frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Realistic attack vectors against modern ecommerce platforms that defenders miss?

2•iksmel•5h ago
I’m interested in understanding attack surfaces beyond the “usual suspects” like SQLi, XSS, or CSRF.

What are some creative but realistic attack vectors that often slip past defenders in modern e-commerce systems?

- Abuse of business logic (e.g., coupon codes, cart manipulation, returns/refunds) - Supply chain risks (malicious dependencies, Docker images, CI/CD compromises) - Authentication bypasses through SSO/OAuth misconfigurations - Exploiting integrations (payment gateways, third-party APIs, shipping providers) - Insider threats or misused admin panels

If you’ve seen or tested interesting vectors in the wild, I’d love to hear about them. Also curious how defenders can realistically monitor or mitigate these risks without overwhelming their teams.

Text Format Feature Matrix

https://keenwrite.com/blog/2025/09/08/feature-matrix/
1•Bogdanp•53s ago•0 comments

Show HN: Narcissistic Abuse Simulator exposes toxic patterns

https://narcissisticabusesimulator.com/
1•n8m8•1m ago•0 comments

Recommended Books for Learning Ruby

https://www.rubynewbie.org/recommended-books-for-learning-ruby
1•jvrc•2m ago•0 comments

Rendering the Mandelbulb

https://www.4rknova.com//blog/2025/09/01/mandelbulb
1•ibobev•3m ago•0 comments

How we SSH into GitHub Actions

https://www.blacksmith.sh/blog/ssh
1•tsaifu•4m ago•0 comments

Accessibility might be AI's biggest breakthrough

https://arstechnica.com/information-technology/2025/09/study-finds-neurodiverse-workers-more-sati...
1•sohkamyung•6m ago•0 comments

Show HN: CLI tool to transfer your chats from Telegram to WhatsApp

https://github.com/rafaelsales/transfer-telegram-to-whatsapp
1•goofed•9m ago•1 comments

Humanoid Olympic Games

https://generalrobots.substack.com/p/benjies-humanoid-olympic-games
1•FromTheArchives•9m ago•0 comments

Unredacted Magazine (September 2025 issue) [pdf]

https://inteltechniques.com/issues/008.pdf
1•jayhoon•10m ago•0 comments

Air pollution can drive dementia

https://www.theguardian.com/environment/2025/sep/04/fine-particulate-air-pollution-trigger-forms-...
3•gmays•11m ago•0 comments

Stumbling Upon

https://thehistoryoftheweb.com/stumbling-upon/
1•m-hodges•12m ago•0 comments

Google Pixel 10 and C2PA Failures

https://hackerfactor.com/blog/index.php?/archives/1077-Google-Pixel-10-and-Massive-C2PA-Failures....
1•zbentley•13m ago•0 comments

Intel ousts CEO of products, establishes new custom-chip design unit

https://www.tomshardware.com/tech-industry/intel-ousts-ceo-of-products-as-part-of-the-latest-exec...
2•heresie-dabord•15m ago•0 comments

Speeding Up PdfTeX

https://blog.vursc.org/fast-pdftex.html
1•isoow•15m ago•0 comments

Faster Rust Builds on Mac

https://nnethercote.github.io/2025/09/04/faster-rust-builds-on-mac.html
1•alongub•16m ago•0 comments

How the AI Boom Is Leaving Consultants Behind

https://www.wsj.com/articles/how-the-ai-boom-is-leaving-consultants-behind-c9088fda
2•ryan_j_naughton•19m ago•1 comments

Show HN: I Built a Free SPF, DKIM, DMARC Generator for Cold Outbound

https://florianwueest.com/spf-dkim-dmarc-generator
1•florianwueest•20m ago•0 comments

AI Browsers: A Needs Analysis

https://chamomile.ai/ai_browsers_needs_analysis/
1•int19h•22m ago•0 comments

Show HN: I built an operating file system for my agent (CRUD)

https://www.youtube.com/watch?v=apDrReT-Ry0
1•JamesKachamila•23m ago•0 comments

Atlassian's move to cloud-only means customers face integration issues and more

https://www.theregister.com/2025/09/09/atlassian_will_go_cloudonly_customers/
3•rntn•26m ago•0 comments

Weaponizing Ads: How Google and Facebook Ads Are Used to Wage Propaganda Wars

https://medium.com/@eslam.elsewedy/weaponizing-ads-how-governments-use-google-ads-and-facebook-ad...
17•bhouston•26m ago•1 comments

Reading Skills of 12th Graders Hit a New Low

https://www.nytimes.com/2025/09/09/us/12th-grade-reading-skills-low-naep.html
2•megacorp•27m ago•0 comments

Widespread NPM Supply Chain Attack: Breaking Down Impact and Scope Across Debug

https://www.wiz.io/blog/widespread-npm-supply-chain-attack-breaking-down-impact-scope-across-debu...
1•Gilitiko•27m ago•0 comments

Building predictive agents (RFM + MCP)

https://kumo.ai/company/news/kumorfm-mcp-server/.
2•agold97•28m ago•0 comments

The Case for Cowboy Coding

https://bevel.work/blog/the-case-for-cowboy-coding/
1•bevelwork•30m ago•0 comments

Pure and Impure Software Engineering

https://www.seangoedecke.com/pure-and-impure-engineering/
2•yurivish•33m ago•0 comments

A designer might be your best startup hire

https://www.youtube.com/watch?v=J2I7At2BCMk
1•AndreasMoeller•34m ago•0 comments

Dispatch – Netflix's incident management system was archived last week

https://github.com/Netflix/dispatch
1•lukesingham•35m ago•0 comments

AI's mental health fix: Stop pretending it's human

https://www.axios.com/2025/08/30/chatgpt-ai-mental-health-human
2•woliveirajr•36m ago•0 comments

"Why I Don't Buy the Dark Forest Hypothesis" [video]

https://www.youtube.com/watch?v=X0SvgT9Lc2M
1•easybake•41m ago•0 comments