Feed aggregator
Don't give them the time of day
Article URL: https://pluie.me/blog/dont-give-them-the-time-of-day/
Comments URL: https://news.ycombinator.com/item?id=49657197
Points: 2
# Comments: 0
Pizza Bot: a local-first inbox for long-running AI agents
Article URL: https://github.com/pizza-bot-app/pizza-bot
Comments URL: https://news.ycombinator.com/item?id=49657189
Points: 1
# Comments: 0
A Inefficient Way to Learn
Article URL: https://www.justinmath.com/a-really-inefficient-way-to-learn/
Comments URL: https://news.ycombinator.com/item?id=49657187
Points: 1
# Comments: 0
Show HN: Take a break, play some puzzles
Free daily logic puzzles without Ads. Check it out: gridmino.com My site offers puzzles where some of them are a new take on already established classics like Minesweeper, Kakuro, or Masyu. For example, my Minesweeper variant is called Dicesweep, where you need to place dice beside numbers while also matching the row and column rules.
Another interesting one is Kakumino. It's like Kakuro, but you place dominoes instead of numbers.
There are a bunch of them, so there's something for everyone's taste.
Check it out: gridmino.com
Comments URL: https://news.ycombinator.com/item?id=49657159
Points: 3
# Comments: 0
Show HN: Number Checker for WA – Check and Verify WhatsApp Numbers
Check WhatsApp registration in bulk. Import phone numbers and export results to CSV, Excel, or JSON.
Comments URL: https://news.ycombinator.com/item?id=49657142
Points: 2
# Comments: 0
Android malware creates a hidden copy of your banking app
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.
To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.
The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.
Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.
How an attack worksVictims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.
To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.
The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.
Fake banking-login overlays steal both banking credentials and the device’s PIN.
The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.
The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.
This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.
How to stay safeThe immediate protection advice is familiar but important:
Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.
Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.
Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.
Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.
Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.
A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Evolution of Attention over the Years
Article URL: https://gargighosh1.substack.com/p/evolution-of-attention-over-the-years
Comments URL: https://news.ycombinator.com/item?id=49657130
Points: 1
# Comments: 0
Homebrew now has an official GUI app
Article URL: https://github.com/Homebrew/BrewUI/
Comments URL: https://news.ycombinator.com/item?id=49657121
Points: 3
# Comments: 0
What is JSONC and is it any better than JSON?
Article URL: https://www.howtogeek.com/what-is-jsonc-is-it-any-better-than-json/
Comments URL: https://news.ycombinator.com/item?id=49657093
Points: 1
# Comments: 0
Airflow re-engineered for speed and scale
Article URL: https://www.astronomer.io/blog/astro-airflow-re-engineered-for-speed-and-scale/
Comments URL: https://news.ycombinator.com/item?id=49657063
Points: 1
# Comments: 0
Conversations with JJ
Article URL: https://laurmaedje.github.io/posts/jj/
Comments URL: https://news.ycombinator.com/item?id=49657057
Points: 1
# Comments: 0
SSH for Developers
Article URL: https://flaviocopes.com/ssh-for-developers/
Comments URL: https://news.ycombinator.com/item?id=49657042
Points: 1
# Comments: 0
PCS union chief met Cabinet Office minister to discuss troubled pension scheme run by Capita
As frontier models outpace cyber defences, two public sector voices set out different answers to the same security question – transparency and procurement leverage
‘Google is in the military kill chain’: Google DeepMind’s AI workers are attempting to unionise over ethical concerns around the provision of cloud and AI technologies to the US and Israeli militaries, but the company is pushing back
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
Gitwal – GitHub Event Archive
Article URL: https://gitwal.com
Comments URL: https://news.ycombinator.com/item?id=49656086
Points: 1
# Comments: 0
Robots Are Learning to Feel
Article URL: https://spectrum.ieee.org/tactile-data-robots
Comments URL: https://news.ycombinator.com/item?id=49656065
Points: 1
# Comments: 0
