Feed aggregator

Step 3.7 Flash

Hacker News - Fri, 05/29/2026 - 8:51am
Categories: Hacker News

Local Git Remotes

Hacker News - Fri, 05/29/2026 - 8:45am
Categories: Hacker News

Signal users targeted in backup-stealing phishing attacks

Malware Bytes Security - Fri, 05/29/2026 - 8:07am

A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. 

The attack is initiated by a text message pretending to come from Signal Support.

“Action Required: Data Recovery Needed
Your Signal account data (message and media) Is at risk of permanent loss due to a sync issue.
To avoid losing your messages and media:
1. Go to Settings -> Backups -> Configure -> Enable backups -> View Recovery Key.
2. Copy the recovery key to your clipboard.
3. Paste the key into this chat.
This links your existing backup to your account. Failure to do this may result in losing access to your account and all stored data.”

There are a few red flags in this message:

  • The “Name not verified” label under the sender
  • Repeated threats of losing all your data
  • Pasting the key into the chat. Signal Support would never ask for your recovery key
Scam or legit? Scam Guard knows.

TRY IT NOW

The attack exploits Signal’s Secure Backups feature, which allows users to store encrypted archives of their conversations on Signal’s servers. These backups are protected by a 64-character recovery key.

That key should never leave the user’s device and is never shared with Signal’s servers. If hackers obtain this key and gain control of a victim’s account, they can download and decrypt the entire message history.

For an attacker, that’s even better than hijacking an account, which would only give them access to future messages.

For now, the attacks appear to be targeted. We have seen reports from journalists, reports of attacks on Chinese activists, and warnings from a researcher who investigates cyberattacks against journalists, dissidents, and human rights activists. But now that other cybercriminals are aware of this opportunity, the tactic could spread rapidly.

How to stay safe

Signal explicitly states that it will never reach out to users first and will never request registration codes, PINs, or recovery keys. 

  • Treat unsolicited messages from “Support” as suspicious by default. Legitimate support for apps like Signal and WhatsApp do not ask you, in a chat message, to send back verification codes, PINs, or passwords.​ If you receive a warning about account problems, do not follow links in the message. Open the app’s settings directly or visit the official website through other means.
  • Never share any secret codes, multi-factor authentication keys, or app PINs. SMS codes are there to prove that you control a phone number. Anyone who has the code can pretend to be you. App‑specific PINs or passcodes are there to protect account changes. Consider anyone asking for them to be a scammer.
  • Use the extra security features these apps offer. Enable options like registration lock, registration PIN and device‑change alerts so that your account cannot be silently re‑registered without an extra secret. Store your PIN in a password manager instead of choosing something easy to guess or reusing a code. This reduces the risk of social engineering or shoulder‑surfing.
  • Another useful feature is disappearing messagesShort‑timer and disappearing messages reduce how much content is available if an attacker gains access to a chat later, or obtains long‑term access to a device or backup. They are not a complete solution, but they can limit the damage.
  • Use Malwarebytes Scam Guard on your device or online to check messages. Malwarebytes Scam Guard identified this message as a phishing attempt and provided further information about how to proceed.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

After 10 Years, Overwatch Has Changed Me Almost as Much as Itself

CNET Feed - Fri, 05/29/2026 - 8:01am
Commentary: A decade after launch, Overwatch has grown into something with a little bit less sparkle, but a lot more reward and engagement.
Categories: CNET

CISA Adds One Known Exploited Vulnerability to Catalog

US-Cert Current Activity - Fri, 05/29/2026 - 8:00am

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

  • CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise.

Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.

Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria

Categories: US-CERT Feed

Show HN: Reduce Claude Code token usage ~50% with Headroom

Hacker News - Fri, 05/29/2026 - 7:59am

Hi HN!

For the past few months I've been building a Mac Menu Bar app that reduces your claude code token usage costs by ~50%.

This unlocks about 2x more usage within your same Claude Code plan.

Users seem to like it so far.

60 DAUs who together have saved 10.5B tokens so far, representing about $35k in savings.

I'd love for the community to try it out and get your feedback. It's admittedly still a bit rough around the edges so any bug reports are more than welcome too!

Comments URL: https://news.ycombinator.com/item?id=48322017

Points: 1

# Comments: 0

Categories: Hacker News

Windows Registry Utility Library

Hacker News - Fri, 05/29/2026 - 7:57am

Article URL: https://github.com/tidev/winreglib

Comments URL: https://news.ycombinator.com/item?id=48322004

Points: 1

# Comments: 0

Categories: Hacker News

Pages