Feed aggregator
Is it 1999? – where the AI boom sits on the dot-com timeline
Article URL: https://isit1999.com/
Comments URL: https://news.ycombinator.com/item?id=49920630
Points: 2
# Comments: 4
Show HN: Silta: family assistant on Matrix with continuity across context limits
Silta is a self-hosted assistant serving multiple users from a single Matrix account, used by me, family, and close friends for the last three weeks. It runs on Claude Code with each person using their own Claude subscription.
Silta answers everyday questions, conducts web research (presenting the results as PDFs), performs scheduled tasks to monitor/research something and notify you if needed.
It uses a deliberate handoff & compaction procedure, writing the compaction summary itself with a custom prompt, so the thread of the conversation and its picture of the user is preserved across context limits. As it turned out, the assistant accessible in a continuous chat (contrary to ChatGPT / Claude Web sessions) builds up better context about you and your tasks, and provides more relevant answers and help.
It runs on Claude Code as the only allowed way to use a personal Claude subscription. Using Claude Code also spares me developing a harness, at the cost of tracking changes as new versions of Claude Code are released. The assistant itself (the daemon, the channel plugin, the supervisor, and the deployment) is open-source, while the model and the harness are Anthropic's and proprietary.
Silta is deployed to a dedicated VM with separate Linux users per session and systemd hardening, protecting sessions from each other. Claude Code's bubblewrap sandbox is used to protect the Claude credential and the harness's state from the agent. This does not protect from prompt injections coming from search results and potentially leaking user data.
Matrix E2EE protects the conversation from a Matrix server operator, but everything in the context is of course sent to the model provider. Private content is never logged, and the operator is expected to respect the privacy and not read the session transcripts on disk. Additionally, it is recommended to use full-disk encryption and tell the users how their data is handled.
Silta only works in its workspace with files explicitly shared by users in the chat. Giving it access to a user's own computer or services like email is not planned.
Since Opus 5.5 has been released, it is possible to run a session on a $20 Claude Pro subscription. Before that, only Fable 5.1 was pleasant enough to talk to. When run on Anthropic API, a moderately used session extrapolates to $100-$150 per month, with each research run costing $6-$12.
Silta is built with Claude Code and Silta itself, reviewed and tested by me.
Comments URL: https://news.ycombinator.com/item?id=49920621
Points: 3
# Comments: 0
Sweden.gov – Swedish Version of America.gov
Article URL: https://sweden.matzielab.com/
Comments URL: https://news.ycombinator.com/item?id=49920609
Points: 1
# Comments: 1
Show HN: Sensii – LeagueOfLegends live AI coach
Hi everyone, I'm Daniel
I built an open-source AI Voice agent where players can talk to a coach during the game. It works based on the awesome repo, live game stat and screenshot (disabled by default)
download: https://sensii.gg/download The agent: https://github.com/sorena-ai/LeagueAiCoach The knowledge base: https://github.com/sorena-ai/awesome-league-of-legends
Comments URL: https://news.ycombinator.com/item?id=49920584
Points: 4
# Comments: 0
Show HN: The Kio Programming Language
Kio is a statically typed, hosted language that is designed to be ultra-portable. Kio 0.1 supports eight host languages and more will be added in the coming weeks.
Kio is based on polymorphic lambda calculus with higher-kinded types. Kio has type-driven macros (elaborators) and it can statically check asserted equivalences using a normalizer.
Kio is a minimalistic language. It doesn't have built-in effectful functions and it doesn't even have built-in string or numeric types. Instead programs declare the capabilities they need and the host supplies them.
The language is designed with AI, which is bound to raise some eyebrows, so I blogged about that here: https://jdevuyst.github.io/kio/blog/2026-10-01-introducing-k...
Comments URL: https://news.ycombinator.com/item?id=49920582
Points: 1
# Comments: 0
Yann LeCun's $1B Bet Against LLMs [Part 1] [video]
Article URL: https://www.youtube.com/watch?v=kYkIdXwW2AE
Comments URL: https://news.ycombinator.com/item?id=49920574
Points: 1
# Comments: 0
Show HN: I want to use Apache Tika from Python, but I don't want to install Java
Article URL: https://github.com/bear0330/tika-ape
Comments URL: https://news.ycombinator.com/item?id=49920569
Points: 1
# Comments: 0
David Wheeler: pg_ClickHouse and chdb updates: Encoding, nesting, and types
Article URL: https://clickhouse.com/blog/pg_clickhouse-chdb
Comments URL: https://news.ycombinator.com/item?id=49920565
Points: 1
# Comments: 0
Omarchy in your Browser
Article URL: https://tryomarchy.dev/
Comments URL: https://news.ycombinator.com/item?id=49920540
Points: 1
# Comments: 0
Comby · Structural code search and replace for ~every language
Article URL: https://comby.dev
Comments URL: https://news.ycombinator.com/item?id=49920530
Points: 2
# Comments: 0
OpenStreetMap Ops Team: tile generation around 3× faster with Mapnik v4.3.2
Article URL: https://en.osm.town/@osm_tech/117360355704853854
Comments URL: https://news.ycombinator.com/item?id=49920526
Points: 1
# Comments: 0
Automating evals with Claude Code native skill
Article URL: https://claude.dev/blog/automating-eval-design-and-hillclimbing/
Comments URL: https://news.ycombinator.com/item?id=49920520
Points: 1
# Comments: 0
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.
The post Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation appeared first on SecurityWeek.
Convincing Free Mobile phishing emails appear after data breach
Free Mobile, one of France’s main cellular providers, was fined €27 million by France’s data protection regulator, the CNIL, in January over failures to protect customer data. The October 2024 breach allowed an unauthorized party to access sensitive customer records, including bank account details and login information. Since the breach, we’ve seen many poorly written scam campaigns targeting Free Mobile customers.
However, over the past few weeks, a well-written scam has appeared, closely copying the design of the official Free Mobile website and email templates.
One of our employees, who is a Free Mobile customer, received this phishing email on Wednesday, September 30. The message used the same logo and template as legitimate emails from the company, but came from the suspicious email address freemobile-regularisation[@]knowledgegrowthcenter[.]help. It included a link that appeared to point to regularisation.free.fr :
The email tells the user that an invoice of €9.99 needs to be paid to avoid having the customer’s service suspended. Clicking the link opens a redirection chain:
1. https://u2l.ai/Q5YwFz301 2. https://espace-free-mobile.pro/Ds41LE/302 3. https://espace-free-mobile.pro/Ds41LE/regularisation/?impaye=92a9e77d…200This final domain, espace-free-mobile.pro, is hosted by Cloudflare and was registered just a month ago.
The final link opens a convincing page with a form asking for credit card details:
The phishing page looks authentic, which sets this campaign apart from many of the Free Mobile scams we’ve seen since the breach.
We initially saw the same campaign using less convincing redirection chains, like this example from July:
1. https://bly.to/93kie5u 2. https://s1181402.ha026.t.mydomain.zone/mbl/ 3. https://s1181402.ha026.t.mydomain.zone/mbl/regularisation/?impaye=505…More recently, we’ve seen more authentic-looking domains, all hosted by Cloudflare:
1. https://s.ink/jmCnZZ2. https://freesas.info/Cf4tP/
3. https://freesas.info/Cf4tP/regularisation/?impaye=f13fa919d1a22833557…
And another example:
1. https://bly.to/jabwpf62. https://regularisation-free.info/portail/
3. https://regularisation-free.info/portail/regularisation/?impaye=83f91… How to stay safe
Malwarebytes can help protect you from these threats, but treat unexpected messages about your accounts and invoices with caution:
- Don’t follow links in unsolicited emails. If a message concerns your account, open the official Free Mobile app or website directly, or call the official help line at 3244.
- Check the actual domain in your browser’s address bar to see if it matches what you expect—https://mobile.free.fr in this case.
- Malwarebytes Browser Guard detects and blocks this scam directly in your browser.
- Use an up-to-date, real-time anti-malware solution with a web protection component on all your devices.
- Malwarebytes Scam Guard can help you determine whether an email is a scam and advise you on what to do next.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
Malwarebytes earns another Top Product award in independent testing
Every few months, Malwarebytes gets a chance to test its mettle against real-world threats in an independent laboratory setting. And the latest round of results gives us plenty to celebrate.
Malwarebytes earned a perfect 18 out of 18 and received another Top Product award from AV-TEST. We also achieved Level 1 Certification from MRG Effitas, and we stopped 100% of threats before they could run in the two latest tests from AVLab Cybersecurity Foundation.
AV-TEST Windows Consumer Security Product TestWith 18 out of 18 points in AV-TEST’s latest Windows Consumer Security Product Test, Malwarebytes nabbed the organization’s Top Product award for the July/August test cycle.
AV-TEST evaluates security products across three key areas: protection against malware, impact on device performance, and the frequency of false positives. Products need at least 17.5 out of 18 points to earn AV-TEST’s Top Product award, and Malwarebytes received full marks across the board.
Since we first began participating in the test in 2018, we’ve secured the Top Product award more than a dozen times.
MRG Effitas Consumer AssessmentMalwarebytes also received a Level 1 Certification in MRG Effitas’ July 2026 Consumer Assessment & Certification Programme, which tested eight security products against malware, phishing, and false positives.
The malware test used 300 live, in-the-wild samples, including Trojans, spyware, ransomware, backdoors, malicious scripts, and financial malware. Malwarebytes blocked every one of them, stopping 99% before they had the chance to run, and the remaining 1% after they began behaving maliciously.
Our product also generated zero false positives across 100 legitimate apps and blocked all five live phishing sites included in the test.
Malwarebytes was one of just two products to earn Level 1 Certification, the highest level awarded in the assessment.
AVLab Cybersecurity Foundation Advanced In-the-Wild Malware TestMeanwhile, the results from AVLab Cybersecurity Foundation’s Advanced In-the-Wild Malware Test brought more good news: Malwarebytes keeps getting better at stopping threats before they can run.
As part of the test, AVLab Cybersecurity Foundation uses threats circulating online and delivers them in ways designed to replicate how people encounter attacks in the real world.
During both the May and July 2026 tests, Malwarebytes stopped 100% of threats before they could run.
These latest results join a growing list of honors, including a Best of CNET award and ZDNET’s Editor’s Choice award.
Independent testing helps keep us sharp. We’re proud to see our work recognized, and even prouder to keep delivering the top-notch protection our customers have come to rely on.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.
The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.
Pentagon breach exposes Social Security numbers and military records of millions
The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC).
The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans, and their families. It maintains over 60 million records for US military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement.
Reportedly, cybercriminals had access from October 2025 to July 2026. CNN reports that the Pentagon confirmed the breach affects 2.76 million living individuals, potentially including current and former defense personnel or their dependents, and 294,000 deceased individuals.
A notification shared on Reddit states:
“A small number of unauthorized users accessed files on a server containing unencrypted PII.”
PII means personally identifiable information. The attackers gained access by exploiting a security vulnerability in an unspecified file-sharing system. The Pentagon says it has “no indication” of misuse. It hasn’t explained how it reached that conclusion or what it considers misuse, and it doesn’t rule out future misuse of the exposed information.
The exposed data is said to include Social Security numbers, names, dates of birth, sex, race, and service details. Some records also include contact information and occupational specialty.
Besides the risk that this data could help foreign intelligence services track US personnel, affected people face a lasting risk of identity theft. Birth dates cannot be changed, and Social Security numbers can only be changed in limited circumstances.
Breaches happen every day. Don’t be the last to know. What to do if you’re affectedThe Pentagon is offering 12 months of credit monitoring through IDX. If you receive a notification letter, take up the offer and consider a credit freeze with all three major credit bureaus: Equifax, Experian, and TransUnion. A freeze is free and restricts access to your credit report, helping prevent someone from opening new credit accounts in your name.
Other recommendations are:
- Get an IRS Identity Protection PIN to prevent someone else from filing a federal tax return using your Social Security number.
- Be suspicious of unexpected calls, emails, and texts, especially ones that mention your unit, rank, or job. Attackers can use the stolen details to make phishing attempts more convincing.
- Verify requests through official channels you look up yourself, rather than through contact details in the message.
- Use unique passwords and multi-factor authentication on email, banking, and benefits accounts.
- Limit location sharing and review privacy settings on phones and apps, since military leaders have raised concerns about commercial location data being used to target personnel.
- Follow instructions in the breach letter and further official communications and report any suspicious approach to your security officer.
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.
The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek.
