Feed aggregator
I built 13 small Apify Actors this month, mostly AI-grounded
Article URL: https://apify.com/rumi7911
Comments URL: https://news.ycombinator.com/item?id=49800300
Points: 1
# Comments: 0
Pushgate
Article URL: https://pushgate.dev/
Comments URL: https://news.ycombinator.com/item?id=49800288
Points: 2
# Comments: 0
What Happened in Austin
Article URL: https://www.freerange.city/p/what-happened-in-austin
Comments URL: https://news.ycombinator.com/item?id=49800284
Points: 1
# Comments: 0
Devin Fusion: the first multi-model coding agent on the Pareto frontier
Article URL: https://twitter.com/ArtificialAnlys/status/2098504939781906684
Comments URL: https://news.ycombinator.com/item?id=49800269
Points: 1
# Comments: 1
What Capital Never Told You About Rent
Article URL: https://www.humansontheloop.com/p/rent
Comments URL: https://news.ycombinator.com/item?id=49800259
Points: 2
# Comments: 0
Show HN: Grading a golf bag from club specs alone, no launch monitor
Article URL: https://app.fitmygolfclubs.com/
Comments URL: https://news.ycombinator.com/item?id=49800252
Points: 2
# Comments: 0
A Summer of AI Optimization
Article URL: https://twitter.com/lemire/status/2102369812806504705
Comments URL: https://news.ycombinator.com/item?id=49800243
Points: 1
# Comments: 0
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.
The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
Malicious B-tree NPM Package Accumulates Millions of Downloads
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
‘Sovereign AI’ is everywhere but rarely defined. It bundles ownership, control, jurisdiction, capability and optionality. The real test for most organisations is, do you know your dependencies, and can you leave if you need to?
The British Medical Association (BMA) has written to MP committees calling for the Capita-run GP pension scheme to be brought in-house
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.”
Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars.
To do that, they need more permissions, account connections, and sensitive data. So, when Meta promised that “Muse is built from the ground up for privacy and security,” we did not expect an AI agent that can easily be manipulated into handing all that access to an attacker.
Meta says Muse can handle appointments, forms, customer-service interactions, purchases, document creation, and connections to services such as WhatsApp, email, calendars, and social platforms. It may also receive macOS permissions to access protected resources, including files, the microphone, camera, location, and calendars.
According to Ars Technica, Wardle found that a locally running application or terminal command could alter an undocumented Muse configuration setting that controls the server used for dictation transcription. By redirecting dictation traffic to an attacker-controlled server, an attacker could capture voice prompts and obtain the authentication token for the victim’s Muse account.
This is not a remote-code-execution vulnerability that can compromise an otherwise clean Mac. The attacker first needs a way to run code locally, such as through malware, a malicious application, or social engineering.
But as we have seen with infostealer malware finding its way onto Macs, that initial access is far from impossible.
Someone’s watching your accounts. Make sure it’s us.Traditional infostealer malware must independently locate browser data, credentials, documents, chat histories, and other valuable material. A compromised AI agent could lower that barrier by bundling access to multiple services and operating-system permissions behind one already authenticated interface.
Ultimately, this is not just about one unsafe configuration setting. It shows why AI agents need a higher security standard than ordinary apps.
How to stay safeWardle’s advice about Muse is simple: “Please don’t install.”
The same caution should apply to other AI agents.
The Open Worldwide Application Security Project (OWASP), a nonprofit foundation that provides free application-security guidance, lists prompt injection, tool abuse, privilege escalation, data exfiltration, excessive autonomy, memory poisoning, and sensitive-data exposure among the major security risks posed by AI agents.
A useful rule is that an AI agent should not have more access than it needs, and it should not be able to turn untrusted instructions into sensitive actions without meaningful checks. In practice, this means:
- Avoid giving a new agent broad access to email, chat apps, calendars, cloud storage, payment methods, and device permissions all at once.
- Regularly review and remove connections the agent does not genuinely need.
- Be aware of prompt injection. Do not assume that an AI agent will recognize malicious instructions embedded in a webpage, document, email, or other external content.
- Watch for unusual agent behavior, such as unexpected requests for new permissions, account reauthentication, external file sharing, or actions you did not initiate.
You should also protect your device against malware:
- Keep your software updated so attackers can’t use known vulnerabilities against you.
- Use an up-to-date, real-time anti-malware solution on all your devices.
- To protect against ClickFix attacks, don’t follow instructions you find on websites and in unsolicited messages that tell you to run commands.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Saudi Arabia wants a car industry, launches Ceer with two EVs
Article URL: https://arstechnica.com/cars/2026/09/saudi-arabia-wants-a-car-industry-launches-ceer-with-two-evs/
Comments URL: https://news.ycombinator.com/item?id=49798754
Points: 1
# Comments: 0
Six ways to integrate Jev into your application
Article URL: https://vercel.com/i/jev-integrations
Comments URL: https://news.ycombinator.com/item?id=49798738
Points: 1
# Comments: 0
TypeSafe AI Jev vs. GPT-6 Astra
Article URL: https://vercel.com/i/jev-vs-gpt-6-astra
Comments URL: https://news.ycombinator.com/item?id=49798734
Points: 1
# Comments: 0
Mudita Kompakt
Article URL: https://www.mudita.com/products/phones/mudita-kompakt/
Comments URL: https://news.ycombinator.com/item?id=49798725
Points: 1
# Comments: 0
