Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Q1 2026 Innovation Graph update: Open source collaboration is accelerating worldwide
New Innovation Graph data shows global developer communities growing faster than ever, with collaboration reaching new highs across many economies. The post Q1 2026 Innovation Graph update: Open source collaboration is accelerating worldwide appeared first on The GitHub Blog.
30papers.com – Ilya's 30 essential ML papers, in a beginner friendly format
Article URL: https://30papers.com/ Comments URL: https://news.ycombinator.com/item?id=48819608 Points: 263 # Comments: 44
Better Auth is joining Vercel
17 points, 5 comments on Hacker News
Why we built yet another Postgres connection pooler
Article URL: https://pgdog.dev/blog/why-yet-another-connection-pooler Comments URL: https://news.ycombinator.com/item?id=48819308 Points: 97 # Comments: 22
Microsoft Fire IdTech Team at Id Software
73 points, 27 comments on Hacker News
Chat Control passed first round in EU Parliament
100 points, 46 comments on Hacker News
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience,
Automating AI Away
81 points, 40 comments on Hacker News
The Revenge of the Philosophy Majors
53 points, 57 comments on Hacker News
Chat Control 1.0 and 2.0 Explained
326 points, 106 comments on Hacker News
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones
I was wrong about game development
Comments
Mechanized type inference for record concatenation
Comments
An iroh powered smart fan
46 points, 4 comments on Hacker News
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intrusion, then to online accounts prosecutors say belong to 19-year-old Peter Stokes. Stokes is
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. "An outsider could go from having no access to taking over any Writer AI
You shouldn't trust Trusted Publishing
Comments
Cloudflare proudly joins the UK government's Cyber Resilience Pledge
The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply chain rigor. For over a decade, Cloudflare has pioneered the core pillars of this framework: democratizing security, leadership accountability, and radical transparency.
Dua Lipa opens library for banned and censored books in Portugal
Article URL: https://www.euronews.com/culture/2026/06/29/dua-lipa-opens-library-for-banned-and-censored-books-in-portugal Comments URL: https://news.ycombinator.com/item?id=48817017 Points: 165 # Comments: 150
The Popup That Says the Quiet Part Out Loud
Comments
Show HN: Yamanote.fun – A complete soundscape for Tokyo's Yamanote line
80 points, 19 comments on Hacker News
98% Isn't Much
289 points, 218 comments on Hacker News
A better way to tie your gym shorts. (Or any drawstring) [video]
234 points, 90 comments on Hacker News
Show HN: PostgreSQL performance and cost across 23 EC2 instance types
33 points, 0 comments on Hacker News
StreetComplete: Fixing OpenStreetMap, one tiny quest at a time
298 points, 62 comments on Hacker News
Put NetHack on my community app and this 38-year-old game keeps outsmarting me
I added NetHack to my community app a while back, unmodified upstream binary running on a shared box. I thought I was adding "an old roguelike". I was not prepared. :D It shipped multiplayer in the 80s and nobody calls it that. Bones files. Someone dies on lvl 12, their ghost and their cursed loot get written to disk, and another player on the same machine walks into that grave later. People are haunting each other with zero configuration. "The DevTeam thinks of everything" is not a meme. Every "surely this won't work" works. Every "surely the game doesn't track that" is tracked. You can wield a cockatrice corpse as a weapon (wear gloves). You can scare monsters by writing Elbereth in the dust. You can dip, rub, sit on, and kick basically anything, and the game has an opinion about all of it. I keep watching people find interactions I didn't know existed, in a game running unmodified on my box. And it's still alive. First released in 1987, still maintained by the DevTeam today, and it
Europe's company websites are mostly served by US vendors
171 points, 126 comments on Hacker News
AWS Expands DevOps Agent with AI-Powered Release Management to Validate Code Before Production
Amazon Web Services (AWS) has announced a major expansion of its AWS DevOps Agent, introducing new release management capabilities designed to assess code changes and autonomously test software before it reaches production. By Craig Risi
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives less in the code a
Signed Integers By Default
Comments
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles