Feed aggregator
Update Chrome now to protect against an actively exploited vulnerability
Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited.
The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.
How to update ChromeIf you don’t want to wait for the rollout to reach you, manually updating is easy.
The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.
To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.
Chrome 153.0.8010.36/.37 is up to dateYou can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.
Technical detailsThe actively exploited vulnerability is tracked as CVE-2026-87491. The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.
This means the bug was found in the part of Chrome that runs JavaScript. A malicious website could exploit it by getting someone to load a specially designed web page, causing Chrome’s JavaScript engine to mishandle memory and run attacker-chosen instructions. Those instructions would initially run within Chrome’s security sandbox rather than with unrestricted access to the whole device.
Chrome’s sandbox is intended to limit that code’s access to the rest of the device, but the flaw is still serious because it gives an attacker a foothold simply by getting a target to view a malicious web page. Emails are unlikely to trigger the flaw because most reputable email clients sanitize incoming HTML before displaying it. They strip or disable active web features that would let a sender run code in the inbox, such as JavaScript. However, an email could contain a link that takes the recipient to a malicious website.
Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library). WebGL is a JavaScript programming interface used to render interactive 2D and 3D graphics inside the browser without needing extra plugins.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
After Claude Mythos circumvented guardrails in July, Anthropic now wants an industry effort to control the pace of frontier model development
Computer science offered seemingly limitless creative possibility for Garth Gibson 50 years ago - much as AI does now. But not everyone invented RAID storage along the way
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online
Copyright scammers get Instagram accounts suspended and demand payment
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC.
Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and demands a ransom to withdraw the complaint.
We’ve reported on a similar scheme before. In that case, scammers abused Instagram’s reporting system to get accounts taken down and then charged their owners to restore them.
The BBC interviewed the owner of a history-focused Instagram account who said that he had been hit by copyright claims multiple times from the same email address. Repeated copyright claims can eventually result in an account being disabled, making this particularly damaging for people who use Instagram to generate income.
The account holder eventually paid $50 in cryptocurrency because he said it could take weeks for Meta to deal with his claim and that they were unhelpful to begin with. However, the scammers targeted him again immediately afterward.
Users do have free support routes, including the appeal option that comes with the copyright notification and Instagram’s in-app Help section. Paid options include the 24/7 access to a support agent that comes with Meta Verified, while Meta Business Support is available to some eligible business and advertising accounts.
The scam works because Meta has automated much of its processing of copyright complaints. It doesn’t verify the authenticity of complaints when they are filed, and repeated complaints can result in an account being temporarily taken down. Its policy says that only rights holders or their authorized representatives can file a complaint, but it doesn’t check their ID before acting. That means criminals can pretend to be rights holders or their lawyers and get away with it.
AI could make it easier for scammers to file these fraudulent complaints at scale, turning the attack into a trawling exercise. If they convince just a few victims to pay a ransom, it can become worth their while, especially if Meta takes too long to resolve the problem manually.
The BBC spoke to one Instagram account owner who said that he had lost brand contracts over the issue. Meta hadn’t been able to assure him that the problem wouldn’t happen again, he said.
This problem is drawing legal scrutiny. In India, the Delhi High Court is examining whether social media platforms can legally suspend user accounts over copyright violations. In a separate case, Meta acknowledged in court that 13 copyright strike notices against one Instagram user were fraudulent and restored the account.
Meta told the BBC that it fights deceptive behavior intended to scam people. After reviewing the accounts identified by the BBC, it restored affected content and added unspecified protections intended to prevent similar attacks. However, the company hasn’t announced any blanket protections designed to fix its “suspend first, verify later” approach.
Law enforcement advises victims not to pay the ransom because that feeds the scammers. It also doesn’t guarantee that they won’t hit you again. In fact, it might make them more likely to do so if they know that you are willing to cough up.
Copyright complaints are also commonly used as phishing lures. We have previously reported on scammers sending fake copyright warnings to X users and convincing copyright notices to YouTube creators. Those attacks tried to steal people’s login details. In this case, the scammers are abusing Instagram’s genuine complaints system to get accounts suspended.
How to protect your Instagram account- Turn on two-factor authentication. This will not prevent fraudulent complaints, but it can help protect your account if scammers also try to steal your login.
- Check copyright complaints in Instagram. Don’t rely on links or screenshots sent by email, Telegram, or another messaging service.
- Don’t pay to have a complaint withdrawn. Paying does not guarantee that the scammer will withdraw it or leave your account alone.
- Don’t share login details or verification codes. A scammer may use the copyright complaint to steer you toward a fake Instagram login page.
- Use Instagram’s official appeal process. Keep copies of the complaint, ransom demands, usernames, email addresses, and payment requests as evidence.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
New Apple Watches have ears
Article URL: https://leancrew.com/all-this/2026/09/new-apple-watches-have-ears/
Comments URL: https://news.ycombinator.com/item?id=49639942
Points: 1
# Comments: 0
Sharpness Is Power
Article URL: https://baku89.com/sharpness-is-power
Comments URL: https://news.ycombinator.com/item?id=49639935
Points: 1
# Comments: 0
OpenAI: Defense Factory
Article URL: https://openai.com/the-defense-factory/
Comments URL: https://news.ycombinator.com/item?id=49639922
Points: 1
# Comments: 0
4K Analog Video Feedback Fractal Device Complete
Article URL: https://www.youtube.com/watch?v=R1z3oM6h8uM
Comments URL: https://news.ycombinator.com/item?id=49639914
Points: 1
# Comments: 0
Curated List of Osint Tools
Article URL: https://osintech.substack.com/p/osintechs-timeline-171-16072026
Comments URL: https://news.ycombinator.com/item?id=49639838
Points: 2
# Comments: 0
If PHP Were British
Article URL: https://aloneonahill.com/blog/if-php-were-british/
Comments URL: https://news.ycombinator.com/item?id=49639831
Points: 1
# Comments: 0
Kelivo: A Flutter LLM Chat Client. Support Mobile and Desktop
Article URL: https://github.com/Chevey339/kelivo
Comments URL: https://news.ycombinator.com/item?id=49639819
Points: 2
# Comments: 0
GPS and the Limits of Control
Article URL: https://www.lawfaremedia.org/article/gps-and-the-limits-of-control
Comments URL: https://news.ycombinator.com/item?id=49639811
Points: 1
# Comments: 0
OpenClaw Dashboards: Personal Use, Team Workflows, and Building Your Own
Article URL: https://openclaw.ai/podcast/episode-10
Comments URL: https://news.ycombinator.com/item?id=49639786
Points: 1
# Comments: 0
Show HN: Sindlish, a programming language for Sindhi speakers
Hi, I’m Amanat, a student from Pakistan, and I’ve been working on a programming language called Sindlish.
The idea started from wondering what programming would feel like if the language used the vocabulary of the language you actually speak. Sindlish is designed for Sindhi-speaking communities and currently uses Romanized Sindhi syntax.
A small example:
```text kaam jor(a, b) -> adad { wapas a + b }
adad jawab = jor(3, 4) * 2 likh("jawab =", jawab) ```
It currently has its own lexer, parser, resolver, bytecode compiler, stack-based VM, type system, error handling, collections, closures, CLI/REPL and VS Code support.
It’s still a work in progress, and I’d really like feedback on the language design and the implementation.
Website: https://sindlish.vercel.app/
The website may be a little slow right now since most of my time is going into the language itself rather than the website.
Comments URL: https://news.ycombinator.com/item?id=49639784
Points: 1
# Comments: 0
Experience Shapes Extraordinary Beliefs
Article URL: https://www.cell.com/trends/cognitive-sciences/fulltext/S1364-6613(25)00310-9
Comments URL: https://news.ycombinator.com/item?id=49639783
Points: 1
# Comments: 0
In this era of AI, it is important to remember what it is like to be a child
Article URL: https://mathstodon.xyz/@tao/117244104044239500
Comments URL: https://news.ycombinator.com/item?id=49639782
Points: 1
# Comments: 0
Ultimate dev environment for Playwright NixOS VM tests
Article URL: https://blog.tiserbox.com/posts/2026-09-09-ultimate-dev-environment-for-playwright-nix-os-vm-tests.html
Comments URL: https://news.ycombinator.com/item?id=49639764
Points: 1
# Comments: 0
