Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
Qwen 3.6 27B is the sweet spot for local development
Article URL: https://quesma.com/blog/qwen-36-is-awesome/ Comments URL: https://news.ycombinator.com/item?id=48721903 Points: 453 # Comments: 404
What is `std::pin::Pin` in Rust?
Comments
Obfuscation: Building the final boss of cryptography (Part I)
62 points, 6 comments on Hacker News
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared first on The GitHub Blog.
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through usernames, as opposed to directly sharing their phone numbers. Username reservations will start rolling out starting today,
European ISPs Want Rightsholders Held Accountable for Overblocking Damage
Article URL: https://torrentfreak.com/european-isps-want-rightsholders-held-accountable-for-overblocking-damage/ Comments URL: https://news.ycombinator.com/item?id=48721072 Points: 289 # Comments: 74
US Supreme Court rules geofence warrants require constitutional protections
Article URL: https://www.theguardian.com/us-news/2026/jun/29/supreme-court-geofence-warrants-case-decision Comments URL: https://news.ycombinator.com/item?id=48720924 Points: 337 # Comments: 153
A native graphical shell for SSH
Article URL: https://probablymarcus.com/blocks/2026/06/28/native-graphical-shell-for-SSH.html Comments URL: https://news.ycombinator.com/item?id=48720758 Points: 193 # Comments: 83
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with
WATaBoy: JIT-Ing Game Boy Instructions to WASM Beats a Native Interpreter
35 points, 0 comments on Hacker News
Linux for the Sega MegaDrive
111 points, 15 comments on Hacker News
WebGL Without a GPU
Article URL: https://microlink.io/blog/webgl-without-a-gpu Comments URL: https://news.ycombinator.com/item?id=48720179 Points: 12 # Comments: 3
Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307
Comments
Working With AI: A concrete example
Article URL: https://htmx.org/essays/working-with-ai/ Comments URL: https://news.ycombinator.com/item?id=48720064 Points: 47 # Comments: 12
Eliya 25 Brings a JVM-Level Diagnostic Profile to OpenJDK 25 LTS
Asymm Systems has released Eliya 25.0.3, an OpenJDK 25 LTS distribution aimed at improving production diagnostics in Java environments. It consolidates several HotSpot features into an opt-in Production profile. Eliya is designed for teams needing reliable diagnostic data, especially in regulated settings. Future enhancements are planned for Phase 2. By A N M Bazlur Rahman
Evaluation order and nontermination in query languages
Comments
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting. Here’s the full Monday recap. ⚡ Threat of the Week New DirtyClone Linux Kernel Flaw Lets Local
Inside Target’s LLM-Based System for Semantic Matching in Marketing Forecast Pipelines
Target built a generative AI system to improve marketing campaign forecasting by retrieving and ranking similar historical campaigns. Using embeddings, vector search, and LLM ranking, it replaces rule-based workflows. Evaluation shows 75% top-1 and 100% top-3 coverage. The system reduces manual effort, improves consistency, and uses feedback loops to refine retrieval using campaign outcomes. By Leela Kumili
A field guide to the modern front end for developers who hand-wrote HTML
Article URL: https://davidpoblador.com/deep-dives/the-descent/ Comments URL: https://news.ycombinator.com/item?id=48719665 Points: 53 # Comments: 33
Mag 7 starting to underperform [pdf]
115 points, 87 comments on Hacker News
You Don't Know Jack About Formal Verification
Article URL: https://queue.acm.org/detail.cfm?id=3819084 Comments URL: https://news.ycombinator.com/item?id=48719521 Points: 79 # Comments: 28
Rocketlab acquires Iridium
83 points, 44 comments on Hacker News
DocumentDB – a MongoDB compatible open-source database
11 points, 6 comments on Hacker News
Loko Scheme 0.13.0
Comments
Typst: Designing for Incrementality
Comments
CachyOS June 2026 Release
35 points, 9 comments on Hacker News
Instagram is incorporating users' photos in ads for Meta Glasses
133 points, 54 comments on Hacker News
Building Principia for Windows XP
62 points, 13 comments on Hacker News
Studio Canal Movies purchased on PlayStation Store removed without refund
94 points, 49 comments on Hacker News
When Impressive Performance Gains Do Not Matter
Comments
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles