frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

6Sense's Privacy Policy Page loads scripts from polyfill(.)io

1•SignalDr•2mo ago
We have completed a forensic investigation into a major B2B marketing vendor's (TrenDemon, linked to 6sense) production SDK and uncovered a systematic vulnerability that impacts thousands of customer sites. We are categorizing this as the Adversarial GTM Architecture.

The system is designed to defeat privacy audits and achieve permanent user tracking.

1. The Core Vulnerability: Remote Code Execution (RCE) Framework The vendor's primary script is not an analytics tool; it is a Remote Code Execution as a Service (RCEaaS) framework.

Mechanism: The SDK uses a proprietary constructor ($TRD\_GenericScriptComponent) to execute arbitrary code delivered from the vendor’s API via dynamic calls to eval() and innerHTML

Vector: This RCE capability is deployed as a "tripwire" that triggers at the moment of highest user engagement (e.g., video completion or form submit).

Result: The vendor can change the functionality of their clients' sites (e.g., deploying new tracking scripts, keyloggers) on the fly without updating the main script file.

2. The Persistence and Evasion Layer This architecture relies on active, high-level evasion to prevent security observation:

Permanent Tracking (The 8,000-Year Cookie): The system sets cookies with an expiration date of December 31, 9999, a clear violation of GDPR's Storage Limitation Principle and evidence of intent for permanent identity persistence.

Audit Evasion Logic: The production code contains detection logic that specifically targets the regex patterns of compliance and legal discovery tools (monitor|checker|validator|analyzer), causing the script to change its behavior when audited.

Supply Chain Risk (PollyWannaCrack): The execution engine relies on loading scripts from polyfill.io, which is a publicly known, compromised CDN.

3. The Payload (Identity Brokering) The primary function of the RCE is to facilitate identity theft:

Cross-Vendor Theft: The system actively encodes and exfiltrates authentication-grade cookies from secondary vendors, specifically the Marketo cookie (maCook), providing TrenDemon with the key to the user's entire marketing identity.

Surveillance Network: The RCE framework is used to dynamically inject and orchestrate a payload array of other surveillance tools (RB2B, LiveIntent, Apollo, etc.) into the host page.

We believe this architecture represents a structural failure in GTM security, demonstrating that the pursuit of attribution has led to the deployment of hostile, RCE-capable code designed for unobservability. We have developed and deployed patches to mitigate this threat.

We encourage security researchers and auditors to independently verify the presence of the $TRD\_GenericScriptComponent and the audit evasion logic within the vendor's production code.

https://www.deployblackout.com/investigations/6sense

GPT-5.3-Codex System Card [pdf]

https://cdn.openai.com/pdf/23eca107-a9b1-4d2c-b156-7deb4fbc697c/GPT-5-3-Codex-System-Card-02.pdf
1•tosh•4m ago•0 comments

Atlas: Manage your database schema as code

https://github.com/ariga/atlas
1•quectophoton•7m ago•0 comments

Geist Pixel

https://vercel.com/blog/introducing-geist-pixel
1•helloplanets•9m ago•0 comments

Show HN: MCP to get latest dependency package and tool versions

https://github.com/MShekow/package-version-check-mcp
1•mshekow•17m ago•0 comments

The better you get at something, the harder it becomes to do

https://seekingtrust.substack.com/p/improving-at-writing-made-me-almost
2•FinnLobsien•19m ago•0 comments

Show HN: WP Float – Archive WordPress blogs to free static hosting

https://wpfloat.netlify.app/
1•zizoulegrande•20m ago•0 comments

Show HN: I Hacked My Family's Meal Planning with an App

https://mealjar.app
1•melvinzammit•20m ago•0 comments

Sony BMG copy protection rootkit scandal

https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal
1•basilikum•23m ago•0 comments

The Future of Systems

https://novlabs.ai/mission/
2•tekbog•24m ago•1 comments

NASA now allowing astronauts to bring their smartphones on space missions

https://twitter.com/NASAAdmin/status/2019259382962307393
2•gbugniot•28m ago•0 comments

Claude Code Is the Inflection Point

https://newsletter.semianalysis.com/p/claude-code-is-the-inflection-point
3•throwaw12•30m ago•1 comments

Show HN: MicroClaw – Agentic AI Assistant for Telegram, Built in Rust

https://github.com/microclaw/microclaw
1•everettjf•30m ago•2 comments

Show HN: Omni-BLAS – 4x faster matrix multiplication via Monte Carlo sampling

https://github.com/AleatorAI/OMNI-BLAS
1•LowSpecEng•31m ago•1 comments

The AI-Ready Software Developer: Conclusion – Same Game, Different Dice

https://codemanship.wordpress.com/2026/01/05/the-ai-ready-software-developer-conclusion-same-game...
1•lifeisstillgood•33m ago•0 comments

AI Agent Automates Google Stock Analysis from Financial Reports

https://pardusai.org/view/54c6646b9e273bbe103b76256a91a7f30da624062a8a6eeb16febfe403efd078
1•JasonHEIN•36m ago•0 comments

Voxtral Realtime 4B Pure C Implementation

https://github.com/antirez/voxtral.c
2•andreabat•38m ago•1 comments

I Was Trapped in Chinese Mafia Crypto Slavery [video]

https://www.youtube.com/watch?v=zOcNaWmmn0A
2•mgh2•45m ago•0 comments

U.S. CBP Reported Employee Arrests (FY2020 – FYTD)

https://www.cbp.gov/newsroom/stats/reported-employee-arrests
1•ludicrousdispla•46m ago•0 comments

Show HN: I built a free UCP checker – see if AI agents can find your store

https://ucphub.ai/ucp-store-check/
2•vladeta•52m ago•1 comments

Show HN: SVGV – A Real-Time Vector Video Format for Budget Hardware

https://github.com/thealidev/VectorVision-SVGV
1•thealidev•53m ago•0 comments

Study of 150 developers shows AI generated code no harder to maintain long term

https://www.youtube.com/watch?v=b9EbCb5A408
1•lifeisstillgood•53m ago•0 comments

Spotify now requires premium accounts for developer mode API access

https://www.neowin.net/news/spotify-now-requires-premium-accounts-for-developer-mode-api-access/
1•bundie•56m ago•0 comments

When Albert Einstein Moved to Princeton

https://twitter.com/Math_files/status/2020017485815456224
1•keepamovin•58m ago•0 comments

Agents.md as a Dark Signal

https://joshmock.com/post/2026-agents-md-as-a-dark-signal/
2•birdculture•59m ago•0 comments

System time, clocks, and their syncing in macOS

https://eclecticlight.co/2025/05/21/system-time-clocks-and-their-syncing-in-macos/
1•fanf2•1h ago•0 comments

McCLIM and 7GUIs – Part 1: The Counter

https://turtleware.eu/posts/McCLIM-and-7GUIs---Part-1-The-Counter.html
2•ramenbytes•1h ago•0 comments

So whats the next word, then? Almost-no-math intro to transformer models

https://matthias-kainer.de/blog/posts/so-whats-the-next-word-then-/
1•oesimania•1h ago•0 comments

Ed Zitron: The Hater's Guide to Microsoft

https://bsky.app/profile/edzitron.com/post/3me7ibeym2c2n
2•vintagedave•1h ago•1 comments

UK infants ill after drinking contaminated baby formula of Nestle and Danone

https://www.bbc.com/news/articles/c931rxnwn3lo
1•__natty__•1h ago•0 comments

Show HN: Android-based audio player for seniors – Homer Audio Player

https://homeraudioplayer.app
3•cinusek•1h ago•2 comments