frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Hackerest – Real-time penetration testing, built by security engineers

https://hackerest.com
2•mcisternino•1h ago
We launched Hackerest last week. We’re a group of security engineers based in Italy (ex-Amazon, Accenture) who spent years doing pentests the traditional way and kept wondering why the workflow still looks like it did in 2010.

Most pentests today (still) work like this:

1. the engagement runs for days or weeks

2. nothing is shared until everything is finished

3. the client gets a PDF long after the issues were actually discovered

4. half of the attack surface has changed by then

What Hackerest does:

* findings appear in real time during the active testing window, as testers discover them

* built-in versioning of findings, so changes, updates, and retests are tracked cleanly

* multiple testers can collaborate without blocking each other

* the final PDF is generated automatically at the end

* customers use a credit-based model to start tests quickly

We DON'T use AI to perform the actual testing. Hacking, in our experience, is a creative and exploratory process that depends heavily on intuition, pattern recognition, and years of hands-on work. Automating that would either produce shallow results or give a false sense of coverage.

We’d rather be transparent about what we offer: real testers, with real experience, working in real time. AI might help with auxiliary tasks in the future (summaries, noise reduction, report cleanup), but the core of the work is done by humans who know what they’re doing. We don’t want to sell automation where it doesn’t belong.

The tester network:

We collaborate with independent, experienced pentesters. The platform handles assignment, access isolation, and report normalization so testers can focus on actual discovery rather than logistics.

What we're building next:

We’re adding workflow integrations (starting with Jira), more granular notification controls, and better tools for teams running multiple engagements in parallel. Longer term, we’d like to expose a structured API to let companies pull findings directly into their internal systems.

--

If you’ve worked on similar problems, we’d really value feedback. Our goal isn’t to reinvent pentesting, just to make it match how engineering teams actually operate today.

My LinkedIn, if you want context on who’s behind the project: https://www.linkedin.com/in/nt-authority-system/

Create a Markdown Editor in Ruby on Rails

https://blog.appsignal.com/2025/12/10/create-a-markdown-editor-in-ruby-on-rails.html
1•amalinovic•30s ago•0 comments

The Future of Software Outsourcing: Productization and On-Demand

https://www.indiehackers.com/post/the-future-of-software-outsourcing-productization-and-on-demand...
1•plakhlani2•38s ago•0 comments

The San José–The 'Holy Grail' of Shipwrecks–Just Yielded Its First Treasure

https://www.popularmechanics.com/science/archaeology/a69546218/holy-grail-of-shipwrecks-first-tre...
1•bookofjoe•2m ago•1 comments

Show HN: Practical programming using only composition

https://github.com/raoofha/r/blob/main/r
1•raoof•2m ago•0 comments

Digital Stimulation: AI and Porn

https://www.economist.com/podcasts/2025/12/10/digital-stimulation-ai-and-porn
1•andsoitis•4m ago•0 comments

AI slop ad backfires for McDonald's

https://www.latimes.com/business/story/2025-12-10/ai-slop-ad-backfires-for-mcdonalds
1•thm•5m ago•0 comments

Show HN: I wrote an open source package manager for AI coding, OpenPackage

https://github.com/enulus/OpenPackage
1•hyericlee•5m ago•0 comments

Ask HN: Post-CVE-2025-55182 – should we be auditing for backdoors?

1•Just_Clive•5m ago•0 comments

Show HN: I made a web piano with recording and playback

https://webpiano.jcurcioconsulting.com
1•Jeremy1026•5m ago•0 comments

Dialing Up the Internet Phonebook

https://pketh.org/internet-phonebook.html
1•cookingoils•6m ago•0 comments

Show HN: A directory of 150 AI bots and crawlers with verifying tools

https://crawlercheck.com/directory
1•bogozi•7m ago•1 comments

Google Calendar Extension – a browser-side enhancement for Calendar users

1•sergey_commit•7m ago•1 comments

Cagent – Docker Docs

https://docs.docker.com/ai/cagent
1•thunderbong•11m ago•0 comments

Black Hole Recorded Blasting Winds at More Than 20% the Speed of Light

https://www.esa.int/Science_Exploration/Space_Science/XMM-Newton/Flaring_black_hole_whips_up_ultr...
2•Willingham•13m ago•0 comments

Trump to make all foreign tourists provide five years of social media history

https://www.lbc.co.uk/article/trump-foreign-tourists-social-media-history-5HjdPCX_2/
6•chrisjj•13m ago•2 comments

Streaming at the Speed of Thought: How Human Perception Affects UX

https://www.red5.net/blog/streaming-at-the-speed-of-thought/
1•mondainx•13m ago•0 comments

US could ask foreign tourists for five-year social media history before entry

https://www.bbc.co.uk/news/articles/c1dz0g2ykpeo
4•neversaydie•13m ago•0 comments

Hard problems in social media archiving

https://alexwlchan.net/2025/hard-problems-in-social-media-archiving/
1•ingve•14m ago•0 comments

Togelius: Please, Don't Automate Science

http://togelius.blogspot.com/2025/12/please-dont-automate-science.html
1•bilsbie•15m ago•0 comments

Ethereum Fusaka upgrade set for early December rollout

https://altcoindesk.com/perspectives/learn/ethereum-fusaka-upgrade-set-for-early-december-rollout...
1•AishwaryaTiwari•17m ago•0 comments

First Analysis of the Lunar GNSS Receiver Experiment Data

https://destevez.net/2025/12/first-analysis-of-the-lunar-gnss-receiver-experiment-data/
1•tverbeure•19m ago•0 comments

History Rhymes: Macro-Contextual Retrieval for Robust Financial Forecasting

https://arxiv.org/abs/2511.09754
1•PaulHoule•20m ago•0 comments

Ask HN: Did Andrew Lee Kill IRC?

1•the_stocker•21m ago•1 comments

Notepad++ Updater Installed Malware

https://www.heise.de/en/news/Notepad-updater-installed-malware-11109726.html
5•mimikasec•23m ago•1 comments

Ask HN: Resources for Learning Springboot

1•peter_bips•24m ago•0 comments

The Java Ring: A Wearable Computer (1998)

https://www.nngroup.com/articles/javaring-wearable-computer/
1•cromulent•26m ago•0 comments

Week 1 of Streaming as a Developer

https://www.twitch.tv/implabinash
1•implabinash•26m ago•1 comments

Docker Best Practices: Read-Only Containers

https://blog.ploetzli.ch/2025/docker-best-practices-read-only-containers/
1•buibuibui•27m ago•0 comments

Ask HNIs early-stage fundraising broken,or founders just pitching the wrong way?

2•paulwilsonn•30m ago•0 comments

Show HN: YM2149 in Rust – Chiptune Emulation from Atari ST to WebAssembly

https://ym2149-rs.org/
1•slippyvex•32m ago•1 comments