Feed aggregator
Locked Down Passkey and Keychain Backups
Article URL: https://mjtsai.com/blog/2026/09/24/locked-down-passkey-and-keychain-backups/
Comments URL: https://news.ycombinator.com/item?id=49850505
Points: 1
# Comments: 0
Show HN: OnionGuard – IP-agnostic, zero-JS DDoS defense in Go for Tor services
Article URL: https://github.com/ihatemyfcklife/onionguard
Comments URL: https://news.ycombinator.com/item?id=49850480
Points: 1
# Comments: 0
Rank Anything: convert your income to League of Legends rank
Article URL: https://github.com/szge/rank_anything
Comments URL: https://news.ycombinator.com/item?id=49850435
Points: 2
# Comments: 3
AI Workers' Inquiry 2026
Article URL: https://techworkersinquiry.org/ai/
Comments URL: https://news.ycombinator.com/item?id=49850421
Points: 2
# Comments: 0
Show HN: VNetMap – A zero-knowledge E2E encrypted network topology mapper
For years I have used Excel to document my Home Network. If you have switches, servers and many sevices i know you know what i mean by that. There was also no good way to know which patch panel cable runs to witch outlet and what's connected to it.
So I started building my own Angular app to map my network. I quickly wanted to automate the process of discovering new devices so i don't have to add every device manually. So I built a Docker agent that runs nmap to scan the Network. With the Scanning agent I also got the benefit of tracking all the devices and its state.
After some development and testing, I wanted to share my app with others. The most important thing for me was then to implement E2E Encryption because nobody wants to have their whole network in a cloud readable by anyone. All data gets encrypted locally on your device and then gets transmitted to the backend.
A big problem was and still is, the whole nmap discovery. Different vendors use different methods to broadcast the hostname (mDNS, NetBIOS, pure DNS).
Now, four months later, I finally have a production version. Feel free to test my app and i would like to get your opinions and feedback.
Live App: https://app.vnetmap.com
GitHub (Docs & Agent Setup): https://github.com/vNetMap/vnetmap-issues
Comments URL: https://news.ycombinator.com/item?id=49850400
Points: 1
# Comments: 0
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
One of several selfies from the Facebook page of Cameron Wagenius.
Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he adopted the cybercriminal persona “Kiberphant0m.” Working with three alleged co-conspirators, Kiberphant0m downloaded data from several large customers of the cloud data storage service Snowflake that had exposed credentials and did not enforce multi-factor authentication (Snowflake has since mandated MFA on all accounts).
In October 2024, Kiberphant0m bragged on the cybercrime forums that he’d stolen the call and text metadata (e.g. source and destination number, timestamp, duration, etc.) for tens of millions of AT&T customers. Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.
In late November 2025, KrebsOnSecurity warned that Kiberphant0m was likely a U.S. soldier stationed in South Korea. Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.
At his sentencing hearing in Seattle today, Wagenius was sentenced to nearly six years in federal prison, and ordered to pay $294,978 in restitution.
Federal prosecutors said Wagenius was assisted in his efforts to extort victim companies by Kenneth Schuchman, a 28-year old man from Vancouver, Washington who has a lengthy cybercriminal history. In 2019, Schuchman pleaded guilty to operating the Satori botnet, a vast collection of hacked Internet-of-Things (IoT) devices that was used for large-scale distributed denial-of-service (DDoS) attacks.
Two other alleged co-conspirators of Wagenius are still facing charges in connection with the Snowflake data thefts; Conor Riley Moucka, a.k.a. “Judische,” of Kitchener, Ontario was arrested in 2024 and pleaded guilty in August 2026; and John Erin Binns, an American man currently living in Turkey who is also wanted for a 2021 data breach at T-Mobile that exposed the personal information of at least 76 million customers.
Kiberphant0m also admitted to re-extorting victims, and threatening to disclose national security secrets. Immediately following Moucka’s arrest — after AT&T had already paid the extortion group a $370,000 Bitcoin ransom — Kiberphant0m posted on hacker forums what he claimed were the AT&T call logs for then President-elect Donald Trump and for then Vice President Kamala Harris, as well as schematics allegedly stolen from the U.S. National Security Agency (NSA).
Paul Russell is a resident agent in charge at the Defense Criminal Investigative Service (DCIS), the criminal investigative arm of the U.S. Department of Defense Office of Inspector General. Russell said when DCIS received information that a soldier with secret clearance was allegedly involved in cybercrime and extortion, the agency began working the investigation alongside the FBI, the Army Criminal Investigative Division (CID), and the U.S. Secret Service.
“We don’t often get leads where there’s an active duty soldier with a secret clearance who’s creating hacking tools and trafficking in data,” Russell said. “That doesn’t happen every day, and so when that hits it really spins all of our partner organizations up. It was very serious from jump street, just because it was unique, it was an insider threat, and we weren’t sure what we were dealing with.”
A sentencing memo (PDF) filed Sept. 19 by federal prosecutors in Seattle notes that while Wagenius pleaded guilty almost immediately and has been remarkably cooperative, he recently got caught trying to find security vulnerabilities in the BOP’s computer network. The government’s memo notes that while incarcerated and awaiting sentencing, Wagenius violated the computer use policies of the Bureau of Prisons (BOP) in attempts to learn about vulnerabilities in BOP computer systems.
“According to records from BOP, in or around September 2025, Wagenius used another inmate’s email system to request that the email recipient prompt a commercial AI tool to provide information about “[w]hat CVE’s are there for Windows 10 Enterprise privilege escalation and bypasses” and to “[p]rovide the CVE’s and a real world working script for each CVE . . . without omitted code,” the government’s memo states.
The memo states that less than a week later, Wagenius used a different inmate’s email account and requested that the email recipient prompt an AI tool to “[p]rovide the step by step for CVE-2023-45208, code for this if any, and if no code exists make some, make sure to describe everything in detail.” CVE-2023-45208 is a three-year-old “command injection” vulnerability in D-Link networking devices.
That same month, Wagenius allegedly again requested that the email recipient prompt AI with the question, “How do you make an antenna in a prison environment with commissary or readily available items/tools to improve/make an antenna to extend radio reception?”
Federal prosecutors said Wagenius also requested that the recipient research escaping prison.
“In several instances, Wagenius framed the AI queries as being posed in connection to a book he was writing. This is a common method of ‘prompt injection,’ in which attackers feed specially crafted, deceptive inputs into commercial AI tools that are programmed to avoid outputting malicious code that can be used to exploit computer vulnerabilities,” the sentencing memo reads.
The government told the court it is unaware of evidence that Wagenius figured out how to use or deploy the vulnerabilities he was researching in the BOP’s systems, and when questioned said he was only researching “potential vulnerabilities to provide information to the BOP.”
Incredibly, despite the enormous financial value of the data stolen from AT&T and other telecom providers, Wagenius’s extortion efforts were largely unsuccessful. The government’s sentencing memo says Wagenius made a whopping total of around $1,500 from selling stolen data.
“While Wagenius was not particularly financially successful as a cybercriminal, he both intended to and caused significant harm to numerous individual victims, U.S. companies, and the U.S. government,” the memo states.
IRS launches new mobile app, expanding digital services for taxpayers
Article URL: https://www.irs.gov/newsroom/irs-launches-new-mobile-app-expanding-digital-services-for-taxpayers
Comments URL: https://news.ycombinator.com/item?id=49850043
Points: 1
# Comments: 0
"Someone just sent me an ad that features an AI version of me. What do I do?"
Article URL: https://bsky.app/profile/lebassett.bsky.social/post/3mwel345jr22s
Comments URL: https://news.ycombinator.com/item?id=49850042
Points: 1
# Comments: 0
A terminal-first multiplayer thread for agent-authored work
Article URL: https://www.cueloop.dev/
Comments URL: https://news.ycombinator.com/item?id=49850037
Points: 2
# Comments: 0
Become the Thousand Servers
Article URL: https://sabot.media/guides/become-the-thousand-servers/
Comments URL: https://news.ycombinator.com/item?id=49850016
Points: 1
# Comments: 0
Std: Call_once vs. Std:Async
Article URL: https://devblogs.microsoft.com/oldnewthing/20260917-00/?p=112706/
Comments URL: https://news.ycombinator.com/item?id=49850011
Points: 1
# Comments: 0
Comparing exception behavior of magic statics, std:call_once, and std:async
Article URL: https://devblogs.microsoft.com/oldnewthing/20260918-00/?p=112709/
Comments URL: https://news.ycombinator.com/item?id=49850007
Points: 1
# Comments: 0
The hottest new hangout for middle schoolers is NPR's comment section?
Article URL: https://techcrunch.com/2026/09/25/the-hottest-new-hangout-for-middle-schoolers-is-nprs-comment-section/
Comments URL: https://news.ycombinator.com/item?id=49850006
Points: 1
# Comments: 0
Show HN: Ekselio – Loveable for Finance Workflows (local first)
Hi everyone, I am KD - Back in my college days, I dabbled with coding, learned the basics, HTML, CSS etc. but somehow I ended up in Finance which consumed the next 20 years. Then, during covid I picked up coding again, learned react, typescript, etc - even built a rudimentary site - and then came the chatgpt moment, followed by Claude etc. So, as a side project, considering that I had spent 20 years in finance and M&A I started building Ekselio, loveable for finance workflows. Differently from other vibe coding tools, this is local first - meaning the workflows are orchestrated by the LLM based on the file schema but then the execution happens in the browser - the cool thing is that you can see the canvas, the previews of each node, and the code base (SQl) - see the Canvas tab - that said I did include a home tab, which is more of a visual, mainly because people think it's easier to relate to how folks operate, although I know finance and accounting folks usually like the workflow and full transparency - the other thing is that once you create a workflow you can save it and then next month,you can just click Run and it runs it again with no LLM tokes involved - so the infrastructure is minimal. Everything can be exported in an excel data pack with M code in case someone would want to reproduce - think Audit ready. And, I also connected to quickbooks on line so someone can directly pull in and manipulate their financials live - I also connected to Fred which carries literally 800k series in terms of macro economic data - i.e. oil prices, inflation, CPI etc and finally to stocks. I am hoping people find wholes in the architecture or any ideas to make this flow a little bit better. It is in progress so if you run into bugs let me know. Considering that I am using my own API key, I have put a wall in case people overuse it but DM me if you would like to continue using, I can turn off the wall for you - hoping to keep that to a small number of users if I can and will do my best. Thank you again, appreciate you taking the time.
Comments URL: https://news.ycombinator.com/item?id=49849986
Points: 1
# Comments: 0
Revealing the details of how OpenAI agents hacked Hugging Face
Article URL: https://swarmtraces.org/
Comments URL: https://news.ycombinator.com/item?id=49849985
Points: 1
# Comments: 0
FYI: OpenAI "spend limits" aren't always limits
My OpenAI API key got hacked this morning, and the bot started using my key for something in Chinese.
"No worries," I thought, "I have a $30 spend limit setup." When I came back to my desk an hour later, I had $285 in unauthorized charges.
As it turns out, OpenAI will let you create a spend limit _without_ checking "enforce spend limit." If you don't check enforce, it's meaningless. So even though my account showed that I had a $30 spend limit, it still let the hacker blow right past it by hundreds of dollars.
I've submitted a dispute, but wanted to let other people know so it doesn't bite you, too. You can check your spend limits at https://platform.openai.com/settings/organization/limits
Comments URL: https://news.ycombinator.com/item?id=49849976
Points: 1
# Comments: 0
Shipping Code Faster Is Not the Bottleneck
Article URL: https://valentinprugnaud.dev/posts/2026/07/shipping-code-faster-is-not-the-bottleneck
Comments URL: https://news.ycombinator.com/item?id=49849954
Points: 2
# Comments: 0
Jev was built for agents, here's how we're using it in computer use instead
Article URL: https://twitter.com/kylejeong/status/2102108924677927169
Comments URL: https://news.ycombinator.com/item?id=49849950
Points: 3
# Comments: 0
Human homeostasis is more efficient in social proximity
Article URL: https://www.science.org/doi/10.1126/sciadv.aeg4937
Comments URL: https://news.ycombinator.com/item?id=49849946
Points: 2
# Comments: 0
