Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
SpaceX bond worth 10% less than issue price – heading for junk bond status
Article URL: https://www.ft.com/content/3a023b95-66c3-41e1-b0ce-df752a499541 Comments URL: https://news.ycombinator.com/item?id=48920181 Points: 320 # Comments: 263
Comparing Obelisk with Temporal and Restate
Comments
Presentation: Postgres for Production Agents: Your Relational Foundation for Enterprise AI
Gwen Shapira shares how teams are scaling AI features using PostgreSQL for mission-critical apps. She explains how to leverage Postgres's multi-modal capabilities - including JSONB parsing and high-recall HNSW vector indexing - to deliver deterministic and semantic context to LLMs. She also discusses vector quantization to speed up queries by 4x and strategies for managing agentic memory. By Gwen Shapira
What's the most popular number in Hacker News titles?
Article URL: https://blog.omgmog.net/post/most-popular-numbers-in-hn-post-titles/ Comments URL: https://news.ycombinator.com/item?id=48919967 Points: 25 # Comments: 10
FreeBSD 16 Retires The Last Of Its GPL Code From Its Base System
Comments
Briar Is in Maintenance Mode
Article URL: https://briarproject.org/news/2026-maintenance-mode/ Comments URL: https://news.ycombinator.com/item?id=48919869 Points: 73 # Comments: 47
a bunch of stuff i used to not know about K&R C
Comments
i've been thinking about null pointers
Comments
The US is advancing AI safety through state and federal action
OpenAI outlines a “reverse federalism” approach to AI governance, where state laws help build a national framework for safe, democratic AI.
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into
Sleep regularity is a stronger predictor of mortality risk than sleep duration (2023)
449 points, 206 comments on Hacker News
Prioritize mental health, and why communication is so important
140 points, 82 comments on Hacker News
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every
AWS Ships Claude Apps Gateway as Self-Hosted Control Plane for Claude Code and Claude Desktop
AWS and Anthropic have released the Claude apps gateway for AWS, a self-hosted control plane that centralizes identity, policy, telemetry, routing, and spend caps for Claude Code and Claude Desktop. The gateway runs as a single stateless container and routes inference to Amazon Bedrock or Claude Platform on AWS. By Steef-Jan Wiggers
Weathergotchi – an open-source climate Tamagotchi
72 points, 20 comments on Hacker News
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt
GPT-Red: Unlocking Self-Improvement for Robustness
Explore GPT-Red, OpenAI’s automated red teaming system that uses self-play to improve AI safety, alignment, and prompt injection robustness.
Over the Edge 2.0: Microsoft’s Design Tactics Still Undermine Browser Choice
Comments
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The
Python 3.15's Ultra-Low Overhead Interpreter Profiling Mode – Ken Jin's Blog
92 points, 2 comments on Hacker News
America pays workers just 27% of what its wealth allows – the worst in the OECD
Article URL: https://fortune.com/2026/07/13/us-worst-oecd-fair-pay-score/ Comments URL: https://news.ycombinator.com/item?id=48918078 Points: 34 # Comments: 4
Sealed tomb filled with paintings and inscriptions discovered in Egypt
39 points, 32 comments on Hacker News
Porting nanochat to a TPU: what carries over from PyTorch, and what breaks
30 points, 4 comments on Hacker News
@clickhouse/rowbinary: when your library is also a parser compiler
I used to do the "proper" parser generation work some time ago and found out that a good enough generator has to make so many opinionated decisions that it starts to feel like writing a… small natural language translation level nuanced machine. Thus the attempt to use modern coding LLMs to please each and every picky user. Comments
Who's running all those tiny RPKI servers?
Article URL: https://blog.apnic.net/2026/07/15/whos-running-all-those-tiny-rpki-servers/ Comments URL: https://news.ycombinator.com/item?id=48917055 Points: 28 # Comments: 0
I tricked Claude into leaking your deepest, darkest secrets
Article URL: https://www.ayush.digital/blog/the-memory-heist Comments URL: https://news.ycombinator.com/item?id=48916975 Points: 297 # Comments: 133
How C++20 improved the for-loop syntax
Comments
RISC-V Is Inevitable: State of the Union Keynote Argues
Article URL: https://www.eetimes.com/risc-v-is-inevitable-state-of-the-union-keynote-argues/ Comments URL: https://news.ycombinator.com/item?id=48916805 Points: 63 # Comments: 44
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles