Feed aggregator
Mechanochemistry of Molecular Motors [video]
Article URL: https://www.youtube.com/watch?v=hpxbMVbL3Ms
Comments URL: https://news.ycombinator.com/item?id=49894143
Points: 2
# Comments: 0
Falling in Love with the Problem, Not the Solution, Is More Important Than Ever
Article URL: https://tonyalicea.dev/blog/fall-in-love-with-the-problem/
Comments URL: https://news.ycombinator.com/item?id=49894131
Points: 2
# Comments: 0
RemoteThreat Launches With $7 Million for Offensive Operations Platform
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.
The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.
Metropolitan Police senior officers admit that only 30% of the force has completed mandatory data protection training following a series of high-profile data incidents
European datacentre associations argue that building datacentres where renewable power is generated could ease grid congestion in the Netherlands and beyond
Reco Raises $55 Million for Agentic Security
The company will use the funds to expand its sales, partnerships, channels, and customer support teams.
The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek.
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek.
Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home
A Facebook Marketplace buyer arrived at a seller’s apartment to collect a keyboard. The seller wasn’t home and didn’t know anyone was coming. Meta’s AI assistant Muse had handled the conversation, shared his address, and arranged the visit without telling him.
We often write about AI misalignment and how to use AI agents and browsers safely. That can sound theoretical, but this is an example of the real-world risk when an agent is allowed to act on someone’s behalf.
Muse is Meta’s semi-autonomous AI assistant, released in the US in September. Meta promotes it as a personal assistant that can help users automate tasks, including responding to Facebook Marketplace messages. Unlike a conventional chatbot, which waits for a prompt and produces an answer, an AI agent may be authorized to take actions within connected apps.
We’ve written about a separate weakness in Muse that researchers considered dangerous. Reportedly, Muse was downloaded 3 million times in its first week.
According to Business Insider, a Facebook Marketplace seller turned on Muse to help handle a keyboard listing. He entered his address as the pickup location and approved automatic replies. Muse then shared that address with a prospective buyer, negotiated over the item, and arranged a visit, the seller said. He says Muse did not ask permission to share his address or arrange the visit, and did not tell him it was happening. The buyer arrived at the seller’s apartment expecting to complete the purchase, but the seller wasn’t home. The sale didn’t happen.
The reported incident is more than a privacy failure. It illustrates a broader AI-agent risk: An agent may treat permission to reply automatically as permission to share sensitive information or commit you to an in-person meeting. Meta says it is looking into the report.
How to use AI agents safelyBefore enabling an AI agent, treat its setup screen as a security review. Do not assume that an integration with a trusted platform means the agent will understand your intentions or apply sensible limits automatically.
Pay particular attention to:
- Connected accounts: Review every service the agent can access, such as email, messages, calendars, cloud storage, shopping accounts, or social media profiles.
- Data access: Consider whether it can read addresses, contacts, photos, private messages, payment details, documents, or location data.
- Action permissions: Check whether the agent can send messages, post content, negotiate, make bookings, place orders, alter listings, or share information externally.
- Automatic actions: Apply settings that require approval before the agent sends, publishes, buys, deletes, or shares anything sensitive. Check how it will notify you about the plans it makes on your behalf.
- Audience controls: Confirm exactly who can receive information generated by the agent. “Anyone who messages me” is very different from “people I approve.”
Give an AI agent the least access necessary for the task. If you only want help writing replies, do not enable automatic sending. If you want an AI agent to manage a listing, use a public meeting location or a separate pickup address rather than your home address.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Pentagon Personnel Agency Data Breach Impacts 3 Million People
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.
The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents
The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.
Andy Burnham visited Kyiv in Aug 2026, the fourth UK PM since 2022. UK-Ukraine tech collaboration has grown with AI-focused military deals, and Ukraine’s tech sector has proven resilient despite the war
Kiteworks customers are back up and running after a highly unusual preemptive shutdown that came amid indications of an impending cyber attack
Four Cyber Threats Harboring Big Plans for the Future
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.
The post OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training appeared first on SecurityWeek.
Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.
The post Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation appeared first on SecurityWeek.
Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27.
The fix is in iOS and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Check Software Update on each of your Apple devices and install the latest version offered.
Updates for your particular deviceThe table below shows which relevant updates are available and links to Apple’s security information for each one.
UpdateAvailable foriOS 26.7.1 and iPadOS 26.7.1iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and latermacOS Tahoe 26.7.1macOS TahoemacOS Sequoia 15.8.1macOS Sequoia How to update your Apple devices How to update your iPhone or iPadTo check if you’re using the latest software version, go to Settings > General > Software Update. You’ll see if an update is available and be guided through installing it.
Turn on Automatic Updates if you haven’t already—you’ll find it on the same screen.
Available update options on iPad How to update macOS on any versionTo update macOS on any supported Mac, use Software Update:
- Click the Apple menu in the upper-left corner of your screen.
- Choose System Settings (or System Preferences on older versions).
- Select General in the sidebar, then click Software Update on the right. On older macOS, look for Software Update directly.
- Your Mac will check for updates automatically. If updates are available, click Update Now (or Upgrade Now for major new versions) and follow the on-screen instructions. Before you upgrade to macOS Tahoe 26, read Apple’s instructions.
- Enter your administrator password if prompted, then let your Mac finish the update. It may need to restart.
- Make sure your Mac stays plugged in and connected to the internet until the update is done.
The bug, CVE-2026-86950, affects CoreGraphics, an Apple framework used throughout its operating systems and apps to display and process visual content such as images and PDFs.
It’s an out-of-bounds write issue, which Apple addressed with improved bounds checking. This type of bug happens when software writes data beyond the limits of its allocated area of memory. It can overwrite other data in memory, interfere with the normal operation of the program, cause a crash, or even let an attacker take control of the affected process. In this case, processing a maliciously crafted file may lead to an attacker running their own code.
Apple says it is aware of a report that the issue may have been exploited in an “extremely sophisticated attack” against specific people using versions of iOS before iOS 27. Although the reported attack was highly targeted, other attackers could try to exploit the flaw now that it has been disclosed.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Fake iPhone Duo preorder scam triggers DarkSword attack
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it.
Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud.
But one fake preorder page was different.
The fake Apple-style page offers a $500 voucher and a ticking preorder deadline.Behind its Apple-style design and $500 voucher, the page uses the leaked DarkSword exploit chain to try to break into vulnerable iPhones. If it succeeds, a separate payload attempts to steal saved credentials, cryptocurrency wallet data, and notes.
You don’t have to fill in the form, tap a download, or approve anything. Opening the page is enough to start the attempt.
The $500 voucher is a distractionThe page looks like Apple’s, down to its logo and “Copyright © 2026 Apple Inc.” footer. It promises an “Authorized Partner Exclusive” $500 voucher and AppleCare+ coverage if you complete a preorder form. The form asks for your name, email, and phone number, with WhatsApp “preferred,” but promises no upfront payment.
The form asks for contact details and offers Duo models and colors that do not match Apple’s.But Apple doesn’t open iPhone Duo preorders until October 16. You cannot place an Apple preorder now. It offers 6.3-inch and 6.9-inch models in colors Apple doesn’t sell for the Duo. Its countdown starts over whenever the page loads, and its privacy, terms, and sales policy links go nowhere.
In the version we captured, submitting the form doesn’t place an order. Its submission handler doesn’t read or send the details entered, and the page generates its own “Pre-Order Successful” message. The exploit attempt has already begun in the background.
How the attack starts when the page opensVisitors using browsers the script doesn’t recognize as Safari see a “Browser Restricted” notice. On iPhones, the page also tries to reopen the link in Safari, the browser the exploit chain targets. That steers visitors toward the intended browser, although background resources may still load in others.
Visitors shown this notice are urged to open the page in Safari.An invisible frame checks the visitor’s iOS version and selects the next code to load. DarkSword then attempts to get past the iPhone’s protections and, if successful, gain deep access to the phone. It doesn’t wait for a button press or form submission.
What attackers could take from an iPhoneIf the exploit succeeds, the payload attempts to contact its server. Its first message includes a device identifier, device information, and status. It also attempts to send a list of installed apps and the contents of Apple Notes.
The code looks for cryptocurrency wallets, including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. It also attempts to recover saved credentials from the phone’s keychain. If it finds a targeted wallet and the first exchanges with its server succeed, it attempts to upload wallet files, recovered keychain data, and photo thumbnails. Exposure of wallet files or credentials could put funds at risk.
The captured code checks for installed cryptocurrency wallet apps. This is part of the list.The payload also tries to access files containing messages, call history, contacts, voicemail, email, calendar entries, and cached location data.
The payload can then repeatedly contact its server for instructions. Its commands can list directories, retrieve files and full-size photos, gather app information, and run JavaScript supplied by the server. The payload also tries to cover its tracks by deleting diagnostic reports that could help investigators spot the attack.
The beacon sends a device identifier, device information and status to the configured server. The command loop uses the response to obtain instructions.The code is designed to run inside a system process, but may stop before the phone restarts. We found no mechanism that automatically brings it back after a reboot.
We analyzed the captured code, but did not test it on an iPhone or observe data leaving one.
Which iPhones could be at risk?Several parts of the captured code match the DarkSword chain described by Google in March. Apple has patched the vulnerabilities Google reported.
When DarkSword was disclosed in March, iVerify estimated that up to 270 million devices were running the iOS 18.4 through 18.6.2 versions targeted by the variant it analyzed. That is not a current count or a measure of how many phones this page could compromise. We haven’t confirmed this page’s exact range; its files also contain code for older iOS versions.
The lure fits the exploit: someone considering a new iPhone may still be using an older, unpatched one. That could make them vulnerable simply by opening the preorder page.
Safari can report an older iOS version to websites, so an updated iPhone may still load the attack code. That doesn’t mean the exploit can break in: Apple says updated devices are protected against the reported attacks.
How to stay safe- Keep your iPhone updated. Go to Settings > General > Software Update and install the latest version available. Turn on Automatic Updates there too. Apple says updated devices are protected against the reported DarkSword attacks.
- Check offers without opening unfamiliar links. Go directly to Apple or a retailer you know by typing its address yourself. A preorder link in an ad, message, or social post could start an exploit attempt as soon as the page opens.
- Opened this page? Restart your iPhone after updating it. We found no code that automatically brings the payload back after a reboot. Restarting cannot undo any data already taken.
- Keep a cryptocurrency wallet on that phone? Take precautions from a trusted device. If the phone may have been compromised and you keep a wallet on it, create a new wallet with a new recovery phrase and move the funds. For an exchange account, secure the account and contact the exchange.
- Change potentially exposed passwords from a trusted device. Start with email, your Apple Account, banking, and crypto accounts, and turn on two-factor authentication.
- Report the page. Save its URL and any screenshots without reopening it, and report it to your national cybercrime reporting service.
- Check a suspicious offer before you act. Scam Guard can give a verdict on a screenshot or link. On desktop, Browser Guard blocks the fake preorder page we analyzed; web protection in Malwarebytes Premium blocks it too.
- pnmrud[.]cc — command-and-control and collection server
- cloud[.]cmatgldn[.]click — ad click and conversion tracker
According to CNET. Read their review →
Apple in Colour. In an age of beige, Apple went all in on colour
Article URL: https://sheets.works/data-viz/apple-in-colour
Comments URL: https://news.ycombinator.com/item?id=49890546
Points: 1
# Comments: 0
Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.
