Feed aggregator

Show HN: Osint Arena – GeoGuessr for OSINT

Hacker News - Thu, 05/21/2026 - 1:58pm

OSINTArena.com — a browser-based OSINT challenge game for practicing geolocation, image investigation, digital forensics, and clue-led research. It includes daily challenges, leaderboards, and user-submitted puzzles.

Comments URL: https://news.ycombinator.com/item?id=48226620

Points: 1

# Comments: 0

Categories: Hacker News

After Automation

Hacker News - Thu, 05/21/2026 - 1:58pm

Article URL: https://every.to/p/after-automation

Comments URL: https://news.ycombinator.com/item?id=48226614

Points: 2

# Comments: 0

Categories: Hacker News

Fitness-Tracking Strava App Upgrades Its Strength Training Feature

CNET Feed - Thu, 05/21/2026 - 1:54pm
You can track your runs, rides and lifts all in one place. This is when you can expect the update.
Categories: CNET

Yagni

Hacker News - Thu, 05/21/2026 - 1:53pm
Categories: Hacker News

Microsoft Defender vulnerabilities are being exploited in the wild

Malware Bytes Security - Thu, 05/21/2026 - 1:36pm

Two Microsoft Defender vulnerabilities are being actively exploited in the wild.

On May 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added a notable set of actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The KEV catalog tracks vulnerabilities known to be exploited in the wild and sets patch deadlines for Federal Civilian Executive Branch (FCEB) agencies.

Five of the added vulnerabilities are quite old by vulnerability standards. Patches were released in 2008, 2009, and 2010. But the Microsoft Defender vulnerabilities are from this year. Those two are:

  • CVE‑2026‑41091 (CVSS score 7.8 out of 10): a Microsoft Defender elevation of privilege vulnerability. A local attacker who already has some access to a machine can abuse Defender to gain SYSTEM‑level permissions, effectively giving them full control over Windows.
  • CVE‑2026‑45498 (CVSS score 4.0 out of 10): a Microsoft Defender denial‑of‑service vulnerability. Here, an attacker can interfere with Defender in a way that disrupts its normal operation. If attackers can crash or disable your antivirus engine on demand, they can create a safer environment for their malware to run undetected.

You should take patching these vulnerabilities seriously if:

  • You rely on Microsoft Defender as your primary endpoint protection
  • You manage Windows systems in a business, school, or local government environment
  • You have shared machines, terminal servers, or any environment where multiple users log on to the same system

As you’d expect from us, we don’t advise relying on Windows Defender alone. There are better options available, and they are not mutually exclusive.

How to patch

Security products are software, and software has bugs. When those bugs end up in a list of known exploited vulnerabilities, ignoring them is like leaving your front door open because “the alarm will catch anyone coming in.” 

Make sure Windows Update is enabled and set to receive updates for Microsoft products. Defender platform updates are often delivered alongside regular cumulative updates.

Also check that recent Microsoft Defender security intelligence and platform updates are installed.

The first version of the Microsoft Defender Antimalware Platform with these vulnerabilities addressed is 4.18.26040.7.

You can usually find that version number in Windows Security:

  1. Open Start and search for Windows Security
  2. Go to Virus & threat protection
  3. Click Settings or the gear icon
  4. Open About

Even with auto-update enabled, I didn’t receive this patch immediately. Defender platform updates can lag behind definitions or only appear when a cumulative Windows update lands. Microsoft typically releases updates for the Microsoft Defender Antimalware Platform once a month, or as needed to protect against new threats. 

So, I’ll have to wait. Good thing I’m protected.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Defenders fall behind, as AI rewrites the rules of a data breach

Graham Cluely Security Blog - Thu, 05/21/2026 - 1:13pm
For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that's no longer the case. Read more in my article on the Fortra blog.
Categories: Graham Cluely

Show HN: Canonry tracks how AI cites you – agent-first, open source

Hacker News - Thu, 05/21/2026 - 1:09pm

Icouldn't find an open-source, agent-first way to monitor AI search results + traffic so I built Canonry out.

There are tons of nuances with AI web search but have gotten really good results using canonry locally as it can cross reference with GSC, GA to really get a holistic view on the search space.

Comments URL: https://news.ycombinator.com/item?id=48225978

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Online Sound Test

Hacker News - Thu, 05/21/2026 - 1:09pm

Article URL: https://soundtestx.com/

Comments URL: https://news.ycombinator.com/item?id=48225970

Points: 1

# Comments: 0

Categories: Hacker News

Pivoting Out of Healthcare

Hacker News - Thu, 05/21/2026 - 1:06pm

Article URL: https://saffron.health/

Comments URL: https://news.ycombinator.com/item?id=48225930

Points: 1

# Comments: 0

Categories: Hacker News

Pages