frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

First public macOS kernel memory corruption exploit on Apple M5

https://blog.calif.io/p/first-public-kernel-memory-corruption
28•quadrige•1h ago

Comments

vsgherzi•1h ago
unfortunately a little light on the details. I'm very curious how the bug survived through MTE
dorianmariecom•41m ago
Memory Tagging Extension

Arm published the Memory Tagging Extension (MTE) specification in 2019 as a tool for hardware to help find memory corruption bugs. MTE is a memory tagging and tag-checking system, where every memory allocation is tagged with a secret. The hardware guarantees that later requests to access memory are granted only if the request contains the correct secret. If the secrets don’t match, the app crashes, and the event is logged. This allows developers to identify memory corruption bugs immediately as they occur.

https://support.apple.com/guide/security/operating-system-in...

vsgherzi•32m ago
Upon further reading on data only attacks

(https://www.usenix.org/publications/loginonline/data-only-at...)

This makes more sense. You don't trigger MTE since you're not doing anything for force MTE to take action the program isn't actually changing.

My other question would be, why didn't apple use fbounds checking here? They've been doing it aggressively everywhere else.

MTE plus fbounds checking everywhere should lead to an extremly hardened OS

landr0id•30m ago
GPU memory/shaders/etc. isn't protected by MTE or PAC. They said "data-only", so I guess GPU commands could fit into this description.

AI Avatars Without the Face

https://www.trayo.ai/blog/ai-avatars-without-the-face/
1•ohadpr•49s ago•0 comments

A new data layer for robot learning

https://rerun.io/blog/data-layer-for-robot-learning
1•Tycho87•2m ago•0 comments

Counting to 3 with a new builder processing 50M+ monthly builds

https://blog.railway.com/p/new-builder-scale-big
1•ndneighbor•4m ago•0 comments

Posit AI is priced for the long run

https://posit.co/blog/posit-ai-priced-long-run
1•ionychal•6m ago•0 comments

Source of Truth: Code, Spec, or Requirement?

https://blog.reqproof.com/p/code-spec-or-requirement
2•LeonidBugaev•6m ago•0 comments

A JavaScript static site generator that will still work in 5 years

https://github.com/termermc/wunphile
1•qwm•8m ago•0 comments

Alchemize: PyMC's model to replace Stan/PyMC, etc. with an LLM

https://statmodeling.stat.columbia.edu/2026/05/14/alchemize-pymcs-model-to-replace-stan-pymc-etc-...
1•Tomte•10m ago•0 comments

We protect and prepare kids for an always-on world

https://www.commonsense.org/
1•lemonberry•10m ago•1 comments

Compression & Decompression w/ FHE via Err Correcting Codes and Copy-and-Recurse

https://eprint.iacr.org/2026/504
1•pizza•12m ago•1 comments

Big tech bets on new mascots in bid to seem more cuddly

https://www.bbc.com/news/articles/c99l1zzp8xzo
3•billybuckwheat•12m ago•0 comments

Latvian government collapses amid dispute over breaches by Ukrainian drones

https://www.washingtonpost.com/world/2026/05/14/latvian-government-collapses-amid-dispute-over-br...
6•washingupliquid•13m ago•1 comments

Postgres minor releases closing 11 CVEs

https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
3•tee-es-gee•15m ago•0 comments

Safety‑First AI Architecture

https://github.com/ElviCore/ElviCore
2•jweng•15m ago•0 comments

YouTube asks my subscribers if I'm emotionally manipulative [video]

https://www.youtube.com/watch?v=6-Nzb-D3xKc
1•hnburnsy•16m ago•0 comments

Messing with Chrome's Local Gemini Nano to Deobfuscate LinkedIn Posts

https://brentfitzgerald.com/posts/linkedin-translator-browser-extension/
1•burnto•16m ago•1 comments

The Inference Shift

https://stratechery.com/2026/the-inference-shift/
2•gmays•20m ago•0 comments

Rice processing research points to evolving milling rates as quality factor

https://phys.org/news/2026-04-rice-evolving-milling-quality-factor.html
1•PaulHoule•21m ago•0 comments

PyTorch, rewritten from scratch in pure Rust

https://github.com/forecast-bio/ferrotorch
3•davidsainez•22m ago•0 comments

2.3x KV Cache Compression at 32k Context – Cut VRAM Costs by 50%

https://github.com/Jamie2111/liquid_memory
1•JamieObala•24m ago•0 comments

Germany's Sovereign Tech Fund Backs KDE with €1.3M

https://www.theregister.com/oses/2026/05/14/kde-bags-13m-as-europe-realizes-it-might-need-an-os-o...
21•Lihh27•25m ago•2 comments

FBI warns of '764' network: violent social engineering targeting kids in games

https://www.fbi.gov/contact-us/field-offices/dallas/news/fbi-dallas-open-letter-to-parents-guardi...
2•templar_snow•27m ago•1 comments

AT&T, T-Mobile, and Verizon to eliminate coverage dead zones

https://www.theverge.com/tech/930336/att-tmobile-verizon-joint-venture-agreement-satellite-coverage
1•mchusma•29m ago•1 comments

Show HN: Claude-stash – an idea queue for Claude Code

https://github.com/AmirSoleimani/claude-stash
3•Amirso•31m ago•0 comments

Firnflow: Fast search over object storage (open-source turbopuffer)

https://github.com/gordonmurray/firnflow
1•jzebedee•31m ago•0 comments

C++: The Documentary (Trailer)

https://www.youtube.com/watch?v=NXwTRzywDSk
3•pjmlp•32m ago•0 comments

Reject AI Prophecies, Free the Future

https://projectlibertynewsletter.substack.com/p/reject-ai-prophecies-free-the-future
2•jackbravo•32m ago•0 comments

Turso v0.6.0

https://turso.tech/blog/turso-0.6.0
2•roflcopter69•33m ago•0 comments

Green Card Holders Targeted for Deportation by New 'Removal Apparatus'

https://www.nytimes.com/2026/05/14/us/politics/green-cards-immigration-deportation-trump.html
7•donohoe•34m ago•3 comments

Production of Medium-Chain Carboxylates from Source-Separated Organics

https://www.biorxiv.org/content/10.64898/2026.03.25.714070v1
1•PaulHoule•35m ago•0 comments

An analysis of how Dishonored 2 renders a frame

https://blog.simonrodriguez.fr/articles/2026/05/a_frame_analysis_of_dishonored_2.html
1•kosua20•38m ago•0 comments