Skip to main content
Live Feed

Engineering &
Security Wire

Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.

25
ENG
5
SEC
0
AI
7376
TOTAL
Thu, Jul 2, 2026
30
1801ENG

Introduction to Genomics for Engineers

10 points, 0 comments on Hacker News

Hacker Newslearngenomics.devJul 2
1802ENG

Is One Layer Enough? A Single Transformer Layer Matches Full-Parameter RL Train

68 points, 15 comments on Hacker News

Hacker Newsarxiv.orgJul 2
1803ENG

jj v0.43.0 released

Comments

Lobstersgithub.comJul 2
1804ENG

The primary purpose of code review is to find code that will be hard to maintain

171 points, 97 comments on Hacker News

Hacker Newsmathstodon.xyzJul 2
1805ENG

Vite+ Beta

164 points, 95 comments on Hacker News

Hacker Newsvoidzero.devJul 2
1806SEC

Identity Lifecycle Management Wasn't Built for AI Agents 

Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance model built for humans develops structural blind spots that traditional IGA tools weren't designed to detect. This guide covers where that model breaks, what it

The Hacker News (Security)thehackernews.comJul 2
1807ENG

Shifting Platform Development from Projects to Products

A company shifted from project- to product-thinking after their platform outgrew single-team use. The limitations that they felt with their platform were one-off deliveries, lack of product vision, and weak feedback loops. They have moved toward a self-service, API-driven, multi-tenant infrastructure with clearer ownership and better abstractions. By Ben Linders

InfoQinfoq.comJul 2
1808ENG

This month in KDE Linux: June 2026

Comments

Lobsterspointieststick.comJul 2
1809ENG

PeerTube is a free, decentralized and federated video platform

48 points, 2 comments on Hacker News

Hacker Newsgithub.comJul 2
1810ENG

Preventing token theft

Comments

Lobsterscodon.org.ukJul 2
1811ENG

The modern app

Comments

Lobstersdbushell.comJul 2
1812ENG

Wordgard Release 0.1

Comments

Lobstersmarijnhaverbeke.nlJul 2
1813ENG

Apple Extends Private Cloud Compute to Google Cloud for the First Time

Apple chose Google Cloud to run Private Cloud Compute outside its own data centers for the first time, using NVIDIA Blackwell GPUs, Intel TDX, and Google's Titan chip. Apple maintains an independent append-only hardware ledger and dual-vendor attestation roots. AWS and Azure are not part of the collaboration. By Steef-Jan Wiggers

InfoQinfoq.comJul 2
1814ENG

Presentation: Enhancing Reliability Using Service-Level Prioritized Load Shedding at Netflix

The speakers discuss Netflix’s architecture for surviving extreme traffic spikes. They explain the mechanics of prioritized load shedding embedded in their Envoy sidecar proxy, allowing user-initiated requests to steal capacity from non-critical traffic. They share automated platform strategies for continuous chaos load testing, config generation, and retry storm mitigation. By Anirudh Mendiratta, Benjamin Fedorka

InfoQinfoq.comJul 2
1815SEC

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company's production database. Ransomware has always

The Hacker News (Security)thehackernews.comJul 2
1816ENG

Google loses fight over record $4.7B EU antitrust fine

56 points, 21 comments on Hacker News

Hacker Newscnbc.comJul 2
1817ENG

Type definitions to retrieve objects from localStorage

Comments

Lobsterstaxorubio.comJul 2
1818ENG

The Fall of the Theorem Economy

30 points, 3 comments on Hacker News

Hacker Newsdavidbessis.substack.comJul 2
1819SEC

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to FortiBleed's infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment

The Hacker News (Security)thehackernews.comJul 2
1820ENG

The Age of Personalized Hardware Is Coming

11 points, 3 comments on Hacker News

Hacker Newsgeastack.comJul 2
1821SEC

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and

The Hacker News (Security)thehackernews.comJul 2
1822ENG

My Story of 3D Realms / Apogee Part I (2020)

47 points, 1 comments on Hacker News

Hacker Newsjoesiegler.blogJul 2
1823SEC

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue

The Hacker News (Security)thehackernews.comJul 2
1824ENG

On Ditching Vagrant

Comments

Lobstersbenjamintoll.comJul 2
1825ENG

CursorBench 3.1

Article URL: https://cursor.com/evals Comments URL: https://news.ycombinator.com/item?id=48756840 Points: 61 # Comments: 42

Hacker Newscursor.comJul 2
1826ENG

Kimi K2.7 Code is generally available in GitHub Copilot

145 points, 57 comments on Hacker News

Hacker Newsgithub.blogJul 2
1827ENG

Herdr: One terminal to rule them all

74 points, 46 comments on Hacker News

Hacker Newsherdr.devJul 2
1828ENG

The Physics of Memory (aka can Javascript ECS?)

Comments

Lobstersdmurph.comJul 2
1829ENG

Show HN: Meow – The 4th and final JavaScript runtime and toolchain

Yes, I said final. Fight me in the comments. But seriously: there are basically exactly 3 serious JS runtimes in the world. (Now 4... or 1, idk). Why? Because the modern JS ecosystem is a fragmented, bloated nightmare. Node, pnpm, tsc, eslint, prettier, vite. Each spins up its own V8 instance, parses your codebase from scratch, and leaves a graveyard of .json configs in your root directory. meow squishes it all into one cute 82MB binary. It’s a drop-in Node replacement, ultra-fast package manager, formatter, test runner, linter, checker and bundler. I didn't write a JS engine from scratch, I'm not that depressed. meow uses V8 for stability and gets Node drop-in compat via deno_node (thanks Deno team). The secret sauce: meow parses your codebase exactly once into an Oxc AST in memory. That single graph natively feeds the runtime, linter, formatter, typechecker, and bundler. No redundant allocations. Just the fastest JavaScript tooling available, completely unified. 0-Byte Duplicated nod

Hacker Newsmeow.styleJul 2
1830ENG

A new Android malware from Google

478 points, 213 comments on Hacker News

Hacker Newsf-droid.orgJul 2

Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles