData Connect AI Python SDK (open source), and CData CLI.

The releases give developers direct, governed access to enterprise systems, Salesforce, Snowflake, NetSuite, Microsoft 365, Workday, and hundreds of others, through the interfaces they already use: SQL, Python, the command line, and MCP.

Most enterprise AI projects stall at the data layer, not because the models are wrong, but because getting governed, reliable access to production systems requires IT involvement at every step. Connect AI is what IT deploys so developers don’t have to ask for permission each time. Business teams get AI workflows. Developers get a stable data interface. IT gets visibility and control over every query.

Connect AI Developer Edition

Connect AI exposes enterprise APIs as a consistent, queryable data layer with standardized schema, read/write support, and automatic handling of authentication, rate limits, versioning, and pagination. Developers write queries. The platform handles the rest.

The free Developer Edition includes the full enterprise feature set: MCP server support, per-user authentication passthrough, query logging with user-level attribution, and a management MCP server. It works out of the box with any MCP-capable coding assistant, client, or framework, including Claude Code, Codex, Cursor, and LangChain, among others.

Connect AI also ships with Toolkits, which let teams package governed data access into a single MCP Server URL scoped to specific use cases, so agents get exactly what they need and nothing more.

Connect AI Python SDK

The Python SDK provides DB-API-compliant access to Connect AI, so developers can pull governed enterprise data into existing Python workflows without changing how they write code. It works with pandas, SQLAlchemy, cursor-based queries, and any other DB-API-compatible tool.

The SDK is open source and available now.

CData CLI

CData CLI is a command-line interface for CData’s JDBC, ODBC, Python, and ADO.NET connectors, designed to speed up development and testing for analytics pipelines, BI integrations, and ETL workflows. It’s built for how developers work today: CLI-native tooling that coding assistants like Claude Code and Cursor can use directly to scaffold connectivity without digging through documentation. The initial release supports JDBC, with support for ADO.NET, Python, and ODBC coming in future releases.

All three products are available today at cdata.com/developers.

Probook Raises $40M from Andreessen Horowitz and Sequoia to Scale the AI Operating System for Home Services

Posted in Commentary with tags on June 23, 2026 by itnerd

Probook, the AI Operating System for home service businesses, today announced $40 million in funding. The investment comprises a $34 million Series A led by Andreessen Horowitz (a16z) and a $6 million Seed round led by Sequoia Capital. Sequoia also participated in the Series A.

Home service operators spent the last three years buying AI. A voice agent. A chat widget. A follow-up tool. Each one owned a slice of the customer, and none of them talked to each other. Every vendor built for the top of the funnel, where leads come in — and ignored dispatch, the brain of every home service business, where customer experience is made or broken. Operators ended up with a stack of point solutions and a piecemeal customer experience.

Probook built dispatch first. Intake, data cleaning, customer messaging, and outbound came next, only possible because everything shares one context layer. Every customer stays on one text thread, with one number, from the first touch through the front door. Every inbound lead is answered with perfect information. Every booking is cleaned before assignment. Humans manage exceptions. Techs sell more. Shops run more jobs. Operators add points to their EBITDA and, for the first time, run a connected customer experience.

George Eliadis spent a summer inside TR Miller, a $40M HVAC, plumbing, and electrical shop in Illinois that became Probook’s first customer. There, he saw the same problems at scale.

Probook deploys with customers in person, configures the platform alongside their front-line teams, and stays on the hook for the outcomes it sells.

Probook serves customers across hundreds of locations nationwide, from independently owned shops to private equity-backed platforms. Notable customers include TurnPoint Services,  Master Trades Group, Del-Air, Peterman Brothers, and Sila Services.

Summers Plumbing, Heating & Cooling, with 14 locations and 260 technicians on the platform, booked 2,542 jobs in its first month on Probook with zero human intervention.

Del-Air, an 8-location operation in Florida, runs Probook across the stack. “We chose Probook 

over other AI vendors because they know dispatch. They’re also part of our front-line CSR,” noted Rick Rogers, CEO.

Konstantine Buhler, Partner at Sequoia Capital, added: “Most founders building for the trades have never worked in them. George has. Pair that with the team’s outlier technical depth, and you see why we backed Probook at Seed and why we’re doubling down now.”

Probook will use the capital to scale its go-to-market team against surging demand, and grow engineering and customer success to deliver on it.