Feed aggregator
Why Aren't There More IMAX 70mm Screens for 'The Odyssey'?
Article URL: https://variety.com/2026/film/news/why-no-more-imax-70mm-screens-the-odyssey-christopher-nolan-1236813019/
Comments URL: https://news.ycombinator.com/item?id=48991505
Points: 1
# Comments: 0
The little type that could too much
Article URL: https://raphael-proust.gitlab.io/code/the-little-type-that-could-too-much.html
Comments URL: https://news.ycombinator.com/item?id=48991501
Points: 1
# Comments: 0
Plain Language Guide Series
Article URL: https://digital.gov/guides/plain-language
Comments URL: https://news.ycombinator.com/item?id=48991499
Points: 1
# Comments: 1
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville
The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.
New ClickLock Stealer locks your Mac until you hand over your password
ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets, and then leave behind a persistent backdoor.
The malware was discovered by Group-IB researchers. They named it after the ClickFix distribution technique and its ability to lock a victim’s Mac if they don’t follow its instructions by killing all visible processes.
The researchers found a malicious shell script typically used to trick users into infecting their own device and followed the trail from there. The script first displays a fake Cloudflare progress bar, suggesting it was intended to be used as part of a fake browser verification flow.
Victims land on a phishing page that mimics Cloudflare verification or another fake system utility, similar to those used in the Infiniti Stealer campaign, and later ClickFix attacks impersonating Claude or cleanup utilities.
The page instructs the user to open Terminal, paste a command, and press Return, presenting it as a required “human verification” step or a quick fix.
The researchers explain:
“the malware orchestrates further modules that search the system for various data including browser credentials, password manager data, crypto wallet extensions, desktop wallet files, etc. and even employs a GSocket backdoor.”
This all happens while the user is distracted by fake Cloudflare images.
A GSocket backdoor abuses GSocket (short for Global Socket), an open-source networking toolkit. While designed for legitimate remote administration and penetration testing, attackers can weaponize it to establish stealthy, persistent, encrypted remote access to compromised systems.
Forcing victims to hand over their passwordWhat really stands out is the way the malware forces the user to provide their macOS system’s password.
First, it displays a convincing fake macOS password prompt using the victim’s real username and a downloaded Apple icon. If the user enters their password, it is sent, along with all the previously stolen data, to a Telegram channel controlled by the attackers.
If the user refuses, the malware triggers a loop that shuts down key processes, including Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, and all major web browsers. It leaves only a password dialog on the screen until the victim complies.
This “kill loop” runs every 210 milliseconds for up to 83 hours, or until the user enters the correct password. The result is a system that’s essentially unusable, with the password prompt becoming the only interactive element.
Once the stolen data has been sent to the Telegram channel, the malware starts deleting its own modules. However, unlike the infostealer modules, the GSocket backdoor remains installed, giving the attacker ongoing remote access to the system.
That means attackers can return later, even after the stealer components have self‑deleted, to install new malware, steal more data, or move through a corporate network using VPNs or SSH access already available on the compromised Mac.
How to stay safeUsers running macOS Tahoe 26.4 and later will see warnings about possible ClickFix attacks, but everyone should remain cautious.
With ClickFix running rampant and inventing new methods all the time, it’s important to stay aware, think twice before following unexpected instructions, and keep your devices protected.
- Slow down. Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy and paste code. Attackers rely on urgency to bypass your critical thinking.
- Avoid running commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand what the action does.
- Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
- Limit copy and paste for commands. Manually typing commands instead of copy and paste can reduce the risk of unknowingly running malicious payloads hidden in copied text.
- Secure your devices. Use an up-to-date, real-time anti-malware solution with web protection. Malwarebytes blocks connections to unsafe sites like these.
- Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected places helps maintain vigilance. Keep reading our blog!
- Stay away from sponsored ads in search results. Anyone can buy them and make them look legitimate.
Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
Don’t trust that “FBI agent” in your DMs
The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already been victims of cybercrime.
The FBI has issued warnings like this before, but scammers posing as IC3 employees and FBI agents continue to evolve their schemes and claim new victims.
The best-known of these scams are recovery scams, complete with FBI logos and branding that make them look far more convincing.
Facebook accounts like the one below—and yes, I reported it—with equally fake reviews prey on people who have already fallen victim to a scammer.
“Have You Been Scammed or Defrauded? We’re Here to Help.
If you’ve fallen victim to online fraud, investment scams, crypto scams, romance scams, or unauthorized transactions, Reliable Scam Recovery Inc is ready to assist you in pursuing the recovery of your lost funds.
Our experienced recovery team works with victims to investigate scam activities, trace transactions, and provide guidance throughout the recovery process with confidentiality and professionalism.
Professional case assessment
Secure and confidential support
Dedicated recovery assistance
Fast response team
Don’t let scammers win. Take the first step toward reclaiming your losses today.
Contact Ic3 Scam Recovery Inc now for support and recovery assistance.”
The scammers count on victims feeling desperate and embarrassed. They have no scruples about victimizing them all over again.
The post contains a lot of the tell-tale signs IC3 warns about. Very vague but reassuring claims: “experienced recovery team,” “professional case assessment,” “secure and confidential support” all sound impressive but provide no verifiable detail. High‑level promises like “investigate scam activities” and “trace transactions” imply special legal or technical powers, but the FBI warns that scammers make similar promises to convince victims they’re dealing with authorized investigators.
Besides setting up fake IC3 accounts, they also monitor social media for posts from victims saying they’ve reported a scam to the FBI, then swoop in posing as FBI follow‑up contacts.
If victims remain unconvinced, the scammers may create videos depicting senior FBI officials or other recognizable public figures urging them to submit their case through a specific link “to speed up recovery.” The FBI says criminals are increasingly using AI-generated deepfake audio and video to make these messages appear genuine.
How to stay safeFirst and foremost, remember that IC3 has no official social media presence, does not investigate crimes via social media, and will never contact victims directly to recover funds.
As the IC3 homepage states:
“The IC3 does not work with any non-law enforcement entity, such as law firms or crypto services, to recuperate lost funds or investigate cases. The IC3 will never directly contact you for information or money.”
So, if an “agent” appears in your direct messages (DMs) right after you post publicly about being a crime victim or planning to report to the FBI, assume they are a scammer until independently verified. A few other tips:
- Never pay upfront: Legitimate government agencies never ask you for advance payment to recover stolen money.
- Ignore unsolicited claims: Be highly suspicious of anyone who reaches out to you out of the blue claiming they can reverse a previous scam.
- Never share your credentials: Do not give remote access to your device or hand over your passwords and recovery phrases to unknown third parties.
- Don’t provide IDs or financial information. Scammers can use them for identity theft or further fraud.
- Use verification tools: If you receive a suspicious email, message, or phone call, you can verify its legitimacy using tools like Malwarebytes Scam Guard.
- Report scammers: If you or someone you know has fallen victim to this scam, file a complaint with the IC3 at ic3.gov.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.
The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.
The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.
AI minister will attend cabinet meetings held by UK prime minister Andy Burnham, with focus on ownership of UK tech
Leaking internal headers in Flask Ninja with deserialization
Article URL: https://eval.blog/research/pickle-gadget-chain-in-flask-ninja/
Comments URL: https://news.ycombinator.com/item?id=48990581
Points: 1
# Comments: 0
Best Foldable Phones
Article URL: https://www.nytimes.com/wirecutter/reviews/best-foldable-phones/
Comments URL: https://news.ycombinator.com/item?id=48990575
Points: 1
# Comments: 0
Boeing asks US to intervene over record EU loan to Airbus
Article URL: https://www.reuters.com/business/aerospace-defense/boeing-asks-us-intervene-over-record-eu-loan-airbus-2026-07-21/
Comments URL: https://news.ycombinator.com/item?id=48990566
Points: 1
# Comments: 0
See each Law of UX broken, then fixed, in a live demo
Article URL: https://laws-of-ux-examples.pagepost.app/
Comments URL: https://news.ycombinator.com/item?id=48990565
Points: 1
# Comments: 1
Chelsea's Defensive Rebuild Gains Momentum as Lacroix Emerges as Priority Target
Flavor Lines
Article URL: https://vova.today/en/works/plofornot/
Comments URL: https://news.ycombinator.com/item?id=48990560
Points: 1
# Comments: 0
An open dataset for modeling consciousness and sedation from EEG under propofol
Article URL: https://zenodo.org/records/18483292
Comments URL: https://news.ycombinator.com/item?id=48990559
Points: 1
# Comments: 0
GitHub Incident with Deploy Keys
Article URL: https://www.githubstatus.com/incidents/g40zcbvchny4
Comments URL: https://news.ycombinator.com/item?id=48990554
Points: 1
# Comments: 0
LibreFolio – Self-hosted portfolio tracker with 11 broker imports
Article URL: https://github.com/Librefolio/LibreFolio
Comments URL: https://news.ycombinator.com/item?id=48990550
Points: 1
# Comments: 0
