Feed aggregator
Tiny-Vedas: a generic accelerator interface for RISC-V, from PyTorch op to GDS
Article URL: https://github.com/spzbrnmrc/Tiny-Vedas
Comments URL: https://news.ycombinator.com/item?id=49757285
Points: 1
# Comments: 0
Adam Tooze on AI Regulation [video]
Article URL: https://www.youtube.com/watch?v=EHU8vXCAsyo
Comments URL: https://news.ycombinator.com/item?id=49757261
Points: 1
# Comments: 0
Sea lion found beheaded at San Francisco's Ocean Beach, prompting investigation
Article URL: https://abc7news.com/post/sea-lion-found-beheaded-san-franciscos-ocean-beach-prompting-investigation/19844789/
Comments URL: https://news.ycombinator.com/item?id=49757251
Points: 4
# Comments: 0
Time To Go – an alarm that shows how long your commute takes
Article URL: https://apps.apple.com/us/app/time-to-go-departure-alarm/id6807446177
Comments URL: https://news.ycombinator.com/item?id=49757242
Points: 1
# Comments: 0
Cackle Pop Roar Reptiles have a lot to say
Article URL: https://knowablemagazine.org/content/article/living-world/2026/the-surprising-sounds-made-by-reptiles
Comments URL: https://news.ycombinator.com/item?id=49757195
Points: 1
# Comments: 0
GLM-5.3-FlashX: Delivering inference speeds of 200 tokens/s
Article URL: https://docs.z.ai/guides/vlm/glm-5.3-flash
Comments URL: https://news.ycombinator.com/item?id=49757191
Points: 3
# Comments: 0
Reinventing issue tracking: Local-first and Git-native
Article URL: https://blog.manganin.dev/blog/reinventing-issue-tracking/
Comments URL: https://news.ycombinator.com/item?id=49757185
Points: 1
# Comments: 0
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackers
Vast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.
The files include criminal records, victim statements, internal emails and sensitive information held by more than 40 police forces across the UK.
Continue reading...An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
New Android malware uses AI to steal bank logins and PINs
Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process.
What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script.
The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan.
It also abuses Android Debug Bridge (ADB), a legitimate tool that lets a computer communicate with an Android device. By turning on Wireless Debugging, RatHat can escape the normal app sandbox.
The attackThe infection chain is unusually elaborate for a mobile threat, combining social engineering, accessibility abuse, and remote AI decision-making into a single pipeline.
- Victims are lured through smishing (SMS phishing) texts and malicious ads that lead to fake download pages, sometimes disguised as a popular streaming app or even a browser like Chrome. These pages trick people into sideloading a malicious APK (Android Package Kit).
- Once installed, the app pressures the user into enabling Android’s Accessibility Service, using a fake “network restriction” excuse or bogus financial incentive. Accessibility services run in the background and can inspect screen content and interact with apps on the user’s behalf.
- With accessibility access, the malware silently taps through Developer Options, turns on Wireless Debugging, and reads the six-digit pairing code straight off the screen. It then pairs with the infected device without a person or computer to complete the process. This is a known, legitimate Android feature (normally used by app developers to test on a phone over Wi-Fi) that RatHat repurposes for self-escalation.
- That self-pairing gives the malware a shell-level ADB session, which it uses to drop two disguised native binaries: A Go-based “agent” that runs system commands with elevated privileges, and a reverse-proxy client that opens a persistent tunnel back to the attacker’s server, bypassing firewalls and NAT (Network Address Translation).
- To steal login credentials, the Trojan creates overlays for targeted apps, most of which are financial. These overlays can also steal one-time passwords (OTPs) and multi-factor authentication (MFA) codes.
- Perhaps its most novel capability records raw touch coordinates (where the finger touches the screen) directly from the input driver. It then matches those coordinates against a database of known keypad and pattern-lock layouts to reconstruct PIN codes and unlock patterns, completely bypassing protections against screen-reading.
Other capabilities include intercepting SMS messages, a form of semi-autonomous device control provided by the AI service, and the ability to restore the malicious app after it has been uninstalled using a hidden background program.
How to stay safeMost of RatHat’s tricks depend on convincing someone to sideload an app and grant it accessibility permissions, which means the usual mobile security advice remains the strongest defense.
- Only install apps from Google Play or another trusted official store. This does not guarantee safety, but it significantly reduces the risk.
- Be suspicious of any app that asks you to enable Accessibility Service for reasons unrelated to accessibility. Consider Android’s Advanced Protection Mode, which Google has started using to restrict which apps can request accessibility permissions in the first place.
- Never enable Developer Options or Wireless Debugging unless you understand why you need them. Legitimate apps have no reason to ask for them.
- Use an up-to-date, real-time anti-malware solution for your device. Malwarebytes for Android detects RatHat as Android/Trojan.Exploit.RatHat.
If your device is infected with RatHat, you will need to perform a factory reset because its persistence mechanism can survive normal app removal.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
A fresh count of the UK’s existing datacentres finds 1.6GW, mostly in London and the M4, while a projected 14.6GW heads north to get on the grid
Flight chaos caused by software defect, says air traffic control body
Article URL: https://www.bbc.co.uk/news/articles/cw0kl1571lpmo
Comments URL: https://news.ycombinator.com/item?id=49754905
Points: 1
# Comments: 0
US judge denies OpenAI bid to review X Corp's settlement with Apple
Article URL: https://www.reuters.com/legal/litigation/us-judge-denies-openai-bid-review-x-corps-settlement-with-apple-2026-09-18/
Comments URL: https://news.ycombinator.com/item?id=49754903
Points: 1
# Comments: 0
The new CC, an AI agent built for families
Article URL: https://blog.google/innovation-and-ai/models-and-research/google-labs/cc-expanding-to-groups/
Comments URL: https://news.ycombinator.com/item?id=49754898
Points: 1
# Comments: 0
Don't Design Your Emails (2016)
Article URL: https://www.gkogan.co/dont-design-emails/
Comments URL: https://news.ycombinator.com/item?id=49754882
Points: 1
# Comments: 0
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
Lawsuit filed against Google for illegal data retention
Discover agent rules and skills from leading OSS projects
Article URL: https://ossrules.md
Comments URL: https://news.ycombinator.com/item?id=49754865
Points: 1
# Comments: 0
An MCP to Sketch Charts
Article URL: https://medium.com/@carmineds/an-mcp-to-sketch-charts-6d18342cee1b
Comments URL: https://news.ycombinator.com/item?id=49754849
Points: 1
# Comments: 0
Fed staff should have known Silicon Valley Bank was vulnerable, new report finds
Article URL: https://www.cnbc.com/2026/09/18/fed-silicon-valley-bank.html
Comments URL: https://news.ycombinator.com/item?id=49754842
Points: 2
# Comments: 0
