Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
May in Servo: user scripts, mp4 compat, blackboxing in DevTools, and more
Comments
Soatok’s Informal Guide to Threat Models
Comments
Elastic Open-Sources Atlas Agent Memory Based on Cognitive Science
Elastic open-sourced Atlas, a system built on Elasticsearch that maintains three categories of memory for agents. Atlas integrates with agents via MCP and maintains per-user isolation of memories. When evaluated on question-answering capability, it scored 0.89 Recall@10. By Anthony Alford
Knoppix
Article URL: https://www.knopper.net/knoppix/index-en.html Comments URL: https://news.ycombinator.com/item?id=48732056 Points: 50 # Comments: 29
Memoirs of Extraordinary Popular Delusions and the Madness of Crowds (1852)
Article URL: https://www.gutenberg.org/ebooks/24518 Comments URL: https://news.ycombinator.com/item?id=48731989 Points: 91 # Comments: 21
Microsoft Brings AI-Powered Vulnerability Remediation to Azure DevOps with Copilot Autofix
Microsoft has announced the limited public preview of Copilot Autofix for GitHub Advanced Security for Azure DevOps, extending AI-powered vulnerability remediation to teams using Azure Repos. By Craig Risi
What the Numbers Say About FIFA 2026 Cyber Risk
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten languages. Check Point Exposure Management published the FIFA World Cup 2026 Cyber Threat Report this month, covering
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated
Diagrams for Penrose Tiles
Comments
Hunting a 16-year-old SQLite WAL bug with TLA+
29 points, 2 comments on Hacker News
Parse, Don't Validate – In a Language That Doesn't Want You To
Article URL: https://cekrem.github.io/posts/parse-dont-validate-typescript/ Comments URL: https://news.ycombinator.com/item?id=48730818 Points: 98 # Comments: 78
European digital ID wallets rely on safety services of Google and Apple
Article URL: https://waag.org/en/article/european-digital-id-wallets-are-gift-google-and-apple/ Comments URL: https://news.ycombinator.com/item?id=48730729 Points: 543 # Comments: 230
Zluda 6 release (run unmodified CUDA applications on non-Nvidia GPUs)
Article URL: https://vosen.github.io/ZLUDA/blog/zluda-update-q1q2-2026/ Comments URL: https://news.ycombinator.com/item?id=48730713 Points: 70 # Comments: 6
Exercise intensity influences body composition in healthy older adults (2025)
Article URL: https://www.maturitas.org/article/S0378-5122(25)00571-7/fulltext Comments URL: https://news.ycombinator.com/item?id=48730694 Points: 135 # Comments: 109
The US ambassador had Belgian police stop our reporting
Article URL: https://europeancorrespondent.com/en/r/the-us-ambassador-had-belgian-police-stop-our-reporting Comments URL: https://news.ycombinator.com/item?id=48730608 Points: 581 # Comments: 232
Local Reasoning for Global Properties
Comments
Furality Ultra Club A/V Writeup
Comments
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on a Mac or iPhone set to receive from anyone, with no tap or prompt. The same research found Quick Share flaws that
AWS Launches Lambda MicroVMs for Isolated Agent and User Code Execution
AWS launched Lambda MicroVMs, a new serverless compute primitive that runs each user session or AI agent in its own Firecracker virtual machine with hardware-level isolation, snapshot-based rapid launch, and state preservation for up to eight hours. Reddit community analysis found the minimum setup costs $3.03/day, roughly 9x Fargate spot pricing. By Steef-Jan Wiggers
Article: Scaling Java-Based Real-Time Systems: The Hidden Tradeoffs of Event-Driven Design
Event-driven architecture promises scalability, but in Java-based real-time systems the tradeoffs only surface in production. Drawing on a Java/Kafka contact center platform handling 80k BHCC across 10k agents, this article details where the design breaks down—state management, partition limits, deduplication, JVM tuning, cascading consumer failures—and the Redis-backed patterns that fixed each. By Sagar Deepak Joshi
How ChatGPT adoption has expanded
New OpenAI Signals data shows how ChatGPT adoption is growing globally, with users increasing usage, exploring more capabilities, and driving growth across regions and languages.
jj_tui: terminal user interface to jujutsu focused on speed and clarity
Comments
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. The targets included OpenAI's ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude browser extension. An
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now. Progress published its advisory on June
Platform Support for GNU Extensions to Basic Regular Expressions
Comments
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebKit vulnerabilities are listed below - CVE-2026-43707 - A memory corruption issue that could result in an
Investigating Linux graphics (2025)
Comments
Popping the GPU Bubble
Article URL: https://moondream.ai/blog/popping-the-gpu-bubble Comments URL: https://news.ycombinator.com/item?id=48728729 Points: 131 # Comments: 32
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances. "Easily exploitable vulnerability allows
Revisiting Yliluoma’s ordered dither algorithm
Comments
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles