1. I initially found it curious that https://news.ycombinator.com/item?id=13718752 ("Cloudflare proxies are dumping uninitialized memory") never seemed to made the mainstream news, while Heartbleed did. There are some awkward conspiracy arguments there, but I eventually realized that there's also the fact that people can just make mistakes at the end of the day, and while Heartbleed was very arguably in the public interest because individuals everywhere needed to take action to keep their systems (arguably) secure, making a website and silly name to highlight the security implications of a single company's mistake just... has the wrong tone, and it doesn't seem too much of a stretch to see major news coverage as somewhat similarly interfering and unhelpful.
2. There was discussion here ~some years ago about a random analytics test portal someone found that, when logged into (with "demo"/"password" or something similar) from a cellular device's IP, doxxed the name/address/last-4 of SSN (or possibly the whole thing, unsure)/etc of the account owner if that device was signed up to a particular US telco. Made quite a splash here; never hit the news. Not only was this not a mistake, it was definitely in the public interest: the company in question was clearly buying a realtime feed of $telco's entire IP address table, an item that should simply not have been for sale, and lack of security on the purchaser's part meant an unbounded number of individual customers were potentially affected (imagine visiting random websites and having them go "hello $yourname $lastname" and getting it right because they've just crammed an XHR to admin:password@portal.demo/api/whatever in their page, which IIRC had `access-control-allow-origin: *` and everything).
3. I've always found it a cute addition to the marketing video Google put out about their datacenter facilities - https://youtu.be/XZmGGAbHqa0?t=138 prominently features an "Alligators present" sign... but it's probably at least vaguely representative of the reality. These places have to deal with all kinds of insanity.
4. There was a story on here a little while back about the Cellebrite analyser (https://news.ycombinator.com/item?id=25522220). Reading the comments, I had a bit of a epiphany about one possible reason why Facebook, Whatsapp, Google, etc, actively want to use end-to-end encryption, which I wrote up at https://news.ycombinator.com/item?id=25522220: owning potentially hundreds of trillions of messages represents an untenable liability. I've read comments here that suggest most security products are good up to $1 million dollars, and a lot of security infrastructure (as installed on arbitrary servers, workstations, laptops, phones, etc) would begin seriously wobbling at even a fifth of that kind of money. (Apple ranked secure ROM extraction at $250k according to http://ramtin-amin.fr/#nvmedma (possibly published circa ~2015).) The thing is, if you have everyone's* messages - for an expansive, inclusive definition of "everyone" - then the value proposition you represent is comprised by every high-level individual who has sent messages using your platform, PLUS the fact that you have the cohesive bigger picture from group conversations between multiple high-level parties. In this light, spending a billion dollars or more to hack into a datacenter doesn't seem too far fetched; as I noted in the linked writeup, you'd be able to start world wars 4 through 16.
5. I randomly heard anecdata that suggest datacenters periodically experience various interesting hardware faults. The response to my expression of curiosity (https://news.ycombinator.com/item?id=26407909) was extremely reasonable: go out for drinks with the old-timers.