frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Show HN: Poddley.com – Follow people, not podcasts

https://poddley.com/guests/ana-kasparian/episodes
1•onesandofgrain•1m ago•0 comments

Layoffs Surge 118% in January – The Highest Since 2009

https://www.cnbc.com/2026/02/05/layoff-and-hiring-announcements-hit-their-worst-january-levels-si...
2•karakoram•1m ago•0 comments

Papyrus 114: Homer's Iliad

https://p114.homemade.systems/
1•mwenge•1m ago•1 comments

DicePit – Real-time multiplayer Knucklebones in the browser

https://dicepit.pages.dev/
1•r1z4•1m ago•1 comments

Turn-Based Structural Triggers: Prompt-Free Backdoors in Multi-Turn LLMs

https://arxiv.org/abs/2601.14340
2•PaulHoule•3m ago•0 comments

Show HN: AI Agent Tool That Keeps You in the Loop

https://github.com/dshearer/misatay
2•dshearer•4m ago•0 comments

Why Every R Package Wrapping External Tools Needs a Sitrep() Function

https://drmowinckels.io/blog/2026/sitrep-functions/
1•todsacerdoti•4m ago•0 comments

Achieving Ultra-Fast AI Chat Widgets

https://www.cjroth.com/blog/2026-02-06-chat-widgets
1•thoughtfulchris•6m ago•0 comments

Show HN: Runtime Fence – Kill switch for AI agents

https://github.com/RunTimeAdmin/ai-agent-killswitch
1•ccie14019•9m ago•1 comments

Researchers surprised by the brain benefits of cannabis usage in adults over 40

https://nypost.com/2026/02/07/health/cannabis-may-benefit-aging-brains-study-finds/
1•SirLJ•10m ago•0 comments

Peter Thiel warns the Antichrist, apocalypse linked to the 'end of modernity'

https://fortune.com/2026/02/04/peter-thiel-antichrist-greta-thunberg-end-of-modernity-billionaires/
1•randycupertino•11m ago•2 comments

USS Preble Used Helios Laser to Zap Four Drones in Expanding Testing

https://www.twz.com/sea/uss-preble-used-helios-laser-to-zap-four-drones-in-expanding-testing
2•breve•16m ago•0 comments

Show HN: Animated beach scene, made with CSS

https://ahmed-machine.github.io/beach-scene/
1•ahmedoo•17m ago•0 comments

An update on unredacting select Epstein files – DBC12.pdf liberated

https://neosmart.net/blog/efta00400459-has-been-cracked-dbc12-pdf-liberated/
1•ks2048•17m ago•0 comments

Was going to share my work

1•hiddenarchitect•21m ago•0 comments

Pitchfork: A devilishly good process manager for developers

https://pitchfork.jdx.dev/
1•ahamez•21m ago•0 comments

You Are Here

https://brooker.co.za/blog/2026/02/07/you-are-here.html
3•mltvc•25m ago•1 comments

Why social apps need to become proactive, not reactive

https://www.heyflare.app/blog/from-reactive-to-proactive-how-ai-agents-will-reshape-social-apps
1•JoanMDuarte•26m ago•1 comments

How patient are AI scrapers, anyway? – Random Thoughts

https://lars.ingebrigtsen.no/2026/02/07/how-patient-are-ai-scrapers-anyway/
1•samtrack2019•26m ago•0 comments

Vouch: A contributor trust management system

https://github.com/mitchellh/vouch
2•SchwKatze•26m ago•0 comments

I built a terminal monitoring app and custom firmware for a clock with Claude

https://duggan.ie/posts/i-built-a-terminal-monitoring-app-and-custom-firmware-for-a-desktop-clock...
1•duggan•27m ago•0 comments

Tiny C Compiler

https://bellard.org/tcc/
1•guerrilla•29m ago•0 comments

Y Combinator Founder Organizes 'March for Billionaires'

https://mlq.ai/news/ai-startup-founder-organizes-march-for-billionaires-protest-against-californi...
1•hidden80•29m ago•2 comments

Ask HN: Need feedback on the idea I'm working on

1•Yogender78•30m ago•0 comments

OpenClaw Addresses Security Risks

https://thebiggish.com/news/openclaw-s-security-flaws-expose-enterprise-risk-22-of-deployments-un...
2•vedantnair•30m ago•0 comments

Apple finalizes Gemini / Siri deal

https://www.engadget.com/ai/apple-reportedly-plans-to-reveal-its-gemini-powered-siri-in-february-...
1•vedantnair•31m ago•0 comments

Italy Railways Sabotaged

https://www.bbc.co.uk/news/articles/czr4rx04xjpo
9•vedantnair•31m ago•2 comments

Emacs-tramp-RPC: high-performance TRAMP back end using MsgPack-RPC

https://github.com/ArthurHeymans/emacs-tramp-rpc
1•fanf2•32m ago•0 comments

Nintendo Wii Themed Portfolio

https://akiraux.vercel.app/
2•s4074433•37m ago•2 comments

"There must be something like the opposite of suicide "

https://post.substack.com/p/there-must-be-something-like-the
1•rbanffy•39m ago•1 comments
Open in hackernews

Show HN: Shannon Uncontained – generate src for live target, go for the pwn

https://github.com/Steake/shannon-uncontained
1•_steake•1mo ago
The security-industrial complex peddles spreadsheets of vibes. Severity badges. Ritual scans. Then, at the moment of truth, it refuses the simple, adult question: can you actually pwn it?

Shannon said yes. It did the unfashionable thing: try the exploit, ship receipts, or shut up. No exploit, no report. That single sentence wipes out half the ceremony and all of the superstition.

Shannon Uncontained is the fork for people who don’t need a container to run Node, don’t always have source, and don’t swear fealty to a single LLM vendor. It runs natively. It speaks Claude, GPT-4.1, support connecting via GitHub Models, and the locals (Ollama/llama.cpp/LM Studio).

And when all you’ve got is a URL and permission, it crawls, fingerprints, and assembles pseudo‑source—a structured model of routes, inputs, and flows—then hands that to the same exploit-first pipeline. Less incense, more impact.

This is a pentester that behaves like it means it:

If it can’t make the vuln sing—shell, XSS pop, auth bypass, SSRF reach—it doesn’t log it as gospel. It maps your mess to OWASP Top 10, spits SARIF for auditors, JSON/HTML for humans, and keeps an audit trail that’s actually evidence, not a confession.

It slots into CI/CD without container cosplay, because “portable” shouldn’t mean “pretend Linux wrapped around JavaScript.”

Yes, the tone is combative. That’s because the default is complacency. “We ran the scanner” is a lullaby. If your app can be owned, your pipeline should find out before someone less poetic does.

If the idea of pseudo‑source offends you, excellent—show me where it fails. If you think it’s useful, tell me the guardrails you want in CI (timeouts, scope fences, auth flows). Either way, the premise stands: suspicion without a proof-of-concept is astrology with YAML.

Repo: https://github.com/steake/shannon-uncontained

Comments

_steake•1mo ago
BTW: “Black box” doesn’t mean blind thrashing. It means disciplined recon: endpoints, forms, tokens, flows—enough to build a working model and push for exploit.
_steake•1mo ago
To clarify; LLM provider mix: practical wins/losses across Claude/GPT/GitHub/local on code reasoning vs. web exploitation.