frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Env-shelf – Open-source desktop app to manage .env files

https://env-shelf.vercel.app/
1•ivanglpz•3m ago•0 comments

Show HN: Almostnode – Run Node.js, Next.js, and Express in the Browser

https://almostnode.dev/
1•PetrBrzyBrzek•3m ago•0 comments

Dell support (and hardware) is so bad, I almost sued them

https://blog.joshattic.us/posts/2026-02-07-dell-support-lawsuit
1•radeeyate•4m ago•0 comments

Project Pterodactyl: Incremental Architecture

https://www.jonmsterling.com/01K7/
1•matt_d•4m ago•0 comments

Styling: Search-Text and Other Highlight-Y Pseudo-Elements

https://css-tricks.com/how-to-style-the-new-search-text-and-other-highlight-pseudo-elements/
1•blenderob•6m ago•0 comments

Crypto firm accidentally sends $40B in Bitcoin to users

https://finance.yahoo.com/news/crypto-firm-accidentally-sends-40-055054321.html
1•CommonGuy•7m ago•0 comments

Magnetic fields can change carbon diffusion in steel

https://www.sciencedaily.com/releases/2026/01/260125083427.htm
1•fanf2•7m ago•0 comments

Fantasy football that celebrates great games

https://www.silvestar.codes/articles/ultigamemate/
1•blenderob•7m ago•0 comments

Show HN: Animalese

https://animalese.barcoloudly.com/
1•noreplica•8m ago•0 comments

StrongDM's AI team build serious software without even looking at the code

https://simonwillison.net/2026/Feb/7/software-factory/
1•simonw•8m ago•0 comments

John Haugeland on the failure of micro-worlds

https://blog.plover.com/tech/gpt/micro-worlds.html
1•blenderob•9m ago•0 comments

Show HN: Velocity - Free/Cheaper Linear Clone but with MCP for agents

https://velocity.quest
2•kevinelliott•9m ago•2 comments

Corning Invented a New Fiber-Optic Cable for AI and Landed a $6B Meta Deal [video]

https://www.youtube.com/watch?v=Y3KLbc5DlRs
1•ksec•11m ago•0 comments

Show HN: XAPIs.dev – Twitter API Alternative at 90% Lower Cost

https://xapis.dev
2•nmfccodes•11m ago•0 comments

Near-Instantly Aborting the Worst Pain Imaginable with Psychedelics

https://psychotechnology.substack.com/p/near-instantly-aborting-the-worst
2•eatitraw•17m ago•0 comments

Show HN: Nginx-defender – realtime abuse blocking for Nginx

https://github.com/Anipaleja/nginx-defender
2•anipaleja•18m ago•0 comments

The Super Sharp Blade

https://netzhansa.com/the-super-sharp-blade/
1•robin_reala•19m ago•0 comments

Smart Homes Are Terrible

https://www.theatlantic.com/ideas/2026/02/smart-homes-technology/685867/
1•tusslewake•20m ago•0 comments

What I haven't figured out

https://macwright.com/2026/01/29/what-i-havent-figured-out
1•stevekrouse•21m ago•0 comments

KPMG pressed its auditor to pass on AI cost savings

https://www.irishtimes.com/business/2026/02/06/kpmg-pressed-its-auditor-to-pass-on-ai-cost-savings/
1•cainxinth•21m ago•0 comments

Open-source Claude skill that optimizes Hinge profiles. Pretty well.

https://twitter.com/b1rdmania/status/2020155122181869666
3•birdmania•21m ago•1 comments

First Proof

https://arxiv.org/abs/2602.05192
7•samasblack•24m ago•2 comments

I squeezed a BERT sentiment analyzer into 1GB RAM on a $5 VPS

https://mohammedeabdelaziz.github.io/articles/trendscope-market-scanner
1•mohammede•25m ago•0 comments

Kagi Translate

https://translate.kagi.com
2•microflash•25m ago•0 comments

Building Interactive C/C++ workflows in Jupyter through Clang-REPL [video]

https://fosdem.org/2026/schedule/event/QX3RPH-building_interactive_cc_workflows_in_jupyter_throug...
1•stabbles•27m ago•0 comments

Tactical tornado is the new default

https://olano.dev/blog/tactical-tornado/
2•facundo_olano•28m ago•0 comments

Full-Circle Test-Driven Firmware Development with OpenClaw

https://blog.adafruit.com/2026/02/07/full-circle-test-driven-firmware-development-with-openclaw/
1•ptorrone•29m ago•0 comments

Automating Myself Out of My Job – Part 2

https://blog.dsa.club/automation-series/automating-myself-out-of-my-job-part-2/
1•funnyfoobar•29m ago•1 comments

Dependency Resolution Methods

https://nesbitt.io/2026/02/06/dependency-resolution-methods.html
1•zdw•30m ago•0 comments

Crypto firm apologises for sending Bitcoin users $40B by mistake

https://www.msn.com/en-ie/money/other/crypto-firm-apologises-for-sending-bitcoin-users-40-billion...
1•Someone•30m ago•0 comments
Open in hackernews

6Sense's Privacy Policy Page loads scripts from polyfill(.)io

1•SignalDr•2mo ago
We have completed a forensic investigation into a major B2B marketing vendor's (TrenDemon, linked to 6sense) production SDK and uncovered a systematic vulnerability that impacts thousands of customer sites. We are categorizing this as the Adversarial GTM Architecture.

The system is designed to defeat privacy audits and achieve permanent user tracking.

1. The Core Vulnerability: Remote Code Execution (RCE) Framework The vendor's primary script is not an analytics tool; it is a Remote Code Execution as a Service (RCEaaS) framework.

Mechanism: The SDK uses a proprietary constructor ($TRD\_GenericScriptComponent) to execute arbitrary code delivered from the vendor’s API via dynamic calls to eval() and innerHTML

Vector: This RCE capability is deployed as a "tripwire" that triggers at the moment of highest user engagement (e.g., video completion or form submit).

Result: The vendor can change the functionality of their clients' sites (e.g., deploying new tracking scripts, keyloggers) on the fly without updating the main script file.

2. The Persistence and Evasion Layer This architecture relies on active, high-level evasion to prevent security observation:

Permanent Tracking (The 8,000-Year Cookie): The system sets cookies with an expiration date of December 31, 9999, a clear violation of GDPR's Storage Limitation Principle and evidence of intent for permanent identity persistence.

Audit Evasion Logic: The production code contains detection logic that specifically targets the regex patterns of compliance and legal discovery tools (monitor|checker|validator|analyzer), causing the script to change its behavior when audited.

Supply Chain Risk (PollyWannaCrack): The execution engine relies on loading scripts from polyfill.io, which is a publicly known, compromised CDN.

3. The Payload (Identity Brokering) The primary function of the RCE is to facilitate identity theft:

Cross-Vendor Theft: The system actively encodes and exfiltrates authentication-grade cookies from secondary vendors, specifically the Marketo cookie (maCook), providing TrenDemon with the key to the user's entire marketing identity.

Surveillance Network: The RCE framework is used to dynamically inject and orchestrate a payload array of other surveillance tools (RB2B, LiveIntent, Apollo, etc.) into the host page.

We believe this architecture represents a structural failure in GTM security, demonstrating that the pursuit of attribution has led to the deployment of hostile, RCE-capable code designed for unobservability. We have developed and deployed patches to mitigate this threat.

We encourage security researchers and auditors to independently verify the presence of the $TRD\_GenericScriptComponent and the audit evasion logic within the vendor's production code.

https://www.deployblackout.com/investigations/6sense