frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

AI Safety Index Winter 2025 Edition

https://futureoflife.org/ai-safety-index-winter-2025/
1•layer8•1m ago•0 comments

Can AI keep particle accelerators in line?

https://www.lanl.gov/media/publications/1663/can-ai-keep-accelerators-in-line
1•LAsteNERD•1m ago•0 comments

Show HN: ApiRealTest Beta – Test APIs Through Real User Scenarios

https://api-real-test.lovable.app
1•sumanthchary•2m ago•0 comments

Ams NanEyeC Integrated Camera Module CMOS Image Sensors

https://ams-osram.com/products/sensor-solutions/cmos-image-sensors/ams-naneyec-integrated-camera-...
1•thunderbong•3m ago•0 comments

Google Cloud's Managed Cross-Cloud Network with AWS

https://cloud.google.com/blog/products/networking/extending-cross-cloud-interconnect-to-aws-and-p...
2•fastest963•5m ago•0 comments

Claude for Nonprofits \ Anthropic

https://www.anthropic.com/news/claude-for-nonprofits
1•raybb•7m ago•1 comments

What is Bending Spoons? Everything to know about Eventbrite's acquirer

https://techcrunch.com/2025/12/03/what-is-bending-spoons-everything-to-know-about-aols-acquirer/
1•unripe_syntax•7m ago•0 comments

JWST Discovers a Milky Way-Like Spiral Galaxy Where It Shouldn't Exist

https://www.iflscience.com/jwst-discovers-a-milky-way-like-spiral-galaxy-where-it-shouldnt-exist-...
2•Brajeshwar•10m ago•0 comments

How to measure the accuracy of forecasts (2016)

https://longform.asmartbear.com/forecast/
1•mooreds•10m ago•0 comments

Show HN: Elements as Linear Combinations

https://zuriby.github.io/math.github.io/lc-pt.html
1•tzury•12m ago•0 comments

Show HN: Synthome – TypeScript SDK for building composable AI media pipelines

https://github.com/synthome-dev/synthome
2•dubovetzky•12m ago•0 comments

Neo-Luddism

https://en.wikipedia.org/wiki/Neo-Luddism
1•kklisura•13m ago•0 comments

Higher Education and AI: Some Musings

https://bastian.rieck.me/blog/2025/education/
1•Pseudomanifold•13m ago•0 comments

Trump calls Somali immigrants 'garbage' as US reportedly targets Minnesota

https://www.theguardian.com/us-news/2025/dec/02/trump-somali-immigrants-minnesota
2•duxup•13m ago•0 comments

Vulkan SDK now ships with SDL3

https://twitter.com/LunarGInc/status/1995884540120928661
1•davikr•16m ago•0 comments

Flint Artifacts and Roman Altar Fragment Found Beneath Houses of Parliament

https://www.smithsonianmag.com/smart-news/archaeologists-digging-beneath-britains-houses-of-parli...
1•divbzero•18m ago•0 comments

Zillow Removes Climate Risk Scores

https://www.theguardian.com/environment/2025/dec/01/zillow-removes-climate-risk-data-home-listings
2•RickJWagner•18m ago•0 comments

Curlie web directory download – 2.9M editor approved websites for your AI

https://curlie.org/download
2•KnowledgeWeaver•22m ago•1 comments

Django 6.0 Released

https://www.djangoproject.com/weblog/2025/dec/03/django-60-released/
6•sirodoht•25m ago•0 comments

AI infrastructure is being built on a mountain of new DEBT

https://twitter.com/GlobalMktObserv/status/1995848679404507467
2•DivingForGold•25m ago•0 comments

Extending yeast lifespan boosts biosynthetic output of valuable compounds

https://phys.org/news/2025-11-yeast-lifespan-boosts-biosynthetic-output.html
2•PaulHoule•25m ago•0 comments

Show HN: Aim-Style Instant Messaging in VSCode

https://marketplace.visualstudio.com/items?itemName=devchat-dev.devchat-im
1•milowata•26m ago•0 comments

Sugars, 'Gum,' Stardust Found in NASA's Asteroid Bennu Samples

https://www.nasa.gov/missions/osiris-rex/sugars-gum-stardust-found-in-nasas-asteroid-bennu-samples/
3•e145bc455f1•26m ago•0 comments

Instant server hot-reload across the Wasm boundary

https://primate.run/blog/primate-035#server-hot-reload
4•sarumake•27m ago•0 comments

Show HN: ToolPlex Desktop – MCP marketplace and AI workflow builder

https://toolplex.ai
1•entrehacker•29m ago•0 comments

Ask HN: Is the absence of affect the real barrier to AGI and alignment?

2•n-exploit•30m ago•0 comments

The War for Seattle [video]

https://www.youtube.com/watch?v=LpaD9qpnzI0
1•surprisetalk•30m ago•0 comments

China will eventually open its borders to mass immigration

https://twitter.com/samoburja/status/1988128253891277071
4•surprisetalk•31m ago•6 comments

Is Watching Video Bad for Children's Skills?

https://www.nber.org/papers/w34466
1•surprisetalk•31m ago•0 comments

OpenAI is facing every startup's VC question: What if Google copies you?

https://gpt3experiments.substack.com/p/openais-vc-question-what-if-google
1•nutanc•31m ago•0 comments
Open in hackernews

Critical RCE Vulnerabilities in React and Next.js

https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182
77•gonepivoting•55m ago

Comments

gonepivoting•30m ago
Just to simplify this - our exploitation tests so far have shown that a standard Next.js application created via create-next-app and built for production is vulnerable to CVE-2025-66478 without any specific code modifications by the developer - so this is essentially exploitable out-of-the-box.
tinco•29m ago
Unsafe deserialization is a very 2010 Ruby on Rails sort of vulnerability. It is strangely interesting that such a vulnerability was introduced so late in the lifetime of these frameworks. It must be a very sneaky vulnerability given how cautious we have become around deserialization since then.
LunaSea•20m ago
I'm willing to bet that this is linked to the magic __proto__ object namespace in JavaScript
Tomuus•16m ago
The React Server Components wire format (Flight) is relatively novel and very new (it has existed in React stable for just a year). This is not a simple JSON parsing bug.
skilled•28m ago
Wow, I am at a loss for words how serious this is. Looking forward to a more technical write up.

This might cause quite a lot of chaos and leaked code / credentials over the next couple of weeks.

mmsc•28m ago
These wiz.io blog posts should be banned from HN; AFAICT, they're AI generated. Here's the original post with the details: https://react.dev/blog/2025/12/03/critical-security-vulnerab... - the vulnerability was not found by a Wiz employee at all, and the Wiz article (unlike the react.dev article) does not provide any meaningful technical information.

The important part to know:

- Even if your app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components.

- The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack

- Some React frameworks and bundlers depended on, had peer dependencies for, or included the vulnerable React packages. The following React frameworks & bundlers are affected: next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk.

jfindper•12m ago
>AFAICT, they're AI generated.

What is the "tell"? I'm not saying they are or aren't, but... people say this about literally everything now and it's typically some flimsy reasoning like "they used a bullet point". I don't see anything in particular that makes me think ai over a standard template some junior fills out.

>the vulnerability was not found by a Wiz employee at all

I've re-read the Wiz article a few times. Maybe I'm just dumb, but where did Wiz claim to have found this vulnerability?

galnagli•11m ago
Hey mmsc, first of all - the blogs are not AI Generated!

Second of all, the blog did add more information

"In our experimentation, exploitation of this vulnerability had high fidelity, with a near 100% success rate and can be leveraged to a full remote code execution. The attack vector is unauthenticated and remote, requiring only a specially crafted HTTP request to the target server. It affects the default configuration of popular frameworks. "

In the end - if it helped spreading the news about this risk so teams can fix them faster, then this is our end-goal with these blog posts : )

internetter•8m ago
There is some value:

> The vulnerability exists in the default configuration of affected applications

Can be inferred from the react blog but isn't really explicit

> According to Wiz data, 39% of cloud environments have instances vulnerable to CVE-2025-55182 and/or CVE-2025-66478.

Numbers!

gonepivoting•7m ago
Hey, researcher from Wiz here - we definitely didn't discover these vulns and all the credit goes to Lachlan Davidson. We have been investigating these vulns throughout the day and decided not to disclose the full extent of our conclusions or release a working exploit until more people get a chance to patch this (and as I mentioned in another comment, exploitation works out-of-the-box so you definitely should patch ASAP).
bri3d•15m ago
Here's a patch diff:

https://github.com/vercel/next.js/compare/v15.0.4...v15.0.5

It looks like the fix is checking hasOwnProperty, so it's almost certainly an issue with prototype chain pollution.

jimmyl02•6m ago
It seems like this might be one of the biggest vulnerabilities in recent times...

The default react / nextjs configurations being vulnerable to RCE is pretty insane. I think platform level protections from Vercel / Cloudflare are very much showing their utility now!