Feed aggregator
X from the Terminal
Article URL: https://twitter.com/marcusforpeace/status/2105577729005678671
Comments URL: https://news.ycombinator.com/item?id=49922714
Points: 1
# Comments: 0
The Extraordinary Case of the Guevedoces
Article URL: https://www.bbc.com/news/magazine-34290981
Comments URL: https://news.ycombinator.com/item?id=49922712
Points: 1
# Comments: 0
Agentic Front End Refactoring with QBDS, Claude Code, & Figma MCP
Article URL: https://medium.com/quantumblack/what-changes-when-your-design-system-can-talk-to-an-ai-0a856b3c40d9
Comments URL: https://news.ycombinator.com/item?id=49922705
Points: 2
# Comments: 0
Claude's Android App: Finding the Internal Settings
Article URL: https://nima-ahmadi.github.io/posts/claude-android-internal-settings/
Comments URL: https://news.ycombinator.com/item?id=49922704
Points: 1
# Comments: 0
Reviving Valve's 15-year-old e-book
Article URL: https://nikolan.net/posts/portal2/
Comments URL: https://news.ycombinator.com/item?id=49922698
Points: 1
# Comments: 0
46th Chess Olympiad
Article URL: https://en.wikipedia.org/wiki/46th_Chess_Olympiad
Comments URL: https://news.ycombinator.com/item?id=49922681
Points: 1
# Comments: 0
Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says.
The post Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass appeared first on SecurityWeek.
Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.
The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared first on SecurityWeek.
Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims.
The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.
Shadow AI explained: The work shortcut that could leak your company’s secrets
Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk.
You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But the thread may contain customer details or confidential plans you’ve just shared with an outside service.
If your employer hasn’t approved that tool or how you’re using it, that’s shadow AI.
The UK’s National Cyber Security Centre (NCSC) defines shadow AI as:
“the use of AI technology which isn’t captured in an organisation’s approved systems and processes.”
A Microsoft study published in 2025 found that 71% of UK employees surveyed said they had used AI tools at work their employer hadn’t approved. Most people aren’t doing this to cause trouble. They want to get their work done faster, and the tools are right there.
Shadow AI isn’t limited to chatbots. It can also be:
- A browser extension that “improves your writing.”
- A meeting-notes bot that joins your calls.
- An AI feature quietly switched on inside an app you already use.
- A small automation you built yourself that sends data to an AI service.
AI features are appearing in search engines, email apps, and phones. Instead of a helpful list of links, Google now tries to answer your question. Microsoft’s Copilot drafts replies to your boss before you’ve had coffee. Your phone summarizes conversations you don’t even remember having. That makes it easy to start using one without checking whether it’s approved for work.
Why it worries IT and security teamsWhen you enter data into a public AI tool, it leaves your company’s control. The service may keep that data or use it to improve its models, unless specific privacy controls are in place. That can lead to data breaches, lost intellectual property, and regulatory problems.
There is also a security angle. AI assistants and agents—tools that can take actions on your behalf—are complex software and can have serious vulnerabilities. If an attacker exploits one, they may gain access to the data and services the tool has.
IBM’s 2025 Cost of a Data Breach research found that one in five organizations reported a breach linked to shadow AI. Only 37% had policies to manage AI or detect shadow AI. Organizations with a lot of shadow AI paid roughly $670,000 more per breach.
In a survey of our newsletter readers, 90% of respondents said they were worried about AI using their data without consent. Company data deserves the same care as your own.
How to use AI more safely at workYou don’t need to avoid AI altogether. Think carefully about which apps and services you use before you share data. Start by talking to your employer, then follow these steps:
- Ask for an approved tool. Security leaders say the best way to reduce shadow AI is to offer something better and safer, such as an enterprise AI platform with guardrails.
- Use your work account, not a personal one. Work accounts are the ones your IT team can protect and govern.
- Find out what’s off-limits. Customer details, financial data, HR records, source code, and confidential meeting content may be restricted. Ask which kinds of data you may and may not use with AI.
- Check the privacy settings. Look at whether the tool stores your inputs or uses them to train its models.
- Register your use case. Many organizations keep a list of approved AI tools and uses. A quick approval process makes it easier to stay on the right side of the rules.
- Be careful with agents and plug-ins. Tools that connect to your email, files, or calendar should be reviewed by your IT or security team first.
- Speak up. If the approved tools aren’t meeting your needs, say so. The NCSC recommends open conversations about security to help reduce reliance on unapproved tools.
If you manage a team, remember that banning AI outright tends to push the use further out of sight. Find out why people are turning to unapproved tools. Providing useful, approved options and clear rules can help staff work faster while protecting company data.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Preparing governments for an era of interconnected cyber risk
According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. Governments are also the most frequently targeted sectors for nation-state activity. They are attractive targets because they hold sensitive information, operate essential services, and sit at the center of networks of agencies, contractors, technology providers, and critical infrastructure operators.
Dwell time, the period between when an attacker gains access and when defenders detect and stop them, also increased this year across multiple sectors. While organizations responded faster once an intrusion was identified, detecting threats early remains a challenge. Attackers increasingly gain access through techniques that mimic legitimate activity, making malicious behavior harder to spot. For example, phishing accounted for 23% of observed intrusions in 2026, up from 7% in 2025, highlighting the continued importance of compromised identities as an entry point for broader attacks.
Taken together, the implication for governments is clear. Security in the AI era is no longer simply about preventing individual intrusions. It is about ensuring institutions can operate effectively in an environment where risks are interconnected, threats move faster, and attackers remain hidden longer. Public-private partnerships are also more important than ever for securing critical government infrastructure and developing the policies and regulations needed for emerging technologies.
In this year’s report, which examines cyber threat trends observed between July 2025 and June 2026, Terrell Cox, Microsoft’s Corporate Vice President & Deputy Chief Information Security Officer, and I explore how these dynamics are reshaping cyber risk. In a companion blog, Terrell takes a closer look at what these findings mean for CISOs and security professionals.
To strengthen resilience, governments should focus on five priorities:
- Prepare for a faster threat environment
AI is compressing the window for action. Adversaries are moving faster. A vulnerability’s discovery in the wild to active weaponization can be well below 24 hours. While the number of publicly disclosed software vulnerabilities (commonly tracked as CVEs) is projected to reach a record 72,000 in 2026.
Governments best prepared for the future will be those that can rapidly gather and assess information, make decisions, coordinate across institutions and industries, and communicate effectively during a crisis. This requires clearly defined responsibilities and trusted relationships established before an incident occurs, enabling swift and coordinated action when it matters most.
- Build security into the AI ecosystem
AI is becoming part of the infrastructure that governments, businesses, and citizens rely on every day. As governments continue to adopt AI across public services and encourage its broader use, they should approach its security as a resilience challenge rather than a narrow technical issue.
AI systems depend on interconnected infrastructure, data, models, applications, suppliers, and governance processes. Governments should promote security across this ecosystem through secure-by-design practices, testing and evaluation, stronger supply chain protections, transparency, accountability, and international cooperation on AI risk.
The goal is not to create a separate AI security agenda. It is to integrate AI security into broader efforts to protect critical infrastructure and build national resilience.
- Plan for incidents to spread
Governments may not immediately know whether an intrusion is criminal, geopolitical, or something else. Cybercriminals and nation-state actors pursue different objectives, but increasingly rely on many of the same entry points, including compromised identities, exposed applications, social engineering, and legitimate administrative tools.
Microsoft found that 52.2% of intrusions involving valid accounts resulted in additional credential theft, highlighting how quickly attackers can expand beyond an initial foothold. A seemingly isolated compromise can evolve into ransomware, espionage, data theft, or disruption of essential services.
Governments should therefore assess incidents not only by how they begin, but by where they could lead. Response plans should account for the suppliers, partners, and service providers supporting critical functions. As attacks expand beyond their initial targets, they can also cross organizational, sectoral, and national boundaries, reinforcing the need for global collaboration.
- Enable timely, two-way public-private information sharing
A compromised account at one organization may provide early warning of a broader campaign. Signals that appear inconclusive in isolation can reveal coordinated activity when combined across organizations and jurisdictions. Modern cybercrime operates through interconnected networks of actors, services, and infrastructure that no single institution can fully see or disrupt on its own.
Information sharing must be timely, trusted, and two-way—also known as bidirectional. The goal is not simply for companies to report threats to government. Public agencies should also return actionable intelligence, guidance, and warnings that help organizations protect their networks, customers, and operations. Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.
Policymakers can support this cooperation through protections for good-faith information sharing, common anonymization standards, and investment in shared threat intelligence and detection capabilities. Information sharing should also lead to action, including investigations, disruption efforts, and accountability for those responsible for serious cyber intrusions.
- Prepare essential services to operate through disruption
The organizations governments depend on to deliver public services, including transportation systems, communications infrastructure, schools, universities, and critical infrastructure operators, are increasingly targeted by cyber threats. Resilience therefore requires understanding not only government systems, but the broader ecosystem that supports them.
Planning documents alone are not enough. Governments should regularly conduct tabletop exercises bringing together policymakers, operational leaders, law enforcement, critical infrastructure operators, and private-sector partners to test how they would respond to incidents disrupting essential services. These exercises can expose gaps in decision-making, information sharing, public communications, and cross-sector coordination before a real-world crisis. Microsoft’s work through initiatives such as the Advancing Regional Cybersecurity (ARC) program, most recently in Kenya, illustrates how scenario-based exercises and cross-sector collaboration can help strengthen preparedness and response capabilities across the broader ecosystem.
Government leaders should also know which services are most critical, which identities, systems, suppliers, and infrastructure support them, and how incidents will be escalated. Shared-service approaches can help extend security and response capabilities to local governments and public institutions that cannot build them independently.
As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.
In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack. It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before. Governments best prepared for the future will be those that can contain harm, adapt quickly, and continue delivering critical services when citizens need them the most.
The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog.
Insights from the 2026 Microsoft Digital Defense Report
Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing. Today, we released the 2026 Report, which reflects a security environment that continues to grow more interconnected.
We see that across the report. Threat activity can span infrastructure, identities, applications, cloud environments, and software supply chains. AI systems and agents increasingly interact with data, tools, and business systems. And activity that looks incomplete in one part of an environment can become clearer when separate signals are considered together. That makes the connections across an environment increasingly relevant to how we understand both cyberthreats and defense.
Read the 2026 Microsoft Digital Defense ReportThe pace of change also matters. AI models are becoming more capable, automation is expanding, and new connections are forming across the systems organizations rely on. These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.
Several findings in this year’s report illustrate that.
AI in the threat landscapeThreat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development, and post-compromise activity. For now, much of their use remains focused on specific parts of existing attack workflows, even as more advanced applications of AI continue to develop.
AI can give threat actors greater speed, scale, and ability to tailor activity more efficiently. We see that in social engineering, where AI can make campaigns more targeted, and in technical work, where automation can compress parts of the attack process. The underlying methods often remain familiar. People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.
AI is also becoming more connected to the systems and processes organizations already rely on. That brings another dimension to the security work.
Securing AI as part of the enterpriseAgents are a good example of these observations. They can interact with enterprise data, applications, APIs, and tools, with different levels of access and autonomy depending on how they are designed and deployed. Those connections are what allow agents to perform useful work, and they are also part of what security teams need to understand.
That makes it increasingly important to look at AI as part of a broader system. A model may be one component, but its security also depends on the data it can reach, the tools it can use, the identities and permissions involved, and the infrastructure and services around it.
The report looks at agent identity, appropriate access, authentication between agents, attribution, and the ability to revoke access. It also examines security considerations specific to AI, including prompt injection, memory, models and data, agent behavior, and the integrity of software and services around AI systems.
There is a lot we are still learning as these technologies develop. Security teams do have a strong foundation to build from. Identity and authorization, data protection, least privilege, monitoring, testing, and secure software development all remain relevant. AI puts those disciplines into new systems and increasingly connected workflows.
Read the executive summary of the 2026 Microsoft Digital Defense Report AI and vulnerability discoveryAdvances in the application of AI toward code analysis are making it possible to examine software and identify weaknesses more effectively. That creates new opportunities to find vulnerabilities earlier and strengthen software before weaknesses are exploited. Those same advances can give threat actors more capable tools for vulnerability discovery and exploit development.
This is an important area to watch as capabilities develop. AI is giving defenders new ways to find and address weaknesses while giving cyberattackers new ways to look for them. The work on both sides continues to advance.
Connecting what defenders knowThe same interconnectedness that shapes how activity moves across systems also shapes how defenders understand it. Security teams work with information from endpoints, identities, cloud environments, applications, email, networks, and threat intelligence. The report shows why those signals become more useful when they can be considered together. Threat activity spanning several systems may leave a pattern that no individual source shows on its own. In a more connected environment, the ability to relate activity across systems becomes an important part of understanding what is happening and where attention is needed.
The same principle extends beyond an individual organization. Trusted sharing of intelligence and information across organizations and public-private partnerships can connect pieces of activity that no one organization sees on its own.
AI can help with that work. Established techniques and repeatable tasks are increasingly candidates for automation, including bringing relevant information together and giving experienced defenders more capacity for deeper investigation.
The discussion of red teaming in this year’s report captures the balance well. Connecting known information and running established techniques can increasingly be automated. Finding an undocumented attack path, or recognizing how weaknesses that appear unrelated fit together, continues to benefit from experienced operators staying close to the work.
That balance will continue to evolve. There is substantial opportunity to use AI to help defenders work more effectively while preserving the human judgment, context, and expertise that remain essential to security work.
The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people. Taken together, those findings give us a broader view of the increasingly interconnected environment security teams are responsible for understanding and protecting.
I encourage you to read the full report for a deeper look at the findings, data, and recommendations from Microsoft’s security and threat intelligence teams.
Read the 2026 Digital Defense Report for the full findings, data, and recommendations.
Get the full 2026 Microsoft Digital Defense ReportTo learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog.
AI Has Changed Attack Speed, Not Security Fundamentals
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.
The post AI Has Changed Attack Speed, Not Security Fundamentals appeared first on SecurityWeek.
Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.
The post Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure appeared first on SecurityWeek.
Trump renames AI to 'super intelligence' and tells Americans they have no choice
Article URL: https://www.independent.co.uk/news/world/americas/us-politics/trump-ai-super-intelligence-rename-order-b3058607.html
Comments URL: https://news.ycombinator.com/item?id=49920735
Points: 1
# Comments: 0
Figure F.02 Decommission
Article URL: https://www.figure.ai/news/f-02-decommission
Comments URL: https://news.ycombinator.com/item?id=49920729
Points: 1
# Comments: 0
Asus ProArt P16 Laptop (H7607, RTX Spark)
Article URL: https://www.asus.com/us/laptops/for-creators/proart/proart-p16-h7607/
Comments URL: https://news.ycombinator.com/item?id=49920697
Points: 1
# Comments: 0
Metriqcon – A client-side unit converter with an inline live math parser
Article URL: https://metriqcon.co/
Comments URL: https://news.ycombinator.com/item?id=49920689
Points: 1
# Comments: 0
Robotaxi Firms Are Buying Up the Garages Before the Votes
Article URL: https://theinference.org/article/robotaxi-firms-are-buying-the-garages-before-the-votes
Comments URL: https://news.ycombinator.com/item?id=49920680
Points: 1
# Comments: 0
When Every AI Agent Action Is Authorized–and the Overall Decision Is Still Wrong
Article URL: https://tasoffices.substack.com/p/when-every-ai-agent-action-is-authorizedand
Comments URL: https://news.ycombinator.com/item?id=49920667
Points: 1
# Comments: 0
