Skip to main content
Live Feed

Engineering &
Security Wire

Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.

22
ENG
7
SEC
1
AI
7356
TOTAL
Fri, Jul 10, 2026
30
1021ENG

Two Ways To Design

Comments

Lobsterswiki.c2.comJul 10
1022ENG

Laylo (YC S20) Is Hiring a Head of Finance

1 points, 0 comments on Hacker News

Hacker Newsycombinator.comJul 10
1023ENG

Linux Foundation Launches Akrites to Protect Critical Open Source Software from AI-Powered Threats

The Linux Foundation has launched Akrites, a new industry-wide initiative aimed at defending the world's most critical open source software against a rapidly evolving generation of AI-enabled cyber threats. By Craig Risi

InfoQinfoq.comJul 10
1024ENG

Late Bronze Age Collapse

165 points, 77 comments on Hacker News

Hacker Newsacoup.blogJul 10
1025SEC

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server

The Hacker News (Security)thehackernews.comJul 10
1026SEC

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every downstream security program inherits whatever the inventory gets wrong. Lumen Technologies, a

The Hacker News (Security)thehackernews.comJul 10
1027ENG

Accretive Editing

7 points, 3 comments on Hacker News

Hacker Newsjustindfuller.comJul 10
1028SEC

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as

The Hacker News (Security)thehackernews.comJul 10
1029ENG

EU Commission: addictive design Instagram and Facebook in breach of the DSA

164 points, 118 comments on Hacker News

Hacker Newsec.europa.euJul 10
1030SEC

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 billion times. The problems are basic, not sophisticated. 29 apps let user traffic leak outside

The Hacker News (Security)thehackernews.comJul 10
1031ENG

What are you doing this weekend?

Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!

Lobsterslobste.rsJul 10
1032ENG

Unified Memory, Explained: Why Mini PCs Can Run 70B Models a Big GPU Can't

32 points, 22 comments on Hacker News

Hacker Newsvettedconsumer.comJul 10
1033ENG

Good Tools Are Invisible

143 points, 96 comments on Hacker News

Hacker Newsgingerbill.orgJul 10
1034SEC

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-UNC-066, has deployed a panel-controlled phishing kit that's capable of targeting the passkey enrollment process. The

The Hacker News (Security)thehackernews.comJul 10
1035ENG

GitHub Copilot CLI Gets Tabs and No-Config-File Tool Setup in Redesigned Terminal UI

GitHub has made the redesigned GitHub Copilot CLI terminal interface generally available. It adds a tabbed layout for sessions, gists, issues, and pull requests; an in-session, form-driven setup for MCP servers, skills, and plugins that avoids hand-editing config files; and a cleaner, theme-aware, more accessible UI with screen reader support. By Mark Silvester

InfoQinfoq.comJul 10
1036SEC

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has confirmed one coordinated sweep on May

The Hacker News (Security)thehackernews.comJul 10
1037ENG

Podcast: Formal Methods for Every Engineer in an AI-Powered Future

In this podcast Shane Hastie, Lead Editor for Culture & Methods spoke to Gabriela Moreira about making formal methods accessible through the Quint specification language, how AI is dramatically lowering the barrier to entry for formal specification and model-based testing, and why defining correct system behaviour remains essential human work in an AI-driven world. By Gabriela Moreira

InfoQinfoq.comJul 10
1038ENG

Article: Trade-Offs in Multi-Region Architectures: Latency vs. Cost

Adding cloud regions changes latency and cost in ways simple math can't capture. This article presents a framework from multiple launches: decompose your latency budget before committing to infrastructure, choose deployment patterns by consistency and traffic profile, and optimize before expanding. A phased approach cut latency 35% through routing alone, before a new region brought it under 60ms. By Uttara Asthana

InfoQinfoq.comJul 10
1039ENG

In Emacs, Everything Looks Like a Service

11 points, 0 comments on Hacker News

Hacker Newsyummymelon.comJul 10
1040SEC

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described Martino as a "

The Hacker News (Security)thehackernews.comJul 10
1041ENG

How Datadog Used Claude and Cursor for Test-Driven Production Migration

In a recent article, Datadog engineer Arnold Wakim shared what worked, what didn't, and the lessons they learned while evolving a critical production system using AI to overcome hard limits in its storage backend and significantly improve performance. By Sergio De Simone

InfoQinfoq.comJul 10
1042ENG

AI-generated videos to maximally drive a target brain region

57 points, 52 comments on Hacker News

Hacker Newsnevo-project.epfl.chJul 10
1043AI

How Deutsche Telekom is rewiring telecommunications with AI

How Deutsche Telekom is becoming an AI-native telco with OpenAI-transforming customer service, employee workflows, network operations, and the future of voice.

OpenAI Blogopenai.comJul 10
1044ENG

WordPress 7.0 Ships with AI Foundations in Core, a Modernized Admin, and New Design Tools

WordPress 7.0, released on May 20, 2026, includes new AI infrastructure, a redesigned admin interface, and updated design tools. Key features comprise an AI Client, Abilities API, and Command Palette, alongside increased PHP requirements. Community feedback is mixed, particularly regarding AI integration. Developers are advised to consult the official documentation for upgrade guidance. By Daniel Curtis

InfoQinfoq.comJul 10
1045ENG

Let's build a simple interpreter for APL

Comments

Lobstersmathspp.comJul 10
1046ENG

Cpp2Rust: Automatic Translation of C++ to Safe Rust

Comments

Lobstersgithub.comJul 10
1047ENG

Ben Bernanke Joins Anthropic Oversight Trust

18 points, 2 comments on Hacker News

Hacker Newsanthropic.comJul 10
1048ENG

Fast Image & Video Fidelity Metrics in C, Zig

Associated blog post: https://halide.cx/blog/fmetrics/ Comments

Lobstersgithub.comJul 10
1049ENG

Superoptimizer -- A Look at the Smallest Program

Comments

Lobstersdl.acm.orgJul 10
1050ENG

Star Just Ate a Planet, and It's Not Done Yet

27 points, 36 comments on Hacker News

Hacker Newsnytimes.comJul 10

Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles