Engineering &
Security Wire
Curated from Hacker News, Lobsters, Krebs on Security, and other top sources. Updated every 6 hours.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
60 points, 12 comments on Hacker News
Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
Cloudflare has deployed two WAF rules in response to high-severity vulnerabilities disclosed to us by the WordPress security team. The new rules protect all Cloudflare customers using affected WordPress versions, but customers should still update immediately to a patched release.
I built a digital F1 garage to learn how Formula 1 cars work
3 points, 1 comments on Hacker News
Everybody's Weirded Out by AI–Except the People Who Foist It on Us
Article URL: https://newrepublic.com/article/213004/everybody-weirded-ai-except-people-foist-us Comments URL: https://news.ycombinator.com/item?id=48952445 Points: 44 # Comments: 14
FAA lets Boeing sign off on 737 MAX, 787 airworthiness certificates again
28 points, 4 comments on Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported
Lobsters Interview with matheusmoreira about Lone Lisp
@matheusmoreira (blog) built lone lisp directly on Linux system calls. In this interview, he shares his knowledge of C and the Linux Kernel. How did you get into computing originally? What was your path before discovering Lisp etc.? I've always liked computers, but what truly got me into programming was video games. When I was a kid, I used to play games from a series called Mega Man Battle Network, and I ended up getting inspired by those games. They're ultimately responsible for my learning English; I used to join forums as a non-English speaker and try to socialize. It was rough at the start but I improved! The same goes for my first language, C++. How young were you when you started with C++? In Brazil there are "technical schools" which is what I attended. They're normal highschool curriculum, with extra professional classes. I'm not sure if these are common abroad, if there is a term for it. There were other courses, also: chemistry, mechatronics... As for quality, it was basic,
The Java Story | The Official Documentary
Comments
Open Book Touch: open-source e-reader
77 points, 17 comments on Hacker News
Topcoat: The full full-stack framework for Rust
55 points, 32 comments on Hacker News
Static search trees: 40x faster than binary search (2024)
67 points, 3 comments on Hacker News
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the
Painting the sides of railroad rails white to reduce derailment
63 points, 29 comments on Hacker News
Tech note: making your own V-I plots at home
25 points, 2 comments on Hacker News
Faulty Towers, vibe sickness, and the vibe bobsled
Comments
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
Show HN: A zoomable timeline of 4M Wikipedia events
32 points, 17 comments on Hacker News
Lego building instructions through time
Article URL: https://www.lego.com/en-us/history/articles/d-lego-building-instructions-through-time Comments URL: https://news.ycombinator.com/item?id=48950518 Points: 19 # Comments: 4
Learning a few things about running SQLite
106 points, 24 comments on Hacker News
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter
Thanks HN for 15 years of support and helping me find my life's work
Tomorrow is the 15th anniversary of the first day of the Recurse Center (https://www.recurse.com/) My cofounders and I did YC all the way back in the Summer of 2010, with the initial idea of building "OkCupid for jobs." That idea quickly fizzled, and we spent the better part of a year pivoting between other ideas that also failed. Finally, we made something that we wanted ourselves: a self-directed programming retreat, where people built fun projects, contributed to open source, and helped each other become better programmers. After running two small batches, we launched on HN[1] and got an incredible reception. That post on HN helped us reach beyond our personal networks and meet programmers from around the world, many of whom have since become friends. HN brought us the majority of people who came to our next few batches, and in the years since, HN has remained our #2 source of applicants (after word of mouth). Alas, pg's comment[2] on HN when we launched turned out to be prescient:
The cost of saying yes has changed
The cost of writing code dropped; the cost of owning it didn't. A framework for deciding which changes are actually cheap in the AI era. The post The cost of saying yes has changed appeared first on The GitHub Blog.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using
Homomorphically encrypted CIFAR-10 inference in 200ms
Article URL: https://sofar.belfortlabs.cloud/ Comments URL: https://news.ycombinator.com/item?id=48949240 Points: 37 # Comments: 28
Show HN: Explore the Workspaces of Modern Creators
8 points, 4 comments on Hacker News
Frame – Linux X server in Assembly
123 points, 83 comments on Hacker News
Introducing Gemini 3.5 Flash Cyber
Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.
Mozilla: The state of open source AI
116 points, 50 comments on Hacker News
Claude Code: Anatomy of a Misfeature
61 points, 26 comments on Hacker News
Show HN: On-chain bond market where the issuers are AI agents
8 points, 6 comments on Hacker News
Aggregated from public RSS feeds & the Hacker News API · All links point to original sources · Clawship does not republish full articles