frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

KeePass trojanised in advanced malware campaign

https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign
3•melicerte•3h ago

Comments

Ukv•3h ago
> signed version of the open-source password manager KeePass [...] KeePass’s actual source code was altered [...] risks of trusted software being hijacked

To be clear, as far as I'm able to tell from the report, the actual KeePass is safe and has not been infiltrated/compromised. The malicious version was from malvertising/typosquatting sites, and signed by random compromised certifications - not by the KeePass developer.

I guess what they're intending to emphasize is that the malware authors recompiled KeePass to add their malware as opposed to just packaging it alongside KeePass in an installer, but it did initally sound like something far worse had happened.

melicerte•2h ago
> Of particular concern, WithSecure Threat Intelligence identified a successful campaign, spanning at least 8 months, where legitimate source code of the popular open-source password manager tool ‘KeePass’ had been modified, and recompiled with trusted certificates.

My understanding is that if you don't pay particularly care to where you get your KeePass from, you can be tricked into downloading and installing a keepass from perfectly valid installer, potentially leaking all your passwords to the attackers.

I don't know if using open source projects with recompiled sources and valid trusted certificate is a common vector of attack but WithSecure reports that it has been installed a number of times across several of their customers.

Show HN: Shorts Stopper – Block YouTube Shorts on Safari iOS

https://apps.apple.com/us/app/shorts-stopper/id6745517488
1•abyesilyurt•43s ago•0 comments

We built AI-powered Root Cause Analysis that works

https://coroot.com/blog/we-built-ai-powered-root-cause-analysis-that-actually-works/
1•ekiauhce•1m ago•0 comments

Microsoft shares rare look at Windows 11 Start menu designs it explored

https://www.windowscentral.com/software-apps/windows-11/microsoft-shares-rare-look-at-radical-windows-11-start-menu-designs-it-explored-before-settling-on-the-least-interesting-one-of-the-bunch
1•taubek•2m ago•0 comments

How the Net Was Won – University of Michigan Heritage Project

https://heritage.umich.edu/stories/how-the-net-was-won/
1•rbanffy•2m ago•0 comments

The Internet 1997 – 2021

https://www.opte.org/the-internet
2•smusamashah•3m ago•0 comments

Ex-UK Special Forces break silence on 'war crimes' by colleagues

https://www.bbc.com/news/articles/cj3j5gxgz0do
1•tartoran•4m ago•0 comments

Spall: A code profiler that runs in the browser

https://gravitymoth.com/spall/spall-web.html
1•surprisetalk•5m ago•0 comments

Why So Many in Gen Z Are Choosing the Creator Economy over Degrees in India

https://www.outlookbusiness.com/magazine/gen-z-is-ghosting-degrees-and-day-jobs-to-go-all-in-on-the-creator-economy-in-india
1•yarapavan•6m ago•0 comments

Show HN: I built a system to make ChatGPT brutally honest with you

https://www.honestprompts.com/
1•moobuilds•6m ago•0 comments

RIP Usenix ATC

https://bcantrill.dtrace.org/2025/05/11/rip-usenix-atc/
2•joecobb•10m ago•0 comments

Google Worried It Couldn't Control How Israel Uses Project Nimbus, Files Reveal

https://theintercept.com/2025/05/12/google-nimbus-israel-military-ai-human-rights/
2•jaredwiener•10m ago•0 comments

The Formula for Business Success

https://sekniqi.com/business-formula/
1•sekniqi•10m ago•0 comments

PKK Kurdish militant group will disband

https://www.npr.org/2025/05/12/g-s1-65852/pkk-kurdish-militant-group-disband
2•marojejian•11m ago•1 comments

Two Supreme Court Cases That Could Break the Internet (2023)

https://www.newyorker.com/news/q-and-a/two-supreme-court-cases-that-could-break-the-internet
1•ColinWright•12m ago•0 comments

The effect of ChatGPT on students' learning performance: meta-analysis

https://www.nature.com/articles/s41599-025-04787-y
1•michalpleban•15m ago•0 comments

Ask HN: Where to get used hardware cheap?

2•laserstrahl•15m ago•2 comments

Tell HN: You can't stop YouTube autoplaying on Chrome with a browser extension

1•benatkin•16m ago•0 comments

Roons

https://whomtech.com/roons/
1•speckx•16m ago•0 comments

Firefox on GitHub

https://github.com/mozilla-firefox/firefox
1•fionera•17m ago•0 comments

What's a Home Playoff Game Worth Now?

https://neilpaine.substack.com/p/whats-a-home-playoff-game-worth-now
1•indigodaddy•17m ago•0 comments

Amazon Unit Price – Sort by Unit Price on Amazon

https://amazonunitprice.netlify.app/
1•danc2050•18m ago•0 comments

Understanding Modern AI Is Understanding Embeddings: A Guide with Lots of Dogs

https://sgnt.ai/p/embeddings-explainer/
1•petesergeant•20m ago•0 comments

Freespoke says it is an unbiased news aggregator showing always both sides

https://freespoke.com
1•DyslexicAtheist•24m ago•2 comments

Kennedy Is Right About the Chemicals in Our Food

https://www.nytimes.com/2025/05/12/opinion/kennedy-ultraprocessed-food-dyes.html
3•koolba•25m ago•0 comments

How to title your blog post or whatever

https://dynomight.net/titles/
1•cantaloupe•27m ago•0 comments

How to title your blog post or whatever: Choose a classifier

https://dynomight.substack.com/p/titles
1•crescit_eundo•27m ago•0 comments

The Largest Search Engine Doesn't Want You to Search

https://www.honest-broker.com/p/the-worlds-largest-search-doesnt
1•yarapavan•29m ago•0 comments

Vulcan Robots: Amazon's Solution to Picking Challenges

https://spectrum.ieee.org/amazon-robotics-vulcan-warehouse-picking
2•WaitWaitWha•29m ago•0 comments

NimbleEdge AI App - First offline voice AI by running Python on-device

https://www.nimbleedge.com/blog/meet-nimbleedge-ai-the-first-truly-private-on-device-assistant
16•vkkhare•31m ago•3 comments

Khajiit Name Generator

https://www.khajiitnamegenerator.xyz/en
1•chenxin2•31m ago•1 comments