Feed aggregator
Show HN: Pappice live demo in browser via WASM
I needed a public demo to show pappice usage, and I just wanted to bypass the public shared contents problem (periodic resets, features disabling, contents restrictions, ecc). The solution was to compile all the server, SQLite included, to WASM and run it entirely in browser, so every user has his own instance now and can mess freely. That's just a 8/9 gzipped MBs download. I'm very proud of the achievement; that demonstrates a lot of how lightweight pappice is.
Comments URL: https://news.ycombinator.com/item?id=49743479
Points: 1
# Comments: 0
Show HN: AutoBot – live voice control for long-running AI work
I wanted to manage long horizon agentic workstreams via voice, then put my phone down, and have a harness manage completion - extending into full computer use.
I was trying to build a personal Jarvis, so I benchmarked AutoBot to see how close I could get:
- OSWorld: 32.41% (moved Sol Max from 4th to 1st, beating Opus 5)
- AssistantBench: 50.70%
Hermes and OpenClaw, but without needing a weekend and VMs. And with the ability to manage deep personalization AND keep strict privacy rules, storing data on encrypted disk.
AutoBot is a passion project that grew out of trying to make this all work for myself.
I’m sharing it here because I suspect other here have the same frustration. And I’m curious what else everyone is doing for this.
It’s an MIT-licensed harness that lives within a project.
Native voice lets me discuss tasks, check progress, and steer work; a local ledger tracks unfinished outputs and the evidence needed to call them done. Memory drives more autonomy over time, and “defrags and locks in learning nightly” while a heartbeat system persists execution.
I’m not selling anything. If you’re building something similar for yourself, I’d love to compare notes.
GitHub: https://github.com/demeyer1/Autobot
Comments URL: https://news.ycombinator.com/item?id=49743478
Points: 1
# Comments: 0
Show HN: Craigslist for agent skills, curated by a human
hey, i'm nick (@skeptrune on X). i have been using ai for a lot of things i'm not an expert in and thought it would be nice to try and buy paid skills for helping it accomplish those tasks more efficiently.
for example, redlining contracts, creating ai generated videos, different website designs, and more.
curious to see if this resonates with folks here. i figure a more engineering'y audience that's ai coding-agent forward would have similar problems to what inspired me to make this
Comments URL: https://news.ycombinator.com/item?id=49743459
Points: 1
# Comments: 0
The Bicycle and the Algorithm: Amber Case on Why AI Has It Backwards
Article URL: https://www.designwhine.com/amber-case-interview-why-ai-has-it-backwards/
Comments URL: https://news.ycombinator.com/item?id=49743450
Points: 1
# Comments: 0
Royal Enfield's Flying Flea C6 Touches Down in Europe
Article URL: https://www.irishnews.com/life/royal-enfields-flying-flea-c6-touches-down-in-europe-X27BGU34YVO4BLP4RCWHNTOX2A/
Comments URL: https://news.ycombinator.com/item?id=49743444
Points: 1
# Comments: 0
Show HN: Dishlist – my favorite things on the menu
Hi HN!
My friend and I wanted to rank our favorite breakfast burritos. Yelp and Beli allow users to rate or rank restaurants, but not individual dishes.
So I built dishlist, an iPhone app around the things on restaurant menus.
I schlepped around Dogpatch, Potrero Hill, and Mission Bay taking photos of restaurant menus. Then, I used Claude with my menu schema to turn the photos into structured data.
Garry Tan likes to say, "The rocks can talk." Also, "The rocks can see."
I represent the menu hierarchy in the database. LLMs can determine what type of thing each menu item is. This lets me index things like breakfast burritos across restaurants rather than just indexing the restaurants themselves.
The app suggests possible tags for a menu item. You decide which ones you want to use on your profile. You can build a list of your favorite breakfast burritos, pizzas, burgers, or whatever else you care about.
I value my privacy, so you can use the app without logging in at all. If you want to save menu items, you can sign in with Apple. I don't collect names, emails, or phone numbers.
If you want to share with friends, you can add a handle. You have to follow another user to see their dishlist, and they have to follow you to see yours. Follow requests are approved or denied by the user.
The app is currently available through TestFlight while the App Store submission is being reviewed.
https://testflight.apple.com/join/VB1YAe63
I'd love feedback on the idea, the search experience, and especially whether organizing things around individual menu items feels useful.
Comments URL: https://news.ycombinator.com/item?id=49743441
Points: 1
# Comments: 0
Show HN: Content-aware PII redaction with Jev in Postgres
Article URL: https://pg-redact.vercel.app
Comments URL: https://news.ycombinator.com/item?id=49743434
Points: 1
# Comments: 0
Ask HN: What Makes Tokens Expensive?
Are there really such architectural differences between for example sol and astra that makes astra twice more in token price? Or maybe token cost covers training expenses? For me it's hard to believe that astra need twice the computing power that sol needs...
Comments URL: https://news.ycombinator.com/item?id=49743419
Points: 1
# Comments: 0
The AI threat isn't what you think – The Econoclasts [video]
Article URL: https://www.youtube.com/watch?v=FOzijIeBGCg
Comments URL: https://news.ycombinator.com/item?id=49743418
Points: 1
# Comments: 0
Priest, Monk, and Mathematician
Article URL: https://logangraves.com/priest-monk-mathematician
Comments URL: https://news.ycombinator.com/item?id=49743400
Points: 1
# Comments: 0
How can I remove the Close button from my window caption?
Article URL: https://devblogs.microsoft.com/oldnewthing/20260911-00/?p=112691
Comments URL: https://news.ycombinator.com/item?id=49743398
Points: 1
# Comments: 0
MSVC C++23: constexpr cmath with LLVM Libc
Article URL: https://devblogs.microsoft.com/cppblog/msvc-c23-constexpr-cmath-with-llvm-libc/
Comments URL: https://news.ycombinator.com/item?id=49743394
Points: 1
# Comments: 0
Improving email security outcomes with real-world Microsoft Defender insights
For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to evolve.
This quarter’s benchmark examines how continuous measurement informs protection across prevention, detection, and adaptation, and how those insights are helping improve customer outcomes.
Read the latest Microsoft benchmarking data for email security Key takeaways- Defender again missed the fewest high-severity threats among the solutions evaluated, about 55% fewer than the next-closest secure email gateway (SEG) vendor.
- Layered security adds the most value in promotional and bulk filtering and works; gains for spam and malicious email remain comparatively modest.
In the latest quarterly SEG comparison from May 2026 through July 2026, Defender missed 221 high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest SEG vendor. The benchmark measures missed threats instead of the total number of malicious emails that were caught and filtered, because catch totals can reflect differences in threat volume and exposure across vendor environments. By normalizing missed threats per 1,000 users we are able to provide a more consistent side-by-side comparison.
Figure 1: High-severity email threats missed by SEG vendors (May 2026 through July 2026), measured as threats missed per 1,000 users protected. Data source: Microsoft Defender.If you’ve read our previous blogs, you’ll see that missed threats have increased across multiple reporting periods, including for Microsoft. This aligns with broader trends we’re seeing as AI makes it easier for cyberattackers to gather public information, tailor messages, and create more convincing impersonation attempts. It reinforces the need for protection that continuously adapts.
Benchmarking results for ICES vendorsEffective email detection combines pre-delivery filtering with post-delivery detection and remediation. This benchmark helps customers evaluate where each layer contributes measurable value.
Similarly to previous quarters, integrated cloud email security (ICES) solutions continue adding the most value in promotional and bulk filtering. We saw an improvement in ICES vendor malicious catch at 0.30% versus 0.13% in the last quarter and spam catch going up to 0.52% versus 0.28% compared to last quarter.
Figure 2: ICES vendor catch contribution (May 2026 through July 2026). Data source: Microsoft Defender.Defender caught 92% of post-delivery malicious messages on average during the benchmark period, highlighting how the combination of pre-delivery and post-delivery remediation delivers strong results for customers.
At the same time it’s key to understand that Defender doesn’t treat post-delivery remediation as a point-in-time action after the email was first delivered to the inbox. Even after a message reaches the inbox, new threat intelligence can reveal risks that were not apparent at the time of delivery. Defender continuously reevaluates delivered messages and remediates threats as new indicators, campaign intelligence, and threat signals emerge.
Figure 3: Post‑delivery malicious catch by Microsoft Defender (May 2026 through July 2026), shown across vendors and overall average. Data source: Microsoft Defender. How our benchmarking is helping shape product innovationThe value of benchmarking is what happens after measurement. Insights from customer feedback, threat telemetry, and benchmarking have informed recent Microsoft Defender investments:
- More control over promotional mail: Across multiple benchmarking periods, we observed that ICES solutions often delivered the greatest incremental benefit in filtering promotional and bulk email. The new Promotions folder in Outlook builds on these insights by helping users reduce inbox clutter while keeping legitimate marketing and bulk messages accessible.
- Redesigned machine learning and AI model stack: By analyzing and incorporating natural language processing signals, including message topic, alongside other AI detection signals, Defender can improve detection accuracy. During a consecutive four-week period, Microsoft research observed a roughly two-thirds reduction in false negatives and a nearly one-fifth reduction in false positives for Defender customers.
- Protection for people and AI: We built prompt injection protection to detect and isolate malicious AI instructions in email before delivery—helping protect not only people, but also Copilot, agents, and other AI systems that read and act on inbox content. This innovation demonstrates how we continue evolving our defenses to address the latest cyberattack techniques and stay ahead of emerging threats.
Since July 2025, our goal has been to bring greater transparency to email security effectiveness. Today, we are using benchmarking to help customers understand how cyberthreats evolve, where defenses add value, and how protection improves over time.
Benchmarking is not simply about demonstrating effectiveness, it is about learning from real-world outcomes and translating those insights into stronger protection. As cyberattackers continue to innovate, we remain committed to sharing evidence, improving our technology, and helping customers stay ahead of emerging cyberthreats.
To explore the latest benchmarking data and learn more about how Defender and ICES partners work together, access the benchmarking site.
Read the latest Microsoft Defender benchmarking results Learn moreLearn more about Microsoft Defender.
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.
US Coast Guard and FBI board oil tanker to investigate cyber attack
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
Revolut phishing texts appear days after data breach
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.
The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.
Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:
- Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
- Copies of IDs such as passports and driver’s licenses
- Verification selfies
- Account statements and transaction histories
Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.
One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.
Phishing text to a Revolut customerAccording to VirusTotal, the phishing domain was first scanned that same day.
In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.
This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.
A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.
If the campaign is connected to the breach, the information obtained from Revolut, combined with login details entered by victims or their approval of a login request, could be enough to take over their accounts.
How to stay safeWe don’t yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly.
Either way, treat unexpected messages about your account with caution:
- Don’t follow links in unsolicited messages. If a message concerns your account, open the official Revolut app directly.
- Check the actual domain in your browser’s address bar to see if it corresponds with what you expect.
- Use an up-to-date, real-time anti-malware solution on your device, preferably with a web protection component.
- Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
'Zuckoff' App Detects Meta Smartglasses, as Meta Plans Camera-Free Version, Loses Money, and Offers Social Media Subscriptions
Show HN: Prokop – Open-source coding environment with agents that learn
Article URL: https://github.com/capek-dev/prokop
Comments URL: https://news.ycombinator.com/item?id=49740924
Points: 1
# Comments: 0
Switch to Codex seamlessly when Claude Code is used up
Article URL: https://raw.githubusercontent.com/zqiren/Orbital/main/docs/screenshots/handoff-codex-continue.gif
Comments URL: https://news.ycombinator.com/item?id=49740917
Points: 1
# Comments: 0
