frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Citrix forgot to tell you CVE-2025–6543 has been used as a zero day since May

https://doublepulsar.com/citrix-forgot-to-tell-you-cve-2025-6543-has-been-used-as-a-zero-day-since-may-2025-d76574e2dd2c
17•speckx•2h ago

Comments

worik•1h ago
> How? Calls are made to the Netscaler box to the endpoint /cgi/api/login, with a client supplied certificate. By sending hundreds of requests, you can overwrite chunks of memory in the hope of executing code.

> I would recommend, if logs exist, checking for web access requests to /cgi/api/login on your Netscaler devices. These will be large POST requests.

So hundreds of invalid certificates? Infeasibly large POST requests? Seems to me that this vulnerability depends on not having good defense in depth

"If logs exist"?! It blows my tiny little mind that keeping logs has gone out of fashion

Our industry is in deep long term shit. We have adopted awful practices because they are cheaper, and secure systems look the same as insecure systems, but cost more.

We can build reliable secure systems from unreliable fault prone parts, we know how, but nobody will let us

I am depressed

Tesla's Europe problem just got even worse

https://www.cnn.com/2025/08/28/cars/tesla-elon-musk-byd-europe-sales
1•breve•2m ago•0 comments

Rupert's Property

https://johncarlosbaez.wordpress.com/2025/08/28/a-polyhedron-without-ruperts-property/
1•robinhouston•4m ago•0 comments

AI Competition explained in 10 minutes [video]

https://www.youtube.com/watch?v=CrJJPlRO9bI
1•lawrenceyan•5m ago•0 comments

Show HN: Security Test Framework – 16 automated security checks

https://www.npmjs.com/package/security-test-framework
1•therealprwilo•6m ago•0 comments

Why Collaborate with XAI?

https://github.com/orgs/community/discussions/171322
1•azkae•6m ago•0 comments

End of the Line?

https://www.thenation.com/article/society/amtrak-public-transit/
1•petethomas•8m ago•0 comments

An eyecare foundation model for clinical assistance

https://www.nature.com/articles/s41591-025-03900-7
1•jameslk•9m ago•0 comments

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift

https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-sale...
2•floren•13m ago•0 comments

Hmpl.js vs. Alpine.js vs. Htmx (Aug. 2025)

https://imgur.com/gallery/G3iIDxd
2•aanthonymax•15m ago•2 comments

Doing Figma Last

https://twitter.com/rjs/status/1961074735904657708
2•tosh•15m ago•0 comments

NX Hack: stolen GitHub credential used to turn private repositories public

https://github.com/nrwl/nx/issues/32522
1•Raed667•17m ago•0 comments

The Evolution: From Atomic Options to Lygos Credit

https://blog.lygos.finance/the-evolution-from-atomic-options-to-lygos-credit/
1•janandonly•18m ago•0 comments

Diablo Game Developers Join Communications Workers of America

https://cwa-union.org/news/releases/hundreds-diablo-game-developers-join-communications-workers-a...
3•ughitsaaron•21m ago•1 comments

Death by PowerPoint: the slide that killed seven people

https://mcdreeamiemusings.com/blog/2019/4/13/gsux1h6bnt8lqjd7w2t2mtvfg81uhx
3•scapecast•22m ago•0 comments

Apple Releases Xcode 26 Beta 7 with GPT-5 Support and Claude Integration

https://www.macrumors.com/2025/08/28/xcode-gpt-5-claude-integration/
2•tosh•22m ago•0 comments

The Dumbest Phone Is Parenting Genius

https://www.theatlantic.com/family/archive/2025/06/landline-kids-smartphone-alternative/683203/
2•SLHamlet•24m ago•0 comments

Why Particle Size Distribution Matters for Optical PM Sensors

https://www.airgradient.com/blog/when-all-pm25-isnt-the-same/
1•ahaucnx•24m ago•0 comments

Eco-driving measures could significantly reduce vehicle emissions

https://techxplore.com/news/2025-08-eco-significantly-vehicle-emissions.html
1•PaulHoule•25m ago•0 comments

In Boston, Trucks Keep Crashing into Low Bridges

https://www.wsj.com/us-news/in-boston-trucks-keep-crashing-into-low-bridges-a18c5c5c
1•bookofjoe•25m ago•1 comments

We Did Margin-Negative Computing Before It Was Cool, and It Was Silly

https://blog.railway.com/p/free-plan
2•dban•25m ago•0 comments

NXSweep: Using the NX AI Exploit Logic for Blue Teaming

https://www.yashthapliyal.com/blog/nxsweep
2•yash1hi•27m ago•0 comments

Linux Foundation Opens the Door to DocumentDB

https://thenewstack.io/linux-foundation-opens-the-door-to-documentdb/
2•CrankyBear•28m ago•0 comments

Sometimes CPU cores are odd – Anubis

https://anubis.techaro.lol/blog/2025/cpu-core-odd/
3•rbanffy•28m ago•0 comments

Starship Will Reduce Bandwidth Launch Cost by Up to 50x

https://research.33fg.com/analysis/starship-will-reduce-bandwidth-launch-cost-by-up-to-50x
3•bilsbie•28m ago•0 comments

Kick Ass – Destroy the Web

https://kickassapp.com
2•nvahalik•29m ago•0 comments

The Authoritarian Checklist

https://donmoynihan.substack.com/p/the-authoritarian-checklist
1•tastyface•29m ago•0 comments

Expert LSP the official language server implementation for Elixir

https://github.com/elixir-lang/expert
3•pimienta•30m ago•0 comments

Top Down versus Bottom Up AI Adoption

https://substack.com/inbox/post/172208814
1•mathattack•32m ago•0 comments

Show HN: Smart Buildings Powered by SparkplugB, Aklivity Zilla, and Kafka

https://github.com/aklivity/zilla-demos/tree/main/smart-buildings
1•luk212•34m ago•0 comments

The Bitter Lesson Is Misunderstood – By Kushal Chakrabarti

https://obviouslywrong.substack.com/p/the-bitter-lesson-is-misunderstood
1•JnBrymn•35m ago•0 comments