Skip to main content
Live Feed

Engineering &
Security Wire

Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.

21
ENG
8
SEC
1
AI
7401
TOTAL
Fri, Jun 26, 2026
30
2371ENG

The Excavator That Digs to a Line It Cannot See – Mobility and Field Robotics

4 points, 0 comments on Hacker News

Hacker Newsatomsfrontier.substack.comJun 26
2372ENG

Presentation: AI Works, Pull Requests Don’t: How AI Is Breaking the SDLC and What To Do About It

Michael Webster discusses the rise of headless AI agents and their impact on software delivery pipelines. He shares how massive, AI-generated pull requests create a severe bottleneck for human reviewers and introduce persistent technical debt. Learn how engineering leaders can leverage test impact analysis and automated validation pipelines to verify agentic output without sacrificing stability. By Michael Webster

InfoQinfoq.comJun 26
2373ENG

Why have papers by one of history's most famous physicists been retracted?

Article URL: https://www.science.org/content/article/why-have-papers-one-history-s-most-famous-physicists-been-retracted Comments URL: https://news.ycombinator.com/item?id=48686834 Points: 152 # Comments: 55

Hacker Newsscience.orgJun 26
2374ENG

Reflecting to optimise

19 points, 1 comments on Hacker News

Hacker Newsmagnusross.github.ioJun 26
2375SEC

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of the CVE assignment on June 16. Red Hat rates the flaw as

The Hacker News (Security)thehackernews.comJun 26
2376SEC

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon's AI coding assistant handled Model Context Protocol (MCP) servers. Wiz

The Hacker News (Security)thehackernews.comJun 26
2377ENG

GuixPkgs: every Guix package, as a Nix flake

Comments

Lobstersfzakaria.comJun 26
2378ENG

Incident CVE-2026-LGTM

Article URL: https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html Comments URL: https://news.ycombinator.com/item?id=48686093 Points: 233 # Comments: 40

Hacker Newsnesbitt.ioJun 26
2379ENG

How PgBouncer Works

Comments

Lobstersaugusteo.comJun 26
2380ENG

Space Shuttle Endeavour's 20-story vertical display

29 points, 4 comments on Hacker News

Hacker Newscaliforniasciencecenter.orgJun 26
2381ENG

Engineering for Bounded Cognition

38 points, 6 comments on Hacker News

Hacker Newsshapeofthesystem.comJun 26
2382SEC

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is

The Hacker News (Security)thehackernews.comJun 26
2383ENG

Transitioning as a hubber

How GitHub's culture and benefits helped me be the best version of myself. The post Transitioning as a hubber appeared first on The GitHub Blog.

GitHub Bloggithub.blogJun 26
2384ENG

Argo CD 3.5 Tightens Supply Chain Security with Internal mTLS and Source Integrity

The Argo CD project released a v3.5 release candidate in June 2026. This version adds mutual TLS enforcement for internal components. It also includes Git commit signature verification for supply chain security and native ApplicationSet management in the UI. The release also graduates two significant features: impersonation and Source Hydrator, from alpha to beta. By Claudio Masolo

InfoQinfoq.comJun 26
2385ENG

Dapr 1.18 Introduces Verifiable Execution, Bringing Cryptographic Trust to AI Agents and Workflows

Diagrid has announced the release of Dapr 1.18, introducing what it calls Verifiable Execution, a new set of capabilities designed to bring cryptographic trust, provenance, and tamper-evident execution records to distributed applications and AI agents. By Craig Risi

InfoQinfoq.comJun 26
2386SEC

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch landed in

The Hacker News (Security)thehackernews.comJun 26
2387ENG

Ultrasound Imaging of the Brain

Article URL: https://alephneuro.com/blog/ultrasound-brain Comments URL: https://news.ycombinator.com/item?id=48685558 Points: 63 # Comments: 16

Hacker Newsalephneuro.comJun 26
2388SEC

Guardian Agents: The Next Layer of Identity Governance

AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn't designed for autonomous actors, and the gap between what enterprises are deploying and what their governance programs actually cover is widening fast. This guide breaks

The Hacker News (Security)thehackernews.comJun 26
2389ENG

Design Patterns Suck

Comments

Lobstersluminousmen.comJun 26
2390SEC

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go

The Hacker News (Security)thehackernews.comJun 26
2391ENG

Chatbots vs Ozone

Comments

Lobstersblog.dshr.orgJun 26
2392AI

Previewing GPT-5.6 Sol: a next-generation model

OpenAI previews GPT-5.6 Sol, a next-generation model with stronger capabilities in coding, science, and cybersecurity, paired with its most advanced safety stack.

OpenAI Blogopenai.comJun 26
2393ENG

All you need is PostgreSQL

Comments

Lobstersebellani.github.ioJun 26
2394SEC

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the activity to a known threat actor, and the operators' end goal is still unclear. The lure plays to how hotels work.

The Hacker News (Security)thehackernews.comJun 26
2395ENG

The Baffling World of Masayoshi Son's Presentations (2020)

29 points, 6 comments on Hacker News

Hacker Newsbloomberg.comJun 26
2396SEC

Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff

Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding, published June 25 by the Citizen Lab, rests on two things that rarely line up: traces on the phone itself and an official Russian

The Hacker News (Security)thehackernews.comJun 26
2397ENG

How much? The hidden costs of restaurant dishes

Article URL: https://www.theguardian.com/food/2026/jun/26/how-much-the-hidden-costs-of-restaurant-dishes Comments URL: https://news.ycombinator.com/item?id=48684060 Points: 10 # Comments: 0

Hacker Newstheguardian.comJun 26
2398ENG

What are you doing this weekend?

Feel free to tell what you plan on doing this weekend and even ask for help or feedback. Please keep in mind it’s more than OK to do nothing at all too!

Lobsterslobste.rsJun 26
2399ENG

Why current LLM costs are not sustainable

Article URL: https://aditya.patadia.org/p/ai-and-cloud-costs Comments URL: https://news.ycombinator.com/item?id=48683588 Points: 86 # Comments: 104

Hacker Newsaditya.patadia.orgJun 26
2400ENG

Wallace the 6 inch f/2.8 telescope, building it, and hiking with it

81 points, 11 comments on Hacker News

Hacker Newslucassifoni.infoJun 26

Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles