Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
What happens when you run a CUDA kernel?
74 points, 4 comments on Hacker News
Tidal AI Policy
179 points, 212 comments on Hacker News
Reading the internals of Postgres: Database cluster, databases, and tables
27 points, 0 comments on Hacker News
Presentation: Million PDFs: Building a Modern Document Infrastructure with Rust and Typst
Erik Steiger discusses the operational pain of legacy PDF generation in regulated banking and manufacturing. He explains how transitioning from resource-heavy engines like Puppeteer and LaTeX to a serverless Rust architecture powered by Typst can drop render latencies below 2ms. He shares how applying Git and Docker concepts to template registries ensures ironclad compliance and rapid debugging. By Erik Steiger
Samsung, SK Hynix, Micron Sued in US over Memory Price Fixing
134 points, 59 comments on Hacker News
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation
Why Post-Quantum Cryptography Starts With Credentials
Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine today can break elliptic curve cryptography or RSA, quantum hardware is advancing rapidly and will inevitably change how organizations protect their data. Ciphertext and credentials captured by
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the year. Primary targets of these
Rebuilding the Computer Room
50 points, 19 comments on Hacker News
Podcast: Architectural Patterns: Moving Beyond Cloud-Native to Local-First - Insights from Adam Wiggins
In this episode, Heroku co-founder and Ink & Switch founder Adam Wiggins argues for a 'local-first' architecture that reconciles cloud-based collaboration with the performance and data ownership of local software. He explores the role of CRDTs and version control primitives in non-code domains, and examines how a hybrid AI future might leverage local models for core productivity tasks. By Adam Wiggins
Article: Virtual panel: Security in the Machine Age: Expert Insights on AI Threat Evolution
This virtual panel brings together AI security experts to examine the evolution of AI-driven threats, from prompt injection and data poisoning to agent abuse and AI-powered social engineering. The discussion explores emerging attack patterns, incident response challenges, and the changes security teams must make as AI systems become more autonomous and integrated into critical workflows. By Claudio Masolo, Elham Arshad, Sabri Allani, Vijay Dilwale, Igor Maljkovic
Sandia National Labs SA3000 8085 CPU
104 points, 28 comments on Hacker News
Pollen (CEO Negus-Fancey, CTO Wright) tried to remove article, and Google helped
12 points, 1 comments on Hacker News
Why did this journal retract two 1940s papers by Max Planck?
120 points, 5 comments on Hacker News
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat actor it says has been active since at least 2021.
AI Tools Accelerates Coding, but Not Overall Software Delivery, GitLab Research Finds
GitLab's 2026 AI Accountability Report highlights an AI Paradox: although 78% of developers say they code faster, overall software delivery has not accelerated due to downstream testing and review bottlenecks and new challenges for enterprise governance and traceability. By Sergio De Simone
What are you doing this week?
What are you doing this week? Feel free to share! Keep in mind it’s OK to do nothing at all, too.
US Grid Constraints: Towards 40GW+ of Behind-the-Meter Datacenter by 2028?
26 points, 30 comments on Hacker News
Canvas patch: we need testers
Comments
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2. libssh2 is a client-side SSH library, not a server.
Mapping Europe’s AI Workforce Opportunity
A new OpenAI report maps how AI could reshape jobs across the EU, highlighting which occupations may face automation, growth, or workflow changes.
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. "This attack avoids the most common npm execution paths through lifecycle scripts, perhaps in an attempt to remain 'compatible' with npm v12's security hardenings," JFrog said in a
My Favorite Keyboards
21 points, 11 comments on Hacker News
Herdr: Agent multiplexer that lives in your terminal
69 points, 35 comments on Hacker News
Kivo - A lightweight desktop teleprompter built with PySide6
Kivo provides a clean, always-on-top reading overlay for scripts, AI-generated content, presentations, and video recordings. Features Frameless, always-on-top overlay Modern rounded UI with a translucent background Draggable window Open any text (.txt) file Automatically reloads when the file changes Smooth teleprompter-style auto-scrolling Adjustable scrolling speed Pause and resume scrolling Lightweight and distraction-free Comments
Optimizing LLVM's bump allocator
Comments
Age verification is just a precursor to automated attribution of speech
39 points, 1 comments on Hacker News
Tell Congress: Don't Force Age Checks Online
Article URL: https://act.eff.org/action/tell-congress-don-t-force-age-checks-online Comments URL: https://news.ycombinator.com/item?id=48713887 Points: 60 # Comments: 16
HackerRank open sourced its ATS. My resume scored 90/100. Oh wait 74. No – 88
443 points, 159 comments on Hacker News
Ante: New Way to Blend Borrow Checking and Reference Counting
Comments
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles