frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Bach Cello Suites

https://bachcellosuites.co.uk/
1•bondarchuk•1m ago•0 comments

Show HN: Kvatch – query APIs, CSVs, Google Sheets, and databases as one source

1•squeakycheese•1m ago•0 comments

How A Billionaire's Plan to Reach Another Star Fell Apart

https://www.scientificamerican.com/article/the-quiet-demise-of-breakthrough-starshot-a-billionair...
1•croes•1m ago•0 comments

US Secret Service dismantles imminent telecommunications threat NY tristate area

https://www.secretservice.gov/newsroom/releases/2025/09/us-secret-service-dismantles-imminent-tel...
1•bookofjoe•3m ago•0 comments

UK Startup Unveils First Quantum Computer Built with Standard Silicon Chips

https://ts2.tech/en/quantum-breakthrough-uk-startup-unveils-first-quantum-computer-built-with-sta...
1•rayanboulares•4m ago•0 comments

Silicon Valley hiring in turmoil after new H-1B fees, move spurs offshoring talk

https://www.reuters.com/sustainability/sustainable-finance-reporting/silicon-valley-hiring-turmoi...
1•alephnerd•5m ago•1 comments

Mesh: I tried Htmx, then ditched it

https://ajmoon.com/posts/mesh-i-tried-htmx-then-ditched-it
1•alex-moon•6m ago•0 comments

Comet

https://www.perplexity.ai/comet
1•krisag•7m ago•0 comments

Oura ring maker raising $875M Series E, bringing valuation to $11B, report says

https://techcrunch.com/2025/09/22/oura-ring-maker-raising-875m-series-e-bringing-valuation-to-11b...
1•bookofjoe•9m ago•0 comments

Deaths Rose in Emergency Rooms After Hospitals Were Acquired by Private Equity

https://hms.harvard.edu/news/deaths-rose-emergency-rooms-after-hospitals-were-acquired-private-eq...
1•geox•10m ago•0 comments

Lark 1.3.0 – Introduces text-slices, Earley fix, and various small improvements

https://github.com/lark-parser/lark/releases/tag/1.3.0
1•todsacerdoti•10m ago•0 comments

Elon Musk's Father Accused of Child Sexual Abuse

https://www.nytimes.com/video/business/100000010404622/elon-musks-father-accused-of-child-sexual-...
2•donohoe•12m ago•0 comments

Insights from the UN Open Source Conf: Reclaiming the Internet's Foundations

https://pulse.internetsociety.org/blog/insights-from-the-un-open-source-conference-reclaiming-the...
1•danyork•12m ago•0 comments

Ask HN: What type of CRM re u using?

1•orbanlevi•12m ago•0 comments

Crowdsource Myth-Busting, Facts, and Wild Debates with the Community

https://truth-wave.lovable.app/
1•liltofu•13m ago•1 comments

The Good, the Bad, and the Iffy: is there such a thing as an ethical designer?

https://www.itsnicethat.com/features/is-there-such-thing-as-an-ethical-designer-creative-industry...
1•speckx•16m ago•0 comments

Did I Just Make Quantum Dots?

https://chillphysicsenjoyer.substack.com/p/did-i-just-make-quantum-dots
1•crescit_eundo•17m ago•0 comments

Show HN: Why clone GBs when you need KBs? Surgical GitHub downloads

https://github.com/AllDotPy/Forklet
1•Einswilli•18m ago•0 comments

Discovering Observers – Part 3

https://www.sandordargo.com/blog/2025/09/17/observers-part3
1•ibobev•18m ago•0 comments

Amazon faces off against FTC over 'deceptive' Prime program

https://www.cnbc.com/2025/09/23/amazon-faces-off-against-ftc-over-deceptive-prime-program.html
1•belter•22m ago•0 comments

Power Law Worlds and AI?

1•bsuki•22m ago•0 comments

Exemplars in OpenTelemetry

https://oneuptime.com/blog/post/2025-09-22-connecting-metrics-to-traces-with-exemplars/view
1•ndhandala•25m ago•0 comments

How the World Became x86-64 Inside

https://computerparkitecture.substack.com/p/the-long-mode-chronicles
1•ibobev•26m ago•0 comments

Qdrant: High-Performance Vector Database and Vector Search Engine in Rust

https://github.com/qdrant/qdrant
1•klaussilveira•26m ago•0 comments

Who knows what actors lurk in the hearts of movies? The LLM knows

https://lars.ingebrigtsen.no/2025/09/21/who-knows-what-actors-lurk-in-the-heart-of-movies-the-llm...
1•internet_points•33m ago•0 comments

Salesforce, Accel backs India's first vibe solutioning startup Rocket, $15M seed

https://techcrunch.com/2025/09/22/rocket-new-one-of-indias-first-vibe-coding-startups-snags-15m-f...
1•irakeshpurohit•34m ago•0 comments

OpenAI does WebRTC in the new GPT-realtime

https://webrtchacks.com/how-openai-does-webrtc-in-the-new-gpt-realtime/
3•feross•36m ago•0 comments

Show HN: Signage Sync

https://signagesync.app/
1•wiradikusuma•39m ago•0 comments

Ruby on Rails Conferences Are Discriminatory, and Unintelligent

https://andymaleh.blogspot.com/2025/09/ruby-on-rails-conferences-are.html
1•bingemaker•41m ago•1 comments

Trump's $100k Visa Fee Puts Many Tech Startups in a Bind

https://www.nytimes.com/2025/09/23/technology/trump-h1b-visa-tech-start-ups.html
2•mistersquid•43m ago•0 comments
Open in hackernews

Crypto Miner in hotio/qbittorrent

https://apogliaghi.com/2025/09/crypto-miner-in-hotio/qbittorrent/
76•tatoalo•1h ago

Comments

dalmo3•58m ago
It's a docker image, NOT qbittorrent.
thephyber•12m ago
For clarity: The post is about a server running a 3rd party docker image of qbittorrent.

But there’s no evidence presented that it was hotio’s docker image on GCHR which was compromised, and there is reason to believe it might be an older, vulnerable version of qbittorrent in the docker image which was compromised.

The vulnerability: (credit crtasm)

https://torrentfreak.com/qbittorrent-web-ui-exploited-to-min...

aquova•47m ago
hotio maintains a lot of Docker images. I suspect that if this is the case, there are a lot of people who would be affected

https://hotio.dev/containers/base/

IlikeKitties•36m ago
Alot around the ARR stack which makes it likely to be used by many less knowledgeable users. Nice Grift.
b-air•34m ago
Finally made an account on hackernews for this after years of reading. I just checked my Unraid server, I'm running five docker containers from Hotio - Prowlarr, Sonarr, Radarr, Overseerr, and Tautulli. If I remember correctly, I originally chose Hotio's configs due to there being a few extra settings missing from the standard images in the Unraid store. This was all to avoid learning anything about docker at the time, but since then I've gained a few skills so I'd say it's time for me to set up the containers myself. Thanks for posting this, I really only read HN so I would have missed this if it were anywhere else.
anotherlogin448•22m ago
There's no actual issue.

OP's system got compromised.

anotherlogin448•21m ago
And that also goes to show how hilariously wrong OP is.

His system was compromised - hotio's containers are all clean

ktosobcy•38m ago
Why use it when there is an official one: `https://github.com/qbittorrent/docker-qbittorrent-nox` ? o_O
Scion9066•34m ago
Lack of a tagged stable/release version with libtorrent 2.0 for one.
jgilias•36m ago
Well. An unpaid volunteer found a way how to get paid!

/s

crtasm•35m ago
If the web UI is exposed that could explain how it got infected:

https://torrentfreak.com/qbittorrent-web-ui-exploited-to-min...

tatoalo•29m ago
In my case, web UI was behind qbittorrent auth + authelia, haven't seen suspected logs that would trace it back to that, really interesting though!
anotherlogin448•20m ago
It's 100% your system that caused the issue not hotio's container and there is no miner that exists

Perhaps take a class in sarcasm?

baobun•34m ago
Supposedly this image.

https://github.com/hotio/qbittorrent/pkgs/container/qbittorr...

Based on https://github.com/hotio/base

Should be tracable via GitHub Actions logs for anyone signed on - if it is indeed supply-chain and not a qbittorrent exploit or something else.

anotherlogin448•18m ago
Indeed. OP's investigation proves nothing other their device / system was compromised and provides 0 evidence the container itself is the issue.
wok4899•29m ago
Omg! I am one of the user! Good find. I maily use for built-in VPN facility, gluetun do not cut out. But now time to re-think. I thought my 2000+ linux iso was causing medium CPU usage. But still lack of GPU, on my unraid server with 50+ docker containers running 24/7 CPU load is 2.31 2.04 2.00 so I wonder mining ever triggered?

Ps. I do have such binary on my machine as well, ps -ef | grep netservlet root 3708105 3665360 0 08:06 pts/2 00:00:00 grep netservlet

anotherlogin448•22m ago
OP got compromised there's no issue in any hotio container.

Code and CI is all open source.

thephyber•17m ago
My money is on the author had not updated their docker image version/tag in over 2 years.

It looks like the app used weak hard-coded admin credentials back then. Appears to have been fixed in 2023.

wok4899•11m ago
I am running, ghcr.io/hotio/qbittorrent:release-5.1.1
wok4899•13m ago
I never have exposed this container to the world ever, and my server do report the existence of such binary. That is the reason based on CPU usage I suspect that mining never triggered.

> ps -ef | grep netservlet > root 3708105 3665360 0 08:06 pts/2 00:00:00 grep netservlet

2OEH8eoCRo0•28m ago
Why do people use these stupid third-party container images?
anotherlogin448•23m ago
And yet everything is open source and easily auditable. Most likely OP got pwnd and clearly is unable to understand sarcasm.

You all really think that hotio snuck a crypto miner in somehow with all clearly open source code - and not a single person but OP noticed for years?

wok4899•5m ago
With the SSH/NPM supply chain attack, we all live in fear now. It just need one very smart person to deploy such hack. I'm not saying hotio did something, all I am saying that with new information, we all should check our deployment. Along with OP I'm affected, where I never have exposed the docker to world ever.

So we should not deny the possibility of something off here.

thephyber•21m ago
The article hasn’t proven that the infection is in the Docker image, let alone the newest version. It only suggests that they had the image installed, then (unknown time later) noticed the infection.

According to some messages on Hotio’s Discord server from 2023-11-25, qBitTorrent moved from fixed admin credentials to randomized at initialization. I think MrHotio’s message about that crypto miner was likely a joke about people installing the older vulnerable version and the efficiency of unauthorized people installing xrig on servers with default credentials.

If author was pinned to an old version of the docker image and their server had internet-visible IP, they probably got their server infected because of weak security defaults in the app installed on the image.

anotherlogin448•19m ago
The comment was 100% in jest / sarcasm.

OP's system got compromised at some point; the images are clean.

Hell if he didn't want to post his clickbait he easily could have verified with a clean image on a known clean system

bakugo•3m ago
Brand new account, 7 different comments on this post, all aggressively trying to discredit it.

A bit suspicious, don't you think?

ponchel•12m ago
Currently, on my own system, the docker container of qBitTorrent definitely doesn't seem to use more resources than it should.