frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Post-Mortem of the EU Europa Breach: A Masterclass in IAM Misconfiguration

https://cyberalert.com.pl/articles/shinyhunters-eu-europa-breach-analysis.html
1•D__S•1h ago

Comments

D__S•1h ago
I’ve spent the last 48 hours dissecting the leak from the European Commission’s "Europa" platform. New evidence from the dump suggests the breach is far larger than initially reported—up to 350GB of exfiltrated data, not just 90GB.

My technical analysis confirms:

Stolen DKIM Signing Keys: Total loss of email authenticity. This allows for perfect impersonation of EU domains, bypassing DMARC.

SSO Directory Exposure: The "Skeleton" of their AWS Organizations was exposed, likely due to a lack of proper Service Control Policies (SCPs). IAM Failures: Evidence points to over-privileged roles (Resource: "*") and failure to enforce IMDSv2, explaining how such a massive volume (350GB) could be exfiltrated.

It is deeply ironic that the institution enforcing GDPR on everyone else failed at basic cloud hygiene.

The site is a 45KB static HTML to stay accessible. I’m curious to hear from other AWS architects—how does an organization of this scale miss such fundamental guardrails?

Ray Tracing Cores for General-Purpose Computing: A Literature Review

https://arxiv.org/abs/2603.28771
1•Brajeshwar•21s ago•0 comments

Carbonyl – A Chromium-based browser built to run in a terminal

https://github.com/fathyb/carbonyl
1•redbell•26s ago•0 comments

Unfolding the Dramatic Turn of Events with the LiteLLM Compromise

https://cycode.com/blog/lite-llm-supply-chain-attack/
1•dominikposmyk•2m ago•0 comments

Show HN: Symbolic regression as an MCP tool (SINDy and PySR, free, no install)

https://occam.fit/
1•CodeReclaimers•3m ago•0 comments

Trial by Fire

https://yusufaytas.com/trial-by-fire/
3•yusufaytas•3m ago•0 comments

Node.js Security Bug Bounty Program Paused

https://nodejs.org/en/blog/announcements/discontinuing-security-bug-bounties
3•0xedb•5m ago•0 comments

Metamorf: Compiler construction meta-language compiling via Zig and Clang

https://github.com/tinyBigGAMES/Metamorf
1•vintagedave•5m ago•0 comments

Google questions family's X-rated Gemini account-ban story

https://www.androidauthority.com/google-account-bans-3654171/
1•croes•5m ago•0 comments

Show HN: Octopoddy – iOS Podcast App Using Transcripts and LLMs to Skip Ads

https://apps.apple.com/us/app/octopoddy-alpha/id6753860890
1•spellbind-dare•6m ago•0 comments

What can I do better with my llms.txt builder?

https://llms-txt.lilbigthings.com/
1•veermanhas•6m ago•1 comments

Show HN: Generateppt, an anti-bloat presentation tool

https://www.generateppt.com/
1•fer_momento•6m ago•0 comments

Apple Rich Text Fundamentals

https://paper.pro/apple-rich-text
1•tobr•7m ago•0 comments

Show HN: Deckard, Claude-first terminal manager

https://github.com/gi11es/deckard
2•kouiskas•8m ago•0 comments

MindsDB Anton: a new powerful autonomous BI agent

https://mindsdb.com/blog/introducing-anton-what-business-intelligence-is-supposed-to-be
1•darksoul•9m ago•0 comments

Network Weather: Quickly diagnose internet connection issues

https://www.networkweather.com/
1•gwbas1c•10m ago•0 comments

Mongoose: Preauth RCE and MTLS Bypass on Devices

https://www.evilsocket.net/2026/04/02/Mongoose-Preauth-Remote-Code-Execution-and-mTLS-Bypass/
1•evilsocket•10m ago•1 comments

Show HN: Reviewskits – Open-source, headless, and self-hostable social proof

https://reviewskits.com
1•LordKode•11m ago•0 comments

Pulled from Headlines: U.S. Manufacturing Rebounds

https://gonzojournalism.substack.com/p/pulled-from-headlines-us-manufacturing
1•KariDonovan•12m ago•0 comments

Jira for AI Agents

https://fluado.com/blog/building-jira-for-ai-agents
1•yvg0•14m ago•0 comments

Trump's rage at NATO allies is binding them together – against him

https://www.politico.eu/article/donald-trump-anger-nato-allies-europe-united/
1•breve•14m ago•0 comments

Blue Owl limits redemptions on private credit funds after exit requests

https://www.msn.com/en-us/money/other/blue-owl-limits-redemptions-on-private-credit-funds-after-m...
2•petethomas•16m ago•0 comments

Show HN: PGP Made Convenient

https://chromewebstore.google.com/detail/pgp-tools-encrypt-decrypt/pgpcdgggohpbombhkffjoiiafdlfcpgp
1•acorn221•17m ago•0 comments

Krishnized License

https://github.com/krishnized/license/
2•hmokiguess•17m ago•0 comments

Who Holds the Keys to the Agent Web – Part 1: Before the Doors Close

https://threadbaire.com/blog/posts/who-holds-the-keys-to-the-agent-web-part-1.html
1•lliberopoulou•17m ago•0 comments

Free Stuff from Dissolving and Restitching Bounds

https://valand.dev/blog/post/dissolving-restitching-bounds
1•valand•18m ago•0 comments

Show HN: Generate IoT applications from plain-language requirements

https://thingsboard.io/blog/ai-solution-creator/
1•vpOb17•18m ago•0 comments

Tobacco plant altered to produce five psychedelic drugs

https://www.newscientist.com/article/2521338-tobacco-plant-altered-to-produce-five-psychedelic-dr...
3•Brajeshwar•19m ago•1 comments

Show HN: Codemode-x – Compress any API into 2 MCP tools for Claude Code

https://github.com/codelitt/codemode-x
1•codelitt•19m ago•1 comments

Give your laptop a new life with ChromeOS Flex

https://blog.google/company-news/outreach-and-initiatives/sustainability/chromeos-flex-back-marke...
1•xnx•20m ago•0 comments

Incident Report: LiteLLM/Telnyx supply-chain attacks, with guidance

https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/
2•clockworksoul•20m ago•0 comments