frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Who else got pwned by the Next.js RCE?

8•whycombinetor•11h ago
I'm a little embarrassed, but not sure what I could have done differently other than reading the Saturday email from GCP with the nondescript subject "New Advisory Notification". Ten hours later, GCP instance suspended due to crypto mining. Now looking at the disk image, it installed something at ~/nxt/ , installed a monero miner at ~/c3pool/ , and added several systemctl services to run these on startup. BRB, killing this machine with fire... This makes me think I should be running everything in Docker, even simple small stuff that "shouldn't" have any potential security issues.

Fortunately this machine wasn't anything important for me and there was no sensitive data to exfil beyond AI API keys. But I imagine there's other orgs that just got catastrophically, irrecoverably pwned.

What's your story?

(RCE context: https://news.ycombinator.com/item?id=46136026 )

Comments

samdoesnothing•9h ago
I'm sure a lot of people and companies got pwned and they aren't going to disclose it. There are chrome extensions that passively polls sites for the vulnerability, and since the vulnerability is so simple to exploit and leaves virtually no trace...

My gut feeling is that we are going to be feeling the consequences of simultaneous enshittification of software, the mounting complexity of our systems, and AI enslopification combine to create far more vulnerabilities in the future. The only defence is to adopt simple systems and software.

yellow_lead•3h ago
I don't use Next.js but I'm curious as well. My impression was that most people run it under Vercel who patches quickly, but maybe that's not the case.

Kinesis Advantage2

https://danishpraka.sh/posts/kinesis-advantage2/
1•prakashdanish•6m ago•0 comments

Show HN: Peargent – A Simple Python Framework for Building AI Agents

https://github.com/Quanta-Naut/peargent
1•Quanta-Naut•9m ago•1 comments

Indian boy, aged 3, becomes youngest rated chess player in history

https://www.nytimes.com/athletic/6869534/2025/12/07/youngest-chess-player-age-india/
2•NewCzech•9m ago•1 comments

Finnix

https://en.wikipedia.org/wiki/Finnix
1•fuzztester•10m ago•1 comments

Fifty Years of Retracted Medical Publications from 1975 to 2024

https://jkms.org/DOIx.php?id=10.3346/jkms.2025.40.e300
1•XzetaU8•11m ago•0 comments

Apple Taps Meta Lawyer as General Counsel in Latest Shake-Up

https://www.bloomberg.com/news/articles/2025-12-04/apple-taps-top-meta-lawyer-as-general-counsel-...
1•mgh2•21m ago•1 comments

Estimate Trend at a Point in a Noisy Time Series

https://github.com/finite-sample/incline
1•neehao•22m ago•0 comments

Publishing Malicious VS Code Extensions: Bypassing VS Code Marketplace Analysis

https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/
1•mazen160•29m ago•0 comments

IBM to Acquire Confluent for $11B

https://www.bloomberg.com/news/articles/2025-12-08/ibm-close-to-buying-confluent-in-11-billion-de...
2•marc__1•31m ago•1 comments

Dewy: Continuous deployments for VPS and bare metal, no K8s required

https://github.com/linyows/dewy
1•linyows•33m ago•1 comments

EVs 80% Worse Consumer Reports Lied – ICE Cars Are Failing at Record Levels

https://www.youtube.com/watch?v=f2kYoahAw5U
1•xbmcuser•34m ago•0 comments

2FAS Pass: Local-First Password Manager

https://2fas.com/pass/
1•thunderbong•35m ago•0 comments

Kazakhstan, France collaborate to boost aviation training capacity

https://qazinform.com/news/kazakhstan-france-collaborate-to-boost-aviation-training-capacity-4d2486
1•Bolat14•39m ago•0 comments

Earth needs energy. Atlanta's Super Soaker creator may have a solution

https://www.seattletimes.com/business/earth-needs-energy-atlantas-super-soaker-creator-may-have-a...
1•Gaishan•41m ago•0 comments

FiwixOS 3.5 Released

https://www.fiwix.org/news/20251115.html
1•coolcoder613•43m ago•0 comments

GeneralGiist – A Global Forum Built for Real, Unfiltered Conversations

1•cimaa•47m ago•1 comments

How to Use Git Worktree for Claude Code Development

https://medium.com/@naveensky/how-to-use-git-worktree-for-claude-code-development-43dfbd554b21
1•naveensky•47m ago•0 comments

Funerary figurines found in royal tomb identifies Pharoah

https://www.sciencealert.com/trove-of-225-exceptional-egyptian-figurines-solves-long-standing-mys...
1•Gaishan•48m ago•0 comments

The Forge Tier List

https://theforgetierlist.com/
1•quchao•49m ago•2 comments

Cybersecurity Must Block AI Browsers for Now

https://www.gartner.com/en/documents/7211030
1•gnabgib•53m ago•0 comments

CDC advisory panel delays vote on hepatitis B vaccines

https://www.nbcnews.com/health/health-news/cdc-advisory-panel-delays-vote-hepatitis-b-vaccines-rc...
1•gmays•55m ago•0 comments

Block all AI browsers for the foreseeable future: Gartner

https://www.theregister.com/2025/12/08/gartner_recommends_ai_browser_ban/
2•defrost•56m ago•0 comments

Show HN: I added coins to Dino Game

https://dinosaurgame.app/
2•coolwebtoolsguy•57m ago•1 comments

Ideavo – Tinder-style validation for startup ideas

1•ideavo•1h ago•1 comments

Reborrowing

https://en.wikipedia.org/wiki/Reborrowing
1•surprisetalk•1h ago•0 comments

Mystery Science Theater 3000: The Definitive Oral History of a TV Masterpiece

https://www.wired.com/2014/04/mst3k-oral-history/
6•indigodaddy•1h ago•1 comments

Top IAM Platforms

https://ssojet.com/blog/best-identity-access-management-tools
2•guptadeepak•1h ago•1 comments

Deposition of cathode metals from the largest lithium-ion battery fire

https://www.nature.com/articles/s41598-025-25972-8
1•Stratoscope•1h ago•1 comments

Ask HN: Has anyone else been hit by React2Shell?

2•jtolly710•1h ago•0 comments

Bots, bias, and bunk: How can you tell what's real on the net?

https://www.theregister.com/2025/12/05/bots_bias_bunk/
1•snorbleck•1h ago•0 comments