Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth
Google and Industry Partners Announce Agentic Resource Discovery Specification for AI Agents
Google and industry partners announced Agentic Resource Discovery (ARD) Specification, an open standard for publishing, discovering, and verifying AI tools, APIs, and agents. ARD introduces a discovery layer built on catalogs and registries, enabling dynamic capability discovery while leveraging existing protocols such as MCP and OpenAPI for execution and emphasizing trust and interoperability. By Leela Kumili
Serena Williams Fit-Dex
Article URL: https://serena-williams-fitdex.netlify.app/ Comments URL: https://news.ycombinator.com/item?id=48906339 Points: 4 # Comments: 0
Meta's Noninvasive Brain–Computer Interface Brain2Qwerty Achieves 61% Accuracy
Meta recently open-sourced Brain2Qwerty v2, a noninvasive Brain–Computer Interface (BCI) that can decode sentences from thoughts using electroencephalography (EEG) or magnetoencephalography (MEG) signals from the brain. In evaluations, the system achieved a word accuracy rate 61% on average, compared to 8% for other non-invasive methods. By Anthony Alford
A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed
When a failed DNSSEC key rollover took down the .AL TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn't have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS error code that signals directly in the response that DNSSEC validation was bypassed.
An Update on Igalia's Layer Based SVG Engine in WebKit (Reducing Layer Overhead)
17 points, 0 comments on Hacker News
Proof of care in the age of AI
Article URL: https://jacobfilipp.com/care/ Comments URL: https://news.ycombinator.com/item?id=48906125 Points: 127 # Comments: 84
Tensor Is the Might
Article URL: https://zserge.com/posts/tensor/ Comments URL: https://news.ycombinator.com/item?id=48906123 Points: 30 # Comments: 14
Guardian Angels: LLM Personalization for Productivity and Security
33 points, 3 comments on Hacker News
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,"
Presentation: Lessons Learned in Migrating to Micro-Frontends
Luca Mezzalira shares proven learnings from guiding hundreds of teams through the migration from monolithic web applications to distributed frontend architectures. He explains the core architectural difference between components and micro-frontends, outlines a 6-step decision framework spanning client vs. server rendering, and discusses how to utilize edge compute for safe, iterative rollouts. By Luca Mezzalira
Show HN: I RL-trained an agent that trains models with RL (for –$1.3k)
53 points, 21 comments on Hacker News
Beautiful Type Erasure with C++26 Reflection
64 points, 26 comments on Hacker News
Using self-hosted Umami for iOS app analytics
17 points, 3 comments on Hacker News
Coding agents think ahead of time
Article URL: https://arxiv.org/abs/2607.05188 Comments URL: https://news.ycombinator.com/item?id=48905764 Points: 66 # Comments: 53
Differentiable Fortran with LFortran and Enzyme
31 points, 9 comments on Hacker News
Linkerd 2.20 Delivers Smarter Traffic Management and Dramatic Efficiency Gains
The Linkerd community has announced the release of Linkerd 2.20, introducing a series of performance, observability, and traffic management enhancements that further strengthen the CNCF-graduated service mesh's position as a lightweight alternative for Kubernetes networking. By Craig Risi
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or
Germany set to restrict its Freedom of Information Act
187 points, 118 comments on Hacker News
How to stop Claude from saying load-bearing
76 points, 139 comments on Hacker News
Mathematical texts from a Maya site in Guatemala identify an ancient astronomer
58 points, 15 comments on Hacker News
Hating AI in 2026
Comments
Punch yourself in the face with reality
101 points, 50 comments on Hacker News
No Spanish reading crisis?
Article URL: https://www.commonreader.co.uk/p/no-spanish-reading-crisis Comments URL: https://news.ycombinator.com/item?id=48905105 Points: 43 # Comments: 66
6× faster binary search: from compiled code to mechanical sympathy
Comments
How Pentera Turns AI Security Workflows into Validation Engines
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and exposure data. That fragmentation matters because attackers do not move through environments one
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begun
Show HN: Rejourney – Open-source revenue leak prediction for web and mobile apps
32 points, 6 comments on Hacker News
Google's Genkit Ships Agents API with Detached Turns and Human-in-the-Loop for TypeScript and Go
Google released the Genkit Agents API in preview for TypeScript and Go. The open-source framework packages message history, tool loops, streaming, and state persistence behind a single chat() interface. Detached turns let agents work after clients disconnect. Interruptible tools provide human-in-the-loop control with anti-forgery validation on resume. By Steef-Jan Wiggers
How to manage AI investments in the agentic era
Learn how enterprises can manage AI investments in the agentic era by measuring useful work per dollar, improving efficiency, and scaling high-value workflows.
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles