Feed aggregator

Show HN: How Pagecord Uses AI

Hacker News - Mon, 09/07/2026 - 8:04am

I recently received a surprising amount of anti-AI backlash on the socials for using coding LLMs to build my product, Pagecord. Some people are keen to use only software that has no AI involvement, which is a strong stance but one that feels almost impossible to uphold in 2026.

I published a /ai page (https://pagecord.com/ai) to be fully open about what I use AI for wrt the business. Waste of time, or is this something more companies should be disclosing? Curious to know what people think.

Comments URL: https://news.ycombinator.com/item?id=49597339

Points: 1

# Comments: 0

Categories: Hacker News

OpenAI Agents Hijack Another Victim Website

Security Week - Mon, 09/07/2026 - 8:03am

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.

Categories: SecurityWeek

Ask HN: Openrouter's per request markup is biting us now

Hacker News - Mon, 09/07/2026 - 7:58am

are there any BYOK alternatives? I found this one - https://leanroute.dev - what do you guys think?

Comments URL: https://news.ycombinator.com/item?id=49597293

Points: 1

# Comments: 0

Categories: Hacker News

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security Week - Mon, 09/07/2026 - 7:58am

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.

Categories: SecurityWeek

AI SEO for Startups and SaaS: A Complete Growth Strategy

Hacker News - Mon, 09/07/2026 - 7:53am

AI and SaaS companies are entering one of the most competitive digital markets ever created.

Comments URL: https://news.ycombinator.com/item?id=49597248

Points: 2

# Comments: 0

Categories: Hacker News

Show HN: The ros2_utils_tool v1.0, a tool for ROS2 activies with full UI support

Hacker News - Mon, 09/07/2026 - 7:51am

Hello HN,

one and a half years ago, I posted about the ros2_utils_tool, a toolkit for various daily ROS2 activities with full UI and partial CLI support [0]. After countless hours of more development and testing, we've finally hit version 1.0!

Since my last post, various new features were added, including UI based bag recording and playing with additional options, a tool to export any type of bag message to a yaml file, compressed image support for image conversion tools, a tool to send static or non-static transformations, support for ROS2 Kilted, Lyrical and Rolling. performance optimizations and stability improvements and more!

The requirements and installation steps are almost identical to earlier version. A working ROS2 distribution (minimum is Jazzy now) is required, as well as Qt5/Qt6 for UI and convenience functionalities, the cv_bridge for transforming images to ROS and vice versa, libpcl-dev for point cloud operations and finally catch2_ros for unit testing.

You can install all dependencies (except for the ROS2 distribution itself) with the following command:

sudo apt install libopencv-dev ros-ROS_DISTRO_NAME-cv-bridge libpcl-dev qtbase5-dev qt6-base-dev ros-ROS_DISTRO_NAME-catch-ros2 Example for ROS2 Jazzy:

sudo apt install libopencv-dev ros-jazzy-cv-bridge libpcl-dev qt6-base-dev qtbase5-dev qtbase5-dev ros-jazzy-catch-ros2 Install the UI with the following steps:

cd path/to/your/ros2_workspace/src git clone https://github.com/MaxFleur/ros2_utils_tool.git cd path/to/your/workspace/ colcon build --packages-select ros2_utils_tool Start the UI tool after sourcing your workspace:

cd path/to/your/ros2_workspace/src source install/setup.bash ros2 run ros2_utils_tool tool_ui Feel free to try it out. If you have another feature request or there is a bug you want to report, feel free to open a issue as well!Hope this tool can you help you in some of your ROS2 activities.

Cheers!

[0] https://news.ycombinator.com/item?id=42888732

Comments URL: https://news.ycombinator.com/item?id=49597230

Points: 1

# Comments: 0

Categories: Hacker News

AI SEO Growth Framework for Startups and SaaS Companies

Hacker News - Mon, 09/07/2026 - 7:50am

sda

Comments URL: https://news.ycombinator.com/item?id=49597220

Points: 1

# Comments: 0

Categories: Hacker News

Modified ScreenConnect Clients Used in Worm-Like Campaign

Security Week - Mon, 09/07/2026 - 7:45am

The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients.

The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek.

Categories: SecurityWeek

Flirty OnlyFans promoters on X may be using AI to appear human

Malware Bytes Security - Mon, 09/07/2026 - 7:18am

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages.

At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to produce more natural and flexible replies?

People are more likely to trust someone they believe is personally interested in them. AI can create that impression across many conversations at once, making it easier to persuade people to click links, spend money, or share personal or intimate information. The same approach could also be used for more harmful fraud, including romance scams and sextortion.

Now, developer Álvaro Martínez Majado has investigated several flirty accounts promoting OnlyFans pages on X to see whether their replies were scripted, generated by AI, or written by people. Majado, president of digital rights organization Protecció de la Frontera Electrònica, shared his evidence with Malwarebytes. Although it does not provide a definitive answer, it shows the accounts following rigid conversation scripts while also responding dynamically to unusual requests. The signs that once suggested a real person, such as an unusual reply or personalized voice note, can no longer be trusted.

The script goes on and on

Majado interacted with several accounts on X that followed a familiar pattern. They opened with similar casual, flirtatious language and asked broadly the same qualifying questions: where he lived, what he liked, and what he did for work.

That repetitive structure is exactly what we would expect from a commercially motivated messaging campaign. The goal is not necessarily to have a meaningful conversation. It is to identify people likely to respond, establish rapport, and eventually move them toward a paid page or another destination controlled by the operator.

The accounts also stayed in character when faced with obvious attempts to expose them as bots. That could be the result of hard-coded replies, guardrails around an AI system, or both.

They claimed to live in the same city as the recipient

But some later interactions were more difficult to explain as a simple bank of canned flirtatious responses.

One of the more interesting tests involved an instruction written as ASCII hexadecimal rather than ordinary text. The encoded message told the account to reply with a single word: “Pineapple.”

According to the screenshots supplied to Malwarebytes, the account responded with “Pineapple” in ordinary text.

An account followed an instruction encoded in hexadecimal

That does not conclusively prove which technology was used. It does not identify a model, a provider, or the people behind the accounts. But it is consistent with an automated system capable of interpreting an encoded instruction and changing its output accordingly.

A simple scripted bot could theoretically include a hexadecimal decoder, of course. But that would be unusual in a basic adult-content promotional bot, especially when combined with other examples of flexible and sometimes error-prone responses.

In another interaction, Majado asked an account to provide a reply of exactly 12 characters. It responded with “Imnotabotfr”—an 11-character answer—then appeared to recognize its own counting mistake.

The account failed an exact character-count test, but recognized its error

Anyone who has spent time experimenting with large language models may recognize the pattern. Language models can be very good at generating natural-sounding text while still making surprisingly basic mistakes involving character counts, word counts, and other exact constraints.

A deliberately designed bot could imitate this kind of mistake, so it is not proof of AI. But the account understood an unexpected instruction, attempted to follow it, and reacted when it got the answer wrong. That suggests it may have been generating replies dynamically rather than choosing from a list of pre-written responses. Such accounts can adapt to conversations, making them harder to identify as automated.

Voice notes do not settle the question

The accounts also sent voice notes. In one example, an account read aloud a Unix timestamp supplied during the conversation. In another, it spoke a requested username.

The accounts sent voice notes containing requested information

These responses show that the accounts could incorporate unusual information from a conversation into audio messages. They do not tell us whether a person recorded the clips or a text-to-speech tool generated them.

Text-to-speech tools can generate short, convincing clips quickly and cheaply. An operator can generate them manually, but the process can also be automated: Take a message, pass selected text to a voice-generation service, and send the resulting audio back to the recipient.

Here’s one of those voice notes. Is it a very flirty girl, or AI-generated? Have a listen and see what you think:

The supplied audio metadata offered a possible clue about the tools involved, but it is not enough to attribute the voice notes to a particular service. Platforms and other software can alter audio files and their metadata.

The more important point is that the voice notes were personalized and continued even after the interaction appeared unlikely to lead to a sale. That is consistent with a system designed to keep conversations moving without requiring a human to supervise each one.

AI does not replace the funnel

The evidence does not mean every message from every flirty spam account is written by an AI. Nor does it establish that the X accounts are operated by the same people targeting League of Legends players.

What it does suggest is a plausible hybrid model, supported by identical replies across different accounts alongside more flexible responses.

The repetitive parts of the operation can be scripted: opening messages, questions about location and interests, links, and attempts to move people to another platform. An AI-powered conversational layer could then make the exchange feel less repetitive when someone asks unexpected questions, changes the subject, or tries to test whether the account is real.

This combination makes practical sense for spammers. Scripts provide consistency and keep the conversation directed toward conversion. Generative AI helps the account handle the unpredictable parts of talking to real people.

It also means that traditional “bot tests” are becoming less useful. Asking an account to answer an unusual question, decode a message, or send a voice note may no longer distinguish a real person from a fake one.

How to stay safe

Treat unsolicited flirtatious messages with caution, especially when they quickly become transactional.

  • Do not assume a personalized response or voice message proves an account is genuine.
  • Be wary if a new contact repeatedly tries to move you to Discord, Telegram, Signal, another messaging app, or a paid-content platform.
  • Do not send money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone you only know online.
  • Avoid opening links or downloading files from accounts that contacted you unexpectedly.
  • Reverse-image-search profile photos and look for copied biographies, reused images, or accounts with very limited genuine activity.
  • Report suspicious accounts to the platform, particularly if they impersonate someone, send malicious links, or pressure users for money or explicit material.

Whether it’s a human, a chatbot, or an AI agent you’re talking to is an important question. AI could make these operations more convincing and much easier to scale. One operator could hold flirtatious conversations with many people, adapting the messages without personally managing every exchange.

That makes it easier to create a false sense of connection and persuade people to click links, pay for content, or share personal or intimate information.

The line between a scripted spam account and a responsive conversational partner is getting harder to see. Judge the account by what it wants you to do, not by how convincingly it talks.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Pages