frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Double Threat: How AI Code Review Eradicates SQL Injection and Hardcoded Secrets

https://codeprot.com/articles/code-security.html
4•allenz_cheung•1d ago

Comments

dfajgljsldkjag•33m ago
Completely made up and hallucinated AI slop. These are real repos but the code doesn't exist.

> Vulnerable Code Analysis (ubccr/xdmod): In classes/DB/EtlJournalHelper.php, the vulnerability occurs when the system directly concatenates unvalidated schema and table names into the SQL query string.

classes/DB/EtlJournalHelper.php does not exist, and git history does not show it ever existed. https://github.com/ubccr/xdmod/commits/main/classes/DB

> Vulnerable Code Analysis (spryker-shop/b2c-demo-shop): In the default configuration file config/Shared/config_default.php, the vulnerability stems from hardcoded OAuth client credentials where the secret is set to null, effectively making it an unprotected public client.

config/Shared/config_default.php is a real file, but the code snippet is fake. It doesn't look anything like the real code. https://github.com/spryker-shop/b2c-demo-shop/blame/master/c...

This AI slop falsely claiming that several innocent projects have critical vulnerabilities feels like it's bordering on defamation. If I was a project admin I would consider sending the lawyers in.

Ghostty is now non-profit

https://mitchellh.com/writing/ghostty-non-profit
873•vrnvu•9h ago•171 comments

Valve reveals it’s the architect behind a push to bring Windows games to Arm

https://www.theverge.com/report/820656/valve-interview-arm-gaming-steamos-pierre-loup-griffais
541•evolve2k•1d ago•508 comments

Average DRAM price in USD over last 18 months

https://pcpartpicker.com/trends/price/memory/
97•zekrioca•3h ago•44 comments

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k
552•bearsyankees•10h ago•182 comments

Micron Announces Exit from Crucial Consumer Business

https://investors.micron.com/news-releases/news-release-details/micron-announces-exit-crucial-con...
417•simlevesque•9h ago•208 comments

1D Conway's Life glider found, 3.7B cells long

https://conwaylife.com/forums/viewtopic.php?&p=222136#p222136
363•nooks•10h ago•129 comments

Acme, a brief history of one of the protocols which has changed the Internet

https://blog.brocas.org/2025/12/01/ACME-a-brief-history-of-one-of-the-protocols-which-has-changed...
70•coffee--•4h ago•30 comments

Kea DHCP: Modern, open source DHCPv4 and DHCPv6 server

https://www.isc.org/kea/
50•doener•3h ago•19 comments

Show HN: I built a dashboard to compare mortgage rates across 120 credit unions

https://finfam.app/blog/credit-union-mortgages
161•mhashemi•7h ago•62 comments

RCE Vulnerability in React and Next.js

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
427•rayhaanj•11h ago•134 comments

Preserving Snow Crystals

https://www.its.caltech.edu/~atomic/snowcrystals/preserve/preserve.htm
26•jameslk•4d ago•3 comments

8086 Microcode Browser

https://nand2mario.github.io/posts/2025/8086_microcode_browser/
57•zdw•6h ago•0 comments

Launch HN: Phind 3 (YC S22) – Every answer is a mini-app

85•rushingcreek•10h ago•71 comments

Greeting Vocalizations in Domestic Cats Are More Frequent with Male Caregivers

https://onlinelibrary.wiley.com/doi/10.1111/eth.70033
66•JumpCrisscross•5h ago•48 comments

Lie groups are crucial to some of the most fundamental theories in physics

https://www.quantamagazine.org/what-are-lie-groups-20251203/
98•ibobev•8h ago•39 comments

How to Synthesize a House Loop

https://loopmaster.xyz/tutorials/how-to-synthesize-a-house-loop
187•stagas•6d ago•68 comments

Everyone in Seattle hates AI

https://jonready.com/blog/posts/everyone-in-seattle-hates-ai.html
640•mips_avatar•8h ago•617 comments

Checked-size array parameters in C

https://lwn.net/SubscriberLink/1046840/3eb9029084cc9e1e/
66•chmaynard•7h ago•25 comments

Schubfach: The smallest floating point double-to-string impleme

https://vitaut.net/posts/2025/smallest-dtoa/
18•fanf2•3d ago•1 comments

What I don’t like about chains of thoughts (2023)

https://samsja.github.io/blogs/cot/blog/
28•jxmorris12•3d ago•4 comments

Cellebrite to Acquire Corellium

https://www.corellium.com/blog/cellebrite-to-acquire-corellium
10•Fnoord•1h ago•1 comments

Why are my headphones buzzing whenever I run my game?

https://alexene.dev/2025/12/03/Why-do-my-headphones-buzz-when-i-run-my-game.html
153•pacificat0r•12h ago•113 comments

Anthropic taps IPO lawyers as it races OpenAI to go public

https://www.ft.com/content/3254fa30-5bdb-4c30-8560-7cd7ebbefc5f
292•GeorgeWoff25•18h ago•243 comments

You can't fool the optimizer

https://xania.org/202512/03-more-adding-integers
237•HeliumHydride•15h ago•145 comments

MinIO is now in maintenance-mode

https://github.com/minio/minio/commit/27742d469462e1561c776f88ca7a1f26816d69e2
428•hajtom•11h ago•247 comments

Show HN: Fresh – A new terminal editor built in Rust

https://sinelaw.github.io/fresh/
132•_sinelaw_•13h ago•80 comments

Prompt Injection via Poetry

https://www.wired.com/story/poems-can-trick-ai-into-helping-you-make-a-nuclear-weapon/
69•bumbailiff•9h ago•31 comments

Rocketable (YC W25) is hiring a founding engineer to automate software companies

https://www.ycombinator.com/companies/rocketable/jobs/CArgzmX-founding-engineer-automation-platform
1•alanwells•10h ago

Are we repeating the telecoms crash with AI datacenters?

https://martinalderson.com/posts/are-we-really-repeating-the-telecoms-crash-with-ai-datacenters/
196•davedx•16h ago•155 comments

Zmx: Session Persistence for Terminal Processes

https://github.com/neurosnap/zmx
11•birdculture•4h ago•3 comments