Hacker & Security News
banner
hacker.at.thenote.app
Hacker & Security News
@hacker.at.thenote.app
#hacker and #security news from Hacker News, LifeHacker, Security Boulevard and others.
Our other projects: #macos, #ios and #android apps for notes TheNote.app
Pinned
We launched a Public Feed on Bluesky with #Hacker and #Security #News from sources like Hacker News, LifeHacker, Security Boulevard and others your convenience 🚀 🤗
bsky.app/profile/hack...
Claim up to $95 today from Apple’s Siri AI settlement – here’s how

Got an iPhone 15 Pro, Pro Max, or 16? Apple is doling out $250 million – here’s how to qualify and file a claim to get your cut.
#apple #hackernews #news
Claim up to $95 today from Apple’s Siri AI settlement – here’s how
Got an iPhone 15 Pro, Pro Max, or 16? Apple is doling out $250 million – here’s how to qualify and file a claim to get your cut.
www.zdnet.com
September 22, 2026 at 4:03 PM
How I Turned a 404 Error Into a Zero-Dependency Game to Save a Domain Migration

How we turned a 404 error page into a zero-dependency JavaScript browser game to rescue lost traffic during a risky domain migration. Read the case study.
#hackernews #news
How I Turned a 404 Error Into a Zero-Dependency Game to Save a Domain Migration
How we turned a 404 error page into a zero-dependency JavaScript browser game to rescue lost traffic during a risky domain migration. Read the case study.
hackernoon.com
September 22, 2026 at 3:43 PM
Can Shiba Inu Reach $1 in 2026? The Math Behind the SHIB Dream

Shiba Inu's $1 dream faces a mathematical reality check as SHIB's huge circulating supply would require an extraordinary $589 trillion market valuation in 2026.
#hackernews #news
Can Shiba Inu Reach $1 in 2026? The Math Behind the SHIB Dream
Shiba Inu's $1 dream faces a mathematical reality check as SHIB's huge circulating supply would require an extraordinary $589 trillion market valuation in 2026.
hackread.com
September 22, 2026 at 3:22 PM
Google fined €403 million over location data privacy violations

Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
#hackernews #news
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
www.bleepingcomputer.com
September 22, 2026 at 3:02 PM
Meet SODAX: HackerNoon Company of the Week

Meet SODAX, HackerNoon’s Company of the Week, connecting blockchain liquidity, plus featured projects SpyderBot, TOON Converter, and Advanced Process Manager.
#hackernews #news
Meet SODAX: HackerNoon Company of the Week
Meet SODAX, HackerNoon’s Company of the Week, connecting blockchain liquidity, plus featured projects SpyderBot, TOON Converter, and Advanced Process Manager.
hackernoon.com
September 22, 2026 at 2:41 PM
Your Health Checks Are Verifying the Wrong Thing

Four production faults passed every health check. An engineer explains how shallow validation hid incorrect metrics, stale data, and exposed credentials.
#hackernews #news
Your Health Checks Are Verifying the Wrong Thing
Four production faults passed every health check. An engineer explains how shallow validation hid incorrect metrics, stale data, and exposed credentials.
hackernoon.com
September 22, 2026 at 2:31 PM
101 Real-World Examples of How to Use Jev

101 real, linked projects built on Jev, TypeSafe AI's System One model — routers, guardrails, browser agents, SQL extensions — and what each one replaced.
#hackernews #news
101 Real-World Examples of How to Use Jev
101 real, linked projects built on Jev, TypeSafe AI's System One model — routers, guardrails, browser agents, SQL extensions — and what each one replaced.
hackernoon.com
September 22, 2026 at 2:11 PM
Why 2-Bit LLM Quantization Fails at the Hardware Boundary

The jump to 2-bit LLM quantization isn't just about smaller integers. Explore the hardware-software boundary and why extreme compression requires co-design
#hackernews #llm #news
Why 2-Bit LLM Quantization Fails at the Hardware Boundary
The jump to 2-bit LLM quantization isn't just about smaller integers. Explore the hardware-software boundary and why extreme compression requires co-design
hackernoon.com
September 22, 2026 at 1:50 PM
Microsoft fixes broken Excel copy and paste for all Office users

Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]
#hackernews #microsoft #news
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]
www.bleepingcomputer.com
September 22, 2026 at 1:29 PM
How Enterprises Evaluate Risk Software in 2026: a Criteria-led Guide

Discover the eight criteria organizations use to evaluate risk software. Learn what good solutions look like and essential questions to ask during procurement.
#hackernews #news
How Enterprises Evaluate Risk Software in 2026: a Criteria-led Guide
Discover the eight criteria organizations use to evaluate risk software. Learn what good solutions look like and essential questions to ask during procurement.
hackernoon.com
September 22, 2026 at 1:09 PM
Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows…
#hackernews #news
Reverse-Engineering Flock Cameras
Hackers captured a Flock camera and got a look (alternate link) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...
www.schneier.com
September 22, 2026 at 12:48 PM
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.

The trouble keeps showing up inside things people already trust: code that take…
#hackernews #news
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
thehackernews.com
September 22, 2026 at 12:28 PM
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.

The backdoor "…
#hackernews #news
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
thehackernews.com
September 22, 2026 at 12:07 PM
FBI's CJIS v6.1: What Security Teams Need to Know.

The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can a…
#hackernews #news
FBI's CJIS v6.1: What Security Teams Need to Know.
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]
www.bleepingcomputer.com
September 22, 2026 at 11:57 AM
The TechBeat: The ‘Backrooms’ Problem of Using AI to Write (9/21/2026)

9/21/2026: Trending stories on Hackernoon today!
#hackernews #news
The TechBeat: The ‘Backrooms’ Problem of Using AI to Write (9/21/2026)
9/21/2026: Trending stories on Hackernoon today!
hackernoon.com
September 22, 2026 at 11:45 AM
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edit…
#hackernews #news
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, takes screenshots, and runs whatever command its operators send. Akshay Gaikwad and Aaron Beardslee of Securonix Threat Research built their analysis from one infected machine, so Securonix cannot say how many organizations are …
www.helpnetsecurity.com
September 22, 2026 at 11:34 AM
ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreadi…
#hackernews #news
ChainScript: the RAT that hides its command server inside a blockchain contract
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]
securityaffairs.com
September 22, 2026 at 11:24 AM
How We Built an LLM Review Pipeline and Why 91.67% Accuracy Wasn’t Enough

How we built a nightly LLM review pipeline across 14 companies—and learned why 91.67% accuracy still couldn’t explain a sudden market signal.
#hackernews #llm #news
How We Built an LLM Review Pipeline and Why 91.67% Accuracy Wasn’t Enough
How we built a nightly LLM review pipeline across 14 companies—and learned why 91.67% accuracy still couldn’t explain a sudden market signal.
hackernoon.com
September 22, 2026 at 11:14 AM
Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]
#hackernews #microsoft #news
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]
www.bleepingcomputer.com
September 22, 2026 at 11:03 AM
Fastly gives enterprises real-time control over AI models and agents

Fastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control across their AI systems. Expanding the Fastly for AI portfo…
#hackernews #news
Fastly gives enterprises real-time control over AI models and agents
Fastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control across their AI systems. Expanding the Fastly for AI portfolio, these new capabilities help organizations govern AI model access and usage, protect the AI applications powering their business, and control how AI agents access enterprise APIs, all on the same Fastly platform already delivering the speed, security, and resiliency businesses depend on at global …
www.helpnetsecurity.com
September 22, 2026 at 10:44 AM
Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
#hackernews #news
Clop gets a taste of its own medicine after ShinyHunters hijack leak site
Rival crew demands eight figures and threatens to expose companies that paid to keep quiet
www.theregister.com
September 22, 2026 at 10:23 AM
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America

FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.
#hackernews #news
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.
hackread.com
September 22, 2026 at 10:03 AM
North Korea’s job interview scam runs both ways

Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warnin…
#hackernews #news
North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project’s crates.io team and security response working group, and described a recurring pattern: a target is invited to a video call framed as a job, contract, or collaboration opportunity, then nudged into installing something or running an …
www.helpnetsecurity.com
September 22, 2026 at 9:42 AM
Google hit with €403 million GDPR fine over location tracking

Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six mont…
#hackernews #news
Google hit with €403 million GDPR fine over location tracking
Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from May 25, 2018, to February 4, 2020. The DPC launched it on its own initiative in February 2020 after receiving complaints from several European consumer-rights organizations, including the European Consumer Organisation (BEUC). The regulator found GDPR …
www.helpnetsecurity.com
September 22, 2026 at 9:22 AM
The AI models that cheat the most, according to new CAIS benchmark

We know models cheat. A new benchmark measures how much, and on what tasks.
#hackernews #news
The AI models that cheat the most, according to new CAIS benchmark
We know models cheat. A new benchmark measures how much, and on what tasks.
www.zdnet.com
September 22, 2026 at 9:01 AM