frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Post-CVE-2025-55182 – should we be auditing for backdoors?

1•Just_Clive•1h ago
Vercel Agent just auto-patched 800K+ projects for CVE-2025-55182 (React2Shell), which is great for stopping future attacks.But I'm curious: is anyone auditing their codebases for malicious artifacts that may have been planted during the 9-day exposure window (Dec 5-9)?

The issue: Patching updates your dependencies to remove the vulnerability. But if attackers exploited it during that window, they could have:

Injected backdoors into components or middleware Added obfuscated malicious code (eval/atob patterns) Planted crypto miners or data exfiltration hooks Modified server actions to leak credentials

Patching doesn't retroactively remove this code. Our experience: We patched immediately on Dec 9. Then spent 6 hours manually auditing our Next.js codebase and found 2 suspicious modifications we didn't write (obfuscated eval calls in middleware). What we built: An AST-based scanner to automate this. It checks for 80+ Indicators of Compromise:

Code obfuscation patterns Unauthorized network calls Modified Next.js internals Crypto mining signatures CVE-2025-55182-specific exploit artifacts

Runs in 30 seconds vs. our 6-hour manual audit. Questions for HN:

Are companies doing post-patch audits, or assuming they're clean? Is there existing tooling for this that we missed? For high-value targets (fintech, healthcare), what's the recommended approach?

We open-sourced the scanner here: [https://github.com/Alcatecablee/Neurolint-CLI/] Curious how others are approaching this, seems like a blind spot in the patching narrative.

Discrete Bayesian Sample Inference for Graph Generation

https://arxiv.org/abs/2511.03015
1•PaulHoule•1m ago•0 comments

I Tried the New Android XR Smart Glasses from Google and XReal

https://www.pcmag.com/news/i-tried-the-new-android-xr-smart-glasses-from-google-they-impressed-me
1•fcpguru•3m ago•0 comments

Toggle the "Light" Switch

https://www.incommonwith.com/collections/all-lighting
1•FelipeCortez•4m ago•0 comments

New benchmark shows top LLMs struggle in real mental health care

https://swordhealth.com/newsroom/sword-introduces-mindeval
2•RicardoRei•6m ago•1 comments

Apple Faces Scrutiny as Sanctioned Entities Slip Through App Store Controls

https://www.washingtonpost.com/technology/2025/12/10/us-sanctions-apple-google/
2•7777777phil•8m ago•1 comments

2025 Cacowards

https://www.doomworld.com/cacowards/2025/index/
1•klaussilveira•9m ago•0 comments

EU welcomes seamless data transfer between iPhone and Android

https://www.heise.de/en/news/EU-welcomes-seamless-data-transfer-between-iPhone-and-Android-111106...
1•doener•11m ago•0 comments

If Dr. Seuss Danced with Nietzche – The Sneetches on the Nietzches

https://philshapirochatgptexplorations.blogspot.com/2025/12/the-sneetches-on-nietzsches.html
1•pshapiro99•11m ago•0 comments

The boundary of copyrightability in AI-generated code under Japan and US Law

https://shujisado.org/2025/12/10/the-boundary-of-copyrightability-in-ai-generated-code/
1•jonymo•11m ago•0 comments

I Wish People Were More Public

https://borretti.me/article/i-wish-people-were-more-public
1•swah•12m ago•0 comments

"Empire of AI" is wildly misleading about AI water use

https://andymasley.substack.com/p/empire-of-ai-is-wildly-misleading
2•Tycho•12m ago•0 comments

Operation Bluebird to relaunch "Twitter," says Musk abandoned the name and logo

https://arstechnica.com/information-technology/2025/12/can-twitter-fly-again-startup-wants-to-pry...
2•pathompong•14m ago•0 comments

Ask HN: Is 13" MacBook good enough without an external monitor?

1•ShahinSorkh•15m ago•0 comments

Show HN: Fastest way for analysts to ship data pipelines – safely

https://www.youtube.com/watch?v=WKVxgCrwQHw
2•adadu2•15m ago•3 comments

Suno Is Changing Music's Future: Thoughts on the AI Music Generator

https://micahblachman.beehiiv.com/p/suno-is-changing-music-s-future
1•subdomain•18m ago•0 comments

Publishing KOReader Highlights

https://tech.stonecharioteer.com/posts/2025/kollector/
1•stonecharioteer•18m ago•0 comments

Show HN: Calamari – single-host restrictive proxy (with squid)

https://github.com/n0id/calamari
1•calamari-proxy•20m ago•0 comments

Google Maps on iOS now remembers where you parked

https://mashable.com/article/google-maps-parking-remember-spot
2•gniting•23m ago•1 comments

Building a Self-Hosted CDN for BSD Cafe Media

https://it-notes.dragas.net/2024/08/26/building-a-self-hosted-cdn-for-bsd-cafe-media/
1•gpi•23m ago•0 comments

"restart on excessive memory usage" experiment: discordapp

https://old.reddit.com/r/discordapp/comments/1pej7l7/restart_on_excessive_memory_usage_experiment/
1•speckx•24m ago•0 comments

Can NASA Bring Mars Rocks Back to Earth?

https://www.scientificamerican.com/podcast/episode/can-nasa-bring-mars-rocks-back-to-earth/
1•quapster•27m ago•0 comments

Vix dev Auto-reload and rebuild loop for C++ applications

https://vixcpp.com
1•gkirira•30m ago•1 comments

Ask HN: Outstanding packets calculation in Go-Back-N ARQ when ACK lost?

1•shivajikobardan•31m ago•0 comments

Ask HN: How can I learn smartphone repair online?

2•rishikeshs•33m ago•0 comments

Boom Superpower: The Supersonic Tech Powering AI Data Centers

https://boomsupersonic.com/superpower
3•embedding-shape•36m ago•0 comments

Show HN: AI that writes reports while your Team codes

https://www.gitmore.io/
1•hamadev•37m ago•0 comments

Show HN: WireTyped – typed, error-first HTTP client for fetch

https://github.com/kasperrt/wiretyped
2•kasperrt•38m ago•0 comments

Interactive Network Learning Platform

https://packet.school
2•r1z4•39m ago•0 comments

Warner Bros Bidding War: Lessons on Aggregator Theory and Hostile Deal Mechanics

https://philippdubach.com/2025/12/09/not-logan-roy-netflix-vs.-paramounts-bidding-war/
5•7777777phil•39m ago•1 comments

Font of 'wasteful' diversity: State Department orders return to Times New Roman

https://www.theguardian.com/us-news/2025/dec/10/trump-times-new-roman-font-return-state-department
1•bux93•39m ago•3 comments