Feed aggregator

Grok Bot by SpaceXAI

Hacker News - Tue, 08/11/2026 - 1:24pm
Categories: Hacker News

How to add package if no pip

Hacker News - Tue, 08/11/2026 - 1:24pm

as title, how to do that just, add python package

Comments URL: https://news.ycombinator.com/item?id=49261522

Points: 1

# Comments: 1

Categories: Hacker News

Tell HN: Striking a Balance Between Stating Your Requirements and Griefers

Hacker News - Tue, 08/11/2026 - 1:23pm

The frontier models have become very capable, so that I'm able to give advanced algorithms and tasks for them to complete autonomously. These sometimes go over the heads of low-IQ bullies who dropped out of their computer science courses because they were too difficult, and went into a career in bullying programmers.

I've noticed that when I make my intention and acceptance criteria very clear to the models, sometimes it's the only part the griefers understand, since the computer science portion goes over their heads. So they focus their bullying on just breaking the intention and final result, whatever is actually truly important.

This puts programmers like me in the awkward position of either talking to the models without telling the models the final intention or reason, i.e. the acceptance criteria, or risk putting it in plain language so the model knows it, but then allowing a bully to fuck that one thing up because it's the only thing they understand, not understanding data structures, algorithms, engineering or architecture, etc.

Basically, if you put into plain words what you're really looking for, a griefer can fuck that one thing up.

There is no easy answer to the problem of these griefers. It's a problem in every anonymous community, but exacerbated when the griefers are granted some special anonymity.

So far, I haven't found a great solution to it, but I am open to new ideas and feedback. How do you deal with low-IQ bully griefers fucking everything up?

Comments URL: https://news.ycombinator.com/item?id=49261515

Points: 1

# Comments: 0

Categories: Hacker News

Grok Bot

Hacker News - Tue, 08/11/2026 - 1:23pm

Article URL: https://x.ai/bot

Comments URL: https://news.ycombinator.com/item?id=49261514

Points: 3

# Comments: 0

Categories: Hacker News

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Security Week - Tue, 08/11/2026 - 12:50pm

The security defects could be exploited for arbitrary code execution and denial-of-service.

The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Valve warns Steam hardware buyers: Expect fake delivery scams

Malware Bytes Security - Tue, 08/11/2026 - 12:31pm

Most of us are wise to phishing emails that don’t contain much personal information. Generic “your account is suspended” messages usually get binned on sight. But what about the phishing emails that use your real name and address, and reference the specific product you bought last month? Even for the most suspicious of people, that can be convincing.

It’s also the situation European Steam hardware buyers walked into this week. On August 10, Valve, the company behind the Steam gaming platform and Steam hardware, warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam email addresses, and details of their hardware orders.

It wasn’t Valve itself that got hacked. Rather, it was its shipping partner CEVA Logistics, which handles delivery of hardware from the gaming store. Passwords and payment information were not touched.

What got stolen

The attack window ran from July 29 to August 1, 2026. Valve learned about it on August 7 and started notifying customers three days later. CEVA stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller, or Steam Machine in Europe over the past three months could be affected.

The exposed information may include:

  • Name
  • Street address, postal code, and city
  • Country
  • Phone number
  • Email address linked to the customer’s Steam account
  • The type and price of the ordered hardware

Exact numbers are still unconfirmed. Neither Valve nor CEVA has said how many customer records were involved. Dutch retailers Bol and De Bijenkorf were reportedly told about the same CEVA incident on August 1 and warned their own customers.

Why shipping data is valuable to scammers

A scammer can send an email, text, or even make a phone call that references your genuine order and delivery address before asking you to pay a small customs or redelivery fee, confirm your delivery, or sign in to “verify” your order.

Scam or legit? Scam Guard knows.

TRY IT NOW

Data like this is already widely traded online. Malwarebytes researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web during the first six months of 2026.

Not Valve’s first security incident

Although Valve’s own systems weren’t compromised, that doesn’t mean the consequences can’t be severe.

In May 2025, a threat actor called Machine1337 tried to sell what looked like a dataset of 89 million Steam user records for $5,000. The data turned out to be older SMS messages carrying expired two-factor codes, routed through a third-party intermediary Valve says it never partnered with.

Valve has suffered a direct breach in the past though. November 2011 saw one that exposed records from 35 million users, including usernames, emails, and encrypted credit card details.

What affected buyers should do

In an email to customers, Valve advises them to assume that any message referencing their recent Steam hardware order is fake. That covers email, SMS, and phone calls, even the ones that quote your address correctly.

Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account problems through its help page.

So you don’t need to rush to reset your password, although it never hurts to use a strong, unique password and enable Steam Guard’s two-factor authentication. Instead, be skeptical of any unsolicited emails, texts, or calls about a recent Steam hardware delivery, even if they include details only a real customer would know.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Social media platforms crack down on drone factory recruiting game

Malware Bytes Security - Tue, 08/11/2026 - 12:05pm

A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are used to influence decisions, build trust, and persuade people to share personal information or take actions they otherwise wouldn’t.

According to Straight Arrow News, the online game Drone Battle: Ukraine is linked to Russia’s Alabuga Special Economic Zone in Tatarstan, a site associated with the production of attack drones used in the war against Ukraine. Investigators say the game is the latest part of a broader campaign that has used major social media platforms, including YouTube, TikTok, Instagram, and X to reach young people.

The game is just the lure. Investigators say it forms the entry point to a recruitment funnel that markets education, careers, travel, community, and technological opportunity to young people before ultimately steering some recruits toward jobs assembling drones at Alabuga.

Available in English, Russian, and Chinese, Drone Battle: Ukraine presents a stylized conflict between Russia and NATO. But investigators say the game is only one part of a larger campaign that combines games, esports tournaments, influencers, and career messaging to recruit young people globally into Russia’s drone industry.

This campaign is not limited to drone combat. The same channels have also promoted games that frame construction work, teamwork, strategy, and professional development as challenges to be completed and levels to be unlocked.

That’s gamification serving a recruitment purpose. The game doesn’t have to persuade someone to take a job on its own. It only needs to make participation feel like a game, make a military-industrial workplace appear modern and exciting, and make the transition between the two seem natural.

Gamification itself isn’t unusual. Companies use games, quizzes, competitions, and rewards in education, training, and recruitment every day. The concern here is how those familiar techniques are combined with social engineering to influence decisions while obscuring the true nature of what’s being offered.

Social engineering

Social engineering is often described as a way of tricking people into giving up a password or opening a malicious attachment. But at its core, social engineering is the manipulation of human decisions. This campaign appears to use several familiar techniques at once.

  • Targeting: Investigators say Drone Battle: Ukraine is described in a registered patent as an “assessment tool in game form.” Rather than simply entertaining players, the game appears designed to engage people who may be receptive to later recruitment.
  • Baiting: The campaign advertises scholarships, training, free travel, housing, and career opportunities while, according to investigators, downplaying or concealing the true nature of the work.
  • Influencers: Social media promotions and seemingly personal testimonials make the campaign more persuasive than a straight-up advertisement.
  • Normalization: A drone in a game is a tool to use for victory and fun. Researchers have warned that game-like recruitment can make militarized narratives feel routine, technical, and emotionally distant.
  • Small steps: It starts with playing a game or following an account. People may then join a tournament, communicate with a recruiter, submit personal details, travel, and only later discover the full nature of the work. As with many social engineering campaigns, each interaction asks for a little more commitment, making the next step feel less significant than it really is.
Social platforms are taking action

US-based social media platforms have increasingly taken action against Alabuga-linked accounts after investigations alleged deceptive recruitment practices and human rights abuses associated with the campaign.

Social media platforms have been trying to disrupt the campaign for nearly two years. Following an Associated Press investigation in 2024, Google, Meta, and TikTok removed accounts linked to Alabuga Start for violating their policies. But according to the Foundation for Defense of Democracies (FDD), the organizers later created new accounts and continued recruiting across multiple platforms.

More recently, Ukraine’s Minister of Foreign Affairs, Andrii Sybiha, said that roughly 600 videos promoting Alabuga were removed from YouTube. The videos had been posted across hundreds of channels with a combined audience of more than 500 million subscribers. He wrote:

“The work does not end with removals. We will be now pursuing sanctions against individual bloggers who accepted payment to promote a sanctioned weapons manufacturer to millions of viewers.”

According to the Straight Arrow News investigation, however, the campaign remains active on X and Telegram.

How to stay safe

For home users, the traditional scam advice still applies: Independently verify a prospective employer, search for complaints and reporting, discuss an offer with someone you trust, and never pay to get a job.

Gamers should treat unsolicited career, travel, competition, and “exclusive training” offers with the same caution they would apply to any job pitch that feels unusually generous or vague. Offers to turn your gaming into a paid job should also be treated as “too good to be true.”

Other actions that might go a long way

Friends, families, educators, and youth organizations should talk openly about recruitment tactics without assuming that people targeted by them are naïve. They are often drawn in through a series of small steps that feel natural.

Platforms should investigate networks, influencer relationships, referral links, and coordinated messaging, not just individual posts or game titles.

Game developers and community platforms need reporting systems that are easy to find and will cater to recruitment concerns, not just cheating or abusive chat.

Governments and civil society groups in targeted countries need practical awareness campaigns that explain the specific promises being used and offer credible alternatives for education and employment.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Zoom Patches Zero-Click Code Execution Vulnerability

Security Week - Tue, 08/11/2026 - 11:49am

Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.

The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

A quick look at zero-knowledge proofs

Hacker News - Tue, 08/11/2026 - 11:35am

Article URL: https://bernsteinbear.com/blog/zkp/

Comments URL: https://news.ycombinator.com/item?id=49259957

Points: 1

# Comments: 0

Categories: Hacker News

Pages