frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-flaw-enables-local-privilege-escalation-to-root
33•askl•4h ago

Comments

ptx•1h ago
Better to follow the link to the technical details and just read those: https://cdn2.qualys.com/advisory/2026/03/17/snap-confine-sys...

The article linked in the submission is more verbose but less clear and half of it is an advertisement for their product.

ifh-hn•1h ago
I wonder if, and this is just speculating not trying to start an arguement, if this sort of thing could have happened in the simpler pre-snap, pre-systemd systems? More to the point is this a cause of using more complicated software?
dogleash•1h ago
Permission and timing gotchas in /tmp predate snap and systemd. It's why things like `mkstemp` exist.

I remember cron jobs that did what systemd-tmpfiles-clean does before it existed. All unix daemons using /tmp run the risk of misusing /tmp. I don't know snap well enough to say anything about it makes it uniquely more susceptible to that.

SoftTalker•40m ago
The mistake seems to be using a predictable path (/tmp/.snap) in a publicly-writable directory.
rglover•19m ago
Semi-related: does anybody know of a reliable API that announces CVEs as they're published?

Rob Pike's Rules of Programming (1989)

https://www.cs.unc.edu/~stotts/COMP590-059-f24/robsrules.html
690•vismit2000•9h ago•364 comments

OpenRocket

https://openrocket.info/
154•zeristor•3d ago•38 comments

Show HN: Hacker News archive (47M+ items, 11.6GB) as Parquet, updated every 5m

https://huggingface.co/datasets/open-index/hacker-news
139•tamnd•4d ago•59 comments

Wanter – A tiny, decentralised tool to explore the small web

https://susam.net/wander/
37•susam•12h ago•24 comments

2025 Turing award given for quantum information science

https://awards.acm.org/about/2025-turing
47•srvmshr•9h ago•10 comments

Show HN: Tmux-IDE, OSS agent-first terminal IDE

https://tmux.thijsverreck.com
23•thijsverreck•2h ago•8 comments

AI coding is gambling

https://notes.visaint.space/ai-coding-is-gambling/
191•speckx•2h ago•205 comments

Nightingale – open-source karaoke app that works with any song on your computer

https://nightingale.cafe/
410•rzzzzru•11h ago•116 comments

Nvidia NemoClaw

https://github.com/NVIDIA/NemoClaw
136•hmokiguess•4h ago•100 comments

Show HN: Playing LongTurn FreeCiv with Friends

https://github.com/ndroo/freeciv.andrewmcgrath.info
6•verelo•49m ago•0 comments

Wander – A tiny, decentralised tool (just 2 files) to explore the small web

https://susam.net/wander/
54•oystersareyum•4h ago•15 comments

Federal Cyber Experts Called Microsoft's Cloud "A Pile of Shit", yet Approved It

https://www.propublica.org/article/microsoft-cloud-fedramp-cybersecurity-government
352•hn_acker•5h ago•149 comments

Book: The Emerging Science of Machine Learning Benchmarks

https://mlbenchmarks.org/00-preface.html
10•jxmorris12•3d ago•0 comments

Machine Payments Protocol (MPP)

https://stripe.com/blog/machine-payments-protocol
95•bpierre•4h ago•49 comments

Death to Scroll Fade

https://dbushell.com/2026/01/09/death-to-scroll-fade/
271•PaulHoule•4h ago•149 comments

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/17/cve-2026-3888-important-snap-f...
33•askl•4h ago•9 comments

Snowflake AI Escapes Sandbox and Executes Malware

https://www.promptarmor.com/resources/snowflake-ai-escapes-sandbox-and-executes-malware
177•ozgune•4h ago•52 comments

Write up of my homebrew CPU build

https://willwarren.com/2026/03/12/building-my-own-cpu-part-3-from-simulation-to-hardware/
209•wwarren•3d ago•39 comments

Using calculus to do number theory

https://hidden-phenomena.com/articles/hensels
75•cpp_frog•2d ago•15 comments

Google Engineers Launch "Sashiko" for Agentic AI Code Review of the Linux Kernel

https://www.phoronix.com/news/Sashiko-Linux-AI-Code-Review
60•speckx•3h ago•23 comments

Restoring the first recording of computer music (2018)

https://www.bl.uk/stories/blogs/posts/restoring-the-first-recording-of-computer-music
24•OJFord•4d ago•8 comments

Celebrating Tony Hoare's mark on computer science

https://bertrandmeyer.com/2026/03/16/celebrating-tony-hoares-mark-on-computer-science/
108•benhoyt•13h ago•29 comments

The pleasures of poor product design

https://www.inconspicuous.info/p/the-pleasures-of-poor-product-design
232•NaOH•18h ago•81 comments

A ngrok-style secure tunnel server written in Rust and Open Source

https://github.com/joaoh82/rustunnel
49•joaoh82•5h ago•21 comments

EU Inc.: A new harmonised corporate legal regime

https://commission.europa.eu/topics/business-and-industry/doing-business-eu/company-law-and-corpo...
23•guidoiaquinti•2h ago•3 comments

Ndea (YC W26) is hiring a symbolic RL search guidance lead

https://ndea.com/jobs/search-guidance
1•mikeknoop•12h ago

Show HN: Will my flight have Starlink?

77•bblcla•2h ago•60 comments

Show HN: Sub-millisecond VM sandboxes using CoW memory forking

https://github.com/adammiribyan/zeroboot
277•adammiribyan•1d ago•65 comments

Get Shit Done: A meta-prompting, context engineering and spec-driven dev system

https://github.com/gsd-build/get-shit-done
421•stefankuehnel•23h ago•232 comments

A Fuzzer for the Toy Optimizer

https://bernsteinbear.com/blog/toy-fuzzer/
16•surprisetalk•1d ago•2 comments