frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Source code graphRAG for Java/Kotlin development based on jQAssistant

https://github.com/2015xli/jqassistant-graph-rag
1•artigent•2m ago•0 comments

Python Only Has One Real Competitor

https://mccue.dev/pages/2-6-26-python-competitor
2•dragandj•3m ago•0 comments

Tmux to Zellij (and Back)

https://www.mauriciopoppe.com/notes/tmux-to-zellij/
1•maurizzzio•4m ago•1 comments

Ask HN: How are you using specialized agents to accelerate your work?

1•otterley•5m ago•0 comments

Passing user_id through 6 services? OTel Baggage fixes this

https://signoz.io/blog/otel-baggage/
1•pranay01•6m ago•0 comments

DavMail Pop/IMAP/SMTP/Caldav/Carddav/LDAP Exchange Gateway

https://davmail.sourceforge.net/
1•todsacerdoti•7m ago•0 comments

Visual data modelling in the browser (open source)

https://github.com/sqlmodel/sqlmodel
1•Sean766•9m ago•0 comments

Show HN: Tharos – CLI to find and autofix security bugs using local LLMs

https://github.com/chinonsochikelue/tharos
1•fluantix•9m ago•0 comments

Oddly Simple GUI Programs

https://simonsafar.com/2024/win32_lights/
1•MaximilianEmel•9m ago•0 comments

The New Playbook for Leaders [pdf]

https://www.ibli.com/IBLI%20OnePagers%20The%20Plays%20Summarized.pdf
1•mooreds•10m ago•0 comments

Interactive Unboxing of J Dilla's Donuts

https://donuts20.vercel.app
1•sngahane•11m ago•0 comments

OneCourt helps blind and low-vision fans to track Super Bowl live

https://www.dezeen.com/2026/02/06/onecourt-tactile-device-super-bowl-blind-low-vision-fans/
1•gaws•13m ago•0 comments

Rudolf Vrba

https://en.wikipedia.org/wiki/Rudolf_Vrba
1•mooreds•13m ago•0 comments

Autism Incidence in Girls and Boys May Be Nearly Equal, Study Suggests

https://www.medpagetoday.com/neurology/autism/119747
1•paulpauper•14m ago•0 comments

Wellness Hotels Discovery Application

https://aurio.place/
1•cherrylinedev•15m ago•1 comments

NASA delays moon rocket launch by a month after fuel leaks during test

https://www.theguardian.com/science/2026/feb/03/nasa-delays-moon-rocket-launch-month-fuel-leaks-a...
1•mooreds•16m ago•0 comments

Sebastian Galiani on the Marginal Revolution

https://marginalrevolution.com/marginalrevolution/2026/02/sebastian-galiani-on-the-marginal-revol...
2•paulpauper•19m ago•0 comments

Ask HN: Are we at the point where software can improve itself?

1•ManuelKiessling•19m ago•1 comments

Binance Gives Trump Family's Crypto Firm a Leg Up

https://www.nytimes.com/2026/02/07/business/binance-trump-crypto.html
1•paulpauper•19m ago•0 comments

Reverse engineering Chinese 'shit-program' for absolute glory: R/ClaudeCode

https://old.reddit.com/r/ClaudeCode/comments/1qy5l0n/reverse_engineering_chinese_shitprogram_for/
1•edward•20m ago•0 comments

Indian Culture

https://indianculture.gov.in/
1•saikatsg•22m ago•0 comments

Show HN: Maravel-Framework 10.61 prevents circular dependency

https://marius-ciclistu.medium.com/maravel-framework-10-61-0-prevents-circular-dependency-cdb5d25...
1•marius-ciclistu•23m ago•0 comments

The age of a treacherous, falling dollar

https://www.economist.com/leaders/2026/02/05/the-age-of-a-treacherous-falling-dollar
2•stopbulying•23m ago•0 comments

Ask HN: AI Generated Diagrams

1•voidhorse•25m ago•0 comments

Microsoft Account bugs locked me out of Notepad – are Thin Clients ruining PCs?

https://www.windowscentral.com/microsoft/windows-11/windows-locked-me-out-of-notepad-is-the-thin-...
5•josephcsible•26m ago•1 comments

Show HN: A delightful Mac app to vibe code beautiful iOS apps

https://milq.ai/hacker-news
6•jdjuwadi•29m ago•1 comments

Show HN: Gemini Station – A local Chrome extension to organize AI chats

https://github.com/rajeshkumarblr/gemini_station
1•rajeshkumar_dev•29m ago•0 comments

Welfare states build financial markets through social policy design

https://theloop.ecpr.eu/its-not-finance-its-your-pensions/
2•kome•33m ago•0 comments

Market orientation and national homicide rates

https://onlinelibrary.wiley.com/doi/10.1111/1745-9125.70023
4•PaulHoule•33m ago•0 comments

California urges people avoid wild mushrooms after 4 deaths, 3 liver transplants

https://www.cbsnews.com/news/california-death-cap-mushrooms-poisonings-liver-transplants/
1•rolph•33m ago•0 comments
Open in hackernews

MCP: May Cause Pwnage – Backdoors in Disguise

https://blog.jaisal.dev/articles/mcp
5•yk•9mo ago

Comments

mirzap•9mo ago
Lol. Can't believe I've read this. It's like saying "REST: may cause pwnage". Everything the author found troubling can be said for any API server under certain implementation (or even some frameworks and their defaults), and everything is an implementation choice, not a protocol vulnerability.
AtomicByte•9mo ago
I really don't want to waste my time explaining this to someone with clearly a subpar understanding of cybersecurity so I'll get an "AI" to:

The blog post "MCP: May Cause Pwnage" highlights critical security vulnerabilities in the Model Context Protocol (MCP) and its associated tools, such as the Inspector. These issues include default configurations that expose services to external networks by binding to 0.0.0.0, the use of GET requests for executing commands—making them susceptible to CSRF attacks—and the potential for DNS rebinding exploits due to the use of Server-Sent Events (SSE). While some may argue these are merely implementation flaws, the fact that these insecure practices are present in official SDKs and tools suggests systemic oversights in the protocol's design and default settings. Given MCP's growing adoption among major AI providers, addressing these vulnerabilities at the protocol level is crucial to ensure secure deployment and operation.

Security experts have echoed these concerns. For instance, in a podcast discussion, professionals highlighted the simplicity and severity of these exploits, emphasizing that such vulnerabilities are inherent in the protocol and its tools, not just in individual implementations. Critical Thinking - Bug Bounty Podcast

Do your research first, kids

mirzap•8mo ago
I bet you used AI to write something that sounds smart, but trust me kid, it doesn't sound that way at all.