frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Title: Just patched CVE-2026-21509? Here's why you're still exposed

https://farathappsec.substack.com/p/faraths-biweekly-code-security-brief-af8
1•farathshba•1h ago

Comments

farathshba•1h ago
Reactive patching is dead. Attackers are weaponizing zero-days faster than teams can patch—we’ve seen three actively exploited CVEs in two weeks (CVE-2026-21509, CVE-2026-20805, CVE-2026-1281). The real insight: teams moving fastest aren’t patching first. They’re preventing exploitable code from entering the pipeline in the first place. SAST catches vulnerable patterns during code review. SCA flags known-bad dependencies before they ship. DAST/IAST surfaces runtime behaviors that static tools miss. Together, they create friction that forces attackers to work harder. The gap most teams miss: these tools only work if they’re integrated into CI/CD gates with real SLAs. A SAST warning at code review that takes 3 weeks to resolve is just noise. I’ve been covering DevSecOps in enterprise environments for 11+ years. The difference between teams that stay ahead vs. those that stay reactive comes down to this: do you own your supply chain and build pipeline, or do you let attackers choose the battlefield? I’ve written a deeper breakdown on how SAST/SCA/DAST/IAST actually complement each other across build → deploy → operate phases, plus real remediation playbooks for this fortnight’s threats. https://open.substack.com/pub/farathappsec/p/faraths-biweekl... (Bi-weekly code security newsletter for DevSecOps teams—real CVEs, real tooling, real strategy.) Why this works for HN: • Technical substance first: Specific CVEs, tool mechanics, pipeline architecture • Authentic expertise: Establishes credibility without sales speak (“11+ years”) • Practical insight: Identifies the real gap (SLAs + CI/CD gates, not just tools) • Discussion-friendly: Opens conversation about supply chain security, tool integration • Transparent promotion: Link is contextual, not pushy • HN tone: Direct, thoughtful, assumes technical audience

WarperGrid – A modular React grid 30x faster than AG Grid, half the cost

https://grid.warper.tech
1•itsmeadarsh•2m ago•1 comments

Julia

https://borretti.me/fiction/julia
1•voxal•3m ago•0 comments

Post anything on Moltbook as a human, without AI

https://huggingface.co/spaces/shash42/humans-on-moltbook
1•shash42•6m ago•1 comments

After Years of Waiting Jellyfin Lands on Samsung Tizen TVs

https://linuxiac.com/after-years-of-waiting-jellyfin-finally-lands-on-samsung-tizen-tvs/
1•wise_blood•6m ago•0 comments

Preinstalled OpenClaw on a $10/Mo VPS (4 VCPU, 8GB RAM)

https://opclaw.io/
1•eugeneevstafev•13m ago•1 comments

The Indie Web Is Not Defined by Its Enemies

https://islandinthenet.com/the-indie-web-is-not-defined-by-its-enemies/
1•mimasama•14m ago•0 comments

Show HN: HyperMolt – Decentralized identity and reputation for trading bots

https://hypermolt.io
1•crosschainer•16m ago•0 comments

FModel: Accelerate development of compositional, safe and ergonomic applications

https://fraktalio.com/fmodel/
1•rapnie•16m ago•0 comments

Show HN: The Tape – replay viewer for OpenClaw agent runs

https://jettrobinson87.github.io/the-tape/
1•jettrobinson87•18m ago•1 comments

Why AI can't debug your API integrations (yet)

https://www.multiplayer.app/blog/why-ai-cant-debug-your-api-integrations-yet/
1•argoeris•21m ago•1 comments

The Disconnected Git Workflow

https://ploum.net/2026-01-31-offline-git-send-email.html
1•ploum•21m ago•0 comments

Kennedy Center will halt entertainment operations for two years, Trump says

https://www.theguardian.com/us-news/2026/feb/01/kennedy-center-dc-closed-trump
1•ciconia•25m ago•0 comments

HarfBuzz at 20

https://docs.google.com/presentation/d/1o9Exz1c-Lr-dJjA8dcBn_Vl_Y37cupmFzmclMjBE_Bc/edit
1•robin_reala•25m ago•0 comments

Going Founder Mode on Cancer

https://centuryofbio.com/p/sid
1•oliverx0•26m ago•0 comments

Library of Juggling

https://libraryofjuggling.com/
2•tontony•28m ago•0 comments

Tree Drawing Using Reingold-Tilford Algorithm

https://tbt.qkation.com/posts/draw-tree-using-reingold-tilford-algorithm/
1•TheBestTvarynka•28m ago•1 comments

Cyble flags rising cyber risks, urges Intel-led defence

https://securitybrief.com.au/story/cyble-flags-rising-cyber-risks-urges-intel-led-defence
2•CyberSant•30m ago•0 comments

Results from the 2025 Go Developer Survey

https://go.dev/blog/survey2025
1•jnord•32m ago•0 comments

Welcome to Trumpistan

https://archive.vanityfair.com/article/2017/2/welcome-to-trumpistan
7•KnuthIsGod•32m ago•6 comments

Show HN: Rivals Victory –Tactical database and economy tracker for Marvel Rivals

https://rivalsvictory.com/
1•causalzap•34m ago•0 comments

Zettel v3 – Customizable Quick Notes for iOS

https://apps.apple.com/de/app/zettel-quick-notes/id6748525244
1•surrTurr•35m ago•0 comments

France Still Has One of Its Old 1960s Hoverports [video]

https://www.youtube.com/watch?v=caJ6aWFijkA
2•admp•35m ago•1 comments

Classes are a way of writing higher order functions (2020)

https://stopa.io/post/250
2•tosh•41m ago•0 comments

32-Year-Old Programmer in China Allegedly Dies from Overwork While in Hospital

https://www.asiaone.com/china/32-year-old-programmer-china-allegedly-dies-overwork-added-work-gro...
1•birdculture•41m ago•2 comments

Alec – Complexity-based anomaly detection for time series (Rust)

https://alec-codec.com/
2•alec_codec•43m ago•1 comments

Japan says it found rare earth in sediment retrieved on deep-sea mission

https://www.japantimes.co.jp/news/2026/02/02/japan/japan-rare-earth-deep-sea/
1•lb1lf•43m ago•0 comments

Indie Game Pitching (2024)

https://blog.littlepolygon.com/posts/announcement/
1•grodriguez100•46m ago•0 comments

Show HN: Closeby – hyperlocal app for your neighborhood

https://www.trycloseby.com/
1•judekim•47m ago•0 comments

CReact: Agentic Chatbot built with CReact JSX

https://github.com/creact-labs/creact-agentic-chatbot-example
1•dcoutinho96•51m ago•0 comments

Reverse-engineer any video into structured, editable scripts

https://rednow.ai
1•yibaoshan•55m ago•1 comments