Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Hy3
Article URL: https://hy.tencent.com/research/hy3 Comments URL: https://news.ycombinator.com/item?id=48847552 Points: 11 # Comments: 1
How to Write an Email
Article URL: https://blog.dannycastonguay.com/how-to-write-an-email/ Comments URL: https://news.ycombinator.com/item?id=48847536 Points: 6 # Comments: 2
Show HN: Policy enforcement for Claude Code, Cursor, and Codex
Show HN: Runtime authorization for Claude Code, Cursor, and Codex Hi HN, Fernando and I built Kastra. Kastra intercepts AI agent tool calls and evaluates them against deterministic policies before they execute. This is aimed at developers using coding agents like Claude Code, Codex, Cursor, and OpenClaw. We built Kastra after one of our Cursor agents almost executed DELETE FROM customers WHERE status='test' against a production database. We caught it before it ran, but it made us realize that nothing in our stack actually decided what the agent was allowed to do. What mattered for us wasn't the mistake; it was realizing nothing in our setup would have stopped it if we weren't actively on top of it. LLMs are probabilistic, and prompts influence behavior, but they don't deterministically decide what an agent is allowed to do. Without a deterministic policy system, nothing could have decided what it was allowed to do. Kastra pushes an allow, hold, and deny decision before the action runs.
A Possible Future for Damn Interesting
Article URL: https://www.damninteresting.com/a-possible-future/ Comments URL: https://news.ycombinator.com/item?id=48847511 Points: 7 # Comments: 0
You paid me, a long-time Linux user, to use Windows 11 exclusively for a month: here’s how it went
Comments
Presentation: Accelerating Netflix Data: A Cross-Team Journey from Offline to Online
Raj Ummadisetty and Ken Kurzweil share Netflix's architectural pivot to CloudStream, a repeatable capture, conversion, and deployment framework. They discuss shifting key-value abstractions from stateless to stateful to move terabytes of bulk data safely. Software architects will learn to exploit data access patterns, use "Pathfinder" prototypes, and maintain a 99% faster rollout. By Rajasekhar Ummadisetty, Ken Kurzweil
Opinionated and Easy Pi.dev Configuration
21 points, 6 comments on Hacker News
Coordination Without Consolidation: On Systems of States [pdf]
6 points, 1 comments on Hacker News
Show HN: LastShelf – an emergency map of your family's documents bills& contacts
17 points, 5 comments on Hacker News
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global
Ways to think about token pricing
Article URL: https://www.ben-evans.com/benedictevans/2026/7/9/ways-to-think-about-token-pricing Comments URL: https://news.ycombinator.com/item?id=48847181 Points: 3 # Comments: 0
TLS certificates for internal services done right
27 points, 17 comments on Hacker News
Announcing Rust 1.97.0
Comments
My burner email blocklist blocked me
31 points, 26 comments on Hacker News
New "Revenue Larping Trend" is this real?
17 points, 1 comments on Hacker News
The console wars have been lost
4 points, 0 comments on Hacker News
Why the Next Era of AI Is About Infrastructure, Not Just Models
Article URL: https://blog.mozilla.ai/the-control-layer-why-the-next-era-of-ai-is-about-infrastructure-not-just-models/ Comments URL: https://news.ycombinator.com/item?id=48846842 Points: 21 # Comments: 7
Why we're moving off Cloudflare Durable Objects
Article URL: https://usewire.io/engineering/why-were-moving-wire-off-cloudflare-durable-objects/ Comments URL: https://news.ycombinator.com/item?id=48846757 Points: 6 # Comments: 0
Show HN: Analog Watch
35 points, 32 comments on Hacker News
New open access book on history of computers and politics
17 points, 0 comments on Hacker News
PostHog Open Sourced
59 points, 33 comments on Hacker News
No leap second will be introduced at the end of December 2026
101 points, 73 comments on Hacker News
Introducing Muse Spark 1.1
140 points, 92 comments on Hacker News
Muse Spark 1.1
287 points, 161 comments on Hacker News
Why we cannot wait for better post-quantum signature algorithms
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best one currently available.
A Prolog library for interfacing with LLMs
Comments
US seeks cheaper hunter-killer drones after Iran destroys $1B worth of Reapers
137 points, 163 comments on Hacker News
The glass backbone: Why the Army's logistics will break in the next war
238 points, 313 comments on Hacker News
Show HN: FableCut – A browser video editor AI agents can drive (zero deps)
69 points, 41 comments on Hacker News
A road to Lisp: Why Lisp
75 points, 75 comments on Hacker News
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles