Feed aggregator

Show HN: I measured my tmux statusbar at 15% of a core and replaced the forks

Hacker News - Thu, 09/24/2026 - 8:18am

tmux status-interval 1 had six #() programs for statusbar, on battery that was 15.4% of a core.

After digging found fork+exec through sh -c is ~14.6 ms and computing the actual segments was 2.6 ms on my device.

Plus had ~1.5k lines of zsh scripts.

Now one deamon process, caches in memory, unix socket and one #() for the whole right side. From 153.77 ms/s → 18.43 ms/s.

Made that into a tmux plugin. You can try it without installing/configuring:

docker run --rm -it lonkarorg/tmux-companion:playground

Comments URL: https://news.ycombinator.com/item?id=49829597

Points: 1

# Comments: 1

Categories: Hacker News

Island Raises $400 Million at $6.4 Billion Valuation

Security Week - Thu, 09/24/2026 - 7:39am

The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. 

The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek.

Categories: SecurityWeek

Update Chrome: 108 security fixes for desktop, new release for Android

Malware Bytes Security - Thu, 09/24/2026 - 7:06am

Over the last few days, Google issued several different Chrome updates.

On September 22, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 154.0.8037.57 for Linux and versions 154.0.8037.57/.58 for Windows and Mac. The update includes 108 security fixes including 11 rated Critical.

It will roll out over the coming days and weeks.

One day later, Google released Chrome 155 for Android, version 155.0.8059.16, to a small percentage of users. It may not be available on Google Play for everyone yet, but keep an eye out for it. Google says it includes stability and performance improvements.

On top of these, Chrome 155 is also available in the Beta channel. The Android release is an Early Stable rollout, meaning Google sends it to a small share of users first, to spot unexpected compatibility or reliability issues before expanding it to everyone. Beta is a separate prerelease version for people who want to try upcoming features roughly four to six weeks before Stable. It is relatively polished but can still contain bugs, so it is best suited to testing rather than everyday use.

How to update Chrome

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

If you don’t want to wait for the rollout to reach you, manually updating is easy. open About Google Chrome from Chrome’s settings or Help menu. Chrome will check for updates. If one is available, click Relaunch to apply it.

Chrome 154.0.8037.58 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

Some of the desktop security fixes deserve a closer look.

Let’s start with CVE-2026-95350, a buffer overflow flaw in ANGLE, Chrome’s graphics-translation layer.

A buffer overflow is a bug in code that allows an attack to happen when a program puts more data into an area of memory than it can hold. Essentially, the attacker writes garbage data that fills up the memory, then writes code that overwrites existing code in adjoining memory, which later gets executed by the vulnerable process.

A crafted webpage could potentially trigger the flaw, which could lead to memory safety bugs, including browser crashes or possible code execution.

Another Critical buffer overflow bug in ANGLE is tracked as CVE-2026-95281. A malicious webpage could potentially reach vulnerable graphics-processing code, so the bug may enable serious impacts such as browser compromise, but Google has not provided exploitation details.

And then there is CVE-2026-95357, an out-of-bounds write in Chrome’s GPU component. This means a program could write data outside its intended area of memory.

The GPU component is the part of Chrome that handles how graphics work with your computer’s graphics processor.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Security Week - Thu, 09/24/2026 - 7:05am

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.

Categories: SecurityWeek

Begin at the End: How to Enable Agentic Remediation

Security Week - Thu, 09/24/2026 - 7:00am

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk.

The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.

Categories: SecurityWeek

An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

Wired Security - Thu, 09/24/2026 - 6:46am
The country’s prime minister expressed disappointment at being informed of the hack only via email. Now Australia is investigating whether OpenAI broke the law.
Categories: Wired Security

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

Security Week - Thu, 09/24/2026 - 6:40am

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek.

Categories: SecurityWeek

Astrana Health Data Breach Impacts Private, Confidential Information

Security Week - Thu, 09/24/2026 - 5:56am

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.

Categories: SecurityWeek

Nick Clegg plays down fears ‘godlike’ AI could exterminate humanity

Guardian Security - Thu, 09/24/2026 - 5:19am

Former deputy PM now involved in tech industry says many within sector are ‘winding themselves up into a lather’

Nick Clegg has dismissed fears over AI’s “godlike power to exterminate humanity”, calling it a sign that tech bosses are “breathing their own fumes”.

The former UK deputy prime minister said that tech bosses should focus on addressing known specific threats such as cybersecurity and bioweapons rather than the “slightly hand-wavy view that this technology is unavoidably going to develop some godlike power which is going to turn on us and exterminate humanity”.

Continue reading...
Categories: The Gaurdian

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

Security Week - Thu, 09/24/2026 - 4:38am

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.

The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

Google’s location data privacy failures draw a €403 million fine

Malware Bytes Security - Thu, 09/24/2026 - 4:31am

The Irish Data Protection Commission (DPC) has fined Google €403 million ($459 million) for violating European privacy law. The penalty follows a six-year inquiry into Google’s management of user location data between May 2018 and February 2020.

During that time, Google collected users’ location data without making clear that it could be used to infer their interests and shape the ads they saw.

Google’s location history keeps track of users’ locations when using their devices. It’s an opt-in service that includes a Timeline feature to display a private map of the places they’ve visited. A separate Android feature, Location Accuracy, helps devices determine their location more accurately than GPS alone.

Google had told users that they could stop Location History tracking by turning off that setting. But a report by the Associated Press in 2018 found that doing so wasn’t enough to stop Google from saving some of that location data. Researchers at Princeton University later confirmed the AP’s findings.

One reason was Web & App Activity, a separate Google account setting that can save information about what Google account holders have been browsing on the web and doing with their apps. That service was also collecting location data. Turning off Location History did not turn off Web & App Activity.

This issue led to payouts in multiple US jurisdictions. Google agreed to pay $85 million to Arizona in October 2022, $392 million to 40 states that November, and $9.5 million to the District of Columbia the following month. It also agreed to pay $39.9 million to Washington State in 2023, $1.38 billion to Texas in May 2025 as part of a two-suit settlement. Last September, a jury awarded $425 million in a separate class action case.

The DPC first looked into the issue in 2018 after the AP investigation and launched an official statutory inquiry in February 2020. Along with the fine, it has ordered Google to bring its location data processing into compliance within six months. The DPC says it will publish the full text of its decision in due course.

Google told Bloomberg that it had revised its practices since 2019 and launched tools to make location data easier to manage. In December 2023, Google announced that it would change its Timeline feature to keep its data on users’ devices. It also said that, for people turning on Location History for the first time, the default period before data is automatically deleted would fall from 18 months to 3 months.

This isn’t the only Google-related investigation that the DPC has launched. It launched one on Google’s processing of EU residents’ data for its AI model two years ago, and another related to the processing of personal data for its online Ad Exchange in 2019.

Check your Google location settings

Turning off Timeline doesn’t stop Google from saving location information through other settings. Check Web & App Activity and, if you see it, Search Services History too.

You can turn these settings off and delete activity already saved to your account.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Pages