frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Topscan.me – a new security platform with a new approach to scanning

1•darius88•56m ago
Topscan.me is a security scanning platform for companies where security is somebody's second job, usually a CTO or a DevOps lead. It covers what is normally bought from three vendors: code analysis, scanning of running web applications and monitoring of the external perimeter, all in one workspace with a deadline on every finding. What distinguishes it is a handful of decisions about how scanning should behave, described below.

What it covers

- Code. GitHub or GitLab repositories, self-managed included, connected with a read-only token: risky patterns, exposed secrets, vulnerable dependencies. The clone is deleted when the scan ends; only the finding and a snippet of the affected lines remain.

- Running web applications. External scanning, with an optional deep mode that crawls the app and runs active OWASP Top 10 tests.

- The perimeter. Open ports, service versions, known vulnerabilities, certificates, and any host that appears where none was before, rescanned on a schedule.

- AWS. Discovery of EC2 and Route 53 resources through keys the customer issues. Nothing is installed on the customer's servers.

Discovery first, scanning only with consent

Adding a domain triggers discovery: Certificate Transparency logs, DNS, and one ordinary HTTP request per host, the same request a browser sends. No ports are touched. Within five to ten minutes the result is a map of what faces the internet.

Nothing else runs until the user confirms a target. Port scans and active checks are limited to confirmed hosts, and confirming a target is how the user asserts authorisation to scan it. The documentation is direct about why: in some jurisdictions an unauthorised port scan is a criminal matter. Hosts discovered and then dismissed are never scanned and use no licence.

One finding per vulnerability, status per host

The same vulnerability on five hosts is one entry in the issue list, so the list stays as long as the problem is. Status, though, is kept per host and port. Mark a finding as a false positive on one host and the other four keep their deadline. When status is stored on the vulnerability itself, as a lot of tools do, one click can quietly hide a real problem on forty other machines. Topscan keys status to target, issue type, port and protocol, and a triage mode expands any grouped entry into its individual occurrences.

A score built on deadlines, not counts

Every finding gets a deadline from the day it was first detected: 7 days for critical, 30 for high, 60 for medium, 90 for low. The Security Score starts at 100 and loses points only when a finding passes its deadline. A workspace that scans more and finds more does not score worse for having looked. Snoozing pauses the clock and resumes it where it stopped. A deferred fix stays visible. A separate, cumulative SLA compliance rate covers the whole history of the workspace for auditors.

Evidence on every finding

Each finding carries what produced it: hostname, status code, response banner or certificate date, and the time of the check, so it can be verified in seconds without trusting the label. The engines are open source and named: naabu for ports, OpenVAS for infrastructure vulnerabilities, Nuclei for web checks, OWASP ZAP for the deep stage. The engine is not the product; the inventory, the deadlines, the evidence and the history are.

Pricing without a sales call

- Two plans, $129 and $269 a month; 14-day trial of the full plan, no card.

- Per target: $4 an infrastructure host, $45 a web application, $9 a repository, the same add-on rate on every plan.

- Users unlimited, scans never billed, read-only seats for auditors free.

- AWS discovery and Slack and Jira routing are on the higher plan.

Getting started

Discovery produces the first perimeter map within five to ten minutes of starting the trial, before anything is scanned.

Tmux Buffers and Popups: Load, Save, Paste

https://saurabhkushwah.com/blog/tmux-buffers
1•saurabh-kushwah•2m ago•0 comments

The AI Safety community is unfortunately doing more harm than good

https://twitter.com/knowerofmarkets/status/2105330652732125602
1•gmays•4m ago•0 comments

Grok Bot (is really good)

https://jamespember.substack.com/p/grok-bot-is-really-good
1•jep888•8m ago•1 comments

Postgres: Are we reverting patches because of bugs found by AI?

https://vondra.me/posts/are-we-reverting-patches-because-of-bugs-found-by-ai/
1•Shorn•13m ago•0 comments

Show HN: Ramen – self-hosted multi-zone MCP server for Kubernetes(Rust & Python)

https://github.com/bkraad47/ramen
1•bulkguy47•13m ago•0 comments

Nix and Home Manager on the steam frame

https://johns.codes/blog/nix-on-steam-frame
1•jrmurray•13m ago•0 comments

How is your country doing on "AI inside Drones"?

https://dronegpt.ai/
1•laumer•16m ago•0 comments

Florida county discovers mysterious Flock cameras with no obvious owner

https://www.washingtonpost.com/nation/2026/10/01/florida-county-discovers-mysterious-flock-camera...
2•WaitWaitWha•16m ago•0 comments

Calling AI 'other intelligence' better describes the advent of a new lifeform

https://www.abc.net.au/news/2026-10-05/is-artificial-intelligence-a-new-lifeform/107226762
2•jyhrow•17m ago•1 comments

Irrelevant visual details interfere with decisions under uncertainty

https://medicalxpress.com/news/2026-10-irrelevant-visual-decisions-uncertainty-brain.html
2•WaitWaitWha•23m ago•0 comments

Secret Microsoft Layoffs and Maybe Another "Voluntary Exit Program"

https://techrights.org/n/2026/10/04/Secret_Microsoft_Layoffs_and_Maybe_Another_Voluntary_Exit_Pro...
1•amcclure•26m ago•0 comments

AWS European Sovereign Cloud: Demonstrating an Independent Operation

https://aws.amazon.com/blogs/security/aws-european-sovereign-cloud-demonstrating-an-independent-o...
1•Betelbuddy•26m ago•1 comments

Can Data Center Design Choices Change Public Acceptance?

https://www.datacenterknowledge.com/sustainability/can-data-center-design-choices-change-public-a...
1•WaitWaitWha•28m ago•0 comments

Anatomy Unzipped: John of Arderne's Sweden Scroll (Ca. 1425–35)

https://publicdomainreview.org/collection/arderne-scroll/
1•prismatic•28m ago•0 comments

Granola Alternative for iphone and watch, free and on-device

https://dictate.donado.co/
1•donadolabs•32m ago•1 comments

Could a Large Language Model Be Conscious? – David J. Chalmers (2024)

https://arxiv.org/abs/2303.07103
1•the-mitr•33m ago•0 comments

Ask HN: What did you think about Digger (2026)?

1•shannadige•34m ago•0 comments

Show HN: Side-by-side California ADU cost ledger (800 vs. 400 sq ft)

https://everylineitem.com/compare/
1•bdhband•34m ago•0 comments

List of Lessons

https://fi-le.net/list/
1•fi-le•36m ago•0 comments

The empty brain – Your brain does not process information it is not a computer

https://aeon.co/essays/your-brain-does-not-process-information-and-it-is-not-a-computer
1•the-mitr•39m ago•0 comments

DeepSeek Builds for Huawei Ascend

https://www.geopolitechs.org/p/deepseek-builds-for-huawei-ascend
1•gmays•43m ago•0 comments

Decision making is becoming the agentic coding bottleneck

https://twitter.com/backnotprop/status/2106932402350174580
2•ramoz•43m ago•0 comments

Turbomail.ai – AI email that lives on your device, not theirs

https://turbomail.ai/
1•namanpundir•54m ago•0 comments

Topscan.me – a new security platform with a new approach to scanning

1•darius88•56m ago•0 comments

OptChat: An endless chat where the AI remembers everything

https://gist.github.com/VictorTaelin/91837951a5ce5b38f341ec1ba1df6449
1•simonpure•56m ago•0 comments

CounterSteer: Suppressing Indirect Prompt Injection with Activation Steering

https://arxiv.org/abs/2609.36570
1•pykello•56m ago•0 comments

Warner Bros/Paramount to change name to Skydance

https://filmstories.co.uk/news/warner-bros-paramount-to-change-name-to-skydance/
1•andsoitis•58m ago•1 comments

Rust clean-room replacements for Photoshop

https://github.com/storytold/photocraft
1•BonoboIO•58m ago•0 comments

Triple SEC – Simple Digital Security Scheme

https://nau.github.io/triplesec/
1•Hbruz0•1h ago•0 comments

Headless B2B quoting, invoicing, and payments engine

https://cordhq.app/
1•andrevallee•1h ago•0 comments