Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices. "This is the first documented case where a frontier AI model
Postgres data stored in Parquet on S3: LTAP architecture explained
23 points, 9 comments on Hacker News
Show HN: Claudoro, Pomodoro timer embedded in the Claude Code statusline
22 points, 17 comments on Hacker News
HeroUI v3 Lands as a Ground-Up Rewrite for React and React Native, Built on Tailwind CSS v4
HeroUI v3 is a redesigned React component library, previously NextUI, offering over 75 components, including 21 new ones, and a new React Native library with 37 components. Built on React Aria and Tailwind CSS v4, it emphasizes accessibility and customization. The library has experienced many updates since its release, and migration from the previous version is necessary. By Daniel Curtis
Physical disc production ending in Jan 2028 for new games on PlayStation
484 points, 547 comments on Hacker News
Announcing Box3D :: Box2D
128 points, 27 comments on Hacker News
Show HN: Frond – a frontend runtime for your app's dependency graph
Article URL: https://frondruntime.dev Comments URL: https://news.ycombinator.com/item?id=48745434 Points: 16 # Comments: 9
The Internet I Grew Up With Doesn’t Exist Anymore
Comments
How Jujutsu Rethinks Git's Working Copy and Conflict Model
Comments
Nintendo has raised its employees base salary by 10%
328 points, 156 comments on Hacker News
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
Organizations have never had greater awareness of cyber risk. Yet turning that awareness into operational resilience has never been more challenging. The 2026 Bitdefender Cybersecurity Assessment confirms this is the case, as this year's findings reveal a series of surprising contradictions. Here are a few examples, based on the independent survey of 1,200 IT and cybersecurity professionals
All Package Management Functionality Moved from Compiler to Build System
Comments
Presentation: The Infrastructure Challenge Behind Production AI
The panelists explain the realities of running AI systems reliably at scale. While building models is solved, maintaining production databases under constant pressure is not. They discuss the emerging architectural decisions separating teams that scale gracefully from those facing catastrophic outages, and what engineering leaders must rethink today. By Simerus Mahesh, Alex Infanzon, Meryem Arik, Luca Bianchi, Renato Losio
Changes to Godot Engine Contribution Policies
Comments
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected. "Advances in quantum research and development have shifted the risk horizon," Mark Russinovich, chief technology officer of Microsoft Azure, said. "We believe
Building a passive Ethernet tap
Comments
Which GitHub features are needed in a code forge before you can migrate?
Which GitHub features would you consider a blocker for migrating to a different code forge, and in what order do you prioritize them? Context: I am heads down building a code forge (https://juju.bi) based on three ideas: Code collaboration part should work offline Should be compatible with GitHub API (like how some services are considered S3 compatible) Support change-id based features (ex: Jujutsu's evolog) I shipped a super-early version that I am currently dogfooding. https://juju.bi/changelog/2026-07-01-alpha-release I am currently focused on improving the experience for small teams working on private repos. I would like to polish the overall product before thinking about public repos. (A lot of great forges exist for public repos right now).
Asahi Linux 7.1 Progress Report
416 points, 125 comments on Hacker News
Dexter (YC F24) Is Hiring a Founding Engineer in Berlin
Comments URL: https://news.ycombinator.com/item?id=48744213 Points: 0 # Comments: 0
Register Korea's First PC 'SE-8001' as a National Important Material
Article URL: https://www.dongascience.com/en/news/30374 Comments URL: https://news.ycombinator.com/item?id=48743655 Points: 7 # Comments: 2
Who's hiring? Q3 2026
Please, use the template: **Company website:** WWW **Position(s):** ABC **Location:** XXX (include whether REMOTE worldwide/US/EU/etc. or ONSITE) **Description:** XYZ **Tech stack:** ABC **Compensation:** XXX (salary, equity, vacation, major benefits) **Contacts:** WWW
Godot will no longer accept AI-authored code contributions
Article URL: https://www.pcgamer.com/gaming-industry/open-source-game-engine-godot-will-no-longer-accept-ai-authored-code-contributions-we-cant-trust-heavy-users-of-ai-to-understand-their-code-enough-to-fix-it/ Comments URL: https://news.ycombinator.com/item?id=48743472 Points: 127 # Comments: 67
Apricot Computers: An underrated British brand
47 points, 13 comments on Hacker News
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way. Palo Alto Networks' Unit 42 calls the trick phantom squatting, and its new research shows it is already happening in the wild. The reason it matters is
Uruky - The Paid European Search Engine
Comments
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a half weeks earlier. Fable 5 returns to users on Wednesday, July 1, across Claude.ai, the Claude Platform, Claude Code, and Claude Cowork. Export controls restrict who can
Hanami 3.0: In full bloom
Comments
Unmasking the crawls with Attribution Business Insights
Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167). "Between June 12 and June 26, the threat
IEEE Rolls Out Large Language Models Training Course
5 points, 0 comments on Hacker News
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles