Feed aggregator
Deadbugz: A new kind of malicious MCP server
Article URL: https://omnafy.com/blog/deadbugz-malicious-mcp-server/
Comments URL: https://news.ycombinator.com/item?id=49629181
Points: 1
# Comments: 0
Android’s September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
You Can Now Destroy Flock Cameras for Cash in GTA V
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
More than 100,000 fake stores are out to steal your card details
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.
The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.
The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.
As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.
BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.
The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.
“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”
Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.
The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.
Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.
How shoppers can stay safeA professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.
- Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
- Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
- Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
- Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
- Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
- Use an up-to-date, real-time anti-malware solution with web protection.
- If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.
If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
The idea of using AI agents to secure AI agents seems compelling, but in doing so, we risk unnecessarily expanding our attack surface.
Government department admits that the Post Office ‘misunderstood the scale of Horizon scandal’
The National Air Traffic Control System was not fully operational for over eight hours, causing major disruption to airlines and passengers
Show HN: Axonpush – Replay production agent failures in CI and fail the build
Article URL: https://axonpush.xyz/
Comments URL: https://news.ycombinator.com/item?id=49625565
Points: 1
# Comments: 0
UK Postcode Map
Article URL: https://abersager.github.io/postcodemap/
Comments URL: https://news.ycombinator.com/item?id=49625560
Points: 1
# Comments: 0
CCAO-F vs. CCAR-F: which Claude certification should you take?
Article URL: https://www.claudecertifiedarchitects.com/blog/ccao-f-vs-ccar-f-claude-certification/
Comments URL: https://news.ycombinator.com/item?id=49625556
Points: 1
# Comments: 0
Show HN: Ctrlb-decompose: Strip the noise before senting it to LLMs
Article URL: https://github.com/ctrlb-hq/ctrlb-decompose
Comments URL: https://news.ycombinator.com/item?id=49625553
Points: 10
# Comments: 0
First HN Post
Show HN: Buymydeadstartup.com – Sell your IP to AI labs
I have had my fair share of failed startups, but none so recent that I could have sold our IP (code, Slack messages -- you name it) to Anthropic, OpenAI or any other AI lab or data buyer.
I know some companies are actively approached by some brokers, but most are not, because a startup often dies as a zombie (= not in a big bang, in most cases).
BuyMyDeadStartup is a bulletin board, not a marketplace. A founder posts a text description of what the company left behind, verified against a working email address and read by a person before it goes up. Buyers write to the founder directly.
Whatever they agree is between them.
I really tried to keep this as simple as possible.
Comments URL: https://news.ycombinator.com/item?id=49625537
Points: 1
# Comments: 0
Show HN: Sahara, a plain-language view of a relative's MyChart record
Article URL: https://sahara.synodha.com/demo
Comments URL: https://news.ycombinator.com/item?id=49625518
Points: 1
# Comments: 0
Where Every Fix Has a Shadow
Article URL: https://medium.com/@gurvinder372/article-13-where-every-fix-has-a-shadow-4498dccbf3ed
Comments URL: https://news.ycombinator.com/item?id=49625517
Points: 1
# Comments: 0
Show HN: Mark 1x-9B – a 9B model that answers with interfaces, not paragraphs
Article URL: https://huggingface.co/Saanora/mark-1x-9b
Comments URL: https://news.ycombinator.com/item?id=49625508
Points: 1
# Comments: 0
