Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Q&A with Micron's VP and GM of Memory
3 points, 0 comments on Hacker News
The Threat of Residential Proxies
Comments
Generating the P3 Tiling
Comments
Night Witches – all-female Soviet aviator regiment WW2
46 points, 16 comments on Hacker News
Amazon seller reveals glimpse of shadow bribery market
Article URL: https://www.latimes.com/business/story/2026-06-30/shadow-bribery-market-inside-amazon-preys-on-desperate-sellers Comments URL: https://news.ycombinator.com/item?id=48736839 Points: 61 # Comments: 33
Claude Sonnet 5
720 points, 394 comments on Hacker News
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire. The work comes from Microsoft Incident Response and its
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing. The end goal is a
I built a mmWave material classification radar (2025)
109 points, 30 comments on Hacker News
How GitHub maintains compliance for open source dependencies
Explore how the Open Source Program Office uses GitHub’s new license compliance product to manage open source dependencies at scale. The post How GitHub maintains compliance for open source dependencies appeared first on The GitHub Blog.
Claude Science
291 points, 100 comments on Hacker News
Show HN: My 13-year-old built an ant colony tracker
17 points, 10 comments on Hacker News
Nano Banana 2 Lite
250 points, 98 comments on Hacker News
Show HN: A statically typed, cross-platform, easily bootstrappable build system
20 points, 6 comments on Hacker News
Start building with Nano Banana 2 Lite and Gemini Omni Flash
Underappreciated builtin: Grand Unified Debugger
Comments
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)
Claude Code Is Steganographically Marking Requests
72 points, 1 comments on Hacker News
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McAfee Labs. "The campaign is delivered through unsigned installers – observed in both .NET and Golang variants – that
The labor share of income in the US is at its lowest post-war level
Article URL: https://libertystreeteconomics.newyorkfed.org/2026/06/the-post-covid-decline-in-the-labor-share/ Comments URL: https://news.ycombinator.com/item?id=48734234 Points: 73 # Comments: 11
We moved our Bluesky data to Eurosky
Article URL: https://waag.org/en/article/why-we-moved-our-bluesky-data-eurosky/ Comments URL: https://news.ycombinator.com/item?id=48733937 Points: 21 # Comments: 5
Presentation: Trustworthy Productivity: Securing AI-Accelerated Development
Sriram Madapusi Vasudevan discusses industry-converging patterns for securing autonomous AI agents in production. He explains the critical vulnerabilities hidden inside the ReAct loop across context, reasoning, and tool execution. He shares how to mitigate risks like memory poisoning and rogue tool execution using defense-in-depth strategies, LLM-as-a-judge critics, and MAESTRO threat modeling. By Sriram Madapusi Vasudevan
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use agents the firm tested. Only one, "Continue," was built to
Have you restarted your computer this week?
71 points, 160 comments on Hacker News
Looking Ahead to Postgres 19
Article URL: https://www.snowflake.com/en/blog/engineering/postgresql-19-features-beta/ Comments URL: https://news.ycombinator.com/item?id=48733031 Points: 89 # Comments: 48
How do wombats poop cubes?
65 points, 24 comments on Hacker News
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key at all. Whoever grabs it can send model requests on the developer's account,
Slint and the Node.js Event Loop
Comments
Red Programming Language: Static linking support
31 points, 4 comments on Hacker News
stop asking writers about "AI"
Comments
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles