frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Naughty Dog Studio Orders Employee Overtime for 'Intergalactic'

https://www.bloomberg.com/news/articles/2025-12-18/sony-s-naughty-dog-studio-orders-employee-over...
3•HelloUsername•4m ago•0 comments

A TS library for connecting videos in your Mux account to multi-modal LLMs

https://github.com/muxinc/ai
1•tilt•7m ago•0 comments

Plaintext Casa First Release

https://github.com/nkoehring/plaintext.casa/releases/tag/v0.3
1•koehr•7m ago•1 comments

The Art of Vibe Design

https://www.ivan.codes/blog/the-art-of-vibe-design
1•dohguy•7m ago•0 comments

Starlink 35956 suffered a failure with venting of the propulsion tank

https://bsky.app/profile/planet4589.bsky.social/post/3mac4a3owxs2c
1•perihelions•7m ago•0 comments

CVSS 10.0 HPE OneView RCE bug identified

https://www.scworld.com/news/10-0-hpe-oneview-rce-bug-identified-patch-now
1•Bender•7m ago•0 comments

Wyoming Blasted by 123 MPH Winds on Wednesday and More Wind to Come

https://cowboystatedaily.com/2025/12/17/wyoming-blasted-by-123-mph-winds-and-fierce-mountain-snow...
1•Bender•8m ago•0 comments

Token-Count-Based Batching: Faster, Cheaper Embedding Inference for Queries

https://www.mongodb.com/company/blog/engineering/token-count-based-batching-faster-cheaper-embedd...
1•fzliu•9m ago•0 comments

New X-ray images show interstellar comet as it makes closest approach to Earth

https://www.cnn.com/2025/12/18/science/interstellar-comet-3i-atlas-xray-earth
1•Bender•9m ago•0 comments

Trump media group agrees $6B merger with Google-backed fusion energy company

https://www.ft.com/content/1e1978d5-535b-4241-872f-38db778df694
2•perihelions•10m ago•0 comments

A Starlink Satellite Exploded

https://twitter.com/Starlink/status/2001691802911289712
2•wmf•10m ago•0 comments

LionsOS Design, Implementation and Performance

https://arxiv.org/abs/2501.06234
1•indolering•11m ago•0 comments

Mitsubishi Electric Technology Detects Intoxication During Driving

https://us.mitsubishielectric.com/en/pr/global/2025/1216/
2•geox•12m ago•0 comments

LLMs' impact on science: Booming publications, stagnating quality

https://arstechnica.com/science/2025/12/llms-impact-on-science-booming-publications-stagnating-qu...
2•pseudolus•14m ago•0 comments

GIJN's Top Investigative Tools of 2025

https://gijn.org/stories/gijn-top-investigative-tools-2025/
1•runningmike•14m ago•1 comments

BoltCache: A High-Performance Redis Alternative Built in Go

https://github.com/wutlu/boltcache
1•spotlayn•14m ago•0 comments

2005 Elon Musk Sounded Like Satoshi Nakamoto

https://old.reddit.com/r/conspiracy/comments/1pp2is1/2005_elon_musk_sounded_like_satoshi_nakamoto/
1•tokenmemory•15m ago•1 comments

Two Kinds of Vibe Coding

https://davidbau.com/archives/2025/12/16/vibe_coding.html
4•jxmorris12•16m ago•0 comments

Control Panel for Twitter

https://soitis.dev/control-panel-for-twitter
1•xnx•17m ago•1 comments

Model hallucinations aren't random. They have geometric structure

https://arxiv.org/abs/2512.13771
2•devy•19m ago•0 comments

Analytical dashboards and AI chat: local dev to prod (Vercel and Boreal)

https://www.fiveonefour.com/blog/chat-analytical-dashboards-guide
1•oatsandsugar•22m ago•0 comments

Most Top-Achieving Adults Werent Elite Specialists in Childhood, New Study Finds

https://www.wsj.com/science/elite-high-performance-adults-children-sports-study-ae8d6bed
3•achristmascarl•23m ago•0 comments

FAA Warns of Military Aircraft Flying Undetected in Caribbean

https://www.bloomberg.com/news/articles/2025-12-18/faa-warns-of-military-aircraft-flying-undetect...
2•toomuchtodo•24m ago•1 comments

GitHub delays GHA price increase

https://twitter.com/github/status/2001372894882918548
2•timvdalen•29m ago•2 comments

Ask HN: Is there an open source "turbopuffer"?

1•koconder•33m ago•0 comments

Calculate founder dilution across funding rounds

https://angelmatch.io/resources/cap-table-calculator
2•educated_panda•33m ago•0 comments

Ask HN: How to spend L&D/Training funds before the end of the year?

2•jamestimmins•35m ago•1 comments

Obscure Polish company launches 122.88TB PCIe 5.0 immersion cooled SSD

https://www.techradar.com/pro/obscure-polish-company-quietly-launches-massive-122-88tb-pcie-5-0-i...
2•piterrro•35m ago•0 comments

State of Radicle CI in 2025

https://blog.liw.fi/posts/2025/radicle-ci-status-quo/
1•aiw1nt3rs•36m ago•0 comments

Backprop in Rust ML lib blogpost

https://cant.bearblog.dev/we-need-to-go-back-to-the-gradient/
1•TuckerBMorgan•38m ago•1 comments
Open in hackernews

How to hack Discord, Vercel and more with one easy trick

https://kibty.town/blog/mintlify/
48•todsacerdoti•1h ago

Comments

devrupt•1h ago
See also https://news.ycombinator.com/item?id=46317098
llmslave2•1h ago
This feels so emblematic of our current era. VC funded vibe coded AI documentation startup somehow gets big name customers who don't properly vet the security of the platform, ship a massive vulnerability that could pwn millions of users and the person who reports the vulnerability gets...$5k.

If I recall last week Mintlify wrote a blog post showcasing their impressive(ly complicated) caching architecture. Pretending like they were doing real engineering, when it turns out nobody there seems to know what they're doing, but they've managed to convince some big names to use them.

Man, it's like everything I hate about modern tech. Good job Eva for finding this one. Starting to think that every AI startup or company that is heavily using gen-ai for coding is probably extremely vulnerable to the simplest of attacks. Might be a way to make some extra spending money lol.

subscribed•59m ago
You bet not all THW vulnerabilities are reported to the vendors. Not with 5k bounty for THAT.
guizadillas•52m ago
Yeah it made me re-evaluate how much I can trust those platforms
llmslave2•37m ago
Yeah thats the scary thing. I know it's a bit of a meme about how as programmers we don't trust other programmers or software, but it's becoming more and more true and necessary. I want to use as little software as possible these days.
gruez•46m ago
> This feels so emblematic of our current era. VC funded vibe coded AI documentation startup somehow ...

Is there any indication Mintify was "vibe coded"?

llmslave2•38m ago
I'm giving them the benefit of the doubt, as the alternative would be that their developers are completely incompetent. The vulnerability is the equivalent to letting a user save HTML to a database and then injecting it into every page completely unsanitized.
sans_souse•51m ago
$5k is such a small payout for this sort of finding.
ChrisArchitect•25m ago
Related:

We pwned X, Vercel, Cursor, and Discord through a supply-chain attack

https://news.ycombinator.com/item?id=46317098

ollybee•8m ago
How is a company like mintlify getting so many big name customers for what appears to be a static site generator + hosting? Is there some secret sauce I'm missing, what is the value proposition?
tommica•3m ago
Convenience and developer uncertainty. I fall pray to the "it's paid, so it must be better" fallacy, and the "they know what they are doing, they are pros" illogicality.