frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Passmark: Open-source Playwright library for AI regression testing

https://passmark.dev
1•hliyan•1m ago•0 comments

Sandboxed AI agent orchestration platform

https://github.com/superhq-ai/superhq
1•purusa0x6c•1m ago•0 comments

AI agents will win over human employees

1•aegiswizard•2m ago•0 comments

The Secret Life of Circuits

https://lcamtuf.coredump.cx/electronics/
1•signa11•3m ago•0 comments

Turtle WoW classic server announces shutdown after Blizzard wins injunction

https://www.pcgamer.com/games/world-of-warcraft/turtle-wow-classic-server-announces-shutdown-afte...
2•Brajeshwar•3m ago•0 comments

Claude Brain

https://github.com/memvid/claude-brain
1•DeathArrow•4m ago•0 comments

Per-Screen Virtual Desktops Is Finally on KDE Plasma

https://www.neowin.net/news/after-21-years-of-waiting-kde-plasma-is-finally-adding-this-long-requ...
1•bundie•6m ago•0 comments

Against an Endless Present

https://thedispatch.com/article/short-video-memory-culture-books/
1•XzetaU8•6m ago•0 comments

What Category Is Prune?

https://contemplativegames.com/prune
1•justinneuman•7m ago•0 comments

Have your agent post Markdown/HTML/JSX to internet

https://www.saved.md/
1•anboias•10m ago•0 comments

Show HN: Find jobs and know your fit before you apply

https://karriero.net/
1•alenn_m•10m ago•0 comments

Who Voted You King?

https://chrisabraham.substack.com/p/who-voted-you-king
1•chrisabraham•11m ago•0 comments

Ηuman collective intelligence through space, body and material symbols

https://royalsocietypublishing.org/rstb/article/381/1948/20240448/481362/Scaffolding-minds-human-...
1•XzetaU8•11m ago•0 comments

Moonspans

https://moonpans.com/
1•tcp_handshaker•11m ago•0 comments

The first compliance-native Git platform

https://www.guardgit.com/
1•quietproof•12m ago•0 comments

Show HN: Ratio Royale – A playable simulation of the Dead Internet theory

https://vibeaxis.com/ratio-royale/
1•XQorp•13m ago•0 comments

Tesla owner uses emergency solar to trickle charge after running out of battery

https://electrek.co/2026/04/18/tesla-model-x-solar-charging-atacama-desert-chile-pan-american-hig...
2•Bender•17m ago•0 comments

I've fired one of Americas most powerful lasers heres what a shot day looks like

https://theconversation.com/ive-fired-one-of-americas-most-powerful-lasers-heres-what-a-shot-day-...
2•Bender•19m ago•0 comments

Steal My Password (Technique)

https://mastodon.social/@DazRunner/116431049586713261
2•keiste_sales•21m ago•0 comments

When I Quit My PhD

https://www.lowimpactfruit.com/p/when-i-quit-my-phd
2•mnky9800n•21m ago•0 comments

What we once had (at the height of the XMPP era of the Internet) (2023)

https://www.kirsle.net/what-we-once-had-at-the-height-of-the-xmpp-era-of-the-internet
2•lolpython•23m ago•0 comments

One codebase → every store, registry, CDN, and channel. Ads on every network

https://github.com/profullstack/sh1pt
2•buffer_overlord•24m ago•0 comments

Scoring 500 Show HN pages for AI design slop

https://www.adriankrebs.ch/blog/design-slop/
2•hubraumhugo•24m ago•0 comments

Ask HN: What makes a good Product Manager

3•chairhairair•25m ago•1 comments

Git Blame: From Passive-Aggressive Forensics to Active-Aggressive Emails [pdf]

https://github.com/BarishNamazov/gitblame/blob/main/paper/gitblame.pdf
2•barishnamazov•25m ago•0 comments

Deploying Gemma 4 26B on an RTX 5090

https://datapnt.com/blog/deploying-gemma-4-26b-a4b-on-rtx-5090
3•sudo_ls_ads•27m ago•1 comments

Vercel Says Internal Systems Hit in Breach

https://decipher.sc/2026/04/19/vercel-says-internal-systems-hit-in-breach/
47•whiteyford•28m ago•2 comments

Reflections on Chi 2026

https://countingfromzero.blog/2026/04/19/reflections-on-chi-2026/
2•mooreds•30m ago•0 comments

The Draft Is Done. Now I Need Reviewers and Feedback (Elm Language)

https://cekrem.github.io/posts/the-draft-is-done-now-i-need-readers/
3•DASD•30m ago•0 comments

Claude Opus 4.7 API removes sampling parameters

https://platform.claude.com/docs/en/about-claude/models/migration-guide
2•curioussquirrel•30m ago•1 comments
Open in hackernews

Vercel April 2026 security incident

https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
105•colesantiago•1h ago

Comments

lukewarm707•1h ago
"a security incident that involved unauthorized access to certain internal Vercel systems."

could they be a little more specific?

OsrsNeedsf2P•1h ago
The lack of details makes me wonder how large this "subset" of users really is
MattIPv4•1h ago
Related: https://news.ycombinator.com/item?id=47824426

https://x.com/theo/status/2045862972342313374

> I have reason to believe this is credible.

https://x.com/theo/status/2045870216555499636

> Env vars marked as sensitive are safe. Ones NOT marked as sensitive should be rolled out of precaution

https://x.com/theo/status/2045871215705747965

> Everything I know about this hack suggests it could happen to any host

https://x.com/DiffeKey/status/2045813085408051670

> Vercel has reportedly been breached by ShinyHunters.

otterley•3m ago
Who is this “theo” person and why are multiple people quoting him? He seems to have little to say that’s substantive at this point.
ofabioroma•56m ago
Time to ipo
neom•55m ago
https://x.com/theo/status/2045871215705747965 - "Everything I know about this hack suggests it could happen to any host"

He also suggests in another post that Linear and GitHub could also be pwned?

Either way, hugops to all the SRE/DevOps out there, seems like it's going to be a busy Sunday for many.

rvz•45m ago
I do remember that OpenAI did use Vercel a year ago. They might have likely moved off of it to something better.
embedding-shape•44m ago
Based on what, "feels like it"? Claiming that Cloudflare is affected by the same hack has to come from somewhere, but where is that coming from?
gruez•39m ago
from his "sources".

> Here’s what I’ve managed to get from my sources:

>3. The method of compromise was likely used to hit multiple companies other than Vercel.

https://x.com/theo/status/2045870216555499636

To be fair journalists often do this too, eg. "[company] was breached, people within the company claim"

phillipcarter•16m ago
I don't know if I'd trust some random programmer-streamer-influencer on anything other than the topic of streamer-influencing.
hvb2•2m ago
The link at the top of the page it to vercel acknowledging it...
techpression•14m ago
”Any host” of what? That’s such a non-descriptive statement and clearly not true at face value.
jtreminio•51m ago
I'm on a macbook pro, Google Chrome 147.0.7727.56.

Clicking the Vercel logo at the top left of the page hard crashes my Chrome app. Like, immediate crash.

What an interesting bug.

farnulfo•43m ago
Same hard crash on Chrome Windows 11
itaintmagic•36m ago
Do you have a chrome://crashes/ entry ?
burnte•2m ago
I'm running 147.0.7727.57 and this doesn't happen. Macbook Air M5. VERY interesting.
rvz•46m ago
There is no serious reason to use Vercel, other than for those being locked into the NextJs ecosystem and demo projects.
gneray•44m ago
Oy vey: https://x.com/theo/status/2045862972342313374?s=46
rubiquity•12m ago
He doesn't work at Vercel but he is the type to never pass up any opportunity to chase clout.
0xy•42m ago
This is why you pay a real provider for serious business needs, not an AWS reseller. Next.js is a fundamentally insecure framework, as server components are an anti-pattern full of magic leading to stuff like the below. Given their standards for framework security, it's not hard to believe their business' control plane is just as insecure (and probably built using the same insecure framework).

Next.js is the new PHP, but worse, since unlike PHP you don't really know what's server side and what's client side anymore. It's all just commingled and handled magically.

https://aws.amazon.com/security/security-bulletins/rss/aws-2...

embedding-shape•37m ago
> Next.js is the new PHP, but worse, since unlike PHP you don't really know what's server side and what's client side anymore. It's all just commingled and handled magically.

Wasn't unheard of back in the day, that you leaked things via PHP templates, like serializing and adding the whole user object including private details in a Twig template or whatever, it just happened the other way around kind of. This was before a fat frontend and thin backend was the prevalent architecture, many built their "frontends" from templates with just sprinkles of JavaScript back then.

sbarre•18m ago
People say "Next.js is the new PHP" because it's the most popular and prominent tooling out there, and so by sheer number of available targets it's the one that comes up the most when things go wrong like this.

But there are more people trying to secure this framework and the underlying tools than there would be on some obscure framework or something the average company built themselves.

Also "pay a real provider", what does that mean? Are you again implying that the average company should be responsible for _more_ of their own security in their hosting stack, not less?

Most companies have _zero_ security engineers.. Using a vertically-integrated hosting company like Vercel (or other similar companies, perhaps with different tech stacks - this opinion has nothing to do with Next or Node) is very likely their best and most secure option based on what they are able to invest in that area.

mikert89•34m ago
Much as I want to rip on vercel, its clear that ai is going to lead to mass security breaches. The attack surface is so large, and ai agents are working around the clock. This is a new normal. Open source software is going to change, companies wont be running random repos off github anymore
lijok•32m ago
ShinyHunters are a phishing group. What does this have to do with AI agents?
mikert89•30m ago
Run ai agents around the clock to do hyper targeted fishing
cj•18m ago
I feel like humans would be better at hyper targeting.

AI agents have the benefit of working at scale, probably "better" used for mass targeting.

freedomben•10m ago
I disagree. Many humans are phishing in a different language than their native tongue, and LLMs are way better at sounding legit/professional than many of them. The best spear-phishing will still be humans, but AI definitely raises the bar.
tcp_handshaker•6m ago
>> ai is going to lead to mass security breaches.

Let that be the end of Microsoft. Was forced to use their shitty products for years, by corporate inertia and free Teams and Azure licenses, free dose is free, curse.

adithyasrin•8m ago
We run on Vercel and I wonder if / how long before we're alerted about a leak. Quick look online suggests environment variables marked as sensitive are ok, but to which extent I wonder.