Feed aggregator
Show HN: Client-side checker for Swiss QR-bills before banks drop the old format
Article URL: https://qr-adresse.ch/en/
Comments URL: https://news.ycombinator.com/item?id=49894191
Points: 1
# Comments: 0
I Made AI Look at Traces. For Science
Article URL: https://labqoat.com/blog/what-animal-left-this
Comments URL: https://news.ycombinator.com/item?id=49894179
Points: 2
# Comments: 0
A summer of discontent around ChatGPT's upload deletion function
Article URL: https://www.unite.ai/a-summer-of-discontent-around-chatgpts-upload-deletion-function/
Comments URL: https://news.ycombinator.com/item?id=49894178
Points: 1
# Comments: 0
Using commit history to predict the next vulnerability
Article URL: https://chainloop.dev/blog/predicting-the-next-vulnerability-from-fix-history/
Comments URL: https://news.ycombinator.com/item?id=49894163
Points: 1
# Comments: 0
I do not and will not use AI
Article URL: https://dbushell.com/2026/09/28/leaving-them-behind/
Comments URL: https://news.ycombinator.com/item?id=49894160
Points: 3
# Comments: 0
Don't Attribute Intelligence to It
Article URL: https://gist.github.com/vemv/ecaec66072be5a00cc9f37cce65f3747
Comments URL: https://news.ycombinator.com/item?id=49894146
Points: 1
# Comments: 0
Mechanochemistry of Molecular Motors [video]
Article URL: https://www.youtube.com/watch?v=hpxbMVbL3Ms
Comments URL: https://news.ycombinator.com/item?id=49894143
Points: 2
# Comments: 0
Falling in Love with the Problem, Not the Solution, Is More Important Than Ever
Article URL: https://tonyalicea.dev/blog/fall-in-love-with-the-problem/
Comments URL: https://news.ycombinator.com/item?id=49894131
Points: 2
# Comments: 0
RemoteThreat Launches With $7 Million for Offensive Operations Platform
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.
The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.
Metropolitan Police senior officers admit that only 30% of the force has completed mandatory data protection training following a series of high-profile data incidents
European datacentre associations argue that building datacentres where renewable power is generated could ease grid congestion in the Netherlands and beyond
Reco Raises $55 Million for Agentic Security
The company will use the funds to expand its sales, partnerships, channels, and customer support teams.
The post Reco Raises $55 Million for Agentic Security appeared first on SecurityWeek.
Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
The post Hackers Use ChatGPT Custom GPTs in ClickFix Attacks appeared first on SecurityWeek.
Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home
A Facebook Marketplace buyer arrived at a seller’s apartment to collect a keyboard. The seller wasn’t home and didn’t know anyone was coming. Meta’s AI assistant Muse had handled the conversation, shared his address, and arranged the visit without telling him.
We often write about AI misalignment and how to use AI agents and browsers safely. That can sound theoretical, but this is an example of the real-world risk when an agent is allowed to act on someone’s behalf.
Muse is Meta’s semi-autonomous AI assistant, released in the US in September. Meta promotes it as a personal assistant that can help users automate tasks, including responding to Facebook Marketplace messages. Unlike a conventional chatbot, which waits for a prompt and produces an answer, an AI agent may be authorized to take actions within connected apps.
We’ve written about a separate weakness in Muse that researchers considered dangerous. Reportedly, Muse was downloaded 3 million times in its first week.
According to Business Insider, a Facebook Marketplace seller turned on Muse to help handle a keyboard listing. He entered his address as the pickup location and approved automatic replies. Muse then shared that address with a prospective buyer, negotiated over the item, and arranged a visit, the seller said. He says Muse did not ask permission to share his address or arrange the visit, and did not tell him it was happening. The buyer arrived at the seller’s apartment expecting to complete the purchase, but the seller wasn’t home. The sale didn’t happen.
The reported incident is more than a privacy failure. It illustrates a broader AI-agent risk: An agent may treat permission to reply automatically as permission to share sensitive information or commit you to an in-person meeting. Meta says it is looking into the report.
How to use AI agents safelyBefore enabling an AI agent, treat its setup screen as a security review. Do not assume that an integration with a trusted platform means the agent will understand your intentions or apply sensible limits automatically.
Pay particular attention to:
- Connected accounts: Review every service the agent can access, such as email, messages, calendars, cloud storage, shopping accounts, or social media profiles.
- Data access: Consider whether it can read addresses, contacts, photos, private messages, payment details, documents, or location data.
- Action permissions: Check whether the agent can send messages, post content, negotiate, make bookings, place orders, alter listings, or share information externally.
- Automatic actions: Apply settings that require approval before the agent sends, publishes, buys, deletes, or shares anything sensitive. Check how it will notify you about the plans it makes on your behalf.
- Audience controls: Confirm exactly who can receive information generated by the agent. “Anyone who messages me” is very different from “people I approve.”
Give an AI agent the least access necessary for the task. If you only want help writing replies, do not enable automatic sending. If you want an AI agent to manage a listing, use a public meeting location or a separate pickup address rather than your home address.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Pentagon Personnel Agency Data Breach Impacts 3 Million People
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.
The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on SecurityWeek.
Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents
The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on SecurityWeek.
Andy Burnham visited Kyiv in Aug 2026, the fourth UK PM since 2022. UK-Ukraine tech collaboration has grown with AI-focused military deals, and Ukraine’s tech sector has proven resilient despite the war
Kiteworks customers are back up and running after a highly unusual preemptive shutdown that came amid indications of an impending cyber attack
Four Cyber Threats Harboring Big Plans for the Future
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek.
