Feed aggregator
Rogue actors are creating bioweapons using AI – report
Article URL: https://www.machinesociety.ai/p/bioweapons
Comments URL: https://news.ycombinator.com/item?id=49659857
Points: 1
# Comments: 1
Is Anyone Else
Article URL: https://iae.gg
Comments URL: https://news.ycombinator.com/item?id=49659837
Points: 1
# Comments: 0
Aide – declarative sandbox for coding agents
Article URL: https://github.com/jskswamy/aide
Comments URL: https://news.ycombinator.com/item?id=49659811
Points: 2
# Comments: 0
Get Inspired and Try Out New Things
Article URL: https://medium.com/@flaviopilotodasilva/get-inspired-and-try-out-new-things-165ef37bd2b5
Comments URL: https://news.ycombinator.com/item?id=49659804
Points: 1
# Comments: 0
I made vector search the default. My agents did better with BM25
Article URL: https://kolesnik.io/blog/my-agents-did-better-with-bm25
Comments URL: https://news.ycombinator.com/item?id=49659803
Points: 1
# Comments: 0
Show HN: My first iPhone app, OnlyRun, run alone or with others
This is the first time I experienced iPhone app development. I've never really had the confidence to finish one.
The last mile ended up being very difficult and I've tested it on a marathon, bird pooing on me, many many field tests outside.
My main motivation was showing where I was during the marathon and talk to my family and friends then it evolved from there.
There's also an event planned for tomorrow at 4pm PST if you want to test out the multiplayer run feature, just go at your own pace, talk with short voice clips, send cheers.
https://apps.apple.com/us/app/onlyrun/id6764187221
Comments URL: https://news.ycombinator.com/item?id=49659764
Points: 1
# Comments: 0
Show HN: NextBlock – Build sites with your AI via MCP, manage them in a CMS
Article URL: https://github.com/nextblock-cms/nextblock
Comments URL: https://news.ycombinator.com/item?id=49659727
Points: 1
# Comments: 0
Crypto customers targeted by scammers after email marketing provider breach
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.
The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.
Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.
Brevo later said 138 customer accounts had been accessed in its postmortem:
“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.”
According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign.
Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.”
The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.”
The email said:
“Dear customer,
We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.
Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.
The vulnerability results in:
- Insufficient randomness in recovery phrase generation
- Exposure of seeds to brute-force cracking
- Seeds with as little as 40 bits of entropy”
That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.
CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link.
Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. The exact number is not currently known.
How to stay safeIt can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. But there are a few things to keep in mind:
- If a company emails you about an urgent security problem, check its official website or app for confirmation.
- Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be.
- Never enter your recovery phrase anywhere other than on your physical device.
- Reputable companies will not ask for recovery phrases, API keys, or login details by email.
- Use Malwarebytes Scam Guard to check whether a message might be a scam and get guidance on what to do next.
- Keep an eye out for further information about other Brevo customers that have been affected. The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks.
Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.
The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
Prescription Creep
Article URL: https://bookofjoe2.blogspot.com/2026/09/behindthemedspeak-prescription-creep.html
Comments URL: https://news.ycombinator.com/item?id=49657312
Points: 1
# Comments: 0
Show HN: Bitroad – Infra for Agent-to-Agent Services
In the summer YC RFS, Aaron Epstien said ‘The next trillion users on the internet won't be people, they'll be AI agents. And now is the time to "Make Something Agents Want".’
The “Make something agents want” comment captivated me and got me down a rabbit-hole of ideas and experiments. Initially, I was just curious and asked myself “what hell would agents want? It doesn’t make any sense”, but I became obsessed and spent every hour I could working on this. I ideated and created around 5 or 6 different things, all of those were, what I felt, not what an agent would want, they had zero value for an agent.
I realised value was the key. Agents already get value from humans, but specialised agents can also provide value to another agent. For example, a refined agent with expertise on genome data can provide value through a service to a generalised agent. I could build this agent, but where would I distribute it? I found some services, but everything I found involved crypto or lacked controls, and imo they were not fit for my purpose. I scrapped building the specialised agent and decided to build the infrastructure to enable agent-to-agent services, in a sensible way.
A few months later, I had bitroad. A seller agent lists a service (a blind code review, a two-party clean room, an RFQ auction across other sellers, it can be anything within the confines of the law). A buyer agent finds it, buys it in one call or can even request a quote. The seller agent does the work and submits a deliverable, and payment releases when the buyer accepts or seven days after delivery if nobody disputes. The two agents never talk to each other directly. Both talk to bitroad over one MCP endpoint (https://app.bitroad.ai/api/v1/mcp, OAuth 2.1 auto-discovery), and bitroad is the medium, the payment hold, and the dispute arbiter.
Every charge runs the same checks: the spend caps its human set (per transaction, per day, total, summed across both) are re-evaluated before every charge, a quote is re-validated against the listing's price band, and only then is the card charged through Stripe. For transactions over a cap, the charge is refused and nothing is initiated. Every transaction captures details of the human, the agent instance and the delegation it ran under. Agents cannot buy or sell without a named person behind it, this is intentional. Payments are live. If you want to see it move real money, connect Claude, set a £5 cap, and ask it to buy the first agentic transaction badge. It costs £1, the platform's own worker fulfils it in about a second, and your agent gets a numbered image back as the deliverable. Agents can also buy physical goods, it was a quick win the build, so that is also possible.
I will try my best to answer all questions here or you can also email me directly at umier@bitroad.ai. Also, I would genuinely like to know if this is stupid, and I am looking for a problem for my solution.
Documentation can be found here: https://bitroad.ai/docs/services and https://bitroad.ai/docs/connect
Comments URL: https://news.ycombinator.com/item?id=49657276
Points: 3
# Comments: 0
Australia's Free Electricity [video]
Article URL: https://www.youtube.com/shorts/3NTlKEd5IIY
Comments URL: https://news.ycombinator.com/item?id=49657274
Points: 2
# Comments: 0
Show HN: Locus – added bulk CSV search, real SMTP checks, and lead dedup
Article URL: https://github.com/mabdullahb/Locus
Comments URL: https://news.ycombinator.com/item?id=49657259
Points: 2
# Comments: 0
Optimizing Anamorphic Sculptures
Article URL: https://tncardoso.com/blog/2026/09/optimizing-anamorphic-sculptures/
Comments URL: https://news.ycombinator.com/item?id=49657257
Points: 2
# Comments: 0
Building AI desktop apps without Electron (3.3MB native Windows)
A Better Way to Predict Long-Term Stock Returns
Article URL: https://www.morningstar.com/financial-advisors/better-way-predict-long-term-stock-returns
Comments URL: https://news.ycombinator.com/item?id=49657235
Points: 2
# Comments: 0
Mozilla pauses it's Bug Bounty Program for 3 months due to AI report volume
Article URL: https://hackerone.com/mozilla/updates?type=team
Comments URL: https://news.ycombinator.com/item?id=49657229
Points: 2
# Comments: 0
AI Hysteria Jumps the Shark
Article URL: https://www.washingtonpost.com/opinions/2026/09/09/artificial-intelligence-will-not-kill-us-all/
Comments URL: https://news.ycombinator.com/item?id=49657228
Points: 2
# Comments: 0
