frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

CASM – open-source external attack surface monitoring

https://github.com/G2CV/CASM
1•rokhlan•1h ago

Comments

rokhlan•1h ago
I built CASM (Continuous Attack Surface Monitoring) to solve attack surface monitoring problems I faced in my work.

Commercial EASM tools are very expensive and are black boxes. You get dashboards but no evidence trail, no transparency, and no way to verify findings. Manual scripting with dig/curl/nmap works but is time-consuming and error-prone.

CASM is an open source EASM tool that: - Discovers DNS subdomains (passive + active sources) - Verifies HTTP security (headers, TLS, redirects) - Tracks changes (automatic baseline comparison) - Provides evidence (complete audit trail in JSONL) - Generates professional reports (PDF, SARIF to be integrated to CI pipeline, Markdown)

It's licensed AGPL v3 so you can verify what it does and use it freely.

For the technical stack, I used Python for orchestration, Go for scanning tools. It works on Linux/macOS. It's designed to be scriptable and automation-friendly.

As a DevSecOps engineer, I often needed to answer: "Do we know our complete external attack surface?". I needed something transparent, evidence-based, and accessible. So I built it.

GitHub: https://github.com/g2cv/casm

Thank you for taking the time to read me, I hope you'll like it and I'd be happy to answer questions or hear feedback!

East Asia AQI/wind vector map

https://sanghoonio.github.io/air/
1•sanghoonio•31s ago•1 comments

Chrome extension to detect AI-written text and anonymous chat to any website

https://chromewebstore.google.com/detail/hiyo/nocfklgnphddgdaengibolefpmombome
1•Saikat2020•1m ago•1 comments

Building Custom Docker Sandboxes

https://substack.com/home/post/p-188153139
1•shelajev•1m ago•0 comments

Bengt Hires a Human–Towards a Happy Future with AI Employers

https://andonlabs.com/blog/bengt-hires-a-human
1•lukaspetersson•2m ago•1 comments

Russian state media meddles in Swiss public broadcasting referendum

https://www.20min.ch/story/halbierungsinitiative-russisches-staatsmedium-mischt-sich-in-srg-absti...
1•leohoferdev•3m ago•0 comments

Deploy your OpenClaw agent in 5 minutes

https://fastclaw.ai/
1•idoubi•3m ago•0 comments

I Joined the MariaDB Foundation

https://lefred.be/content/i-joined-the-mariadb-foundation/
2•eatonphil•4m ago•0 comments

A Love Letter to Self-Hosting

https://lukaswerner.com/post/2026-02-13@self-hosting-letter
1•chilipepperhott•4m ago•0 comments

If AI writes most of the code, understanding codebases becomes the bottleneck

https://app.tryarchaic.com/
2•baijan•4m ago•1 comments

Break Stasis

https://oldmanrahul.com/2026/02/15/break-stasis/
1•oldmanrahul•4m ago•0 comments

Undetected Past Contacts with Technological Species and Technosignature Science

https://iopscience.iop.org/article/10.3847/1538-3881/ae394b
1•bikenaga•4m ago•0 comments

Password managers less secure than promised

https://ethz.ch/en/news-and-events/eth-news/news/2026/02/password-managers-less-secure-than-promi...
5•winterdeaf•4m ago•0 comments

Trying New Things

https://daoudclarke.net/2026/02/16/trying-new-things
2•daoudc•5m ago•0 comments

macOS Tahoe Finder Bug Underscores Apple's Slipping UI Polish

https://www.macrumors.com/2026/02/13/macos-tahoe-finder-bug-slipping-ui-polish/
2•akyuu•7m ago•0 comments

Google warns EU against 'erecting walls' in tech sovereignty push

https://www.ft.com/content/0847914c-be27-4573-8600-8cdb54e604b7
2•spiffyk•8m ago•1 comments

How to take a photo with scotch tape (lensless imaging) [video]

https://www.youtube.com/watch?v=97f0nfU5Px0
3•surprisetalk•8m ago•0 comments

GrowthClaw: Marketing workflows for OpenClaw with evaluation gates

https://github.com/mrrkrieg/growthos
3•dankrieg•9m ago•2 comments

Unitree's humanoid robot team's performance at the 2026 Spring Festival Gala

https://twitter.com/cyberrobooo/status/2023378370592174272
3•DustinEchoes•10m ago•0 comments

Programming a 144-computer chip to minimize power (2013) [video]

https://www.youtube.com/watch?v=0PclgBd6_Zs
2•tosh•10m ago•0 comments

Show HN: CabbageSEO: Check if AI mentions your business, then fix it if not

https://www.cabbageseo.com/
2•arjun060601•10m ago•0 comments

Show HN: Comfy Pilot – MCP server that lets Claude Code edit ComfyUI workflows

https://github.com/ConstantineB6/comfy-pilot
2•0xConstantine•11m ago•0 comments

(Un)portable defer in C

https://antonz.org/defer-in-c/
1•birdculture•14m ago•0 comments

Dyslexia, Programming and Lisp

https://www.iwillig.me/blog/on-dyslexia-and-lisp/
2•_emacsomancer_•15m ago•0 comments

Integration patterns: How we connect software

https://staffbase.com/blog/integration-patterns
2•goblin89•16m ago•0 comments

Architecting AI-ready infrastructure for the agentic era

https://thenewstack.io/ai-ready-infrastructure/
1•dmk•17m ago•0 comments

What's Your Attention Worth? – The Ad Spend Calculator

https://attentionworth.com/
1•thunderbong•17m ago•0 comments

A Historical Reference of React Criticism

https://www.zachleat.com/web/react-criticism/
1•ishandotpage•17m ago•0 comments

Show HN: Hackable Skinny Clawdbot for Telegram

https://github.com/vseplet/smith
1•vseplet•17m ago•0 comments

Show HN: An beautiful webpage I made

https://github.com/adityaprasad-sudo/ExploreSingapore
1•gigachadai•18m ago•0 comments

Effective Vibe Coding (Determinism)

https://www.stevenathompson.com/effective-vibe-coding-best-practices-useful-tools/
1•StevenThompson•19m ago•0 comments