Feed aggregator

Update Chrome now to protect against an actively exploited vulnerability

Malware Bytes Security - Thu, 09/10/2026 - 6:52am

Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited.

The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.

How to update Chrome

If you don’t want to wait for the rollout to reach you, manually updating is easy.

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.

Chrome 153.0.8010.36/.37 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

The actively exploited vulnerability is tracked as CVE-2026-87491. The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.

This means the bug was found in the part of Chrome that runs JavaScript. A malicious website could exploit it by getting someone to load a specially designed web page, causing Chrome’s JavaScript engine to mishandle memory and run attacker-chosen instructions. Those instructions would initially run within Chrome’s security sandbox rather than with unrestricted access to the whole device.

Chrome’s sandbox is intended to limit that code’s access to the rest of the device, but the flaw is still serious because it gives an attacker a foothold simply by getting a target to view a malicious web page. Emails are unlikely to trigger the flaw because most reputable email clients sanitize incoming HTML before displaying it. They strip or disable active web features that would let a sender run code in the inbox, such as JavaScript. However, an email could contain a link that takes the recipient to a malicious website.

Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library). WebGL is a JavaScript programming interface used to render interactive 2D and 3D graphics inside the browser without needing extra plugins.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

After Claude Mythos circumvented guardrails in July, Anthropic now wants an industry effort to control the pace of frontier model development

Computer Weekly Feed - Thu, 09/10/2026 - 6:10am
After Claude Mythos circumvented guardrails in July, Anthropic now wants an industry effort to control the pace of frontier model development
Categories: Computer Weekly

Computer science offered seemingly limitless creative possibility for Garth Gibson 50 years ago - much as AI does now. But not everyone invented RAID storage along the way

Computer Weekly Feed - Thu, 09/10/2026 - 6:10am
Computer science offered seemingly limitless creative possibility for Garth Gibson 50 years ago - much as AI does now. But not everyone invented RAID storage along the way
Categories: Computer Weekly

Organizations Warned of Cisco Secure FMC Exploitation

Security Week - Thu, 09/10/2026 - 6:06am

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.

Categories: SecurityWeek

Clearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life Online

Wired Security - Thu, 09/10/2026 - 6:00am
InquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.
Categories: Wired Security

Copyright scammers get Instagram accounts suspended and demand payment

Malware Bytes Security - Thu, 09/10/2026 - 5:59am

Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC.

Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and demands a ransom to withdraw the complaint.

We’ve reported on a similar scheme before. In that case, scammers abused Instagram’s reporting system to get accounts taken down and then charged their owners to restore them.

The BBC interviewed the owner of a history-focused Instagram account who said that he had been hit by copyright claims multiple times from the same email address. Repeated copyright claims can eventually result in an account being disabled, making this particularly damaging for people who use Instagram to generate income.

The account holder eventually paid $50 in cryptocurrency because he said it could take weeks for Meta to deal with his claim and that they were unhelpful to begin with. However, the scammers targeted him again immediately afterward.

Users do have free support routes, including the appeal option that comes with the copyright notification and Instagram’s in-app Help section. Paid options include the 24/7 access to a support agent that comes with Meta Verified, while Meta Business Support is available to some eligible business and advertising accounts.

The scam works because Meta has automated much of its processing of copyright complaints. It doesn’t verify the authenticity of complaints when they are filed, and repeated complaints can result in an account being temporarily taken down. Its policy says that only rights holders or their authorized representatives can file a complaint, but it doesn’t check their ID before acting. That means criminals can pretend to be rights holders or their lawyers and get away with it.

AI could make it easier for scammers to file these fraudulent complaints at scale, turning the attack into a trawling exercise. If they convince just a few victims to pay a ransom, it can become worth their while, especially if Meta takes too long to resolve the problem manually.

The BBC spoke to one Instagram account owner who said that he had lost brand contracts over the issue. Meta hadn’t been able to assure him that the problem wouldn’t happen again, he said.

This problem is drawing legal scrutiny. In India, the Delhi High Court is examining whether social media platforms can legally suspend user accounts over copyright violations. In a separate case, Meta acknowledged in court that 13 copyright strike notices against one Instagram user were fraudulent and restored the account.

Meta told the BBC that it fights deceptive behavior intended to scam people. After reviewing the accounts identified by the BBC, it restored affected content and added unspecified protections intended to prevent similar attacks. However, the company hasn’t announced any blanket protections designed to fix its “suspend first, verify later” approach.

Law enforcement advises victims not to pay the ransom because that feeds the scammers. It also doesn’t guarantee that they won’t hit you again. In fact, it might make them more likely to do so if they know that you are willing to cough up.

Copyright complaints are also commonly used as phishing lures. We have previously reported on scammers sending fake copyright warnings to X users and convincing copyright notices to YouTube creators. Those attacks tried to steal people’s login details. In this case, the scammers are abusing Instagram’s genuine complaints system to get accounts suspended.

How to protect your Instagram account
  • Turn on two-factor authentication. This will not prevent fraudulent complaints, but it can help protect your account if scammers also try to steal your login.
  • Check copyright complaints in Instagram. Don’t rely on links or screenshots sent by email, Telegram, or another messaging service.
  • Don’t pay to have a complaint withdrawn. Paying does not guarantee that the scammer will withdraw it or leave your account alone.
  • Don’t share login details or verification codes. A scammer may use the copyright complaint to steer you toward a fake Instagram login page.
  • Use Instagram’s official appeal process. Keep copies of the complaint, ransom demands, usernames, email addresses, and payment requests as evidence.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Sharpness Is Power

Hacker News - Thu, 09/10/2026 - 3:50am
Categories: Hacker News

OpenAI: Defense Factory

Hacker News - Thu, 09/10/2026 - 3:49am
Categories: Hacker News

If PHP Were British

Hacker News - Thu, 09/10/2026 - 3:38am
Categories: Hacker News

Show HN: Sindlish, a programming language for Sindhi speakers

Hacker News - Thu, 09/10/2026 - 3:33am

Hi, I’m Amanat, a student from Pakistan, and I’ve been working on a programming language called Sindlish.

The idea started from wondering what programming would feel like if the language used the vocabulary of the language you actually speak. Sindlish is designed for Sindhi-speaking communities and currently uses Romanized Sindhi syntax.

A small example:

```text kaam jor(a, b) -> adad { wapas a + b }

adad jawab = jor(3, 4) * 2 likh("jawab =", jawab) ```

It currently has its own lexer, parser, resolver, bytecode compiler, stack-based VM, type system, error handling, collections, closures, CLI/REPL and VS Code support.

It’s still a work in progress, and I’d really like feedback on the language design and the implementation.

Website: https://sindlish.vercel.app/

The website may be a little slow right now since most of my time is going into the language itself rather than the website.

Comments URL: https://news.ycombinator.com/item?id=49639784

Points: 1

# Comments: 0

Categories: Hacker News

Pages