-
1. [Personal Project/Experiment Ideas]
-
2. [Race Condition Symphony: From Tiny Idea to Pwnie]
-
3. [CUDA de Grâce]
-
4. [Déjà Vu in Linux io_uring]
-
5. [Google 'Looking into' Gmail Hack Locking Users Out with No Recovery]
-
6. [Sam Altman's Dirty DRAM Deal]
-
7. [A struct sockaddr sequel]
-
8. [Let's Critique Mirai's Source-Code With a Glass (or a few) of Bitter Leaf.]
-
9. [Let's Critique Mirai's Source-Code With a Glass (or a few) of Bitter Leaf.]
-
10. [The missing standard library for multithreading in JavaScript]
-
11. [Leaving Intel]
-
12. [Adenosine on the common path of rapid antidepressant action: The coffee paradox]
-
13. [Kiwix RAG: Terminal Chat Interface with Local Kiwix Content Integration]
-
14. [Perpetual Futures]
-
15. [Frank Gehry has died]
-
16. [Osaurus Demo: Lightning-Fast, Private AI on Apple Silicon – No Cloud Needed!]
-
17. [The Debug Adapter Protocol is a REPL protocol in disguise]
-
18. [A $20 drug in Europe requires a prescription and $800 in the U.S.]
-
19. [Fizz Buzz in CSS]
-
20. [Fatemeh Sedighian Kashi & Mohammad Bagher Shirinkar – Rewards For Justice]
-
21. [macOS Stealers: Technical Analysis of Credential Harvesting]
-
22. [Judge Signals Win for Software Freedom Conservancy in Vizio GPL Case]
-
23. [Framework Sponsors CachyOS]
-
24. [Advertising as a major source of human dissatisfaction (2019) [pdf]]
-
25. [Zellij: A terminal workspace with batteries included]
-
26. [Coupongogo: Remote-Controlled Crypto Stealer Targeting Developers on GitHub]
-
27. [Return of ClayRat: Expanded Features and Techniques]
-
28. [UDPGangster Campaigns Target Multiple Countries]
-
29. [New FvncBot Android banking Trojan targets Poland]
-
30. [CYBERSEC MCP-MARKETPLACE (for free)]
-
31. [SpaceX in Talks for Share Sale That Would Boost Valuation to $800B]
-
32. [WikiFlix: Full Movies Hosted on Wikimedia Commons]
-
33. [Wall Street races to protect itself from AI bubble]
-
34. [Gemini 3 Pro: the frontier of vision AI]
-
35. [Show HN: SerpApi MCP Server]
-
36. [We Built Lightpanda in Zig]
-
37. [Synadia and TigerBeetle Pledge $512,000 to the Zig Software Foundation]
-
38. [Tried a soc alert management software trial and it caught the one real threat hiding in 200+ alerts]
-
39. [The AI Backlash Is Here: Why Public Patience with Tech Giants Is Running Out]
-
40. [Patterns for Defensive Programming in Rust]
-
41. [Jony Ive's OpenAI Device Barred from Using 'Io' Name]
-
42. [Onlook (YC W25) the Cursor for Designers Is Hiring a Founding Fullstack Engineer]
-
43. [Shingles vaccination prevented or delayed dementia]
-
44. [What do you think about this method to detect and prevent bias in LLM output?]
-
45. [Blood and stardust! Watch 9 local LLMs debate Star Wars vs Star Trek]
-
46. [New Vulnerable Web App: Duck Store – Explore & Learn Business Logic Vulnerabilities]
-
47. [Framework Laptop 13 gets ARM processor with 12 cores via upgrade kit]
-
48. [I'm Peter Roberts, immigration attorney who does work for YC and startups. AMA]
-
49. [LongCat-Image: 6B model with strong efficiency, photorealism, and Chinese text rendering]
-
50. [Windows Defender hijack]
-
51. [Show HN: Pbnj – A minimal, self-hosted pastebin you can deploy in 60 seconds]
-
52. [Jolla Phone Pre-Order]
-
53. [Covid-19 mRNA Vaccination and 4-Year All-Cause Mortality]
-
54. [Cloudflare outage on December 5, 2025]
-
55. [[Weekly Purple Team] Charon Loader/Cobalt Strike Defender Bypass + CS Beacon Detection]
-
56. [Behind the Walls: Techniques and Tactics in Castle RAT Client Malware]
-
57. [Weekly Purple Team: Learn the Bypass, Build the Detection (Charon Loader + CS Beacons)]
-
58. [Tracing JavaScript Value Origins in Modern SPAs: Breakpoint-Driven Heap Search (BDHS)]
-
59. [Influential study on glyphosate safety retracted 25 years after publication]
-
60. [Emerge Career (YC S22) Is Hiring]
-
61. [Translating WEBPAGES using LOCAL MODEL on IPAD - pushing what is possible on mobile devices]
-
62. [Hydrangea-C2-Payloads: A cross-platform, collaborative C2 for red-teaming. Agents are cross-compilable (e.g, you can generate Windows DLLs on Linux), cross-compatible, and built with evasion, anti-analysis and stability in mind. All capabilities are natively implemented from scratch.]
-
63. [[Weekly Purple Team] Charon Loader/Cobalt Strike + Defender Bypass + CS Beacon Secondary Action Detection]
-
64. [SSRF Payload Generator for fuzzing PDF Generators etc...]
-
65. [Turning 40]
-
66. [Show HN: Kraa – Writing App for Everything]
-
67. [Making RSS More Fun]
-
68. [Most technical problems are people problems]
-
69. [Trustable allows to build full stack serverless applications in Vibe Coding using Private AI and deploy applications everywhere, powered by Apache OpenServerless]
-
70. [Burp CVE-2025-55182CVE-2025-66478 React2Shell bambda]
-
71. [AI/LLM Red Team Handbook and Field Manual]
-
72. [Sugars, Gum, Stardust Found in NASA's Asteroid Bennu Samples]
-
73. [Netflix to Acquire Warner Bros. In an $82.7B Deal]
-
74. [I Replaced McKinsey With AI Agents — And Today I’m Finally Showing It]
-
75. [Whitebox (simulation) vs. blackbox (red team) phishing]
-
76. [Why We Can't Quit Excel]
-
77. [Basketball AI with RF-DETR, SAM2, and SmolVLM2]
-
78. [Kenyan court declares law banning seed sharing unconstitutional]
-
79. [The US polluters that are rewriting the EU's human rights and climate law]
-
80. [China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)]
-
81. [LIVE! Analyzing TTD traces in Binary Ninja with esReverse]
-
82. [Cloudflare Down Again – and DownDetector Is Also Down]
-
83. [Unredacted Magazine Issue 008 SEP 2025]
-
84. [Microsoft Silently Patched CVE-2025-9491 - We Think Our Patch Provides More Security]
-
85. [Undisclosed Deaths in the Pfizer mRNA Covid-19 Vaccine Trial [pdf]]
-
86. [UniFi 5G]
-
87. [Where AI Is Really Going ?]
-
88. [摩诃草(APT-Q-36)利用 WebSocket 的新木马 StreamSpy 分析 - Analysis of the new Trojan StreamSpy using WebSocket, which is called Mahayana (APT-Q-36).]
-
89. [Yesterday I came across this method in medium]
-
90. [Warner Bros Begins Exclusive Deal Talks With Netflix]
-
91. [Decoding Brickstorms Garble strings]
-
92. [Investigating Shai-Hulud: Inside the NPM Supply Chain Worm]
-
93. [Calisto Targets Reporters Without Borders in Phishing Campaign]
-
94. [Rats Snatching Bats Out of the Air and Eating Them–Researchers Got It on Video]
-
95. [State Department to deny visas to fact checkers and others, citing 'censorship']
-
96. [Netflix in exclusive talks to buy HBO]
-
97. [Privilege escalation with SageMaker and there's more hiding in execution roles]
-
98. [Fast trigram based code search]
-
99. [Blogging in 2025: Screaming into the Void]
-
100. [I have been writing a niche history blog for 15 years]
-
101. [Brussels writes so many laws]
-
102. [Doradus/MiroThinker-v1.0-30B-FP8 · Hugging Face]
-
103. [Spear Phishing/Loader Distribution to Malware Analysts]
-
104. [What is better: a lookup table or an enum type?]
-
105. [NeurIPS best paper awards 2025]
-
106. [The Ofcom Files, Part 4: Ofcom Rides Again]
-
107. [BMW PHEV: When EU engineering becomes a synonym for "unrepairable" (EV Clinic)]
-
108. [Scam Telegram: Uncovering a network of groups spreading crypto drainers]
-
109. [StardustOS: Library operating system for building light-weight Unikernels]
-
110. [AV1 – Now Powering 30% of Netflix Streaming]
-
111. [We gave 5 LLMs $100K to trade stocks for 8 months]
-
112. [SMS phishers pivot to points, taxes, fake retailers]
-
113. [What is a Package Manager?]
-
114. [Gemma-2-MoE: Frankenstein MoE Builder for Gemma 2]
-
115. [I built a browser automation agent that runs with NO LLM and NO Internet. Here’s the demo.]
-
116. [State of AI: An Empirical 100T Token Study with OpenRouter]
-
117. [Countdown until the AI bubble bursts]
-
118. [[open source] I finetuned my own LLM in 20m on my personal notes. Now it thinks in my style.]
-
119. [speed optimizations for Qwen Next on CUDA have been merged into llama.cpp]
-
120. [Qwen3 Next now with full CUDA support (#16623 merged)]
-
121. [Thoughts on Go vs. Rust vs. Zig]
-
122. [Django 6]
-
123. [CUDA-L2: Surpassing cuBLAS Performance for Matrix Multiplication Through RL]
-
124. [Plane crashed after 3D-printed part collapsed]
-
125. [HalluBench: LLM Hallucination Rate Benchmark]
-
126. [Using Cobalt Strike to Find (More) Cobalt Strike]
-
127. [Small blue 'stylized' globe in the right bottom corner just appeared. PC performance lagging]
-
128. [EU's Top Court Just Made It Impossible to Run a User-Generated Platform Legally]
-
129. [Who Hooked Up a Laptop to a 1930s Dance Hall Machine?]
-
130. [Hammersmith Bridge – Where did 25,000 vehicles go?]
-
131. [Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks]
-
132. [My EDR now parses PE NT headers (Machine, Sections, EntryPoint, Subsystem)]
-
133. [Prompt Injection Inside GitHub Actions]
-
134. [PyTogether: Collaborative lightweight real-time Python IDE for teachers/learners]
-
135. [Why are 38 percent of Stanford students saying they're disabled?]
-
136. [The RAM shortage comes for us all]
-
137. [Intellexa’s Global Corporate Web]
-
138. [Crucial shutting down as Micron wants to sell RAM/SSDs to AI companies instead]
-
139. [The Big Security Problem Of Google Antigravity]
-
140. [Computer Use with Claude Opus 4.5]
-
141. [Agent for AdaptixC2 containing lateral movement capabilities ( WMI, SCM, WinRM, DCOM), bof/dotnet/shellocde in memory executions, postex modules with shellcode and bof with possibilities of fork executions (spawn/explicit)]
-
142. [Adventures in Dynamic Evasion]
-
143. [Intellexa’s Prolific Zero-Day Exploits Continue]
-
144. [Israeli Spyware firm owned by ex-intel officer still active despite U.S. sanctions]
-
145. [To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab]
-
146. [Building trust in the digital age: a collaborative approach to content provenance technologies]
-
147. [BRICKSTORM Backdoor]
-
148. [Live Stream from Inside Lazarus Group’s IT Workers Scheme]
-
149. [CVE Proof-of-Concept Finder: A Direct Lens Into Exploit Code]
-
150. [Second order prompt injection attacks on ServiceNow Now Assist]
-
151. [The End of the Train-Test Split]
-
152. [Autism should not be treated as a single condition]
-
153. [Converge (YC S23) is hiring a martech expert in NYC]
-
154. [Multivox: Volumetric Display]
-
155. [Rust HF Downloader, version 1.1 (final?)]
-
156. [Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary]
-
157. [Bootloader Unlock Wall of Shame]
-
158. [Feynman vs. Computer]
-
159. [Show HN: OnlyRecipe 2.0 – I added all features HN requested – 4 years later]
-
160. [Proxmox Datacenter Manager 1.0 available]
-
161. [Microsoft drops AI sales targets in half after salespeople miss their quotas]
-
162. [Launch HN: Browser Buddy (YC W24) – A recommendation system for Internet writing]
-
163. [The Math Legend Who Just Left Academia–For an AI Startup Run by a 24-Year-Old]
-
164. [The Free Software Foundation Europe deleted its account on X]
-
165. [SVG Filters - Clickjacking 2.0]
-
166. [How We Caught Lazarus's IT Workers Scheme Live on Camera]
-
167. [Imo.im – Instant Messenger]
-
168. [Human hair grows through 'pulling' not pushing, study shows]
-
169. [The Age-Gated Internet Is Sweeping the US. Activists Are Fighting Back]
-
170. [Japanese Four-Cylinder Engine Is So Reliable Still in Production After 25 Years]
-
171. [Transparent Leadership Beats Servant Leadership]
-
172. [RAM is so expensive, Samsung won't even sell it to Samsung]
-
173. [Functional Quadtrees]
-
174. [NRC Completes Safety Review of TerraPower Natrium [pdf]]
-
175. [30 years ago today "Netscape and Sun announce JavaScript"]
-
176. [I ignore the spotlight as a staff engineer]
-
177. [Programming peaked]
-
178. [Token Visualizer]
-
179. [CVE PoC Search]
-
180. [Porn company fined £1M over inadequate age checks (UK)]
-
181. [Building optimistic UI in Rails (and learn custom elements)]
-
182. [NextJS Security Vulnerability]
-
183. [Tunnl.gg]
-
184. [How do I Inspect virtual memory page tables physical memory on windows]
-
185. [Unreal Tournament 2004 is back]
-
186. [Oracle, it’s time to free JavaScript]
-
187. [How do sites like SnapTik get the TikTok video without the watermark?]
-
188. [The Mysterious Realm of JavaScriptCore (2021)]
-
189. [Are You Curiouser? - Pick a topic and try to create the most curious question]
-
190. [GitHub - Ilke-dev/E2EE-py: Simple End-2-End-Encryption for python]
-
191. [How AI is transforming work at Anthropic]
-
192. [Elites Could Shape Mass Preferences as AI Reduces Persuasion Costs]
-
193. [New model, microsoft/VibeVoice-Realtime-0.5B]
-
194. [ConcoLLMic: Symbolic execution on any language with LLMs]
-
195. [Opinion on this method that i came across.]
-
196. [High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)]
-
197. [Show HN: Mirror_bridge – C++ Reflection powered Python binding generation]
-
198. [Uncloud - Tool for deploying containerised apps across servers without k8s]
-
199. [Saturn (YC S24) Is Hiring Senior AI Engineer]
-
200. [[Tool] Tiny MCP server for local FAISS-based RAG (no external DB)]
-
201. [Beyond Decompilers: Runtime Analysis of Evasive Android Code]
-
202. [Show HN: A Minimal Monthly Task Planner (printable, offline, no signup)]
-
203. [Mirror_bridge – C++ reflection for generating Python/JS/Lua bindings]
-
204. [Why WinQuake exists and how it works]
-
205. [Russia Bans Roblox]
-
206. [Euler Conjecture and CDC 6600]
-
207. [New homes in London were delayed by 'energy-hungry' data centres]
-
208. [Cellebrite to Acquire Corellium]
-
209. [Apple’s head of user interface design, Alan Dye, will join Meta]
-
210. [Average DRAM price in USD over last 18 months]