Feed aggregator
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.
The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.
Begin at the End: How to Enable Agentic Remediation
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.
The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek.
Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.
The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
Nick Clegg plays down fears ‘godlike’ AI could exterminate humanity
Former deputy PM now involved in tech industry says many within sector are ‘winding themselves up into a lather’
Nick Clegg has dismissed fears over AI’s “godlike power to exterminate humanity”, calling it a sign that tech bosses are “breathing their own fumes”.
The former UK deputy prime minister said that tech bosses should focus on addressing known specific threats such as cybersecurity and bioweapons rather than the “slightly hand-wavy view that this technology is unavoidably going to develop some godlike power which is going to turn on us and exterminate humanity”.
Continue reading...US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
Google’s location data privacy failures draw a €403 million fine
The Irish Data Protection Commission (DPC) has fined Google €403 million ($459 million) for violating European privacy law. The penalty follows a six-year inquiry into Google’s management of user location data between May 2018 and February 2020.
During that time, Google collected users’ location data without making clear that it could be used to infer their interests and shape the ads they saw.
Google’s location history keeps track of users’ locations when using their devices. It’s an opt-in service that includes a Timeline feature to display a private map of the places they’ve visited. A separate Android feature, Location Accuracy, helps devices determine their location more accurately than GPS alone.
Google had told users that they could stop Location History tracking by turning off that setting. But a report by the Associated Press in 2018 found that doing so wasn’t enough to stop Google from saving some of that location data. Researchers at Princeton University later confirmed the AP’s findings.
One reason was Web & App Activity, a separate Google account setting that can save information about what Google account holders have been browsing on the web and doing with their apps. That service was also collecting location data. Turning off Location History did not turn off Web & App Activity.
This issue led to payouts in multiple US jurisdictions. Google agreed to pay $85 million to Arizona in October 2022, $392 million to 40 states that November, and $9.5 million to the District of Columbia the following month. It also agreed to pay $39.9 million to Washington State in 2023, $1.38 billion to Texas in May 2025 as part of a two-suit settlement. Last September, a jury awarded $425 million in a separate class action case.
The DPC first looked into the issue in 2018 after the AP investigation and launched an official statutory inquiry in February 2020. Along with the fine, it has ordered Google to bring its location data processing into compliance within six months. The DPC says it will publish the full text of its decision in due course.
Google told Bloomberg that it had revised its practices since 2019 and launched tools to make location data easier to manage. In December 2023, Google announced that it would change its Timeline feature to keep its data on users’ devices. It also said that, for people turning on Location History for the first time, the default period before data is automatically deleted would fall from 18 months to 3 months.
This isn’t the only Google-related investigation that the DPC has launched. It launched one on Google’s processing of EU residents’ data for its AI model two years ago, and another related to the processing of personal data for its online Ad Exchange in 2019.
Check your Google location settingsTurning off Timeline doesn’t stop Google from saving location information through other settings. Check Web & App Activity and, if you see it, Search Services History too.
You can turn these settings off and delete activity already saved to your account.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Rogue OpenAI Agent Tried to Breach Government Site in May When Prompted for Simple Data-Retrieving Tasks
UK's Rudest Street Names
The Year of Internal Tools
Article URL: https://www.geocod.io/code-and-coordinates/2026-09-23-the-year-of-internal-tools
Comments URL: https://news.ycombinator.com/item?id=49827383
Points: 1
# Comments: 0
Nuros – AI study tools from notes, PDFs, videos, and links
Article URL: https://nuros.app/
Comments URL: https://news.ycombinator.com/item?id=49827376
Points: 2
# Comments: 0
Show HN: Air-gapped file encryption as self-decrypting HTML page
Air-gapped file encryption packed into a single, self-decrypting HTML page. AI-free.
Comments URL: https://news.ycombinator.com/item?id=49827375
Points: 2
# Comments: 0
Flatpark: A more inclusive Flatpak app store for Linux, alternative to Flathub)
Article URL: https://flatpark.org/apps/
Comments URL: https://news.ycombinator.com/item?id=49827344
Points: 3
# Comments: 0
Meta Launches $1,299 VR Headset That Look Like Glasses
Italian parliament backs Meloni's plan to restart nuclear power
Article URL: https://www.reuters.com/world/italian-parliament-backs-melonis-plan-restart-nuclear-power-2026-09-23/
Comments URL: https://news.ycombinator.com/item?id=49827328
Points: 2
# Comments: 1
Wealth Taxes Could Kill Privately-Owned Companies
Article URL: https://www.palladiummag.com/2026/09/22/wealth-taxes-could-kill-privately-owned-companies/
Comments URL: https://news.ycombinator.com/item?id=49827297
Points: 2
# Comments: 1
Google Private AI Compute with server-side memory
Article URL: https://deepmind.google/blog/advancing-private-ai-compute-with-secure-server-side-memory/
Comments URL: https://news.ycombinator.com/item?id=49827294
Points: 2
# Comments: 0
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.
The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
