Feed aggregator

Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway

Security Week - Thu, 08/06/2026 - 8:00am

(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of experience in the field.

The post Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway appeared first on SecurityWeek.

Categories: SecurityWeek

My Precious Attention

Hacker News - Thu, 08/06/2026 - 7:59am
Categories: Hacker News

Run coding agents with local models

Hacker News - Thu, 08/06/2026 - 7:54am

Article URL: https://lanes.sh/blog/whats-new-v046

Comments URL: https://news.ycombinator.com/item?id=49195429

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Jolt a decentralised content syndication network

Hacker News - Thu, 08/06/2026 - 7:52am

Hey HN i’m a platform engineer and my day job I mainly focus on kubernetes clusters and terraform with the occasional C#, Typescript when building services, so this could well be completely out of my depth. Jolt started as an experiment to see whether I could build my own network at all. I’ll also be honest that most of this code was agentically written. However the high level decisions and architecture were mine based on research, experimentation, trial and error. Canary testing was one of the consequences of that when you build this way you need something slapping your AI-driven confidence back to reality.

This year I asked myself a question... Is it possible to have a platformless world? A world where no platform controls your data, mines it for ad targeting or bans you and takes away your audience with it. So I started working on that as a challenge just to see if it's possible... and I ended up with Jolt.

Jolt is a p2p distributed content syndication network. Lol that's a mouthful, it's basically my solution to platformless content distribution. Someone can publish content using a cryptographic identity and others can discover that content. Apps can build on top of the network however they are decoupled from the audience or the account.

Jolt achieves this with a daemon capability model kinda like how mobile apps ask for permissions, but for your identity and content.

Apps don’t own your identity. They ask for a scoped session from the daemon (eg. "publish under /pastes/*") that you approve or decline. You can uninstall the app and you still keep the audience and the data.

I'm gonna give you the jist of the work in this post and talk about the architecture in a comment but check out the RFC section on the github pages site if you want a deep dive.

When I was building this the actual hardest part was not protocol design or crypto. Funny enough it was testing. LAN is deceptively simple and things just work; why? mDNS will find your peers instantly and make you feel cracked. Only to be humbled when you do a 3 node canary test to try to replicate the messy real world on a small scale.

The 3 way canary tested my laptop on my home broadband, a relay in hetzner and my mac running on a mobile hotspot, finicky I know but that's all I had. I was trying to answer a hard question at v0: 2 nodes on different networks could communicate and more importantly behind actual NATs and how.

The first attempt was via the relay so I knew that worked but I wasn’t really satisfied. I wanted direct communication and I spent about 2 days getting QUIC hole punching working for direct node to node communication.

That being said im not fully sure it holds up in the wild, the realist developer in me doesn’t think so. One thing I'm sure about is that one canary test doesn’t cover all edge cases. I would need more nodes and people on the network telling me something is broken thats how I work lol and that's why I am posting this.

You can jolt find here https://alexanderwanyoike.github.io/jolt/

So does this thing even work. Well I can happily say that I was able to build 2 applications on it Spoke (https://alexanderwanyoike.github.io/spoke/) my attempt at building a platformless social network and Pastey (https://alexanderwanyoike.github.io/pastey/) a simple pastebin like application when you want to send data to different places. Spoke is more maintained and I plan on getting Pastey to the same level of polish. They are still very early “hello world” prototypes.

Otherwise if you wanna chat add me up on spoke fsjj2nvibhmztsw2w3klgkbjorqbze3qsi2tcwzbs5pepdigohiq.jolt ;)

Comments URL: https://news.ycombinator.com/item?id=49195406

Points: 1

# Comments: 0

Categories: Hacker News

The Labor Market Impacts of GLP-1s

Hacker News - Thu, 08/06/2026 - 7:51am

Article URL: https://www.nber.org/papers/w35475

Comments URL: https://news.ycombinator.com/item?id=49195399

Points: 1

# Comments: 1

Categories: Hacker News

We got model fusion at home

Hacker News - Thu, 08/06/2026 - 7:49am
Categories: Hacker News

Scammers target OnlyFans users with deepfakes

Malware Bytes Security - Thu, 08/06/2026 - 7:38am

OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance.

How the catfishers hook their bait

This is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice. They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.

Once there, the “creator” asks for a Cash App payment in exchange for exclusive content. Cash App is a peer-to-peer payments service built for casual sends between friends, not for commerce. Transfers clear instantly and settle in the recipient’s balance within seconds. Once it’s been sent, it’s very difficult to recover.

That informal design is exactly what makes it useful here. As soon as the fan pays up, the criminal blocks them and disappears.

Why the laws don’t reach the actual servers

Lawmakers are tackling this with multiple state-level anti-deepfake bills. Federally, the Take It Down Act criminalizes non-consensual explicit content, including AI-generated images, and requires rapid platform takedowns. In the EU, the AI Act requires anyone who uses AI for image generation to disclose it publicly.

So why is this still happening?

The problem is that domestic laws only apply to domestic platforms. The stolen material largely sits on overseas hosts, making it difficult to control.

Even if laws could be universally enforced, it might not matter. In three experiments conducted this year, researchers at the University of Bristol found that most participants relied on deepfake content even after being told it was fake.

What actually helps

This kind of fraud has two victims: the fans who lose money to scams, and the creators. The latter lose income that they might have collected from fans, and also run the risk of retribution from disgruntled followers who think they’ve been taken advantage of.

One creator, Jessieanna Campbell, told USA Today that confused fans complained to her after mistakenly thinking she had taken their money. “I get messages all the time, like, ‘Hey, why did you take my $150 and block me?’ and I’m like, ‘What are you talking about?'”

USA Today also interviewed one creator who had angry fans visit her home, and is now sometimes scared to leave her house.

Some creators are hiring private content takedown services to try and fix the problem themselves. Others are posting public service announcements warning of these fake accounts. But it’s up to the fans to listen.

If a “creator” on a third-party platform contacts you, watch the video closely; the deepfakes are often flawed. USA Today reported that a TikTok video impersonating creator Elaina St. James, made by animating a still photo and cloning her voice, showed distorted teeth and frozen eyebrows. Here’s our guide to spotting deepfakes of any kind.

Common sense is the bottom line. If someone steers you into a direct messaging platform and solicits money for exclusive content, think twice. Check with the creator via a verified account to see if it’s real.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

FDA Approves First mRNA Flu Shot

SlashDot - Thu, 08/06/2026 - 7:09am
Categories: SlashDot

Critical Paperclip Flaw Allowed Admin Access, Code Execution

Security Week - Thu, 08/06/2026 - 7:09am

An attacker could self-register, sign in for board-level API access, and import a new company for code execution.

The post Critical Paperclip Flaw Allowed Admin Access, Code Execution appeared first on SecurityWeek.

Categories: SecurityWeek

Pages