Iran launched missiles at Israel in first such attack since April ceasefire
Tehran had warned of retaliation after Israel on Sunday struck Beirut’s southern suburbs without warning, in defiance of Washington’s request days ago to stand down. ⌘ Read more
Israel says Iran launched missiles at it in first such attack since April ceasefire
Tehran had warned of retaliation after Israel on Sunday struck Beirut’s southern suburbs in defiance of Washington’s request days ago to stand down ⌘ Read more
Tributes for ‘adored’ spearfisher killed in WA shark attack
The man killed in a suspected shark attack off Western Australia’s south coast has been identified as 35-year-old Daniel Turpin. ⌘ Read more
Ruby’s Bundler adds a cooldown feature
Version\
4.0.13 of Ruby’s Bundler
package-manager has added\
dependency cooldowns in order to help mitigate the effect of
supply-chain attacks:
Most supply-chain attacks against RubyGems exploit a narrow window:
an account is compromised, a malicious version ships, and any
bundle installin the minutes that follow resolves
str … ⌘ Read more
New IronWorm Malware Hits 36 Packages In npm Supply-Chain Attack
A new npm supply-chain attack has infected 36 packages with Rust-based infostealer malware called IronWorm. According to BleepingComputer, the malware “targets 86 environment variables (key-value pairs) and 20 credential files that may contain OpenAI, AWS, Anthropic, and npm credentials, vault configuration files, SSH keys, and Exodus cryptocurrenc … ⌘ Read more
Quentin Tarantino Calls Hollywood a ‘Flavorless Sausage Factory,’ Praises 1 Movie
Quentin Tarantino just torched modern Hollywood, but one recent movie earned his rare stamp of approval. The legendary director shared his unfiltered thoughts on the current state of filmmaking. Further, he revealed the single film that actually impressed him. Quentin Tarantino blasts modern Hollywood Quentin Tarantino has harshly criticized the current state of Hollywood in […]
Th … ⌘ Read more
Android Gets Fake Call Detection That Uses RCS
An anonymous reader quotes a report from 9to5Google: Phone by Google wants to combat the “growing threat of impersonation scams” and protect Android users against “sophisticated, AI-powered deepfake attacks” with fake call detection. […] Fake call detection requires that both parties are on Android and use the Phone by Google app, while Google Messages and Google Contacts also … ⌘ Read more
Archive 81’s Nick Pasqual Gets 32 Years to Life Sentence for Stabbing Ex-Girlfriend
Nick Pasqual, known for appearances in Archive 81 and How I Met Your Mother, has been sentenced to 32 years to life in prison in connection with the 2024 stabbing of Hollywood makeup artist Allie Shehorn. Shehorn survived the attack after being stabbed multiple times. Nick Pasqual gets life sentence for stabbing ex-girlfriend more than […]
The post [Archive 81’s Nick Pasqual Gets 32 Years … ⌘ Read more
Linux 7.2 Proceeding To Deprecate AF_ALG Due To “Massive Attack Surface”, Drops Offloading
The Linux kernel’s AF_ALG interface for user-space applications to directly access the Linux kernel’s built-in cryptographic engine is proceeding with a quick deprecation cycle due to a “massive attack surface” with increased vulnerabilities coming to light due to AI/LLM-based tooling… ⌘ Read more
Leo’s first encyclical attacks technological messianism
Article URL: https://www.economist.com/europe/2026/05/28/leos-first-encyclical-attacks-technological-messianism
Comments URL: https://news.ycombinator.com/item?id=48334710
Points: 8
# Comments: 1 ⌘ Read more
The GOP’s Attacks on James Talarico Are Straight Out of the Incel Handbook
Claims about low testosterone and false accusations of veganism might play well to the online far-right, but will they win an election? ⌘ Read more
Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks
Customer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams. ⌘ Read more
Greens attack Government over claimed $1.4b carbon auction shortfall
The Green Party says a string of failed carbon auctions has left a $1.4 billion fiscal hole because the Government was banking on the revenue they would generate.
Of 10 carbon auctions held between December 2023 and March this year, only auctions in March and December 2024 actually cleared. ⌘ Read more
The AI Era Is Creating a Bug Hunting Arms Race
As attackers ramp up their AI exploit development, the search for software vulnerabilities is changing rapidly. ⌘ Read more
Trump says he is in no rush for an Iran deal that is far from finished
By Summer Said, Anat Peled and Alexander Ward
President Trump said Sunday he was in no hurry to complete an end-of-war agreement with Iran after spending weeks insisting Tehran had to quickly make nuclear concessions or face renewed attacks. ⌘ Read more
FBI director’s Based Apparel site has been spotted hosting a ‘ClickFix’ attack
Article URL: https://www.pcmag.com/news/kash-patels-apparel-site-is-trying-to-trick-visitors-into-installing-malware
Comments URL: https://news.ycombinator.com/item?id=48243293
Points: 16
# Comments: 4 ⌘ Read more
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations. ⌘ Read more
GitHub’s Internal Repos Breached Via Employee’s Use of Malicious VS Code Extension
Longtime Slashdot reader Himmy32 writes: GitHub has announced on X that their internal repositories have been breached through a compromised VS Code Extension on an employee’s workstation. Bleeping Computer reported that the attack is linked to TeamPCP who have been in the news for a recent campaign affecting Checkm … ⌘ Read more
Microsoft Exchange Server Vulnerability Actively Exploited, in a Bad Week for Microsoft
Forbes describes it as “definitely already out there, and under active exploitation according to the U.S. Cybersecurity and Infrastructure Security Agency, urging all organizations to prioritize timely remediation as the attack vector poses a significant risk.”
“We have issued CVE-2026-42897 to address … ⌘ Read more
Pieck Finger (XTER) [Attack on Titan] ⌘ Read more
California Law Limits ‘Recyling’ Logo in New Attack on Plastic Waste
“Most of the plastic waste in California is about to lose the recycling symbol,” writes the Washington Post’s “climate coach.”
The “chasing arrows” symbol, created in 1970 by a college student inspired by the burgeoning environmental movement, has been stamped indiscriminately on plastic bottles, clamshell takeout containers, chip bags and … ⌘ Read more
Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording
Plus: Instructure’s Canvas ransomware debacle comes to a close, an alleged dark net market kingpin gets arrested, OpenAI workers fall victim to a supply chain attack, and more. ⌘ Read more
Ukraine verstärkt Angriffe auf Ölsektor
Im Kampf gegen die russischen Invasoren hat die Ukraine seine Angriffe auf Russlands Ölsektor heuer stark ausgeweitet. Am Freitag meldete die ukrainische Armee eine Attacke auf die drittgrößte Raffinerie Russlands in der Stadt Rjasan. In Kiew wurden nach der jüngsten russischen Angriffswelle – einer der schwersten seit Kriegsbeginn – die Flaggen auf halbmast gesetzt. Beim Einschlag einer russischen Rakete in einen Wohnblock waren 24 Menschen getötet worden. ⌘ Read more
Mystery Microsoft Bug Leaker Keeps the Zero-Days Coming
An anonymous researcher known as Nightmare-Eclipse, who has already leaked several Windows zero-days this year, has disclosed two more: YellowKey and GreenPlasma. The Register reports: Nightmare-Eclipse described YellowKey as “one of the most insane discoveries I ever found.” They provided the files, which have to be loaded onto a USB drive, and if the attacker co … ⌘ Read more
Your iPhone Gets Stolen. Then the Hacking Begins
A bustling underground ecosystem is providing criminals with the tools to unlock iPhones—and wage phishing attacks against their contacts to access bank accounts and more. ⌘ Read more
Sam Altman Testifies That Elon Musk Wanted Control of OpenAI
OpenAI CEO Sam Altman took the stand Tuesday in Elon Musk’s trial against the company, testifying that Musk repeatedly sought control of OpenAI before leaving in 2018. Altman said he opposed putting AI “under the control of any one person,” while Musk’s lawyer used a pointed cross-examination to attack Altman’s trustworthiness. An anonymous reader shares … ⌘ Read more
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
Famous for helping build Apple’s iPhones, Foxconn just suffered another cyberattack, highlighting the perils of warehousing some of the world’s most valuable data. ⌘ Read more
The Canvas Hack Is a New Kind of Ransomware Debacle
Wired describes the recent Canvas breach as an unusually disruptive ransomware-style extortion incident because one attack on Instructure’s learning platform temporarily paralyzed thousands of schools during finals and end-of-year assignments. The hackers using the “ShinyHunters” name claim more than 8,800 schools were affected, while Instructure says exposed data included … ⌘ Read more
卡巴斯基披露,上古软件 DAEMON Tools 爆大规模供应链攻击
DAEMON Tools 是一款有20多年历史的著名虚拟光盘工具,它可以把镜像文件虚拟成一张真实的光盘,广泛应用在上世纪的 Windows 电脑中。是的,它还活着。 感谢肯尼同学的提醒。 卡巴斯基近日披露:我们的专家发现了通过 DAEMON Tools 进行的大规模供应链攻击。攻击者设法将恶意代码注 ⌘ Read more
US Government Warns of Severe CopyFail Bug Affecting Major Versions of Linux
An anonymous reader quotes a report from TechCrunch: A severe security vulnerability affecting almost every version of the Linux operating system has caught defenders off-guard and scrambling to patch after security researchers publicly released exploit code that allows attackers to take complete control of vulnerable sys … ⌘ Read more
Hackers Are Actively Exploiting a Bug In cPanel, Used By Millions of Websites
Hackers are actively exploiting a critical cPanel and WHM vulnerability, tracked as CVE-2026-41940, that allows remote attackers to bypass the login screen and gain full administrative access to affected web servers. Major hosts including Namecheap, HostGator, and KnownHost have taken mitigation steps or patched systems, bu … ⌘ Read more
New Linux ‘Copy Fail’ Vulnerability Enables Root Access On Major Distros
A newly disclosed Linux kernel flaw dubbed “Copy Fail” can let a local, unprivileged attacker gain root access on major Linux distributions, with researchers claiming the bug affects kernels shipped since 2017. “The POC exploit works out of the box today, but a future version that can escape from containers like Docker is promised soon … ⌘ Read more
OpenAI Rolls Out ‘Advanced’ Security Mode for At-Risk Accounts
OpenAI is rolling out Advanced Account Security for people concerned that their ChatGPT or Codex accounts could be potential targets of phishing attacks. ⌘ Read more
Elon Musk Testifies That He Started OpenAI to Prevent a ‘Terminator Outcome’
The judge also warned Musk and Sam Altman to curb their “propensity to use social media to make things worse outside the courtroom” after both sides traded attacks online. ⌘ Read more
Here’s How Much San Francisco Tech Companies Pay for Police Protection
A recent attack on Sam Altman’s home and OpenAI offices has put corporate security under renewed scrutiny. Records reveal how much some tech firms spend to arm up. ⌘ Read more
Google Studies Prompt Injection Attacks Against AI Agents Browsing the Web
Are AI agents already facing Indirect Prompt Injection attacks? Google’s Threat Intelligence teams searched for known attacks that would target AI systems browsing the web, using Common Crawl’s repository of billions of pages from the public web).
We observed a number of websites that attempt to vandalize the machine of anyone … ⌘ Read more
‘STAGED’: Conspiracy Theories Are Everywhere Following White House Correspondents’ Dinner Shooting
The word “staged” exploded on social media following the attack, as both right and left-wing influencers and anonymous accounts spread unfounded conspiracy theories. ⌘ Read more
Bitwarden CLI Is the Next Compromise In Checkmarx Supply Chain Campaign
Longtime Slashdot reader Himmy32 writes: Socket Security published an article on the compromise of the Bitwarden CLI client, which was pushed from Bitwarden’s client repository. This breach was the next in a chain of supply-chain attacks that have affected Checkmarx KICS and Aqua Security’s Trivy scanners.
The breach was quickly dete … ⌘ Read more
又是 npm 包投毒,密码管理器 Bitwarden CLI 中招(放心:本体安全)
密码管理器 Bitwarden 本体没有问题,命令行工具 @bitwarden/cli@bitwarden/cli 版本中招。如果你和你的 AI 不曾使用 CLI,就可以不管它。@Appinn 发生了什么? 来自 socket.dev 的消息:攻击者入侵了 Bitwarden 的发布流程(CI/CD),把一个 ⌘ Read more
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
Researchers have finally cracked Fast16, mysterious code capable of silently tampering with calculation and simulation software. It was created in 2005—and likely deployed by the US or an ally. ⌘ Read more
[$] Dependency-cooldown discussions warm up
Efforts to introduce malicious code into the open-source supply
chain have been on the rise in recent years, and there is no indication that they
will abate anytime soon. These attacks are often found quickly, but not quickly
enough to prevent the compromised code from being automatically injected into other
projects or code deployed by users where it can wreak havoc. One method of avoiding
supply-chain attacks is to add a delay of a few days before pulling upates in what
is known as a “dep … ⌘ Read more
Florida Launches Criminal Investigation Into ChatGPT Over School Shooting
Florida’s attorney general has launched a criminal investigation into OpenAI over allegations that the accused gunman in a shooting at Florida State University last year used ChatGPT to help plan the attack. OpenAI says the chatbot is “not responsible for this terrible crime” and only provided factual information available from p … ⌘ Read more
Cal.com Is Going Closed Source Because of AI
Cal is moving its flagship scheduling software from open source to a proprietary license, arguing that AI coding tools now make it much easier for attackers to scan public codebases for vulnerabilities. “Open source security always relied on people to find and fix any problems,” said Peer Richelsen, co-founder of Cal. “Now AI attackers are flaunting that transparency.” CEO Bailey Pumflee … ⌘ Read more
CPUID Site Hijacked To Serve Malware Instead of HWMonitor Downloads
Attackers briefly hijacked part of CPUID’s backend and swapped legitimate download links on its site with malware-laced ones. “The issue hit tools like HWMonitor and CPU-Z, with users on Reddit and elsewhere starting to notice something wasn’t right when installers tripped antivirus alerts or showed up under odd names,” reports The Register. F … ⌘ Read more
[$] LWN.net Weekly Edition for April 9, 2026
Inside this week’s LWN.net Weekly Edition:
Front: TPM attacks; arithmetic overflow protection; Ubuntu GRUB changes; kernel IPC proposals; fre:ac; Scuttlebutt.
Briefs: Nix vulnerability; OpenSSH 10.3; Sashiko reviews; FreeBSD testing; Gentoo GNU/Hurd; SFC on router ban; Quotes; …
Announcements: Newsletters, conferences, security updates, patches, and more. ⌘ Read more
Avoiding supply chain attacks in Go
1 points posted by Elton Minetto ⌘ Read more
Top NPM Maintainers Targeted with AI Deepfakes in Massive Supply-Chain Attack, Axios Briefly Compromised
“Hackers briefly turned a widely trusted developer tool into a vehicle for credential-stealing malware that could give attackers ongoing access to infected systems,” the news site Axios.com reported Tuesday, citing security researchers at Google.
The compromised package … ⌘ Read more
@movq@www.uninformativ.de Yeah. Unfortunately. :-( I tried to bring up the subject of dependency upgrade reviews a few times, but nobody else cared. We finally experienced a supply chain attack (luckily, didn’t turn out too horrible for us, could have been worse) and this got the discussion slowly rolling again. So, publication of this article is perfect timing. Let’s see. Admittedly, I don’t have high hopes. And I bet someone suggests to use AI agents…
@lyse@lyse.isobeef.org Indeed. Very unpopular, though. I’ve long given up that fight at work.
In reality, there are too few real incidents. It doesn’t hurt enough. It’s always: “Something could happen!” But we’ve never been hit big time by an attack like this … so I just look like a paranoid idiot.
MacOS 26.4 Adds Warnings For ClickFix Attacks to Its Terminal App
An anonymous Slashdot reader writes: ClickFix attacks are ramping up. These attacks have users copy and paste a string to something that can execute a command line — like the Windows Run dialog, or a shell prompt.
But MacRumors reports that macOS 26.4 Tahoe (updated earlier this week) introduces a new feature to its Terminal app where it will … ⌘ Read more