frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Catching the LiteLLM and Telnyx supply chain zero-days via semantic analysis

https://point-wild.github.io/who-touched-my-packages/
4•justinmsnider•1h ago
Following the discussions around the LiteLLM compromise and today's terrifying telnyx zero-day, my team and I wrote up a technical breakdown of how the TeamPCP actors are bypassing legacy SCA tools.

The tl;dr is that traditional scanners are looking for signatures, while the attackers are weaponizing context. By hiding an executable payload inside mathematically valid .wav audio frames, TeamPCP ensured that content filters and CVE databases waved the Telnyx payload right through.

We spent the weekend building an open-source CLI (wtmp) to hunt for this exact behavior. Instead of asking "Is this package on a blacklist?", it maps your Node/Python dependency graph and uses a LangGraph process to actually read the code. It asks things like: "Why is a telephony SDK running an XOR decryption loop on an audio file and piping it to a shell?"

The reality check: Because it relies on LLMs to infer intent, expect false positives. It is not a deterministic CI/CD blocker; it’s a flashlight to help you triage your blast radius during an active crisis like today.

I’ll be hanging out in the comments. I’d love for you to read the write-up, test the CLI against your local trees, and absolutely tear apart our prompt architecture and logic.

ADL Shut Down Sora

https://twitter.com/ADL/status/2037585125765185572
1•black6•32s ago•0 comments

Netscape News Feed Straight Out of the Late 00s

https://isp.netscape.com/
2•mistyvales•50s ago•0 comments

Claude Code Chronicles

https://darshanmakwana412.github.io/2026/03/claude-code-chronicles/
1•darshanmakwana•2m ago•0 comments

Show HN: I built an 8-axis MTG draft advisor that runs inside ChatGPT

https://savecraft.gg/games/mtga
1•Veraticus•3m ago•1 comments

Show HN: Escape the Room, bounded AI stats game

https://github.com/AymanJabr/Escape-the-room-AI-stats-game
1•AymanJabr•4m ago•0 comments

Wp-tarpit – A honeypot that wastes WordPress scanners' time

https://github.com/lakeforestcomputer-com/wp-tarpit/
1•xLFCx•7m ago•1 comments

Ask HN: I'm hiring a SysAdmin in El Paso. Is there a place on HN to share?

1•WarcrimeActual•11m ago•2 comments

Shipping a Week's Work in a Day using parallel Claude agents

https://thewriting.dev/shipping-a-weeks-work-in-a-day-using-claude-code/
1•r0rshrk•13m ago•0 comments

Small Programming Tricks · will keleher

https://will-keleher.com/posts/small-programming-tricks-matter/
1•sharjeelsayed•13m ago•0 comments

Reddit Users Are Being Targeted by Stake's Covert Advertising Tactics

https://old.reddit.com/r/redscarepod/comments/1s3xvw6/how_reddit_users_are_being_maliciously_targ...
4•47thpresident•15m ago•0 comments

The Tmux Intro I Wish I Had Gotten – Simple Thread

https://www.simplethread.com/the-tmux-intro-i-wish-i-had-gotten/
1•sharjeelsayed•16m ago•0 comments

LLMs Do Not Grade Essays Like Humans

https://arxiv.org/abs/2603.23714
2•PretzelFisch•17m ago•1 comments

First Western Digital, now Sony: The tech giant suspends SD card sales

https://mashable.com/article/sony-sd-card-sales-suspended-memory-shortage
4•_tk_•20m ago•0 comments

Spot – Git repo code search, replace, diff and merge

https://github.com/gritzko/librdx/tree/master/spot
1•gritzko•20m ago•2 comments

Cursor Pagination out-of-the box for PrimeFaces and JPA

https://docs.flowlogix.com/#section-jpa-lazymodel-cursor-pagination
1•lprimak•23m ago•0 comments

What to Know: Working in China [video]

https://www.youtube.com/watch?v=bz7KuzEPqcs
1•simonpure•23m ago•0 comments

JP Morgan map shows crude oil ticking time bomb hits oil supply in April

https://www.msn.com/en-us/money/markets/this-map-shows-a-crude-ticking-time-bomb-that-hits-much-o...
3•ck2•26m ago•1 comments

CVE-2026-33691: OWASP CRS whitespace padding bypass vulnerability

1•relunsec•26m ago•0 comments

Show HN: /slot-machine development (CC vs. Codex; CE vs. superpowers)

https://github.com/pejmanjohn/slot-machine
2•pejmanjohn•27m ago•0 comments

Pretext: browser independent text layouting engine for the web

https://twitter.com/i/status/2037713766205608234
1•lewisjoe•28m ago•0 comments

Anthropic Donations: Guesses and Uncertainties

https://www.lesswrong.com/posts/NAwqT8wDkLRovcbZ9/anthropic-donations-guesses-and-uncertainties
1•joozio•30m ago•0 comments

Show HN: Create setups, deploy and share them

3•victorzidaroiu•32m ago•1 comments

Folie à Machine: LLMs and Epistemic Capture

https://www.lesswrong.com/posts/2hyGiAnLKEFv3jBHt/folie-a-machine-llms-and-epistemic-capture
1•joozio•32m ago•0 comments

Every Country in Our Supply Chain Has Declared an Emergency

https://energyandresilience.substack.com/p/every-country-in-our-supply-chain
2•measurablefunc•33m ago•0 comments

Pretext

https://chenglou.me/pretext/
2•sysbot•33m ago•0 comments

Quantum frontiers may be closer than they appear

https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/
4•OJFord•35m ago•0 comments

Show HN: Danobang! – Multiplayer CJK (Chinese, Japanese, Korean) Word Game

https://danobang.com
3•maenbalja•35m ago•1 comments

LeaseWitness – Free lease agreement generator (15 types, no sign-up)

1•alexchemours•37m ago•0 comments

Show HN: Baton – A daemon that sends Claude to fix your GitHub issues

https://github.com/mraza007/baton
2•mr_o47•38m ago•0 comments

Eye drops made from pig semen deliver cancer treatment to mice

https://www.nature.com/articles/d41586-026-00982-2
2•gnabgib•40m ago•1 comments