Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Tendril – a self-extending agent that builds and registers its own tools
Article URL: https://github.com/serverless-dna/tendril Comments URL: https://news.ycombinator.com/item?id=47921377 Points: 52 # Comments: 19
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust. Same
Microsoft and OpenAI end their exclusive and revenue-sharing deal
Gift Article: https://www.bloomberg.com/news/articles/2026-04-27/microsoft... https://openai.com/index/next-phase-of-microsoft-partnership... https://x.com/ajassy/status/2048806022253609115 Comments URL: https://news.ycombinator.com/item?id=47921248 Points: 474 # Comments: 404
Show HN: OSS Agent I built topped the TerminalBench on Gemini-3-flash-preview
3 points, 0 comments on Hacker News
We still don't have a more precise value for "Big G"
33 points, 15 comments on Hacker News
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds. The debate that followed has mostly focused on the right
PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks
A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025. That's according to a report published by Positive Technologies, which found the threat actors to be leveraging an exploit chain comprising three vulnerabilities to execute commands remotely on susceptible
China blocks Meta's acquisition of AI startup Manus
289 points, 190 comments on Hacker News
Show HN: A terminal spreadsheet editor with Vim keybindings
6 points, 1 comments on Hacker News
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of their legitimate counterparts. Of these, six have been confirmed to be malicious, with the remaining acting as seemingly
Men who stare at walls
263 points, 138 comments on Hacker News
Pgbackrest is no longer being maintained
Article URL: https://github.com/pgbackrest/pgbackrest Comments URL: https://news.ycombinator.com/item?id=47919997 Points: 128 # Comments: 52
What are you doing this week?
Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!
httpxyz one month in
Comments
FDA approves first gene therapy for treatment of genetic hearing loss
158 points, 59 comments on Hacker News
France's Mistral Built a $14B AI Empire by Not Being American
Article URL: https://www.forbes.com/sites/iainmartin/2026/04/16/how-frances-mistral-built-a-14-billion-ai-empire-by-not-being-american/ Comments URL: https://news.ycombinator.com/item?id=47919725 Points: 47 # Comments: 17
4TB of voice samples just stolen from 40k AI contractors at Mercor
306 points, 118 comments on Hacker News
Moleskine's AI Lord of the Rings collection can only mock
Article URL: https://cjleo.com/blog/moleskine-ai-lord-of-the-rings-collection-can-only-mock/ Comments URL: https://news.ycombinator.com/item?id=47919386 Points: 44 # Comments: 30
From Milliseconds to 26 Nanoseconds: How a $20 eBay SFP Module Beat My Entire NTP Setup
Comments
Quarkdown – Markdown with Superpowers
Article URL: https://quarkdown.com/ Comments URL: https://news.ycombinator.com/item?id=47919240 Points: 16 # Comments: 4
The gold standard of optimization: A look under the hood of RollerCoaster Tycoon
Comments
It's OK to abandon your side-project (2024)
Article URL: https://robbowen.digital/wrote-about/abandoned-side-projects/ Comments URL: https://news.ycombinator.com/item?id=47918961 Points: 111 # Comments: 55
Can You Find the Comet?
72 points, 31 comments on Hacker News
The Mushroom That Makes People Have the Exact Same Hallucination
Article URL: https://www.vice.com/en/article/meet-the-mushroom-that-make-people-have-the-exact-same-hallucination/ Comments URL: https://news.ycombinator.com/item?id=47918657 Points: 75 # Comments: 51
Announcing our partnership with the Republic of Korea
Google DeepMind and Korea partner to accelerate scientific breakthroughs using frontier AI models
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their mobile bills, generating illicit revenue for the threat actors who lease the phone numbers. According to a new report published by Infoblox, the operation is believed to
Wasm is not quite a stack machine
Comments
The next phase of the Microsoft OpenAI partnership
OpenAI and Microsoft announce an amended agreement that simplifies the partnership, adds long-term clarity, and supports continued AI innovation at scale.
Let's Build the Terminal Pt. 1
Comments
Patch applies fake diffs from commit messages
76 points, 22 comments on Hacker News
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles