frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

6Sense's Privacy Policy Page loads scripts from polyfill(.)io

1•SignalDr•2mo ago
We have completed a forensic investigation into a major B2B marketing vendor's (TrenDemon, linked to 6sense) production SDK and uncovered a systematic vulnerability that impacts thousands of customer sites. We are categorizing this as the Adversarial GTM Architecture.

The system is designed to defeat privacy audits and achieve permanent user tracking.

1. The Core Vulnerability: Remote Code Execution (RCE) Framework The vendor's primary script is not an analytics tool; it is a Remote Code Execution as a Service (RCEaaS) framework.

Mechanism: The SDK uses a proprietary constructor ($TRD\_GenericScriptComponent) to execute arbitrary code delivered from the vendor’s API via dynamic calls to eval() and innerHTML

Vector: This RCE capability is deployed as a "tripwire" that triggers at the moment of highest user engagement (e.g., video completion or form submit).

Result: The vendor can change the functionality of their clients' sites (e.g., deploying new tracking scripts, keyloggers) on the fly without updating the main script file.

2. The Persistence and Evasion Layer This architecture relies on active, high-level evasion to prevent security observation:

Permanent Tracking (The 8,000-Year Cookie): The system sets cookies with an expiration date of December 31, 9999, a clear violation of GDPR's Storage Limitation Principle and evidence of intent for permanent identity persistence.

Audit Evasion Logic: The production code contains detection logic that specifically targets the regex patterns of compliance and legal discovery tools (monitor|checker|validator|analyzer), causing the script to change its behavior when audited.

Supply Chain Risk (PollyWannaCrack): The execution engine relies on loading scripts from polyfill.io, which is a publicly known, compromised CDN.

3. The Payload (Identity Brokering) The primary function of the RCE is to facilitate identity theft:

Cross-Vendor Theft: The system actively encodes and exfiltrates authentication-grade cookies from secondary vendors, specifically the Marketo cookie (maCook), providing TrenDemon with the key to the user's entire marketing identity.

Surveillance Network: The RCE framework is used to dynamically inject and orchestrate a payload array of other surveillance tools (RB2B, LiveIntent, Apollo, etc.) into the host page.

We believe this architecture represents a structural failure in GTM security, demonstrating that the pursuit of attribution has led to the deployment of hostile, RCE-capable code designed for unobservability. We have developed and deployed patches to mitigate this threat.

We encourage security researchers and auditors to independently verify the presence of the $TRD\_GenericScriptComponent and the audit evasion logic within the vendor's production code.

https://www.deployblackout.com/investigations/6sense

Will Future Generations Think We're Gross?

https://chillphysicsenjoyer.substack.com/p/will-future-generations-think-were
1•crescit_eundo•1m ago•0 comments

Kernel Key Retention Service

https://www.kernel.org/doc/html/latest/security/keys/core.html
1•networked•1m ago•0 comments

State Department will delete Xitter posts from before Trump returned to office

https://www.npr.org/2026/02/07/nx-s1-5704785/state-department-trump-posts-x
1•righthand•4m ago•0 comments

Show HN: Verifiable server roundtrip demo for a decision interruption system

https://github.com/veeduzyl-hue/decision-assistant-roundtrip-demo
1•veeduzyl•5m ago•0 comments

Impl Rust – Avro IDL Tool in Rust via Antlr

https://www.youtube.com/watch?v=vmKvw73V394
1•todsacerdoti•6m ago•0 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
2•vinhnx•6m ago•0 comments

minikeyvalue

https://github.com/commaai/minikeyvalue/tree/prod
3•tosh•11m ago•0 comments

Neomacs: GPU-accelerated Emacs with inline video, WebKit, and terminal via wgpu

https://github.com/eval-exec/neomacs
1•evalexec•16m ago•0 comments

Show HN: Moli P2P – An ephemeral, serverless image gallery (Rust and WebRTC)

https://moli-green.is/
2•ShinyaKoyano•20m ago•1 comments

How I grow my X presence?

https://www.reddit.com/r/GrowthHacking/s/UEc8pAl61b
2•m00dy•21m ago•0 comments

What's the cost of the most expensive Super Bowl ad slot?

https://ballparkguess.com/?id=5b98b1d3-5887-47b9-8a92-43be2ced674b
1•bkls•22m ago•0 comments

What if you just did a startup instead?

https://alexaraki.substack.com/p/what-if-you-just-did-a-startup
3•okaywriting•29m ago•0 comments

Hacking up your own shell completion (2020)

https://www.feltrac.co/environment/2020/01/18/build-your-own-shell-completion.html
2•todsacerdoti•32m ago•0 comments

Show HN: Gorse 0.5 – Open-source recommender system with visual workflow editor

https://github.com/gorse-io/gorse
1•zhenghaoz•32m ago•0 comments

GLM-OCR: Accurate × Fast × Comprehensive

https://github.com/zai-org/GLM-OCR
1•ms7892•33m ago•0 comments

Local Agent Bench: Test 11 small LLMs on tool-calling judgment, on CPU, no GPU

https://github.com/MikeVeerman/tool-calling-benchmark
1•MikeVeerman•34m ago•0 comments

Show HN: AboutMyProject – A public log for developer proof-of-work

https://aboutmyproject.com/
1•Raiplus•34m ago•0 comments

Expertise, AI and Work of Future [video]

https://www.youtube.com/watch?v=wsxWl9iT1XU
1•indiantinker•35m ago•0 comments

So Long to Cheap Books You Could Fit in Your Pocket

https://www.nytimes.com/2026/02/06/books/mass-market-paperback-books.html
3•pseudolus•35m ago•1 comments

PID Controller

https://en.wikipedia.org/wiki/Proportional%E2%80%93integral%E2%80%93derivative_controller
1•tosh•39m ago•0 comments

SpaceX Rocket Generates 100GW of Power, or 20% of US Electricity

https://twitter.com/AlecStapp/status/2019932764515234159
2•bkls•40m ago•0 comments

Kubernetes MCP Server

https://github.com/yindia/rootcause
1•yindia•41m ago•0 comments

I Built a Movie Recommendation Agent to Solve Movie Nights with My Wife

https://rokn.io/posts/building-movie-recommendation-agent
4•roknovosel•41m ago•0 comments

What were the first animals? The fierce sponge–jelly battle that just won't end

https://www.nature.com/articles/d41586-026-00238-z
2•beardyw•49m ago•0 comments

Sidestepping Evaluation Awareness and Anticipating Misalignment

https://alignment.openai.com/prod-evals/
1•taubek•49m ago•0 comments

OldMapsOnline

https://www.oldmapsonline.org/en
2•surprisetalk•52m ago•0 comments

What It's Like to Be a Worm

https://www.asimov.press/p/sentience
2•surprisetalk•52m ago•0 comments

Don't go to physics grad school and other cautionary tales

https://scottlocklin.wordpress.com/2025/12/19/dont-go-to-physics-grad-school-and-other-cautionary...
2•surprisetalk•52m ago•0 comments

Lawyer sets new standard for abuse of AI; judge tosses case

https://arstechnica.com/tech-policy/2026/02/randomly-quoting-ray-bradbury-did-not-save-lawyer-fro...
5•pseudolus•52m ago•0 comments

AI anxiety batters software execs, costing them combined $62B: report

https://nypost.com/2026/02/04/business/ai-anxiety-batters-software-execs-costing-them-62b-report/
1•1vuio0pswjnm7•52m ago•0 comments