frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Obsidian plugin was abused to deploy a remote access trojan

https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
21•cmbailey•1h ago

Comments

slowmover•1h ago
> The victim is prompted to enable the "Installed community plugins" synchronization feature.

Obsidian has the proper protections in place to prevent this type of attack, and the victims are being convinced to ignore them. This is just a successful social engineering event. I hate to see Obsidian dragged down by this headline, since this attack is not exploiting a vulnerability in it or its plugin system.

cmbailey•57m ago
Right, I'm a heavy Obsidian user myself, and love it.

I think the value of this disclosure is more in spreading awareness about plugins, and demonstrating the vector. Where less sophisticated users may think, "Oh, this is just a collection of markdown files. I don't need to be too worried about malicious code."

Groxx•20m ago
Ehm. No? https://obsidian.md/help/plugin-security#Plugin+capabilities

>Due to technical limitations, Obsidian cannot reliably restrict plugins to specific permissions or access levels. This means that plugins will inherit Obsidian's access levels. As a result, consider the following examples of what community plugins can do:

    Community plugins can access files on your computer.
    Community plugins can connect to internet.
    Community plugins can install additional programs.

Obsidian has no protection at all. Installing a plugin gives it full access to your computer.

This was only a matter of time, and honestly I think it's inexcusably negligent that they shipped a plugin system like this at all since about 2010 (or arguably much earlier).

pointlessone•8m ago
It does give full access but Obsidian does tell you that. Community plugins are not enabled by default, you have to enable them manually. Same happens with a shared vault: once you get it you still have to manually enable plugins. So far no one managed to sneak in a plugin completely unnoticed.
zhivota•15m ago
Even being social engineering, the design of the plugin system allowing this means the platform is completely unusable as a sharing tool. It's good to know but to me this is not "I need to remember to have these settings correct to use a shared Obsidian vault", this for is instead "never accept a shared Obsidian vault, demand a plaintext export".

Zero-native by Vercel: Build tiny desktop and mobile apps with Zig and web UI

https://github.com/vercel-labs/zero-native
1•maxloh•8m ago•0 comments

Antikythera Mechanism (oldest known analogue computer)

https://www.historyofinformation.com/detail.php?id=120
1•p0u4a•12m ago•0 comments

Show HN: Gawk Dev – live feed tracking what's happening across AI tools

https://gawk.dev
1•Srinathprasanna•12m ago•0 comments

You can have your composer.lock and not make others eat it too

https://kevinullyott.com/blog/2026-05-05-composer-lock-gitattributes/
1•orrison•19m ago•0 comments

Riding the D in Los Angeles: city hopes new subway stations will be game changer

https://www.theguardian.com/us-news/2026/may/09/los-angeles-subway-public-transportation
1•raybb•19m ago•0 comments

Running local models on an M4 with 24GB memory

https://jola.dev/posts/running-local-models-on-m4
3•shintoist•20m ago•0 comments

The Mythology of Rice and Beans

https://economistwritingeveryday.com/2024/12/13/the-mythology-of-rice-and-beans/
1•ksymph•23m ago•0 comments

How Fast Does Claude, Acting as a User Space IP Stack, Respond to Pings?

https://dunkels.com/adam/claude-user-space-ip-stack-ping/
2•adunk•27m ago•0 comments

ReactOS ARM64-port finally boots to desktop and even works

https://www.youtube.com/watch?v=c1LjnFKGDhQ
1•jeditobe•27m ago•0 comments

Canada admits bill C-22 would allow govt to secretly order microphone activation

https://xcancel.com/rebelprazz/status/2053606378238009832#m
4•CGMthrowaway•31m ago•0 comments

Time Lock Encryption Oracle

https://timelock.sh
3•leishman•31m ago•1 comments

Proprioception

https://en.wikipedia.org/wiki/Proprioception
2•andsoitis•37m ago•0 comments

Why DC's Metro Wants to Automate Its Trains

https://www.bloomberg.com/news/articles/2026-05-07/dc-s-metro-makes-a-case-for-driverless-red-lin...
2•raybb•39m ago•0 comments

I'm Leaving Gemini for Tax Reasons

3•liamOR•43m ago•2 comments

Ask HN: Can you make money from writing short stories with the help of AI?

2•amichail•48m ago•2 comments

ELIZA: A Computer Program for the Study of Natural Language Communication [pdf]

https://hackaday.com/wp-content/uploads/2024/02/WEIZENBAUM-1966-ELIZA-A-Computer-Program-For-the-...
3•tcp_handshaker•53m ago•1 comments

Ask HN: What are some good resources on AI Engineering and Prompting

4•mraza007•55m ago•3 comments

Show HN: I trained a chess engine to play like humans

5•hazard•58m ago•0 comments

I run a company with 30 engineers. Built this app with AI and none of them

https://footbeen.com/blog/i-built-a-production-app-with-ai-no-developers
3•dmgmyza•1h ago•0 comments

Frankfurt expands commercial EV fleet with 10 new vocational trucks

https://electrek.co/2026/05/10/frankfurt-expands-commercial-ev-fleet-with-10-new-vocational-trucks/
2•breve•1h ago•0 comments

Large-Scale Photogrammetric Documentation of St. John's Co-Cathedral [pdf]

https://mkenely.com/publications/preprints/large-scale-photogrammetric-st-johns.pdf
2•andsoitis•1h ago•0 comments

Checkmate in Iran

https://www.theatlantic.com/international/2026/05/iran-war-trump-losing/687094/
6•xqcgrek2•1h ago•1 comments

Design Framework for Conversational AI, Curatorial Insights in Cultural Heritage [pdf]

https://mkenely.com/publications/preprints/from-broadcast-to-dialogue.pdf
1•andsoitis•1h ago•0 comments

Anthropic says 'evil' portrayals were responsible for Claudes blackmail attempts

https://techcrunch.com/2026/05/10/anthropic-says-evil-portrayals-of-ai-were-responsible-for-claud...
2•evo_9•1h ago•0 comments

Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web

https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-th...
2•abdelhousni•1h ago•1 comments

Obsidian plugin was abused to deploy a remote access trojan

https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
22•cmbailey•1h ago•5 comments

Chris Hohn's fund slashes $8B Microsoft stake in warning over AI disruption

https://www.ft.com/content/639703f3-064c-4065-96dc-11a9dfd6d83c
2•fallinditch•1h ago•1 comments

Amazon uses its logistics empire to take on UPS and FedEx in freight, shipping

https://www.geekwire.com/2026/amazon-turns-its-logistics-empire-into-a-new-business-taking-on-ups...
1•TMWNN•1h ago•0 comments

Mycelium: A protocol spec to replace the Web – feedback welcome

https://mycelium-network.netlify.app
2•Nexi_CSN•1h ago•0 comments

Plex's price hikes prove I was right to switch to Jellyfin

https://www.androidauthority.com/plex-price-hikes-get-jellyfin-3663600/
14•Brajeshwar•1h ago•8 comments