Feed aggregator

Show HN: Readplace – Read the Web Not the Slop

Hacker News - Wed, 09/23/2026 - 9:06am

Article URL: https://readplace.com/import

Comments URL: https://news.ycombinator.com/item?id=49815498

Points: 1

# Comments: 0

Categories: Hacker News

Daily Food Recalls

Hacker News - Wed, 09/23/2026 - 9:05am

Article URL: https://dailyfoodrecalls.com/

Comments URL: https://news.ycombinator.com/item?id=49815483

Points: 1

# Comments: 0

Categories: Hacker News

Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw

Wired Security - Wed, 09/23/2026 - 8:54am
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.
Categories: Wired Security

Fake Claude Max giveaway hides a Google account phishing trap

Malware Bytes Security - Wed, 09/23/2026 - 8:45am

Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information.

Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure.

Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware.

The campaign we found takes a different approach. There is no form to collect card details and no download. Instead, it offers a free upgrade and asks you to sign in with your Google account.

The fake giveaway claims that only a limited number of free Claude Max subscriptions remain.What the page shows you and what it collects

The site announces that Anthropic has passed 100 million users and is thanking people by giving away 10,000 free one-month subscriptions to Claude Max, its highest-usage plan.

The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages. This is probably the most effective trust signal on the site, and it cost the operator nothing.

A counter claims that fewer than 750 of the 10,000 slots remain, dropping by a few every several seconds. Nothing is actually being counted. The number is generated inside your browser and resets when you reload the page, so every visitor sees the same manufactured shortage.

The frequently asked questions repeatedly promise that no payment details are needed. That part is true, which helps make the offer persuasive. Many people associate scams with requests for card details, and this page never asks for them.

What it wants instead is your Google login. Two sign-in options appear, but only one works. The Apple button produces a pre-written notice saying that the method is temporarily unavailable. The email box discards whatever you type into it and triggers the Google button instead. Every route leads to the same place, and the prize is far bigger than the lure suggests.

A Google account can provide access to email, documents, and the password-reset messages for other accounts. If you use Google to sign in to Claude, it could also give the criminals a route into your Claude account. Paid AI accounts are valuable in their own right because their usage allowances cost money. Last month, our research covered infostealers hijacking Claude accounts and using the victims’ paid allowances.

The fake sign-in form steers visitors toward Google by claiming that Apple sign-in is unavailable.Why this sample is notable

Clicking the Google button doesn’t open a real Google sign-in window. Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page.

The address bar, padlock, and everything inside the supposed window belong to the phishing page, not Google. It begins with a human-verification step rather than a password box, which may reassure visitors while helping to keep automated scanners away from the next stage.

The page displays a fake Google verification window with a fraudulent address bar and padlock.

Researchers have documented this “browser-in-the-browser” technique since 2022. Unit 42 reported a campaign in June that used draggable fake browser windows to target Microsoft 365 users.

What makes this sample instructive is how little the operator had to do. The malicious functionality is loaded through a single line of code from an outside service that presents itself as a reusable sign-in widget and provides installation instructions.

Comments inside the code are written in Russian and refer to the target as the victim. One explains that dark-themed fake windows used to flash white while loading, so the widget now fetches the correct color in advance to remove the flicker. The code appears to be a maintained, reusable product rather than something built for this one campaign.

How to spot a fake browser window

The design assumes you will check the wrong address bar. People have been taught to look for a padlock and the correct address on a login page, so this attack draws both inside a window that does not really exist.

The only address bar that matters is the one belonging to your actual browser at the top of the screen. Throughout this process, it continues to show the phishing site’s domain.

  • Try to drag the sign-in window beyond the edge of the webpage. A real popup is a separate browser window and can be moved anywhere on your screen. A fake one is trapped inside the page that created it and stops at its edge. It takes two seconds and is the most reliable test a non-technical user has.
  • Let your password manager decide. It checks the real web address rather than what the page displays. It should not offer to fill your Google password on a site that does not belong to Google. If it stays silent where it normally fills, believe it over your own eyes.
  • Don’t arrive through links. If a promotion is real, you should also be able to find it on the company’s own site. Type the address or use a bookmark and look for the offer there.
  • Treat countdowns and slot counters as decoration. Any page can show a number falling toward zero. It does not prove that an offer is limited.
  • Be suspicious when only one sign-in option works. Claiming that one provider is temporarily unavailable can steer everyone toward the path the attacker built.
  • If you already signed in, secure the account. Change your password through the provider’s real website, sign out of all other sessions, and review connected apps and unfamiliar devices. Closing the tab does not undo a login.
How Malwarebytes helps

Malwarebytes Browser Guard blocks phishing and scam domains before the page can load. In an attack like this, once the page is open, the criminals control nearly every visual cue you would normally use to judge whether it’s legitimate.

If you’ve been sent an offer and you’re unsure, Scam Guard can assess it before you engage and advise you on what to do next.

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review →

Categories: Malware Bytes

Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Security Week - Wed, 09/23/2026 - 8:17am

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek.

Categories: SecurityWeek

ShinyHunters claims FBI breach was revenge for “false” report

Malware Bytes Security - Wed, 09/23/2026 - 8:03am

Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI.

After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group.

In a very long post on its leak site, the group outlines its grievances:

“PSA – READ THIS NOW

Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI,

During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended.

We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.

For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that.

Our PSA today works to address these allegations and correct them.

We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.

We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations:

  • “Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims.”
  • “To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting”
  • “Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that.

We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats.

We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS.

Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of “The Com”. We have NEVER been apart of “The Com”. “The Com” is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense.

As a big believer and supporter of the U.S. Constitution – we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated.

We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to “disrupt” our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation.

We welcome any and all journalists to inquire us at shinygroup@onionmail[.]com to hear our side of the story.

Make the right decision, don’t be the next headline.

Thank you for your attention to this matter. -SH

Updated: 23 Sep 2026“

The post is essentially a hostile “correction notice” directed at FBI leaders Brett Leatherman and Kash Patel. Its central grievance is an FBI advisory that says ShinyHunters commonly harasses victims and their families, including through threatening messages, phone calls, and, in some cases, swatting.

It also warns that threat actors may exaggerate their access to personal information or falsely claim to possess compromising photos or videos. The advisory does not use the word “sextortion,” but ShinyHunters appears to have interpreted the reference to compromising material that way. The group denies much of the FBI’s account while simultaneously using coercive language of its own.

The document it appears to mean is the FBI/IC3 public advisory “ShinyHunters: Cyber Criminal Group Attacks Learning Management System,” issued on May 15, 2026. Despite ShinyHunters calling it a “2026 Quarter 2 FLASH report,” the publicly accessible document is labeled a Public Service Announcement (PSA), not a FLASH.

The picture may have been further confused by a sextortionist who pretended to be ShinyHunters. ShinyHunters declares:

“WE ARE NOT SEXTORTIONISTS.”

It also denies carrying out swatting attacks or sending threatening messages to the family members of people working for its corporate victims.

The group also denies being part of The Com, a decentralized network linked to cybercrime and violence. It calls that connection:

“propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalizing this nonsense.”

The group then threatens journalists it accuses of spreading these “false narratives.”

The most worrying part of the message is the group’s claim that it stole sensitive data on:

“almost ALL FBI Agents, and ​individuals who filed an application with the FBI for a job.”

According to 404 Media, ShinyHunters provided a sample containing information on roughly 5,000 FBI agents, including names, home addresses, phone numbers, and details about their spouses. The publication reportedly verified portions of the sample, but the full dataset and the wider claims about the breach have not been independently confirmed.

The group also reportedly defaced the FBI’s jobs website. The FBI says it is aware of claims involving unauthorized activity affecting FBIjobs.gov and is investigating, although “broken” does not necessarily mean “breached.”

What to do if you’re affected

The FBI has not yet confirmed what information was accessed or who was affected. If you are a current or former FBI employee, a relative of one, or have applied for an FBI job:

  • Check the FBI’s advice. Every breach is different, so check FBI.gov for updates and follow any specific advice it offers.
  • Change your password. If you have an FBI Jobs account and reuse its password elsewhere, change it on those other accounts. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonators. Cybercriminals may contact you posing as the FBI, another government agency, or someone you know. Verify the identity of anyone who contacts you.
  • Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Adobe Patches Critical Flaws in Connect, AEM Forms

Security Week - Wed, 09/23/2026 - 7:40am

The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.

The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.

Categories: SecurityWeek

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

Security Week - Wed, 09/23/2026 - 7:23am

The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.

The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.

Categories: SecurityWeek

In the wake of a string of incidents involving badly managed AI agents, security firm Okta enhanced its year-old agentic services proposition with capabilities to securely manage agentic lifecycles

Computer Weekly Feed - Wed, 09/23/2026 - 7:21am
In the wake of a string of incidents involving badly managed AI agents, security firm Okta enhanced its year-old agentic services proposition with capabilities to securely manage agentic lifecycles
Categories: Computer Weekly

Z80 REPL

Hacker News - Wed, 09/23/2026 - 7:04am
Categories: Hacker News

Pages