Feed aggregator

From guidance to action: Security fundamentals that materially reduce risk 

Microsoft Malware Protection Center - Thu, 09/17/2026 - 1:00pm

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross identities, endpoints, applications, networks, and AI systems. A single foothold can become a broader compromise, making it increasingly difficult for security teams to determine which risks matter most and where to act first as their organizations adopt AI.

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift. It provides actionable guidance for strengthening the foundational security needed for AI adoption, with recommendations focused on areas where autonomous attacks can create outsized exposure.

Explore actionable cyberthreat guidance on Secure Now

We continue to see evidence that AI is reshaping the threat landscape. These developments reinforce many of the foundational practices we use internally to secure Microsoft, while also expanding our understanding of where organizations need additional visibility, governance, and control. The examples in this blog illustrate how familiar weaknesses are evolving in the AI era and why continuous exposure reduction remains essential.

When AI agents test their boundaries

Recent frontier model-related agentic security disclosures offered early lessons in how autonomous agents may test the boundaries of their instructions and environments.

In an incident disclosed by OpenAI, agents moved beyond their intended isolation, exploited vulnerabilities in shared Hugging Face infrastructure, and reached production systems. In separate incidents disclosed by Anthropic, agents exploited familiar weaknesses, including SQL injection, exposed credentials, weak passwords, and a malicious PyPI package.

Our customers are asking us how they can reduce this risk by governing agent identities and tools, isolating execution, restricting outbound connectivity, monitoring behavior, and defending against increasingly autonomous external cyberthreats, so that an unexpected agent action or exposed weakness do not become a path across the enterprise.

Explore recommended controls for this attack path.

When trusted paths cross attack surfaces

Microsoft Threat Intelligence recently observed Storm-2945, a subcluster of Midnight Blizzard, manipulating DNS and HTTP traffic across hospitality networks in the CaptiveCrunch campaign. Travelers were redirected into two attack paths: device-code phishing through a legitimate Microsoft sign-in page, or fake software updates that delivered malware.

One network interaction could therefore become either cloud identity access or endpoint compromise. The malware could collect multiple categories of host intelligence, including credentials, session tokens, security configurations, and remote-access history.

Identity remains a leading attack surface, and protecting it requires securing the authentication flow as well as the credential. Security leaders can expand phishing-resistant authentication, block device-code flow where it is unnecessary, and constrain legitimate use through Conditional Access and sign-in risk policies. Endpoint protections can disrupt the parallel malware path.

Explore recommended controls for this attack path.

When cyberattackers exploit everyday operations

A third campaign began with attackers impersonating IT support through Microsoft Teams. After persuading a user to grant control through legitimate remote-support software, they used PowerShell to download a malicious Windows Installer (MSI) package, stage a portable Node.js runtime, and establish persistent command-and-control. From that endpoint, the operator mapped Active Directory and attempted to use WinRM to reach dozens of systems, including domain controllers and certificate authorities.

Each step relied on technology common in enterprise environments—a Teams conversation, remote-support software, Windows Installer, a legitimate runtime, and a native administrative protocol—enabling the cyberattacker to move laterally while blending with expected operations.

Security leaders can disrupt that path with phishing-resistant access controls, managed-device requirements, endpoint attack surface-reduction rules, and tighter restrictions on remote-support tools and WinRM.

Explore recommended controls for this attack path.

Security fundamentals work together

Cyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them. Through the Secure Future Initiative, Microsoft is operationalizing security as a continuous discipline and applying and sharing lessons from strengthening our own environment. Guided by Zero Trust principles—verify explicitly, use least privilege, and assume breach—we will continue to make high-impact protections easier to adopt and enabled by default where appropriate.

Governed identities, well-defined permissions, protected data, and visibility into AI systems and agents provide resilience as organizations accelerate AI adoption. They also give AI-powered security the context and trusted mechanisms needed to help defenders prioritize risk and act faster. Strengthening these foundations reduces exposure today while preparing organizations for what comes next.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains. This brings together guidance on recommended controls and enables customers to take relevant actions to continuously strengthen your posture.

Visit Secure Now to understand recent threats, identify areas of focus, and take action.

Explore the latest exposure management guidance in Secure Now Learn more

Learn more about Microsoft Security Exposure Management.

FastTrack provides eligible customers with access to technical specialists as an included benefit at no additional cost to help strengthen foundational security controls, reduce exposure to cyberthreats, and prepare for broader AI adoption. Get started now.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post From guidance to action: Security fundamentals that materially reduce risk  appeared first on Microsoft Security Blog.

Categories: Microsoft

Show HN: Repodify: Make Podcasts Out of Podcasts

Hacker News - Thu, 09/17/2026 - 12:57pm

Article URL: https://www.repodify.app/

Comments URL: https://news.ycombinator.com/item?id=49743515

Points: 1

# Comments: 1

Categories: Hacker News

Ask HN: Co-Founder(s). Do I need any? How would I even find them?

Hacker News - Thu, 09/17/2026 - 12:55pm

I'm a technologist and have experience in academia, private, and now public sector work. I had an idea stewing in the back of my mind for about a year and it became 'fully-formed' enough to be a proof-of-concept such that I filed a provisional patent a few months ago. At this point, I don't want to quit my day job (federal agency, GS11, but have an in to be GS15 within 3 years). But I really want my idea to succeed (or at the very least, see the light of day). I have some savings piled up, but I'm hesitant to spend it on 'grown-up' patent papers yet. I also already have 3 other 'side gigs' (not to mention 4 kids and a blushing bride) that take up more than most of my time. How would I even find someone that I could trust enough to help me take my idea and hit a home run with it?

I don't want to talk about the details of my invention. I did talk to a patent attorney that's done a couple dozen startups through their firm though. He said I could probably get $20k-$50k in seed money for it. It's not a "better mousetrap", it's more a "new thing" that's never existed before (but also never really 'needed to' before).

Do I NEED a co-founder, or can I 'slow-walk' launching a business based solely on a new gizmo? I'm not very good at social media/marketing, which is where I think my gizmo would thrive the most (but that's purely a guess). I feel like if I could find the perfect person, it really could explode, but I have literally not even the faintest clue where/how to start that. Am I an employer all-of-a-sudden even though I have no revenue to pay salaries?

Somebody heard that I had invented this thing and they asked me, "So, I hear you're an inventor?" And I kind of stammered and said "well.... it was an accident. I didn't mean to, I promise." This was mostly to be funny/silly, not that I don't believe in the idea. But I know this sort of 'startup/founder(s)/seed-money' thing is HN's bread-and-butter, so I at least thought I'd ask.

Comments URL: https://news.ycombinator.com/item?id=49743493

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Pappice live demo in browser via WASM

Hacker News - Thu, 09/17/2026 - 12:55pm

I needed a public demo to show pappice usage, and I just wanted to bypass the public shared contents problem (periodic resets, features disabling, contents restrictions, ecc). The solution was to compile all the server, SQLite included, to WASM and run it entirely in browser, so every user has his own instance now and can mess freely. That's just a 8/9 gzipped MBs download. I'm very proud of the achievement; that demonstrates a lot of how lightweight pappice is.

Comments URL: https://news.ycombinator.com/item?id=49743479

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: AutoBot – live voice control for long-running AI work

Hacker News - Thu, 09/17/2026 - 12:54pm

I wanted to manage long horizon agentic workstreams via voice, then put my phone down, and have a harness manage completion - extending into full computer use.

I was trying to build a personal Jarvis, so I benchmarked AutoBot to see how close I could get:

- OSWorld: 32.41% (moved Sol Max from 4th to 1st, beating Opus 5)

- AssistantBench: 50.70%

Hermes and OpenClaw, but without needing a weekend and VMs. And with the ability to manage deep personalization AND keep strict privacy rules, storing data on encrypted disk.

AutoBot is a passion project that grew out of trying to make this all work for myself.

I’m sharing it here because I suspect other here have the same frustration. And I’m curious what else everyone is doing for this.

It’s an MIT-licensed harness that lives within a project.

Native voice lets me discuss tasks, check progress, and steer work; a local ledger tracks unfinished outputs and the evidence needed to call them done. Memory drives more autonomy over time, and “defrags and locks in learning nightly” while a heartbeat system persists execution.

I’m not selling anything. If you’re building something similar for yourself, I’d love to compare notes.

GitHub: https://github.com/demeyer1/Autobot

Comments URL: https://news.ycombinator.com/item?id=49743478

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Craigslist for agent skills, curated by a human

Hacker News - Thu, 09/17/2026 - 12:53pm

hey, i'm nick (@skeptrune on X). i have been using ai for a lot of things i'm not an expert in and thought it would be nice to try and buy paid skills for helping it accomplish those tasks more efficiently.

for example, redlining contracts, creating ai generated videos, different website designs, and more.

curious to see if this resonates with folks here. i figure a more engineering'y audience that's ai coding-agent forward would have similar problems to what inspired me to make this

Comments URL: https://news.ycombinator.com/item?id=49743459

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Dishlist – my favorite things on the menu

Hacker News - Thu, 09/17/2026 - 12:53pm

Hi HN!

My friend and I wanted to rank our favorite breakfast burritos. Yelp and Beli allow users to rate or rank restaurants, but not individual dishes.

So I built dishlist, an iPhone app around the things on restaurant menus.

I schlepped around Dogpatch, Potrero Hill, and Mission Bay taking photos of restaurant menus. Then, I used Claude with my menu schema to turn the photos into structured data.

Garry Tan likes to say, "The rocks can talk." Also, "The rocks can see."

I represent the menu hierarchy in the database. LLMs can determine what type of thing each menu item is. This lets me index things like breakfast burritos across restaurants rather than just indexing the restaurants themselves.

The app suggests possible tags for a menu item. You decide which ones you want to use on your profile. You can build a list of your favorite breakfast burritos, pizzas, burgers, or whatever else you care about.

I value my privacy, so you can use the app without logging in at all. If you want to save menu items, you can sign in with Apple. I don't collect names, emails, or phone numbers.

If you want to share with friends, you can add a handle. You have to follow another user to see their dishlist, and they have to follow you to see yours. Follow requests are approved or denied by the user.

The app is currently available through TestFlight while the App Store submission is being reviewed.

https://testflight.apple.com/join/VB1YAe63

I'd love feedback on the idea, the search experience, and especially whether organizing things around individual menu items feels useful.

Comments URL: https://news.ycombinator.com/item?id=49743441

Points: 1

# Comments: 0

Categories: Hacker News

Ask HN: What Makes Tokens Expensive?

Hacker News - Thu, 09/17/2026 - 12:50pm

Are there really such architectural differences between for example sol and astra that makes astra twice more in token price? Or maybe token cost covers training expenses? For me it's hard to believe that astra need twice the computing power that sol needs...

Comments URL: https://news.ycombinator.com/item?id=49743419

Points: 1

# Comments: 0

Categories: Hacker News

Pages