Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Selective Test Execution at Stripe: Fast CI for a 50M-line Ruby monorepo
Comments
Design and implementation of DuckDB internals
95 points, 8 comments on Hacker News
Why Aren't We uv Yet?
Comments
CPU-Z and HWMonitor compromised
125 points, 63 comments on Hacker News
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
Cybersecurity researchers have flagged yet another evolution of the ongoing GlassWorm campaign, which employs a new Zig dropper that's designed to stealthily infect all integrated development environments (IDEs) on a developer's machine. The technique has been discovered in an Open VSX extension named "specstudio.code-wakatime-activity-tracker," which masquerades as WakaTime, a
Cooperative Vectors Introduction
31 points, 2 comments on Hacker News
Git Repositories as a Module System
Comments
Women are getting most of the new jobs. What's going on with men?
11 points, 0 comments on Hacker News
Intel 486 CPU announced April 10, 1989
Article URL: https://dfarq.homeip.net/intel-486-cpu-announced-april-10-1989/ Comments URL: https://news.ycombinator.com/item?id=47716809 Points: 26 # Comments: 3
Anastasia (1997) live action reference material
15 points, 2 comments on Hacker News
White House staff told not to place bets on prediction markets
Article URL: https://www.bbc.co.uk/news/articles/cgld65x396go Comments URL: https://news.ycombinator.com/item?id=47716663 Points: 19 # Comments: 3
watgo - a WebAssembly Toolkit for Go
Comments
FBI used iPhone notification data to retrieve deleted Signal messages
Article URL: https://9to5mac.com/2026/04/09/fbi-used-iphone-notification-data-to-retrieve-deleted-signal-messages/ Comments URL: https://news.ycombinator.com/item?id=47716490 Points: 64 # Comments: 24
Microsoft suspends dev accounts for high-profile open source projects
Article URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-suspends-dev-accounts-for-high-profile-open-source-projects/ Comments URL: https://news.ycombinator.com/item?id=47716412 Points: 155 # Comments: 35
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
While much of the discussion on AI security centers around protecting ‘shadow’ AI and GenAI consumption, there's a wide-open window nobody's guarding: AI browser extensions. A new report from LayerX exposes just how deep this blind spot goes, and why AI extensions may be the most dangerous AI threat surface in your network that isn't on anyone's
France Launches Government Linux Desktop Plan as Windows Exit Begins
Article URL: https://www.numerique.gouv.fr/sinformer/espace-presse/souverainete-numerique-reduction-dependances-extra-europeennes/ Comments URL: https://news.ycombinator.com/item?id=47716043 Points: 543 # Comments: 208
Installing every* Firefox extension
Comments
Favorite programmer website?
I recently stumbled across John Walker's awesome old website. It's such a gem of personality and interests: https://www.fourmilab.ch/. What's your favorite website made by a programmer that isn't just a blog?
Show HN: Keeper – embedded secret store for Go (help me break it)
Keeper is an embeddable secret store (Argon2id, XChaCha20-Poly1305 by default). Four security levels, audit chains, crash-safe rotation. Vault is overkill for most use cases. This is for when you ge paranoid about env and need encrypted local storage that doesn't suck. No security through obscurity, hence, It's still early, so now's the best time to find weird edge cases, race conditions, memory leaks, crypto misuse, anything that breaks. The README has a full security model breakdown if you want to get adversarial. Comments URL: https://news.ycombinator.com/item?id=47715339 Points: 36 # Comments: 21
The acyclic e-graph: Cranelift's mid-end optimizer
Comments
What are you doing this weekend?
Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in an upcoming Chrome release. "This project represents a significant
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including
maki - the efficient coder (AI agent)
Comments
Artemis II and the invisible hazard on the way to the Moon
Article URL: https://www.ansto.gov.au/news/artemis-ii-and-invisible-hazard-on-way-to-moon-part-1 Comments URL: https://news.ycombinator.com/item?id=47714573 Points: 30 # Comments: 30
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations across its free and Pro
Penguin 'Toxicologists' Find PFAS Chemicals in Remote Patagonia
Article URL: https://www.ucdavis.edu/health/news/penguin-toxicologists-find-pfas-chemicals-remote-patagonia Comments URL: https://news.ycombinator.com/item?id=47714273 Points: 43 # Comments: 11
Show HN: GNU Grep as a PHP Extension
8 points, 0 comments on Hacker News
YouTube locked my accounts and I can't cancel my subscription
9 points, 1 comments on Hacker News
CollectWise (YC F24) Is Hiring
Article URL: https://www.ycombinator.com/companies/collectwise/jobs/Ktc6m6o-ai-agent-engineer Comments URL: https://news.ycombinator.com/item?id=47713744 Points: 0 # Comments: 0
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles