Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Cursor 0day: When Full Disclosure Becomes the Only Protection Left
Article URL: https://mindgard.ai/blog/cursor-0day-when-full-disclosure-becomes-the-only-protection-left Comments URL: https://news.ycombinator.com/item?id=48910676 Points: 136 # Comments: 52
MoonBASIC: A modern BASIC for building 2D and 3D games
26 points, 7 comments on Hacker News
Bonsai 27B: A 27B-Class model that runs on a phone
Article URL: https://prismml.com/news/bonsai-27b Comments URL: https://news.ycombinator.com/item?id=48910545 Points: 262 # Comments: 90
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt path in May as part of its response to the
Kontigo (YC S24) Is Hiring (Head of Security)
Article URL: https://www.ycombinator.com/companies/kontigo/jobs/uNttrlv-head-of-security Comments URL: https://news.ycombinator.com/item?id=48909820 Points: 0 # Comments: 0
The Tower Keeps Rising
Article URL: https://lucumr.pocoo.org/2026/7/13/the-tower-keeps-rising/ Comments URL: https://news.ycombinator.com/item?id=48909785 Points: 263 # Comments: 125
Temper Language
Comments
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. "Once deployed, it can profile the host,
Measuring Input Latency on Linux: X11 vs. Wayland, VRR, and DXVK
Article URL: https://marco-nett.de/blog/measuring-input-latency-on-linux-x11-vs-wayland-vrr-dxvk/ Comments URL: https://news.ycombinator.com/item?id=48909424 Points: 325 # Comments: 195
Too many words about DIDs
Comments
Launch HN: Agnost AI (YC S26) – Extract user feedback from agent conversations
Hey HN, we’re Shubham & Parth, childhood friends building Agnost AI (https://agnost.ai), product analytics for teams building chat and voice agents. We read production conversations and find behavioral failures like users rageprompting (cursing at the agent), repeatedly rephrasing the same request, correcting the agent, asking for missing features, or leaving after an answer that was technically successful. We have an interactive demo with no signup here: https://app.agnost.ai?demo=true Here's a demo video: https://www.tella.tv/video/agnost-ai-launch-hn-demo-9haa The core problem is that chat and voice products do not have the same metrics as web apps. When the product interface is language, clicks and funnels become much less useful. Users also rarely give explicit feedback, and when they do it's usually sugarcoated. I barely type /feedback in Claude or Codex myself. Most users just curse, ask again, correct the agent, or leave. So product engineers get technical visibility from laten
Pseudpocalypse
44 points, 19 comments on Hacker News
How my images are dithered
Comments
Show HN: Opening lines of famous literary works
24 points, 11 comments on Hacker News
I'm a USB-C Maximalist
Article URL: https://shkspr.mobi/blog/2026/07/im-a-usb-c-maximalist/ Comments URL: https://news.ycombinator.com/item?id=48908214 Points: 91 # Comments: 160
Are we offloading too much of our thinking to AI?
68 points, 50 comments on Hacker News
Show HN: Low-latency local LLM runner via OpenJDK Panama FFM (Java 22)
16 points, 2 comments on Hacker News
The Agentic Loop: Three loops in a trench coat
Article URL: https://www.bobbytables.io/p/the-agentic-loop-three-loops-in-a Comments URL: https://news.ycombinator.com/item?id=48907672 Points: 60 # Comments: 12
The Zen of Parallel Programming
56 points, 3 comments on Hacker News
New York becomes the first state to impose a data center moratorium
95 points, 61 comments on Hacker News
Agnes Callard’s theory of the uni-context
55 points, 40 comments on Hacker News
Reviving a 15-year-old netbook with Arch Linux
110 points, 69 comments on Hacker News
The Conservationist Who Turned 40 Terabytes of Public Data into a Video Game
34 points, 3 comments on Hacker News
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth
Google and Industry Partners Announce Agentic Resource Discovery Specification for AI Agents
Google and industry partners announced Agentic Resource Discovery (ARD) Specification, an open standard for publishing, discovering, and verifying AI tools, APIs, and agents. ARD introduces a discovery layer built on catalogs and registries, enabling dynamic capability discovery while leveraging existing protocols such as MCP and OpenAPI for execution and emphasizing trust and interoperability. By Leela Kumili
Serena Williams Fit-Dex
Article URL: https://serena-williams-fitdex.netlify.app/ Comments URL: https://news.ycombinator.com/item?id=48906339 Points: 4 # Comments: 0
A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
When a failed DNSSEC key rollover took down the .AL TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn't have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS error code that signals directly in the response that DNSSEC validation was bypassed.
Meta's Noninvasive Brain–Computer Interface Brain2Qwerty Achieves 61% Accuracy
Meta recently open-sourced Brain2Qwerty v2, a noninvasive Brain–Computer Interface (BCI) that can decode sentences from thoughts using electroencephalography (EEG) or magnetoencephalography (MEG) signals from the brain. In evaluations, the system achieved a word accuracy rate 61% on average, compared to 8% for other non-invasive methods. By Anthony Alford
An Update on Igalia's Layer Based SVG Engine in WebKit (Reducing Layer Overhead)
17 points, 0 comments on Hacker News
Proof of care in the age of AI
Article URL: https://jacobfilipp.com/care/ Comments URL: https://news.ycombinator.com/item?id=48906125 Points: 127 # Comments: 84
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles