Feed aggregator
Which Doc Format Is Best for AI Specifications?
Article URL: http://blog.vanillajava.blog/2026/07/which-doc-format-is-best-for-ai.html
Comments URL: https://news.ycombinator.com/item?id=48918007
Points: 1
# Comments: 1
Be using a meta harness for agents
Article URL: https://garrit.xyz/posts/2026-07-15-you-should-be-using-a-meta-harness-for-agents
Comments URL: https://news.ycombinator.com/item?id=48917995
Points: 5
# Comments: 0
Ask HN: How are you productive with GPT 5.6 Sol?
I recently switched from Opus/Fable to GPT 5.6 Sol, and so far I’ve found it so dumb that it often makes me lose time. I can ask Opus/Fable one thing and I know it’ll take some time but will do it almost perfectly. With GPT I constantly have to steer it; its investigations almost always end up with overreached conclusions after minutes of looking in random places unrelated to the issue; it adds a lot of useless defensive code just like previous 5.x models. I do use AGENTS.md; I have a couple of MCPs; I enabled memories.
I see people happy about GPT 5.6 Sol everywhere, so there must be something I’m missing. If you’ve tested both model families, what have been your experience so far? Have you noticed that some things that work well with Claude don’t with GPT or vice-versa?
Comments URL: https://news.ycombinator.com/item?id=48917993
Points: 1
# Comments: 0
This fake Apple app can unlock your Mac’s password vault
CrashStealer is a new macOS infostealer that masquerades as Apple’s CrashReporter component, uses an Apple‑notarized installer to slip past Gatekeeper, tricks users into handing over their password, and then systematically loots browsers, password managers, crypto wallets, and Keychain secrets before exfiltrating them in AES‑encrypted bundles.
Researchers have been following the development of CrashStealer since May 2026. It impersonates Apple’s CrashReporter component by taking the name CrashReporter.app. It also creates a LaunchAgent named com.apple.crashreporter.helper and uses the legitimate tool’s icon and metadata to look as trustworthy as possible.
Gatekeeper, basically macOS’s bouncer at the door, checks whether an app looks safe before letting it run. By using a notarized installer—one that Apple has scanned and stamped as acceptable—Gatekeeper is more likely to let it through without raising alarms. Getting notarized doesn’t mean Apple intentionally approved the malware. It means the installer passed Apple’s automated checks, and the attackers abused that trust.
The notarized installer, called “Werkbit Setup” is distributed from a fake software site registered in late June and gated behind a meeting PIN (Personal Identification Number), suggesting a targeted, invitation‑only campaign.
When launched, the malware displays a fake macOS password prompt that users will expect to see when running a legitimate system operation requiring administrator privileges. In reality, the malware uses that password to unlock the user’s Keychain, which stores passwords and other sensitive data in macOS’s encrypted password vault.
Image courtesy of Jamf LabsThe malware then steals browser credentials and cookies, cryptocurrency wallet extensions, password manager data, and small files from common user directories. The stolen data is encrypted and sent to a command and control (C2) server.
CrashStealer is a reminder that macOS is firmly in the sights of credential‑stealing operations. Notarization and Gatekeeper reduce many classes of risk, but they do not remove the need for layered defenses, cautious user behavior, and ongoing threat monitoring.
How to stay safeThere are a few things you can do to protection yourself from CrashStealer and other infostealers.
- Be skeptical of “CrashReporter” downloads. Apple’s crash‑reporting tools ship with macOS, so you should never need to download a separate CrashReporter app from a third‑party site.
- Treat PIN‑gated installers with caution. If a meeting invite or collaboration tool requires you to download software from an unfamiliar domain and enter a private PIN to unlock the installer, verify the request with the organizer through a separate trusted channel.
- Treat a password request that appears immediately after launching a new or unfamiliar app—especially one claiming to be a system component—as a red flag.
- Use reputable security software that supports macOS. Keep it, and macOS itself, up to date.
- Separate your risk. Avoid keeping high‑value crypto wallets, password vaults, and everyday browsing credentials on the same machine and user profile wherever possible.
Malwarebytes detects CrashStealer as MacOS.Stealer.Crash.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Billions of pounds are being lost - and hundreds of thousands of people excluded from the economy - because so much of our technology and working lives are not inclusive by design
I Asked Experts Why Dishwashers Fail. A Simple Step You're Skipping Was the Top Answer
Cyber security expert Rik Ferguson charts an unlikely career from The Hobbit through childhood thespianism to the cutting edge of cyber defence
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.
The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek.
Decibri – unified audio layer for AI agents and Voice AI applications
Article URL: https://decibri.com
Comments URL: https://news.ycombinator.com/item?id=48917379
Points: 1
# Comments: 0
Magic Cap OS
Article URL: https://en.wikipedia.org/wiki/Magic_Cap
Comments URL: https://news.ycombinator.com/item?id=48917375
Points: 1
# Comments: 0
Clean Up Kernel (2020)
Article URL: https://lkml.org/lkml/2020/5/29/1038
Comments URL: https://news.ycombinator.com/item?id=48917372
Points: 1
# Comments: 0
Show HN: VulnCast – open-source e-paper dashboard for live CVE/exploit Intel
Article URL: https://github.com/vulnersCom/VulnCast
Comments URL: https://news.ycombinator.com/item?id=48917323
Points: 1
# Comments: 0
We need to talk about the Bun Rust rewrite [video]
Article URL: https://www.youtube.com/watch?v=kAjNWanR3n8
Comments URL: https://news.ycombinator.com/item?id=48917306
Points: 1
# Comments: 0
At last, a good reason to buy an AI PC: Reining in runaway token bills
PDF Batch Translator
Article URL: https://github.com/markmatsu/pdf-batch-translator
Comments URL: https://news.ycombinator.com/item?id=48917303
Points: 1
# Comments: 0
Show HN: A free tool that turns any AI topic into an interactive, cited lesson
Article URL: https://prathibhax.com/
Comments URL: https://news.ycombinator.com/item?id=48917300
Points: 1
# Comments: 0
IBM loses quarter of its value as tech giant's shares plunge and profits falter
Article URL: https://www.theguardian.com/technology/2026/jul/14/ibm-shares-profit-drop-value
Comments URL: https://news.ycombinator.com/item?id=48917294
Points: 2
# Comments: 1
Australia to establish government AI office, curb data centres' water use
Article URL: https://www.reuters.com/world/asia-pacific/australia-establish-government-ai-office-coordinate-regulation-2026-07-14/
Comments URL: https://news.ycombinator.com/item?id=48917281
Points: 1
# Comments: 0
Ask HN: Insightful research or longreads on core teams in IT?
Core teams serve internal Software Engineers in larger software companies. Think of Platform Operations, CICD, developer tools, etc.
With the advent of AI, code became cheap and this exposed inefficiencies everywhere. Having spent many years in many companies, I feel like there is little we know about how a successful core team should operate and what are the pitfalls.
I have anecdotal evidence about core teams operations, but I am sorely missing more substantial reading.
Comments URL: https://news.ycombinator.com/item?id=48917264
Points: 1
# Comments: 0
