pypdf silently fails to check boxes when wrong on-state string is passed
A quirk in pypdf's update_page_form_field_values() allows developers to set a checkbox value using strings like 'Yes', 'true', '1', or Python's True boolean, yet the box remains visually unchecked in PDF viewers. The function returns no error, raises no exception, and logs nothing, even though the underlying field value and appearance state are never actually updated. This happens because PDF checkboxes have no universal on-state name — the checked value is defined per field inside the document's own appearance dictionary, commonly '/Yes' but sometimes '/On', '/1', or a custom string. The only reliable fix is to read the correct on-state string directly from the PDF field's '_States_' list at runtime, rather than hardcoding an assumed value. Developers using pypdf 6.18.0 should update their form-filling logic to dynamically retrieve the field-specific on-state before calling the update function.
BeaconKVM Lets You Access BIOS and Fix Crashed PCs Remotely via Browser
BeaconKVM is a hardware-based KVM device that allows users to remotely access a computer at the BIOS level, even when the operating system has crashed or is unresponsive. Unlike conventional remote desktop tools such as TeamViewer, a KVM works by acting as a virtual monitor, keyboard, and mouse, enabling control before the OS loads. Users set up the device by purchasing or building it on a Raspberry Pi 4B, registering it via a QR code, and then accessing it through the Beacon Console in a browser. The solution supports BIOS-level tasks like changing settings or reinstalling an operating system remotely, without requiring third-party networking tools like Tailscale or ZeroTier. BeaconKVM is designed for non-technical users and small businesses, with no monthly subscription fee.

Hackers Use Google Sheets and Tampermonkey to Steal Crypto via Browser Hijack
Cisco Talos has disclosed a high-priority ClickFix campaign in which attackers distribute fake cryptocurrency API vulnerability reports through forums and Telegram to trick users into pasting malicious JavaScript into their own browsers. The injected code establishes persistence via the Tampermonkey browser extension and fetches obfuscated scripts from publicly accessible Google Sheets using the Google Visualization API. Once active, the scripts hook browser fetch requests and clipboard activity, silently replacing legitimate cryptocurrency deposit addresses with attacker-controlled ones. Because the campaign relies entirely on legitimate Google infrastructure and user-trusted sites, the malicious traffic blends into normal browsing activity and largely evades detection. Security researchers recommend managing browser extension allowlists, monitoring script retrievals from Google Sheets APIs, and independently verifying destination wallet addresses through a separate trusted channel.
ClearFake Campaign Uses WebDAV and Fake CAPTCHAs to Deploy Stealers and Remote Access Tools
Cisco Talos has identified a ClearFake attack campaign, tracked as UAT-10820, that uses fake Google CAPTCHA pages to trick users into pasting malicious commands into the Windows Run dialog. The infection chain leverages WebDAV and BNB Smart Chain to deliver malware, with rundll32.exe loading DLLs remotely to deploy the Amatera stealer. One attack branch also installs ZigCryptoStealer and a Go-based reverse proxy, and attempts to disable endpoint detection using a vulnerable driver. A separate branch, observed at a Ukrainian government organization, progresses from Amatera to an unauthorized NetSupport Manager installation for persistent remote access. Talos recommends blocking rundll32.exe execution from internet UNC paths, restricting WebDAV access, and educating users not to paste commands from browser instructions into system dialogs.
Critical SAP NetWeaver Flaw CVE-2026-58240 Allows Unauthenticated Cluster-Wide RCE
A critical vulnerability tracked as CVE-2026-58240, dubbed S4GET, has been disclosed by Onapsis on September 8, 2026, affecting SAP NetWeaver Message Server. The flaw allows an unauthenticated attacker to manipulate the Message Server into treating their IP address as a trusted cluster host, subsequently enabling OS command execution via SAP Gateway with administrator-level privileges. Commands run as the 'adm' OS user across all application servers in the cluster, potentially enabling credential theft, backdoor installation, and lateral movement. SAP has issued Security Note 3759472 with patches across multiple kernel branches, and administrators are urged to restrict SAP GUI connection sources and remove direct internet exposure of the Message Server port. No real-world exploitation has been publicly reported, but the attack requires no user interaction and poses severe risk to any reachable SAP deployment.
Critical SAP Kernel Flaw CVE-2026-44756 Allows Pre-Auth Remote Code Execution
A maximum-severity vulnerability dubbed OVERPASS (CVE-2026-44756, CVSS 10.0) has been disclosed in the SAP Kernel, affecting products including SAP NetWeaver AS ABAP, SAP Web Dispatcher, and SAP S/4HANA. The flaw is a buffer overflow in Extended Passport (EPP) processing that can be triggered before any authentication takes place, allowing attackers to execute arbitrary OS commands with SAP administrative privileges. It is exploitable remotely over HTTP(S), SAP GUI, or RFC, requiring no valid SAP account or user interaction. SAP addressed the issue through Security Note 3747649, published on its September 2026 Security Patch Day, and urges organizations to prioritize patching internet-facing systems first. Until patches are applied, SAP recommends restricting access via SAProuter, jump hosts, and Web Dispatcher, while monitoring for application-layer anomalies and suspicious SAP process activity.
India Amends E-Commerce Rules to Curb Dark Patterns and Sponsored Listings
The Indian government has introduced the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, targeting deceptive practices on online platforms. The amendments aim to address dark patterns and undisclosed sponsored listings that mislead consumers. These changes were announced by the Centre and are designed to strengthen transparency and accountability in the e-commerce sector. The new rules are set to come into effect from January 1, 2027, giving platforms time to comply with the updated regulations.

Shami stays motivated in domestic cricket, marks 100th first-class match milestone
Indian pacer Mohammed Shami recently celebrated his 100th first-class match appearance with a Duleep Trophy victory. Despite his current absence from the national team, Shami says he remains strongly self-motivated and focused on performing at the highest level. He stressed that hard work is the cornerstone of his approach, leaving the rest to fate. Shami continues to look for every opportunity to make a meaningful contribution to his team's success in domestic cricket.
Another researcher says OpenAI trained on conversations, then claimed breakthrou
Article URL: https://bsky.app/profile/did:plc:ckaz32jwl6t2cno6fmuw2nhn/post/3mv4mt4ikss2d Comments URL: https://news.ycombinator.com/item?id=49643112 Points: 46 # Comments: 13
The Feminist Was a Spy
Article URL: https://uscpublicdiplomacy.org/blog/feminist-was-spy Comments URL: https://news.ycombinator.com/item?id=49643077 Points: 15 # Comments: 16
BRICS Summit Triggers Traffic Restrictions Across Delhi; Commuters Advised to Plan Ahead
Delhi is set to experience significant traffic disruptions due to the upcoming BRICS Summit being held in the city. VVIP convoy movements will lead to temporary road closures and diversions at various points, particularly affecting routes to the airport, central, and south Delhi. Commuters should anticipate longer travel times and are advised to plan their journeys in advance. Delhi Metro and bus services will continue to operate, though some route adjustments are possible. Authorities have urged residents to rely on official traffic updates for the most accurate and current information.
n8n Launches AI Assistant with Credential Approval Gates and Credit-Based Usage
n8n has released n8n Assistant, a preview chat-based tool that helps users plan, build, test, and debug automation workflows directly within the n8n canvas. The assistant introduces explicit approval controls, requiring user confirmation before accessing credentials or activating any workflow, ensuring AI actions do not affect live operations without human sign-off. Credentials are never exposed to the AI model and continue to be managed through n8n's standard credential screens. The feature operates on a separate token-based AI credit system, distinct from the older AI Workflow Builder, with credit consumption varying based on the complexity of assistance required. n8n notes the tool is still in preview and may contain errors, so workflows should be reviewed and tested before activation, especially those handling sensitive or business-critical data.
How to Design Make.com Workflows That Stay Maintainable Over Time
A developer writing for DEV Community outlines practical principles for building automation workflows on Make.com that remain manageable long-term. The core advice is to keep each scenario focused on a single purpose rather than chaining every action into one complex flow. Assigning clear responsibilities to each service — such as Telegram for notifications and Notion for data storage — makes debugging faster and more predictable. The author also recommends validating incoming webhook data early, standardizing logic across workflows, and maintaining structured logs that capture order IDs, timestamps, statuses, and errors. These practices collectively reduce the risk of silent failures and make it easier to diagnose problems when automations break unexpectedly.
Survey Reveals Who People Turn to for Support During Difficult Times
A data-driven analysis explores the support networks people rely on when facing personal struggles. The findings, published on the 'Graphs About Religion' platform, examine patterns in who individuals choose to confide in during hard times. The research appears to investigate the role of various relationships, including friends, family, and religious figures, in providing emotional support. The article has gained modest attention on Hacker News, prompting early discussion among readers.
Developer Builds Open-Source Bracket Generator for Non-Power-of-Two Player Counts
A developer has created a single-elimination tournament bracket generator that correctly handles participant counts that are not powers of two, such as 6, 10, or 14. The tool automatically assigns BYE slots using a mirrored seeding algorithm so that top seeds are placed in opposite halves of the bracket. It accepts player names via comma- or newline-separated input, strips duplicates, and refuses to generate a bracket for fewer than two distinct participants. Winners progress automatically through the bracket by index position, and any change to an earlier round triggers recalculation of all subsequent rounds. The generator offers both a shuffled and an ordered seeding mode, making it suited for small, informally organised tournaments.
Developer builds browser-based tool to analyze SQL schemas locally without cloud upload
A developer has created Code Architect Pro, a browser-based tool designed to analyze SQL database schemas entirely on the user's device without sending data to any external server. The tool uses JavaScript and WebAssembly to parse SQL dump files locally, generating visual schema graphs and flagging issues such as missing indexes, normalization problems, and inefficient table relationships. During testing on a legacy e-commerce database, the tool identified a missing index on a foreign key join between an orders and users table, and flagged an Entity-Attribute-Value pattern in a product attributes table. The developer built it as a privacy-first alternative to cloud-based database analysis tools, noting that schema files often contain sensitive or proprietary information. The project reflects a broader trend toward local-first software that gives developers greater control over their data and infrastructure decisions.
Nielsen's 30-Year UX Thresholds Break Down When Applied to Voice AI
Jakob Nielsen's 1993 response-time thresholds — 100ms, 1 second, and 10 seconds — have long defined acceptable UI performance, but researchers and developers now argue they don't translate well to voice interfaces. Unlike graphical UIs, voice systems offer no visual feedback such as loading spinners or typing indicators, meaning silence is the only signal a user receives while waiting for a response. Without these visual cues, even a one-second delay can feel like a dropped connection or a system failure, pushing the effective tolerance threshold down to around 300 milliseconds. Studies on human conversation, including Stivers et al. (2009), show that natural turn-taking gaps average roughly 200ms, meaning voice AI must respond far faster than web interfaces to feel natural. Developers are responding by using brief auditory acknowledgements — chimes or soft sounds — to fill the perceptual gap and signal that the system is processing.
