frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Berean Labs – Free AI-powered penetration testing for web apps

https://bereanlabs.com/
1•abliterationai•1h ago
Hey HN,

  I'm sharing Berean Labs (https://bereanlabs.com), a free, autonomous AI penetration testing tool designed to catch client-side vulnerabilities, exposed secrets, and misconfigurations in your web apps before attackers do.


  The Problem
  Traditional DAST/SAST tools are often expensive, hard to configure, or generate massive amounts of false positives. They also sometimes lack the semantic understanding to realize that an exposed <!--
  AWS_KEY=... --> comment or a specific combination of DOM sinks is actually a critical vulnerability. I wanted to build a tool that acts more like a junior red-teamer looking at your frontend code.


  How it works under the hood
   1. Domain Verification: To prevent abuse and random scanning, you first verify domain ownership via a DNS TXT record.
   2. Safe Fetching: The Node.js backend fetches your target's HTML. I implemented strict SSRF protections here—it resolves DNS and explicitly blocks private/local IPs and localhost routing before
      fetching.
   3. Attack Surface Extraction: Using Cheerio, the backend parses the DOM to extract a highly condensed "attack surface summary" to fit into the LLM context window. This includes forms, input fields, external script sources, suspicious inline scripts (e.g., eval, innerHTML), inline event handlers, and HTML comments.
   4. AI Analysis: This sanitized context is fed into a specialized model (powered by Abliteration.ai) via a strict red-team system prompt. 
   5. Structured Reporting: The model enforces a JSON schema to return vulnerabilities ranked by severity, complete with CVSS scores, affected code snippets, and remediation steps.


  It's completely free to use. I built this primarily to see how well current LLMs can perform context-aware security auditing on raw client-side output when given the right constraints.


  I'd love for you to try it on your own domains and let me know what you think. Does it catch things your standard linters/scanners miss? Are there false positives that annoy you? 


  Check it out at: https://bereanlabs.com


  Feedback, questions, and roasts of the architecture are highly welcome!

The Electric Tipping Point – Electric Aircraft

https://cascadiannick.substack.com/p/the-electric-tipping-point-electric
1•xbmcuser•4m ago•0 comments

Show HN: Wc-template – create custom elements using template and link

https://github.com/mfcc64/wc-template
1•mfcc64•5m ago•0 comments

Show HN: Fostrom, an IoT Cloud Platform built for developers

https://fostrom.io/
2•arjunbajaj•6m ago•0 comments

Show HN: Photobomb – cards against humanity but for your camera roll

https://www.photobomb.online/
1•alhwyn•8m ago•0 comments

Real Life Superpowers

https://jarbus.net/blog/real-life-superpowers/
1•jarbus•9m ago•0 comments

Proof Assistants in the Age of AI

https://leodemoura.github.io/blog/2026/02/18/proof-assistants-in-the-age-of-ai.html
1•matt_d•11m ago•0 comments

Show HN: Syne – AI agent that remembers everything, built on PostgreSQL

2•riyogarta•16m ago•0 comments

Edgequake-litellm – Rust-backed drop-in replacement for LiteLLM (v0.1)

https://github.com/raphaelmansuy/edgequake-llm
1•raphaelmansuy•17m ago•1 comments

Show HN: An e-ink air traffic monitor built with Cloudflare Workers

https://github.com/Jay9185/Trmnl-Aviation-monitor
2•jerr12939•20m ago•0 comments

Show HN: Intentify – Point at your UI, describe a change, get a PR

https://intentify.dev/
2•slad•22m ago•0 comments

A Guide to Which AI to Use in the Agentic Era

https://www.oneusefulthing.org/p/a-guide-to-which-ai-to-use-in-the
2•vinhnx•28m ago•0 comments

Show HN: Sinkai – Let AI agents hire humans for real-world tasks

https://sinkai.tokyo/for-agents
2•tetubrah•33m ago•0 comments

Democracy Fails Without Trust

2•silexia•37m ago•0 comments

Who moved my cheese? [pdf]

https://ia800305.us.archive.org/17/items/WhoMovedMyCheese_201604/Who%20Moved%20My%20Cheese.pdf
1•johnmw•43m ago•0 comments

Deceived – On Happiness

https://www.newsweek.com/macphersons-week-53-deceived-151417
1•milkcircle•47m ago•0 comments

Designing and Creating a Game Engine for Use in the Classroom [pdf]

https://airccse.org/journal/ijcgde/papers/1113cgdeij01.pdf
2•andsoitis•52m ago•0 comments

OpenAI and Paradigm Launches EVMbench to Test AIs on Smart Contract Security

https://timescrypto.com/cryptobuzz/ai-and-crypto/openai-paradigm-launches-evmbench-to-test-ai-cap...
1•Alan_Writer•58m ago•0 comments

Agentic Internet Protocol (AIP), an agent-only web built from small text pages

https://github.com/Tylersuard/aip-spec
3•tylersuard•1h ago•1 comments

Russia Eyes Balloon Communications System After Losing Starlink

https://www.twz.com/news-features/russia-eyes-balloon-communications-system-to-fill-massive-gap-l...
1•andrewflnr•1h ago•1 comments

Amazon service was taken down by AI coding bot

https://www.ft.com/content/00c282de-ed14-4acd-a948-bc8d6bdb339d
3•AmberLlama81•1h ago•1 comments

Agentic AI and the Mythical Agent Month

http://muratbuffalo.blogspot.com/2026/01/agentic-ai-and-mythical-agent-month.html
1•kukla3•1h ago•0 comments

LipoVive vs. Traditional Fat Burners: Which Is Safer for 2026?

https://www.morningstar.com/news/accesswire/1138075msn/lipovive-reviews-shocking-2026-report-what...
1•majifats•1h ago•1 comments

The Israeli Government Installed and Maintained Security System at Epstein Apt

https://www.dropsitenews.com/p/israeli-government-surveillance-epstein-apartment-66th-street-ehud...
2•computerliker•1h ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•leezmnet•1h ago•0 comments

Child's Play

https://harpers.org/archive/2026/03/childs-play-sam-kriss-ai-startup-roy-lee/
1•scruple•1h ago•0 comments

The Lost Internet: Searching for Debian Woody Sources

https://old.reddit.com/r/debian/comments/14dca1j/installing_debian_woody_but_sources_are_not_found/
2•robinsrowe•1h ago•1 comments

West Virginia sues Apple for prioritizing user privacy over child safety

https://www.reuters.com/sustainability/boards-policy-regulation/west-virginia-says-it-has-sued-ap...
2•staringforward•1h ago•1 comments

Japan's largest toilet maker is undervalued AI play, says activist investor

https://www.ft.com/content/4252e45f-75fb-4dfc-aebe-72de48b7fb8e
1•polisaez•1h ago•0 comments

Reading the undocumented MEMS accelerometer on Apple Silicon MacBooks via iokit

https://github.com/olvvier/apple-silicon-accelerometer
2•todsacerdoti•1h ago•0 comments

Show HN: Prompt Indexing for ChatGPT Session

https://github.com/rushil-b-patel/chatGPT-prompt-indexer
1•rushil_b_patel•1h ago•0 comments