frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A WhatsApp bug lets malicious media files spread through group chats

https://www.malwarebytes.com/blog/news/2026/01/a-whatsapp-bug-lets-malicious-media-files-spread-through-group-chats
29•iamnothere•3h ago

Comments

jeroenhd•1h ago
Awful reporting. Vague workarounds for an issue "reported by Google Project Zero" without links to said report, but with links to Forbes (who interviewed one of WhatsApp's competitors about WhatsApp's security while their own app doesn't even do proper E2EE). Was there a human involved in publishing this page? If so, was leaving out the link to Project Zero intentional?

Anyway, according to Google Project Zero, the issue has been fixed with a comprehensive fix: https://project-zero.issues.chromium.org/issues/442425914

You can always enable lockdown mode and disable downloading media to protect against undetected vulnerabilities of course, but the bug has been fixed and you just need to update for the problem to go away.

mikkupikku•55m ago
Journalists (and their editors) are allergic to proper citations. This is just standard reporting stuff, not unusual in the least.
charcircuit•32m ago
What is the actual implication of the attack. That your mobile data might be wasted?
testdelacc1•18m ago
The implication being that if the attacker could also craft a malicious payload that would cause a buffer overflow, they could chain the exploits to get remote code execution on the client.

While anyone can perform the attack described in the bug, it takes a very sophisticated attacker to craft the payload that can exploit Android’s media library.

toast0•15m ago
Sure, excess data use.

But media files that exploit parsers is the bigger issue. Errors in parsing have allowed for code execution, etc, in whatever context the parser runs; look into Stagefright and the many similar exploits before and after. Accepting media files from anywhere without user interaction is pretty risky. WhatsApp has a media file sanitizer, but it may not catch everything.

Disclosure: I worked at WhatsApp until 2019; but not on the media file sanitizer.

j45•25m ago
Neat tool.

Prolificity (ooh, invented word?) could be more than quantity of words, maybe quality too?

Qwen3-Coder-Next

https://qwen.ai/blog?id=qwen3-coder-next
197•danielhanchen•1h ago•83 comments

Agent Skills

https://agentskills.io/home
205•mooreds•3h ago•139 comments

Prek: A better, faster, drop-in pre-commit replacement, engineered in Rust

https://github.com/j178/prek
44•fortuitous-frog•1h ago•24 comments

What's up with all those equals signs anyway?

https://lars.ingebrigtsen.no/2026/02/02/whats-up-with-all-those-equals-signs-anyway/
448•todsacerdoti•8h ago•131 comments

France dumps Zoom and Teams as Europe seeks digital autonomy from the US

https://apnews.com/article/europe-digital-sovereignty-big-tech-9f5388b68a0648514cebc8d92f682060
76•AareyBaba•1h ago•9 comments

AI Didn't Break Copyright Law, It Just Exposed How Broken It Was

https://www.jasonwillems.com/technology/2026/02/02/AI-Copyright/
28•at1as•1h ago•30 comments

Heritability of intrinsic human life span is about 50%

https://www.science.org/doi/10.1126/science.adz1187
78•XzetaU8•2d ago•47 comments

Defining Safe Hardware Design [pdf]

https://people.csail.mit.edu/rachit/files/pubs/safe-hdls.pdf
6•rachitnigam•29m ago•0 comments

Bunny Database

https://bunny.net/blog/meet-bunny-database-the-sql-service-that-just-works/
129•dabinat•5h ago•60 comments

Kilobyte is precisely 1000 bytes

https://waspdev.com/articles/2026-01-11/kilobyte-is-1000-bytes
7•surprisetalk•47m ago•8 comments

Launch HN: Modelence (YC S25) – App Builder with TypeScript / MongoDB Framework

13•eduardpi•1h ago•3 comments

The Everdeck: A Universal Card System (2019)

https://thewrongtools.wordpress.com/2019/10/10/the-everdeck/
37•surprisetalk•6d ago•11 comments

Show HN: difi – A Git diff TUI with Neovim integration (written in Go)

https://github.com/oug-t/difi
35•oug-t•3h ago•36 comments

Show HN: Sandboxing untrusted code using WebAssembly

https://github.com/mavdol/capsule
32•mavdol04•3h ago•13 comments

Show HN: Octosphere, a tool to decentralise scientific publishing

https://octosphere.social/
5•crimsoneer•29m ago•3 comments

Floppinux – An Embedded Linux on a Single Floppy, 2025 Edition

https://krzysztofjankowski.com/floppinux/floppinux-2025.html
214•GalaxySnail•13h ago•138 comments

Emerge Career (YC S22) is hiring a product designer

https://www.ycombinator.com/companies/emerge-career/jobs/omqT34S-founding-product-designer
1•gabesaruhashi•5h ago

Show HN: C discrete event SIM w stackful coroutines runs 45x faster than SimPy

https://github.com/ambonvik/cimba
5•ambonvik•1h ago•1 comments

GitHub Browser Plugin for AI Contribution Blame in Pull Requests

https://blog.rbby.dev/posts/github-ai-contribution-blame-for-pull-requests/
28•rbbydotdev•3h ago•23 comments

Data Brokers Can Fuel Violence Against Public Servants

https://www.wired.com/story/how-data-brokers-can-fuel-violence-against-public-servants/
52•achristmascarl•2h ago•18 comments

Tadpole – A modular and extensible DSL built for web scraping

https://tadpolehq.com/
3•zachperkitny•1h ago•1 comments

Banning lead in gas worked. The proof is in our hair

https://attheu.utah.edu/health-medicine/banning-lead-in-gas-worked-the-proof-is-in-our-hair/
242•geox•15h ago•173 comments

The Codex App

https://openai.com/index/introducing-the-codex-app/
765•meetpateltech•23h ago•575 comments

Athena Parthenos: A Reconstruction (2000)

http://www.goddess-athena.org/Museum/Sculptures/Alone/Parthenos_reconstruction_x.htm
11•joebig•4d ago•0 comments

Anki ownership transferred to AnkiHub

https://forums.ankiweb.net/t/ankis-growing-up/68610
517•trms•20h ago•206 comments

Show HN: Safe-now.live – Ultra-light emergency info site (<10KB)

https://safe-now.live
129•tinuviel•8h ago•57 comments

Todd C. Miller – Sudo maintainer for over 30 years

https://www.millert.dev/
569•wodniok•1d ago•297 comments

Archive.today is directing a DDoS attack against my blog?

https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/
293•gyrovague-com•2d ago•122 comments

How does misalignment scale with model intelligence and task complexity?

https://alignment.anthropic.com/2026/hot-mess-of-ai/
228•salkahfi•17h ago•71 comments

The next steps for Airbus' big bet on open rotor engines

https://aerospaceamerica.aiaa.org/the-next-steps-for-airbus-big-bet-on-open-rotor-engines/
3•CGMthrowaway•2h ago•1 comments