frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Catching the LiteLLM and Telnyx supply chain zero-days via semantic analysis

https://point-wild.github.io/who-touched-my-packages/
6•justinmsnider•3h ago
Following the discussions around the LiteLLM compromise and today's terrifying telnyx zero-day, my team and I wrote up a technical breakdown of how the TeamPCP actors are bypassing legacy SCA tools.

The tl;dr is that traditional scanners are looking for signatures, while the attackers are weaponizing context. By hiding an executable payload inside mathematically valid .wav audio frames, TeamPCP ensured that content filters and CVE databases waved the Telnyx payload right through.

We spent the weekend building an open-source CLI (wtmp) to hunt for this exact behavior. Instead of asking "Is this package on a blacklist?", it maps your Node/Python dependency graph and uses a LangGraph process to actually read the code. It asks things like: "Why is a telephony SDK running an XOR decryption loop on an audio file and piping it to a shell?"

The reality check: Because it relies on LLMs to infer intent, expect false positives. It is not a deterministic CI/CD blocker; it’s a flashlight to help you triage your blast radius during an active crisis like today.

I’ll be hanging out in the comments. I’d love for you to read the write-up, test the CLI against your local trees, and absolutely tear apart our prompt architecture and logic.

Comments

phromo•1h ago
The linked page seems to be a normal known vuln checker? From doc :

""" The tool will:

    Recursively find all package.json and requirements.txt files
    Parse the dependencies
    Query OSV
    Display a beautiful report
"""
justinmsnider•6m ago
Thanks for taking a look at the docs. That section covers the default behavior of the CLI, which acts as a standard OSV known-vulnerability checker (since basic signature hygiene is still step one).

The semantic/behavioral analysis we built to hunt for these Telnyx/LiteLLM zero-days is a new module we just pushed this weekend. You trigger it using the --supply-chain flag (which requires an Anthropic API key).

When run with that flag, it moves past the OSV database and runs the LangGraph intent analysis on the actual dependency code. I'll get the landing page updated today to make the --supply-chain flag and LLM capabilities more prominent.

Voyager 1 runs on 69 KB of memory and an 8-track tape recorder

https://techfixated.com/a-1977-time-capsule-voyager-1-runs-on-69-kb-of-memory-and-an-8-track-tape...
174•speckx•3h ago•77 comments

C++26 is done ISO C++ standards meeting, Trip Report

https://herbsutter.com/2026/03/29/c26-is-done-trip-report-march-2026-iso-c-standards-meeting-lond...
53•pjmlp•1h ago•16 comments

Pretext: TypeScript library for multiline text measurement and layout

https://github.com/chenglou/pretext
75•emersonmacro•1d ago•10 comments

The RISE RISC-V Runners: free, native RISC-V CI on GitHub

https://riseproject.dev/2026/03/24/announcing-the-rise-risc-v-runners-free-native-risc-v-ci-on-gi...
68•thebeardisred•3d ago•18 comments

Neovim 0.12.0

https://github.com/neovim/neovim/releases/tag/v0.12.0
92•pawelgrzybek•1h ago•42 comments

AyaFlow: A high-performance, eBPF-based network traffic analyzer written in Rust

https://github.com/DavidHavoc/ayaFlow
48•tanelpoder•3h ago•3 comments

The rise and fall of IBM's 4 Pi aerospace computers: an illustrated history

https://www.righto.com/2026/03/ibm-4-pi-computer-history.html
32•zdw•2h ago•7 comments

Typing and Keyboards

https://lzon.ca/posts/series/grateful/typing-and-keyboards/
7•jpmitchell•37m ago•5 comments

Show HN: QuickBEAM – run JavaScript as supervised Erlang/OTP processes

https://github.com/elixir-volt/quickbeam
25•dannote•22h ago•3 comments

Nitrile and latex gloves may cause overestimation of microplastics

https://news.umich.edu/nitrile-and-latex-gloves-may-cause-overestimation-of-microplastics-u-m-stu...
431•giuliomagnifico•9h ago•187 comments

Police used AI facial recognition to wrongly arrest TN woman for crimes in ND

https://www.cnn.com/2026/03/29/us/angela-lipps-ai-facial-recognition
211•ourmandave•4h ago•79 comments

The Epistemology of Microphysics

https://www.edwardfeser.com/unpublishedpapers/microphysics.html
14•danielam•4d ago•6 comments

LinkedIn uses 2.4 GB RAM across two tabs

402•hrncode•10h ago•257 comments

A nearly perfect USB cable tester

https://blog.literarily-starved.com/2026/02/technology-the-nearly-perfect-usb-cable-tester-does-e...
228•birdculture•3d ago•107 comments

Miasma: A tool to trap AI web scrapers in an endless poison pit

https://github.com/austin-weeks/miasma
229•LucidLynx•9h ago•173 comments

Full network of clitoral nerves mapped out for first time

https://www.theguardian.com/society/2026/mar/29/full-network-clitoral-nerves-mapped-out-first-tim...
94•onei•3h ago•30 comments

First Western Digital, now Sony: The tech giant suspends SD card sales

https://mashable.com/article/sony-sd-card-sales-suspended-memory-shortage
33•_tk_•1h ago•23 comments

Show HN: Create a full language server in Go with 3.17 spec support

https://github.com/owenrumney/go-lsp
69•rumno0•4d ago•14 comments

Netscape News Feed Straight Out of the Late 00s

https://isp.netscape.com/
28•mistyvales•1h ago•7 comments

Show HN: BreezePDF – Free, in-browser PDF editor

https://breezepdf.com/?v=3
35•philjohnson•5h ago•19 comments

I turned my Kindle into my own personal newspaper

https://manualdousuario.net/en/how-to-kindle-personal-newspaper/
147•rpgbr•2d ago•51 comments

Show HN: Sheet Ninja – Google Sheets as a CRUD Back End for Vibe Coders

https://sheetninja.io
55•sxa001•7h ago•61 comments

The bot situation on the internet is worse than you could imagine

https://gladeart.com/blog/the-bot-situation-on-the-internet-is-actually-worse-than-you-could-imag...
149•ohjeez•2h ago•100 comments

The Failure of the Thermodynamics of Computation (2010)

https://sites.pitt.edu/~jdnorton/Goodies/Idealization/index.html
40•nill0•2d ago•7 comments

Observations from carbon dioxide monitoring

https://grieve-smith.com/ftn/2026/03/nine-observations-from-carbon-dioxide-monitoring/
8•coloneltcb•2d ago•1 comments

When do we become adults, really?

https://www.newyorker.com/culture/annals-of-inquiry/when-do-we-become-adults-really
47•benbreen•3d ago•64 comments

Cuts in publishing and book reviewing imperil the future of narrative nonfiction

https://newrepublic.com/article/207659/non-fiction-publishing-threat-important-ever
43•Hooke•3d ago•30 comments

Alzheimer's disease mortality among taxi and ambulance drivers (2024)

https://www.bmj.com/content/387/bmj-2024-082194
198•bookofjoe•18h ago•130 comments

The loneliness of A Room of One’s Own

https://newrepublic.com/article/206731/loneliness-room-one-virginia-woolf-hold-up
31•prismatic•3d ago•6 comments

Founder of GitLab battles cancer by founding companies

https://sytse.com/cancer/
1303•bob_theslob646•1d ago•248 comments