Anker’s Soundcore Liberty 5 Pro came out swinging in May with incredible call quality, something that competing ear buds have struggled to get right. They’ve become part of our reviewer John Higgins’ rotation of earbuds for more than just taking calls; The Liberty 5 Pro have fantastic audio once you make some tweaks in their […]
Bill fails at second reading despite near-identical legislation being approved by Commons in last parliament UK politics live – latest updates A bill to permit assisted dying in England and Wales has been voted down by MPs, almost certainly stopping such a measure from being enacted before the next general election at the very least least. In the second reading of the bill, put forward by Labour’s Lauren Edwards, MPs voted by 286 to 270 for it to be blocked. Continue reading...
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
Developers & Open Source · cloudflare/workers-sdk Releases
Patch Changes #15592 945aaa3 Thanks @WillTaylorDev ! - Add a provisioning delay note when custom domain Preview URLs change Wrangler now explains that DNS and TLS certificate provisioning may continue after a deploy adds a custom domain or enables its Preview URLs. Stable redeploys don't repeat the note. This assumes that a request which matches the stored custom domain state doesn't restart provisioning. The client infers this from the API changeset and current domain record because this repository can't verify the backend behavior. #15592 945aaa3 Thanks @WillTaylorDev ! - Clarify production status labels for custom domain routes Wrangler now prefixes explicit custom domain production states with production: so they match Preview labels. The updated labels appear in deployed trigger output and WRANGLER_OUTPUT_FILE_PATH . #15602 47d906f Thanks @dependabot ! - Update dependencies of "miniflare", "wrangler" The following dependency versions have been updated: Dependency From To @cloudflare/workers-types ^5.20260910.1 ^5.20260911.1 workerd 1.20260910.1 1.20260911.1 #15592 945aaa3 Thanks @WillTaylorDev ! - Avoid replacement prompts for custom domains already on the Worker Wrangler now updates Preview settings without asking to replace a custom domain when that domain already belongs to the deployed Worker. It still asks before replacing domains attached to another Worker. #15592 945aaa3 Thanks @WillTaylorDev ! - Explain how to enable Preview URLs when a Preview deployment has none wrangler preview now shows URL shapes and configuration snippets for Workers.dev and custom domains. The custom domain snippet preserves every configured route, and the guidance distinguishes missing settings from disabled ones. This changes a private beta feature. The warning also makes clear that wrangler deploy publishes code from the current checkout. Updated dependencies [ 47d906f , c2699bf ]: miniflare@5.20260911.0-alpha
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek .
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight
Graham Dumpleton's new monkey patching package wrapture is shaping up to be an indispensable tool for Python developers. I'm not sure why I've seen so little buzz about it! Graham has been posting new tutorials for it almost daily since the initial release on August 31st. Here's everything he's published so far: Introducing wrapture - a new monkey patching library that serves both testing and observability (think New Relic style tracing) at the same time. Unit testing with wrapture - how to use it for the same kinds of thing as unittest.mock . Recording calls with wrapture - recording method calls as timelines and processing and displaying them as trees. Phased behaviour in wrapture - arranging patched methods to change behavior across multiple calls. Beyond callables in wrapture - monkey patching attributes, dictionaries, generators. Live tracing with wrapture - tracing a live application to see exactly how it works. Zero-code tracing with wrapture - configuring tracing in a separate TOML file without modifying Python code at all. Tracing Flask with wrapture - using the separate wrapture-instrumenation package to instrument a Flask application. That package also provides instrumentation for aiohttp.client , aiohttp.web , django , fastapi , flask , grpc , http.client , httpx , jinja2 , requests , sqlalchemy , sqlite3 , starlette , urllib.request , urllib3 , uvicorn , werkzeug.serving , wsgiref.simple_server , xmlrpc.client , xmlrpc.server . Finding slow code with wrapture - wrapture's tools for recording timing information, both individually and aggregated across multiple calls. OpenTelemetry export in wrapture - exporting traces to OpenTelemetry. Graham also has a set of interactive workshops for wrapture, implemented as JupyterLab notebooks. Wrapture is still alpha software but it's already very usable - especially given you can configure and try it out with a TOML file without modifying any Python code at all. This feels like one of those Swiss Army Knife packages that, once mastered, will provide value against all sorts of problems for years to come. Tags: graham-dumpleton , open-source , testing , python , observability , monkey-patching
Anthropic's new threat intelligence report documents eight months of Claude abuse. Chinese AI labs like Alibaba's Qwen team, DeepSeek, and Moonshot AI relayed requests en masse or extracted training data, with Qwen alone accounting for more than 151 million exchanges. Actors also used Claude for missile software, autonomous kamikaze drones, and nationwide surveillance systems. The article How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data appeared first on The Decoder .
We listen back to interviews recorded in the aftermath of Sept. 11, with a particular focus on stories of survival and loss at the World Trade Center, and some reflections in poetry and music.
Uber's departure from Nigeria and Uganda has left countless customers high and dry. But what about drivers? With fuel prices, maintenance, and other operating costs rising, many say they're struggling to make a living.
Over past couple months I noticed that HN feed is almost exclusively AI or AI-adjacent news. Meanwhile the legitimately, broadly-hacker stuff gets left out for the most part. I noticed that because the things I find genuinely interesting that I post here now get zero traction, which is the stuff that I believe would previously be met with some discussion. Note that I don't care that my submissions were ignored, I don't need that validation. Problem is that if my stuff gains no traction, I am myself not seeing similar stuff posted by others, stuff I am genuinely also interested in and would want to hear about from this community. Here are two most recent examples: - Lenovo showed a model that incorporates solid-state air cooling. That technology has been around for a while but it looks like it matured and is production-ready. This allows for super-light and slim designs, which, in turn, should allow for bigger batteries installed and I think it's some sort of breakthrough: https://news.ycombinator.com/item?id=49580229 - Brax Industries devices, genuinely interesting, open-soruce and innovative, especially the wall display, with its modularity and on-device processing compatible with Home Assistant. I also appreciate the very clean design: https://news.ycombinator.com/item?id=49643215 As said, I honestly believe this would gain some traction here on HN a year or two ago. I no longer find HN a good source of "what's new" in the industry, it's almost exclusively AI talk now. So I think the point I am trying to make is that maybe YC could start curating the content somehow to give those easily-drowned-out articles a visibility bump? Or, at the very least, introduce simple tagging, so we can start filtering stuff out. Comments URL: https://news.ycombinator.com/item?id=49657850 Points: 675 # Comments: 331
Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention.
MPs have been debating a bill to legalise assisted dying in England and Wales. The bill would allow terminally ill adults with less than six months to live to end their lives, after the approval of a panel of experts. Speaking in the Commons, Labour's Claire Hazelgrove, who is in favour of the bill, said her mother, Ruth, died alone last October after living with a rare blood cancer for half of her life. Fellow Labour MP Ashley Dalton, who has been diagnosed with metastatic breast cancer, said the assisted dying bill does not adequately protect people with treatable depression who also have a terminal illness UK politics: latest updates Continue reading...
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek .