Feed aggregator
Ask HN: Who knows someone at GitHub/NPM team?
I will keep this brief:
I am the author of FastMCP node.js framework – which is the most popular MCP framework in JavaScript ecosystem. However, "fastmcp" name clashes with another framework in Python ecosystem. Therefore, I have been trying to rename my project to vitemcp.
I own vitemcp.com, github.com/vitemcp, x.com/vitemcp, etc. _and_ I also own npmjs.com/vite-mcp
I have been trying to rename "vite-mcp" to "vitemcp" for over a month, but hit dead ends through every channel. Support refused the request on the grounds of 'security'
I would greatly appreciate anyone who could assist with the matter.
Comments URL: https://news.ycombinator.com/item?id=48858400
Points: 2
# Comments: 0
'Complex numbers are not needed for quantum mechanics'
GPS Camerastamp Photo
Article URL: https://play.google.com/store/apps/details?id=com.gpsmapcamera.timestamp.geotaglocation.video&hl=en_US
Comments URL: https://news.ycombinator.com/item?id=48858374
Points: 1
# Comments: 1
Stardew Valley Mod Enables 3D and VR
Show World
Article URL: https://zenodo.org/records/21294371
Comments URL: https://news.ycombinator.com/item?id=48858372
Points: 1
# Comments: 0
Show HN: TTSC, TypeScript v7 ToolChain, plugin and codegraph reducing 90% tokens
Article URL: https://github.com/samchon/ttsc
Comments URL: https://news.ycombinator.com/item?id=48858343
Points: 1
# Comments: 0
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages.
The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek.
How mule betting scams recruit ordinary people
Mule betting or third-party betting account scams are a form of money mule scam where criminals recruit or coerce people into opening gambling accounts in their own name. The criminals then use those accounts to place bets to help launder money and obscure the source or ownership of funds.
The UK Gambling Commission describes “mule” betting accounts as online betting accounts created using another person’s personal details, with or without that person’s knowledge. It says criminals can control large numbers of these accounts to disguise who is betting and where the money came from. The Commission also warns that criminals may move illicit funds through third-party bank accounts to break the audit trail, often targeting vulnerable people and university students.
A common pattern is that the scammer offers easy money, “helps” the victim open an account, or claims they can’t use their own identity. That matches broader money mule recruitment tactics, where criminals approach people online, promise quick cash, and use the victim’s account to move or launder funds.
Barclays defines a money mule as:
“A money mule is someone who lets criminals use their bank account to move money. Often the mule doesn’t know what’s really happening, and has been manipulated into believing a cover story, or lured by an offer of payment.”
A UK study published in 2025 found that 21% of adults had been asked to receive money into their bank account, apply for a loan on someone else’s behalf, or open a new account—all in exchange for cash.
Mule betting is a specialized form of money mule scam. As well as helping to hide the source and destination of criminal funds, these accounts can also end up being involved in betting-related crime, including match fixing.
It is important to realize that by acting as a money mule, you’re getting involved with organized crime. In the US, money mules can face criminal prosecution, and authorities warn that claiming “you didn’t know” is not always a defense.
The FBI says common targets include students, job seekers, and people using dating sites. The “mule herder” usually promises easy money, then quickly asks the victim to open a bank or betting account or receive and transfer money on their behalf. Money gets deposited into that account from a fraud victim, a stolen source, or another mule who is a link in the chain.
The criminal then uses the account to place bets, move funds, or cash out in ways that make the money appear to be gambling winnings rather than the proceeds of fraud.
The key gain for the criminals is layering: each extra account, bet, transfer, or cash-out step makes the money harder to trace. On paper, the account holder appears to be the person carrying out the transactions, even though someone else is controlling the account.
From the victim’s perspective, it can look like a legit side hustle at first: easy money, simple tasks, and a promise they can keep a percentage. After that, the requests usually escalate into more frequent transfers, identity verification, sending card details, or handing over full control of the account.
How to stay safeLike many scams, money mule schemes often start with small, seemingly harmless requests before escalating. The safest approach is simple: if someone asks you to move money in exchange for an easy reward, assume it’s a scam unless you can independently prove otherwise.
- Never use your own bank account to move money for someone else. Legitimate employers or businesses do not ask you to receive and forward funds through your personal account. This is a common follow-up tactic in romance, friendship, and job scams.
- Be skeptical of easy-money offers, especially “work-from-home” jobs that promise quick pay for simple transfers. If it sounds too good to be true, it usually is.
- Research any company or person making the offer before you respond. Check that the business is real, registered, and traceable, and be extra cautious with overseas or hard-to-verify contacts.
- Never share banking details, passwords, PINs, or one-time passcodes with anyone you do not fully trust. Protecting access to your accounts helps block both coercion and takeover attempts.
- Monitor your accounts regularly and act fast on unexpected deposits or suspicious requests. If money appears out of nowhere, do not touch it; contact your bank immediately.
Pro tip: If someone contacts you out of the blue, Malwarebytes Scam Guard can help you determine whether it’s a scam.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Parliamentarian Lord Tim Clement-Jones highlights the growing impact of technology in politics across his career
Computer Weekly security editor Alex Scroxton looks back at how a fascination with people watching became realised through technology
Two Chrome updates in two days fix critical vulnerabilities
Updating Chrome is becoming an almost daily task lately. But it’s too important to ignore.
On Wednesday, July 8, Google released another Chrome update, just one day later after the previous one.
Between them, the two updates fixed 27 security vulnerabilities, including two critical flaws that could be exploited to compromise Chrome. Google says both are “use-after-free” memory vulnerabilities, which can sometimes allow attackers to run malicious code. Google has not reported any of these vulnerabilities as being actively exploited.
The Stable channel has been updated to 150.0.7871.114/.115 for Windows and macOS, and 150.0.7871.114 for Linux. The updates will roll out over the coming days and weeks.
How to update ChromeIf you don’t want to wait for the rollout to reach you, manually updating is easy.
The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you rarely close your browser or if something goes wrong, such as an extension preventing the update.
To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.
Chrome 150.0.7871.115 is up to dateYou can find an explanation of the version numbering system and step-by-step instructions in our guide to how to update Chrome on every operating system.
The version numbering systemWith updates arriving within days of each other, it’s helpful to understand Chrome’s version numbering system so you can quickly tell whether you’re running the latest release.
The Chrome version number consists of four parts separated by dots, like this:
MAJOR.MINOR.BUILD.PATCH
Each part has a specific meaning. In order of relevance they are:
- MAJOR: This number increases with each major Chrome release, which may include new features or changes.
- MINOR: This number is typically zero and rarely changes. It mainly supports the versioning scheme but doesn’t usually affect how users track updates.
- BUILD: This number increases steadily and identifies a specific build of Chrome’s source code. When comparing versions, it is the first number to check after the major version.
- PATCH: This number increases as Google releases smaller fixes and security updates for a particular build. It resets with each new build and helps identify minor updates within the same build.
For example, a version like 137.0.7151.56 means:
- Major version 137 (the milestone release)
- Minor version 0 (almost always 0)
- Build number 7151 (the code snapshot)
- Patch number 56 (the latest fix for that build)
The BUILD and PATCH numbers together identify the exact version of Chrome you’re running. Even if two versions share the same major number, higher build or patch numbers means you have a newer, more up-to-date Chrome version.
Sometimes you might see slightly different patch numbers on the same major build, for example, 118.0.5993.117 vs. 118.0.5993.118. This usually happens because Google released a quick fix or minor patch shortly after the initial release. Both are part of the same major update, but the higher patch number is newer.
How to check if you have the latest versionTo verify your Chrome version:
- Open Chrome.
- Click the three-dot menu (⋮) in the top-right corner.
- Go to Help > About Google Chrome.
Chrome will display your current version and automatically check for updates. If an update is available, it will download automatically and prompt you to restart your browser.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
The US Federal Data Center Enhancement Act expires soon and will remove critical physical security baselines. This risks eroding standards during the AI-driven global infrastructure boom
Show HN: Drag boxes around and watch a layout engine infer the Flexbox (no AI)
Article URL: https://wpconverters.com/playground/
Comments URL: https://news.ycombinator.com/item?id=48857637
Points: 1
# Comments: 0
The Ambulatory Intelligence Gap
Article URL: https://www.databricks.com/blog/ambulatory-intelligence-gap
Comments URL: https://news.ycombinator.com/item?id=48857631
Points: 1
# Comments: 0
Best Offline Sudoku App?
Article URL: https://sudokui.app/
Comments URL: https://news.ycombinator.com/item?id=48857607
Points: 1
# Comments: 1
The SBC hobby is dying (Geerling, 3 months ago) [video]
Article URL: https://www.youtube.com/watch?v=HeX22LnKdFY
Comments URL: https://news.ycombinator.com/item?id=48857592
Points: 2
# Comments: 0
GigaWiper Combines Multiple Malware for System-Level Sabotage
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek.
Motel – A 1989 Documentary [video]
Article URL: https://www.youtube.com/watch?v=XT0VUPi4vus
Comments URL: https://news.ycombinator.com/item?id=48857581
Points: 1
# Comments: 0
Show HN: Vuci – make the spoken word searchable
hi, I'm Reuben Over the past few months I've been building a platform where all the information is sourced from spoken conversations, and I wanted to make this content searchable, savable, and shareable. Presented in a well-designed format, similar to Yahoo but with higher IQ content.
Like most, I listen to a lot of podcasts, but I wanted to connect the dots on different topics and read the parts which are interesting more deeply. Sharing bits and pieces with friends was also a motivating factor, as well as alerts which feed into my other pipelines.
That said, I'm not sure which parts of the platform will resonate with users or not, so it's an experiment in progress.
Technicals: I love my craft (both design, and code), so I took ample time to think about UX and design it in Figma. It's cookiecut from ample projects I have in Django and HTMX, and scaffolded my way through. Hosted on Digitalocean, and AI agnostic from an LLM perspective. I can go deeper into these, but they probably deserve their own posts. Hope you like!
Comments URL: https://news.ycombinator.com/item?id=48857577
Points: 1
# Comments: 0
