Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Browser Run: give your agents a browser
Browser Rendering is now Browser Run, with Live View, Human in the Loop, CDP access, session recordings, and 4x higher concurrency limits for AI agents.
Rearchitecting the Workflows control plane for the agentic era
Cloudflare Workflows, a durable execution engine for multi-step applications, now supports higher concurrency and creation rate limits through a rearchitectured control plane, helping scale to meet the use cases for durable background agents.
Add voice to your agent
An experimental voice pipeline for the Agents SDK enables real-time voice interactions over WebSockets. Developers can now build agents with continuous STT and TTS in just ~30 lines of server-side code.
Things you didn't know about indexes
Comments
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that enables threat actors to seize control of the Nginx service. It has been codenamed MCPwn by Pluto Security. "
Show HN: Every CEO and CFO change at US public companies, live from SEC
Built this solo. It watches SEC filings for executive and board changes, extracts the data, and shows it in real time. 2,100+ changes in the last 30 days. The comp data is interesting: average new CEO total comp is $8.4M across 284 appointments. The /explore page is fully open, no login needed. Comments URL: https://news.ycombinator.com/item?id=47778306 Points: 148 # Comments: 60
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database
Do you even need a database?
102 points, 181 comments on Hacker News
Proliferate (YC S25) Is Hiring Founding Engineers
Article URL: https://www.ycombinator.com/companies/proliferate/jobs/L3copvK-founding-engineer Comments URL: https://news.ycombinator.com/item?id=47777902 Points: 0 # Comments: 0
IPv6 traffic crosses the 50% mark
11 points, 2 comments on Hacker News
New bill would let New Yorkers hang solar panels from windows
8 points, 1 comments on Hacker News
Retrofitting JIT Compilers into C Interpreters
Comments
Nanopass Framework: Clean Compiler Creation Language
88 points, 14 comments on Hacker News
Deterministic + Agentic AI: The Architecture Exposure Validation Requires
Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across industries, leadership teams have embraced its broader potential, and boards, investors, and executives are already pushing organizations to adopt it across operational and security functions. Pentera’s AI Security and Exposure Report 2026 reflects that momentum: every CISO surveyed
My 14-Year Journey Away from ORMs - a Series of Insights Leading to Creation of a SQL-First Code Generator
Blog post about how I went from shipping a popular ORM in 2012… to throwing it all away… to realizing that the database itself should be the single source of truth. Comments
Modern Common Lisp with FSet
Comments
The next evolution of the Agents SDK
OpenAI updates the Agents SDK with native sandbox execution and a model-native harness, helping developers build secure, long-running agents across files and tools.
Want to Write a Compiler? Just Read These Two Papers (2008)
160 points, 50 comments on Hacker News
'Seeking connection': video game where players stopped shooting, started talking
Article URL: https://www.theguardian.com/games/2026/apr/15/arc-raiders-players-stopped-shooting-started-talking Comments URL: https://news.ycombinator.com/item?id=47776723 Points: 38 # Comments: 39
Direct Win32 API, Weird-Shaped Windows, and Why They Mostly Disappeared
84 points, 37 comments on Hacker News
Connie Converse was a folk-music genius. Then she vanished
18 points, 6 comments on Hacker News
Good Sleep, Good Learning (2012)
107 points, 42 comments on Hacker News
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
Microsoft on Tuesday released updates to address a record 169 security flaws across its product portfolio, including one vulnerability that has been actively exploited in the wild. Of these 169 vulnerabilities, 157 are rated Important, eight are rated Critical, three are rated Moderate, and one is rated Low in severity. Ninety-three of the flaws are
Testing OpenGraph on localhost from the CLI before you go public
Comments
Anna's Archive loses $322M Spotify piracy case without a fight
174 points, 193 comments on Hacker News
Wacli – WhatsApp CLI: sync, search, send
137 points, 105 comments on Hacker News
MDalgorithms (AI Healthcare) – Hiring Growth Marketer – Remote – $80K-$140K
Article URL: https://www.ycombinator.com/companies/mdalgorithms-inc/jobs/LVODKN7-growth-marketer-for-a-rapidly-growing-consumer-ai-healthcare-startup Comments URL: https://news.ycombinator.com/item?id=47775606 Points: 0 # Comments: 0
Amazon to acquire Globalstar and expand Amazon Leo satellite network
Article URL: https://www.businesswire.com/news/home/20260414237496/en/Amazon-to-Acquire-Globalstar-and-Expand-Amazon-Leo-Satellite-Network Comments URL: https://news.ycombinator.com/item?id=47775183 Points: 24 # Comments: 1
Google Gemma 4 Runs Natively on iPhone with Full Offline AI Inference
88 points, 60 comments on Hacker News
Fixing a 20-year-old bug in Enlightenment E16
Article URL: https://iczelia.net/posts/e16-20-year-old-bug/ Comments URL: https://news.ycombinator.com/item?id=47774789 Points: 43 # Comments: 10
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles