frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A US Government iPhone-hacking toolkit is now in foreign spy and criminal hands

https://www.wired.com/story/coruna-iphone-hacking-toolkit-us-government/
104•alwillis•2h ago

Comments

oxfeed65261•1h ago
https://archive.ph/r7jGc
mentalgear•1h ago
How could something as sensitive get out of an administration as competent as the current one? At least they have no access to lets say AI or autonomous weapons and the tools of mass surveillance ...
happyopossum•58m ago
"Possible" stripped from the headline on HN. That word seems particularly important given that it's speculative:

"Clues suggest it was originally built for the US government."

tptacek•22m ago
The Google threat analysis report doesn't say anything about USG involvement; that it was found on compromised Ukrainian sites, has code written in "native English", but also signs of LLM authorship. The Google report says the kit they found can't compromise current iOS, which is a capability you'd assume USG would have --- though it's important remember that "USG" comprises dozens of different buyers each with different toolchains.

Maybe this was the Fisheries Department exploit toolkit.

iVerify, which spun out of Trail of Bits and presumably knows what they're talking about, says it bears "hallmarks" of being connected to USG CNE work. I believe it. But the USG is on net a buyer, not a producer, of CNE tooling. Whatever a given service agency or IC arm buys, dozens of other aligned countries are also buying.

(And, of course, the non-aligned countries have their own commercial supply chains).

doctorpangloss•56m ago
the government doesn't have superpowerful code crackers though

it has a guy working at apple who introduces the subtle vulnerability he is instructed to do

tptacek•32m ago
I expect the evidence for this claim is axiomatic, which is to say that you think it sounds good.
lightedman•26m ago
No, anyone who remembers the Best Buy/FBI debacle knows that this statement is very well-grounded in reality. If you took your laptop to Best Buy for repairs, the FBI got a copy of your hard drive contents.
everdrive•33m ago
No matter the risk, I must carry my smartphone everywhere and install every app. It would be unimaginable to have the urge to look something up, but then wait to do it later until I'm using a real computer. No negative outcome will EVER shake my deep, permanent need to carry a smartphone all the time and use it for as much as possible.
theearling•25m ago
Webapps exist for a reason, they don't get all the special permissions apps get when fully installed.

at the very least use a VPN / more secure phone like a pixel with graphene

You keep doing you though

thewebguyd•1m ago
Ironically, the exploits in this leaked kit all involved flaws in webkit, so you'd have been safer sticking to native apps assuming they didn't have any webviews in them to load the malicious site.

Sen. Wyden Warns of Mass Surveillance Amid Pentagon's Fight with Anthropic

https://gizmodo.com/sen-wyden-warns-of-mass-surveillance-amid-pentagons-fight-with-anthropic-2000...
1•WarOnPrivacy•29s ago•0 comments

Bluesky adds (broken) age verification

https://bsky.app
1•neogodless•32s ago•0 comments

Show HN: Webact – token-efficient browser control for AI agents (GitHub)

https://github.com/kilospark/webact
1•kxbnb•2m ago•0 comments

In startups, "I assumed" is the most expensive sentence you can say [video]

https://www.tiktok.com/@taxhero_ai/video/7613137316227353887?is_from_webapp=1&sender_device=pc
1•salleisha•2m ago•1 comments

Ask HN: Why don't MacBooks have Cellular Modems yet?

1•avonmach•3m ago•1 comments

Show HN: Proofd – Free AI career risk score based on your tasks, not job title

https://www.proofd.ai
1•dixalex•4m ago•0 comments

Is Shopify Good for SEO in 2026?

https://www.techwrath.com/is-shopify-good-for-seo-2026/
1•techwrath11•6m ago•0 comments

EURO-3C Project to build a federated Telco-Edge-Cloud infrastructure

https://digital-strategy.ec.europa.eu/en/news/commission-announces-eu75-million-euro-3c-project-b...
1•_____k•6m ago•0 comments

Show HN: TypeShim – .NET WebAssembly Meets TypeScript

https://github.com/ArcadeMode/TypeShim
1•ArcadeMode•6m ago•0 comments

How to Choose the Right Shopify Development Agency in 2026

https://www.techwrath.com/how-to-choose-right-shopify-development-agency/
1•techwrath11•6m ago•0 comments

Neovim cookies for the pluginless – random nvim native tips

https://eduardofuncao.com/blog/neovim-cookies/
1•xGoivo•7m ago•1 comments

The Social Media Discoverability Problem

https://samranda.com/blog/social-media-discoverability/
1•performative•8m ago•0 comments

Millennium Challenge 2002: Persian Gulf War Game Exercise

https://en.wikipedia.org/wiki/Millennium_Challenge_2002
2•Jimmc414•8m ago•1 comments

Open-source community gets a Claude-sized gift

https://www.thedeepview.com/articles/open-source-community-gets-a-claude-sized-gift
1•CrankyBear•10m ago•0 comments

Turning 4,668 comments into AGENTS.md rules to automate Pydantic AI reviews

https://pydantic.dev/articles/scaling-open-source-with-ai
2•yoredana•11m ago•0 comments

I Use Neovim by the Way

https://stupid-ideas.com/blog/2026_03_02__nvim_setup.html
2•KuSpa•13m ago•0 comments

Scripting on the JVM with Java, Scala, and Kotlin

https://mill-build.org/blog/19-scripting-on-the-jvm.html
2•PaulHoule•13m ago•0 comments

Show HN: Validatedata 0.3.0 – lightweight inline data validation for Python

https://pypi.org/project/validatedata/
1•EdwardK1•13m ago•0 comments

OpenWRT 25.12.0 Released

https://openwrt.org/releases/25.12/notes-25.12.0
3•voxadam•14m ago•1 comments

Incident postmortem in the age of AI agents

https://blog.firetiger.com/postmortem-on-the-march-1-2026-ingest-incident/
1•achille-roussel•14m ago•0 comments

CIA Station Hit in Drone Attack

https://www.washingtonpost.com/national-security/2026/03/03/cia-saudi-arabia-drone-attack-iran/
7•jbegley•14m ago•2 comments

Chat at your own risk Data brokers are selling deeply personal bot transcripts

https://www.theregister.com/2026/03/03/chatbot_data_harvesting_personal_info/
2•jjgreen•15m ago•1 comments

Trae Stephens: I want to buy Wired

https://twitter.com/i/status/2028824764656283997
1•mudil•18m ago•0 comments

Show HN: I build a free topical authority map generator for blog

https://kitful.ai/write-tools/topical-map-generator
1•eashish93•19m ago•0 comments

Show HN: Headless Obsidian Sync Client

https://github.com/alexjbarnes/vault-sync
1•recouptreadmill•20m ago•0 comments

Show HN: VibeDiff – Blocks Claude Code from shipping breaking changes

https://github.com/SallahBoussettah/vibe-diff
1•Boussettah•20m ago•0 comments

Buckle Up for Bumpier Skies

https://www.newyorker.com/projects/interactive/2026/20260226-bilger-turbulence-header-prod/202602...
1•rbanffy•22m ago•0 comments

How To Put 30 Languages Into 1.1MB – hypher, a fast hyphenation library for Rust

https://laurmaedje.github.io/posts/hypher/
2•zdw•22m ago•0 comments

Prediction markets on Deutsche Bahn departure delays

https://bahn.bet
2•dancric•23m ago•0 comments

AI causing programmers to work longer hours fixing bugs

https://www.scientificamerican.com/article/why-developers-using-ai-are-working-longer-hours/
5•timoth3y•24m ago•1 comments