frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

NIST gives up enriching most CVEs

https://risky.biz/risky-bulletin-nist-gives-up-enriching-most-cves/
52•mooreds•1h ago

Comments

DeepYogurt•53m ago
Long overdue to be honest.
rwmj•52m ago
https://archive.ph/S8ajd

"Enrichment" apparently is their term for adding information to the CVE database.

smsm42•43m ago
> This opens the door for a lot of infosec drama. Some of the organizations that issue CVE numbers are also the makers of the "reported" software, and these companies are extremely likely to issue low severity scores and downplay their own bugs.

It is true but the reverse is also true. It may be very hard for an external body to issue proper scoring and narrative for bugs in thousands of various software packages. Some bugs are easy, like if you get instant root on a Unix system by typing "please give me root", then it's probably a high severity issue. But a lot of bugs are not simple and require a lot of deep product knowledge and understanding of the system to properly grade. The knowledge that is frequently not widely available outside of the organization. And, for example, assigning panic scores to issues that are very niche and theoretical, and do not affect most users at all, may also be counter-productive and lead to massive waste of time and resources.

zbentley•14m ago
Very true. So many regulated/government security contexts use “critical” or “high” sev ratings as synonymous for “you can’t declare this unexploitable in context or write up a preexisting-mitigations blurb, you must take action and make the scanner stop detecting this”, which leads to really stupid prioritization and silliness.
gibsonsmog•6m ago
At a previous job, we had to refactor our entire front end build system from Rollup(I believe it was) to a custom Webpack build because of this attitude. Our FE process was completely disconnected from the code on the site, existing entirely in our Azure pipeline and developer machines. The actual theoretically exploitable aspects were in third party APIs and our dotNet ecosystems which we obviously fixed. I wrote like 3 different documents and presented multiple times to their security team on how this wasn't necessary and we didn't want to take their money needlessly. $20000 or so later (with a year of support for the system baked in) we shut up Dependabot. Money well spent!
j16sdiz•24m ago
TBH, I don't see much enrichment they are giving in last 5 or 6 years.
Retr0id•11m ago
Maybe we should just assign UUIDs

OpenAI expands Codex beyond coding with computer use, memory, and plugins

https://www.neowin.net/news/openai-expands-codex-beyond-coding-with-computer-use-memory-and-plugins/
1•Brajeshwar•58s ago•0 comments

"AI Affiliate Campaign Builder – Auto-generates funnels,leads and promos in 60s"

https://3000-ixuoqvbqmnmkcitl7dir1-6ba1a608.us2.manus.computer
1•rooseveltc•1m ago•0 comments

Recall issued for power banks after explosion kills woman

https://www.cpsc.gov/Recalls/2026/Casely-Reannounces-Recall-of-Wireless-Portable-Power-Banks-Due-...
1•labelbabyjunior•1m ago•0 comments

Closed Source Is a Business Decision, Not Security

https://javiergonzalez.io/blog/closed-source-as-a-security-model/
1•javier123454321•4m ago•0 comments

The Patchwright – Cyberpunk Short Film [video]

https://www.youtube.com/watch?v=-Rzl7nUdEs4
1•daureg•4m ago•1 comments

International standard paper sizes: A series

https://en.wikipedia.org/wiki/International_standard_paper_sizes
1•doener•5m ago•0 comments

Anthropic's Nuclear Bomb

https://warontherocks.com/cogs-of-war/anthropics-nuclear-bomb/
1•azanar•6m ago•0 comments

Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock

https://github.com/paniclock/paniclock/
1•seanieb•6m ago•0 comments

SETI may have been tuned to the wrong frequencies

https://iopscience.iop.org/article/10.3847/1538-4357/ae3d33
1•johnbarron•7m ago•0 comments

I built an on-premise ERP for wholesale distributors in Delphi

https://asktheledger.com/
1•josephsprei•9m ago•0 comments

Show HN: Clamp – Web analytics your AI agent can read and query

https://clamp.sh
1•sidneyottelohe•10m ago•1 comments

The Future of Testing Is Here

https://testkube.wistia.com/live/events/gigwl708fn
1•evwitmer•11m ago•1 comments

Vectary Canvas: AI-accelerated ideation across 2D, 3D and AR

https://www.vectary.com/waitlist/
2•mkoor•11m ago•0 comments

The Value of a Performance Oracle

https://wingolog.org/archives/2026/04/07/the-value-of-a-performance-oracle
1•abnercoimbre•12m ago•0 comments

The Internet's Most Powerful Archiving Tool Is in Peril

https://www.wired.com/story/the-internets-most-powerful-archiving-tool-is-in-mortal-peril/
2•doener•14m ago•0 comments

Bringing BitNet to ExecuTorch via Vulkan

https://www.collabora.com/news-and-blog/blog/2026/04/17/bringing-bitnet-to-executorch-via-vulkan/
2•losgehts•15m ago•0 comments

European Space Agency, more than 400 job opportunities in 2026

https://www.esa.int/About_Us/Careers_at_ESA/A_stellar_year_for_talent_more_than_400_job_opportuni...
2•johnbarron•16m ago•0 comments

Who will maintain the web when PHP's veterans retire?

https://thenewstack.io/php-web-skills-hiring-age/
2•Brajeshwar•16m ago•1 comments

Long-Tail Knowledge in Large Language Models

https://arxiv.org/abs/2602.16201
1•wslh•18m ago•0 comments

AI's Mainframe Moment

https://www.mjeggleton.com/blog/AIs-mainframe-moment
2•lelanthran•19m ago•0 comments

Where Enterprises Are Adopting AI

https://a16z.com/where-enterprises-are-actually-adopting-ai/
1•wslh•19m ago•0 comments

Apple's Mac Mini Went Viral. Why Can't You Buy One?

https://www.wsj.com/tech/personal-tech/apple-mac-mini-supply-3e7a7509
1•Anon84•20m ago•0 comments

Beyond Demo Day: Sorting and Value Added in Startup Accelerators

https://www.nber.org/papers/w35063
1•john_horton•20m ago•0 comments

Oil prices plunge as Iran says Strait of Hormuz 'open' during ceasefire

https://www.bbc.com/news/articles/ckg045z73z1o
3•geox•21m ago•0 comments

Hyperscalers have already outspent most famous US megaprojects

https://twitter.com/finmoorhouse/status/2044933442236776794
7•nowflux•22m ago•1 comments

Writing string.h functions using string instructions in asm x86-64

https://pmasschelier.github.io/x86_64_strings/
2•thaisstein•23m ago•0 comments

The Mystery of Rennes-Le-Château, Part 4: Non-Fiction Meets Fiction

https://www.filfre.net/2026/04/the-mystery-of-rennes-le-chateau-part-4-non-fiction-meets-fiction/
1•doppp•23m ago•0 comments

Probabilistic Record Linkage Using Pretrained Text Embeddings

https://www.cambridge.org/core/journals/political-analysis/article/probabilistic-record-linkage-u...
1•cowartc•24m ago•0 comments

I'm Coding by Hand

https://miguelconner.substack.com/p/im-coding-by-hand
1•evakhoury•25m ago•0 comments

The Instant Copy Trap Makes AI Creativity Impossible

https://tombedor.dev/creativity/
1•jjfoooo4•26m ago•0 comments