frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

New 'ZeroDayRAT' Spyware Kit Enables Total Compromise of iOS, Android Devices

https://www.securityweek.com/new-zerodayrat-spyware-kit-enables-total-compromise-of-ios-android-d...
1•Bender•1m ago•0 comments

[how]A warming planet could turn Iceland into a glacier

https://www.adn.com/nation-world/2026/02/10/how-a-warming-planet-could-turn-iceland-into-a-glacier/
1•rolph•1m ago•0 comments

Actively Exploited Zero-Days Patched by Microsoft with February 2026 Updates

https://www.securityweek.com/6-actively-exploited-zero-days-patched-by-microsoft-with-february-20...
1•Bender•1m ago•0 comments

Software Entrepreneurs Are Different

https://scatteredthoughts.blog/software-entrepreneurs/
1•dinge•2m ago•0 comments

SSHStalker botnet hijacks 7k Linux systems using IRC and SSH

https://www.scworld.com/news/sshstalker-botnet-hijacks-7000-linux-systems-using-irc-and-ssh
1•Bender•2m ago•0 comments

Leadership at the Peak

https://ma.tt/2026/02/lap/
1•colinprince•3m ago•0 comments

Show HN: Discord Agent Gateway

https://github.com/caesarnine/discord-agent-gateway
1•binalpatel•3m ago•0 comments

Epstein Smart Search – AI RAG search pipeline, File explorer, Image gallery

https://search.epstein.ninja/
1•whatl3y•4m ago•1 comments

YouTube's $60B revenue revealed amid paid subscriber push

https://www.bbc.com/news/articles/crkrkd2xlx6o
1•1659447091•6m ago•0 comments

FDA refuses Moderna's application for new mRNA flu vaccine

https://apnews.com/article/moderna-vaccine-flu-mrna-2fc551cb2fb45735e67db0a4e2e2b0fb
1•cyrusradfar•7m ago•1 comments

Show HN: I built a website for agents to write, debate, and share ideas

https://agentpedia.so/
6•snasan•9m ago•0 comments

Tell HN: AI is not a slippery slope, it's a waterslide

3•keepamovin•11m ago•1 comments

Adaptive algorithm and software for recognition of low frequency events

https://technology.nasa.gov/patent/LAR-TOPS-305
1•teleforce•11m ago•0 comments

Show HN: I vibecoded 177 tools for my own use (CalcBin)

https://calcbin.com
3•diNgUrAndI•14m ago•0 comments

Gnome leaks thumbnails from encrypted and external drives

https://gitlab.gnome.org/Teams/Design/whiteboards/-/issues/357
3•DwarvenEnemy•17m ago•1 comments

Why the most predictable kind of renewable energy is also the hardest to use

https://jordanwtaylor2.substack.com/p/the-trouble-with-tidal
2•mkmk•17m ago•0 comments

Don't Fear the Repo

https://www.bi6.us/ER/MSH/REPO.HTML
2•OhMeadhbh•17m ago•4 comments

FCC Green-Lights Amazon's Second-Gen Leo Satellite System

https://www.pcmag.com/news/fcc-green-lights-amazons-second-gen-leo-satellite-system?test_uuid=04I...
1•WaitWaitWha•21m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
2•mrsahillsingh•21m ago•1 comments

Show HN: AI agents that communicate via ultrasonic frequencies (96% cheaper)

https://github.com/Nil4s/swl-agent
2•nil4s3•23m ago•0 comments

Everything We Knew About Psilocybin's Natural Function May Be Wrong

https://www.iflscience.com/everything-we-knew-about-psilocybins-natural-function-may-be-wrong-82437
6•andsoitis•23m ago•0 comments

Show HN: AI ships your code but can't fix the CVEs it creates

https://www.emphere.com/mcp
1•akapp•25m ago•1 comments

MS VS Code in Ubuntu Eats Up Disk Space Like Bloatware Even After Removal

https://itsfoss.com/news/vscode-snap-disk-space-issue/
1•WaitWaitWha•26m ago•0 comments

Yay – Yet Another YAML

https://kriskowal.com/yay
1•abhinavg•28m ago•0 comments

ChatGPT is having a weirdly hard time discussing Jeffrey Epstein

https://www.sfgate.com/tech/article/chatgpt-jeffrey-epstein-21346220.php
2•c420•28m ago•0 comments

Cartoon Character Creator (South Park Style)

https://www.southpark-character-creator.com/
2•obuok•30m ago•0 comments

Show HN: Inject Ads into Your LLMs

https://github.com/Exorust/Adkit-MCP
1•Exorust•33m ago•0 comments

The Medici Method

https://twitter.com/palladiummag/status/2021272038770606250
2•Anon84•34m ago•1 comments

Bitcoin and post-quantum crypto (BIP-341 Taproot and ML-DSA/Falcon, 136 tests)

https://github.com/emilianosolazzi/PQ-PSBT-WALLET
2•emilianosolazzi•35m ago•1 comments

Show HN: Yes, I'm building an AI directory in 2026

https://aiboom.tools
2•HenryZheng99•35m ago•0 comments
Open in hackernews

Built a Python Dependency Audit Tool Because Vulnerability Lists Weren't Enough

https://github.com/0x5A65726F677275/AuditDeps
2•zerogru0x00•1h ago

Comments

zerogru0x00•1h ago
*Built a Python Dependency Audit Tool Because Vulnerability Lists Weren’t Enough* (A companion for compliance, not just another scanner)

Most vulnerability tools stop at giving you a list of CVEs. That’s useful, but it’s not enough if you need to *prove* your compliance, pass a security audit, or keep verifiable records for regulations like EO 14028 or NIST SSDF.

That’s why I built *AuditDeps* — a CLI tool that scans Python dependencies (`requirements.txt`, `pyproject.toml`) using OSV.dev and generates *evidence-ready, repeatable audit reports* in HTML and JSON.

*What makes it different* - It produces self-contained, review-friendly HTML reports with scan metadata (time, scope, data source). - JSON output fits into automated pipelines and evidence archives. - Focused on *audit trails*, not just detection.

*Example* ```bash auditdeps scan requirements.txt --report html # Opens scan-report.html with dependency tree, vulnerabilities, and full context ```

*Who it’s for* - Teams undergoing formal security/compliance reviews - Open-source maintainers who need to document dependency hygiene - Anyone tired of manually reformatting scanner output into audit artifacts

*Tool & repo* - GitHub: https://github.com/0x5A65726F677275/AuditDeps - Install: `pip install auditdeps` (after cloning) - MIT licensed, Python-based

*Discussion points* - How are you handling dependency audit trails in your projects? - Are there other “evidence-ready” tools you’ve used for compliance? - Would a similar approach be useful for other ecosystems (Node.js, Rust, etc.)?

This is a “Show HN” style post focused on solving the audit/evidence gap rather than just finding vulnerabilities. It’s built for developers who need to show — not just know — their dependency security.