Skip to main content
Live Feed

Engineering &
Security Wire

Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.

18
ENG
9
SEC
3
AI
7354
TOTAL
Wed, Jul 8, 2026
30
1201SEC

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user's

The Hacker News (Security)thehackernews.comJul 8
1202SEC

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Connect Application that an attacker

The Hacker News (Security)thehackernews.comJul 8
1203ENG

Airbnb Shares Architecture Behind Sitar-Agent Dynamic Configuration Sidecar for Kubernetes Services

Airbnb engineers detailed Sitar-agent, a Kubernetes sidecar for dynamic configuration delivery across tens of thousands of pods, processing updates several times per minute. The system was redesigned with Java, Amazon S3 snapshot bootstrapping, and a migration from Sparkey to SQLite to improve reliability, startup performance, and configuration availability at scale. By Leela Kumili

InfoQinfoq.comJul 8
1204ENG

The 'absolute magic' of Morse code that still connects people globally

58 points, 21 comments on Hacker News

Hacker Newsbbc.comJul 8
1205ENG

Tiny Tapeout Explorer: WASM FET-level circuit SIM&vis

3 points, 0 comments on Hacker News

Hacker Newsznah.netJul 8
1206ENG

Mistral's Robostral Navigate: a state of the art robotics navigation model

Article URL: https://mistral.ai/news/robostral-navigate/ Comments URL: https://news.ycombinator.com/item?id=48832212 Points: 126 # Comments: 24

Hacker Newsmistral.aiJul 8
1207ENG

Presentation: The Multi-Agent Approach: Building Reliable and Controllable Software Development Automation

Itamar Friedman discusses how architects and engineering leaders can break through the AI productivity ceiling using adaptive multi-agent systems. He shares insights on moving past simple autocomplete to resilient workflows by integrating autonomous testing, intelligent code review, and robust arbitration. Learn how to govern agent communication and build a context-driven SDLC that scales. By Itamar Friedman

InfoQinfoq.comJul 8
1208ENG

Funding open-source software without compromising it

Comments

Lobstersyorickpeterse.comJul 8
1209ENG

Unicode's Transliteration Rules Are Turing-Complete

Comments

Lobstersseriot.chJul 8
1210ENG

First look at Quest, the final ship of Antarctic explorer Shackleton

10 points, 0 comments on Hacker News

Hacker Newscbc.caJul 8
1211ENG

Preemption is GC for memory reordering (2019)

18 points, 3 comments on Hacker News

Hacker Newspvk.caJul 8
1212AI

Our approach to government and national security partnerships

Learn how OpenAI approaches government and national security partnerships, with principles for responsible AI use, democratic accountability, and public safety.

OpenAI Blogopenai.comJul 8
1213ENG

Cloudflare Meerkat - Globally distributed consensus

Article URL: https://blog.cloudflare.com/meerkat-introduction/ Comments URL: https://news.ycombinator.com/item?id=48831565 Points: 83 # Comments: 11

Hacker Newsblog.cloudflare.comJul 8
1214ENG

A bug which only affected left-handed users

Comments

Lobstersshkspr.mobiJul 8
1215ENG

Text art tools

38 points, 14 comments on Hacker News

Hacker Newshlnet.notion.siteJul 8
1216AI

Separating signal from noise in coding evaluations

A new analysis from OpenAI reveals issues in SWE-Bench Pro, a popular coding benchmark, raising concerns about reliability and accuracy in evaluating AI models.

OpenAI Blogopenai.comJul 8
1217SEC

New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time

The Hacker News (Security)thehackernews.comJul 8
1218SEC

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed

The Hacker News (Security)thehackernews.comJul 8
1219SEC

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Krebs on Securitykrebsonsecurity.comJul 8
1220ENG

Democratizing Abandonware

Comments

Lobstersgeopjr.devJul 8
1221ENG

It seems that the age of reading might be a short anomaly in human history

Article URL: https://www.theatlantic.com/magazine/2026/08/reading-crisis-postliterate-age/687618/ Comments URL: https://news.ycombinator.com/item?id=48830868 Points: 62 # Comments: 125

Hacker Newstheatlantic.comJul 8
1222SEC

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters

The Hacker News (Security)thehackernews.comJul 8
1223ENG

Apple to increase spend with Broadcom to produce billions more U.S. chips

Article URL: https://www.apple.com/newsroom/2026/07/apple-to-increase-spend-with-broadcom-to-produce-billions-more-us-chips/ Comments URL: https://news.ycombinator.com/item?id=48830565 Points: 189 # Comments: 146

Hacker Newsapple.comJul 8
1224ENG

Otary – Image and Geometry Python Library Now Has Tutorials

16 points, 0 comments on Hacker News

Hacker Newsalexandrepoupeau.comJul 8
1225SEC

The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in. Passkeys are now mainstream.

The Hacker News (Security)thehackernews.comJul 8
1226SEC

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused

The Hacker News (Security)thehackernews.comJul 8
1227ENG

Digital Deli, 1984 book by early PC hackers and enthusiasts

10 points, 0 comments on Hacker News

Hacker Newsatariarchives.orgJul 8
1228AI

Helping K–12 educators build practical AI skills

OpenAI Academy and the Walton Family Foundation are bringing hands-on AI Skills Jams to help K–12 educators build practical AI skills for the classroom.

OpenAI Blogopenai.comJul 8
1229SEC

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025.

The Hacker News (Security)thehackernews.comJul 8
1230ENG

Accessibility in GNOME

Comments

Lobstersblogs.gnome.orgJul 8

Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles