frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
18•signa11•3h ago

Comments

nesarkvechnep•1h ago
All these mid sentence questions in parentheses look so unprofessional to me.
ggm•1h ago
Blame post modernism.
timfsu•1h ago
Wow, this is pretty scary. LLMs have made phishing attempts look so much more legit, and the damage they can do so much greater.
tptacek•1h ago
I snagged right away at "the kind of low-level reliability judgment that most teams only notice when something breaks." Real people don't talk like the J. Peterman catalog.
bobkb•13m ago
This type of attack is going on for few years now. I had 2 in my credit.

Some details https://freebird.in/malicious-code-source-code-shared-via-jo...

ThreatSystems•6m ago
I run training courses on developer security to broaden their understanding of threat surface from their behaviour, day-to-day tooling, the repositories they work on and broader supply chain. One of the models covers this exact scenario, it's amazing how many people do these exercises on corporate machines let alone their personal device!

There are mitigations you can put in place by using containers, virtual machines or even the execution environment e.g. Deno's ability to block/whitelist network calls[0], Bun's --ignore-scripts [1] and supply chain package managers have made some strides here like pnpm [2]. But it's knowing your threat surface and how to use your tooling which can be quite overbearing on cognitive load, especially in fast paced scenarios like "job of a lifetime offer!" from linked in.

Easiest way by default is to use ephemeral VMs / Sandbox Containers for such tasks which don't have mounted directories to your system etc. Or spin up a cheap EC2 / VPS to work on them in a short period of time.

[0] - https://deno.com/blog/deno-protects-npm-exploits and https://docs.deno.com/runtime/fundamentals/security/

[1] - https://bun.com/docs/pm/lifecycle

[2] - https://pnpm.io/supply-chain-security

[2] - https://

OpenTTD 16.0-Beta1

https://www.openttd.org/news/2026/06/25/openttd-16-0-beta1
33•untilted•2h ago•2 comments

Previewing GPT‑5.6 Sol: a next-generation model

https://openai.com/index/previewing-gpt-5-6-sol/
935•minimaxir•13h ago•576 comments

WordStar: A Writer's Word Processor (1996)

https://www.sfwriter.com/wordstar.htm
45•droidjj•3h ago•17 comments

Why does kinetic energy increase quadratically, not linearly, with speed? (2011)

https://physics.stackexchange.com/questions/535/why-does-kinetic-energy-increase-quadratically-no...
195•ProxyTracer•7h ago•88 comments

IBM MCGA Gate Array Reverse Engineering

https://github.com/schlae/IBM_MCGA
11•userbinator•1h ago•2 comments

U.S. allows Anthropic to release Mythos AI to ‘trusted’ US organizations

https://www.semafor.com/article/06/27/2026/us-releases-powerful-anthropic-model-mythos-to-some-us...
351•bobrenjc93•7h ago•350 comments

Hellishly Slow Level 13 Deflate Compression

https://kirill.korins.ky/articles/hellishly-slow-level-13-deflate-compression/
36•zX41ZdbW•4d ago•7 comments

Show HN: Hacker News on a train station-style flip board

https://popflame.quickish.space/hn-flipboard/
48•PaybackTony•5h ago•9 comments

Fusion Programming Language

https://fusion-lang.org/
38•efrecon•2d ago•18 comments

MicroVMs: Run isolated sandboxes with full lifecycle control

https://aws.amazon.com/blogs/aws/run-isolated-sandboxes-with-full-lifecycle-control-aws-lambda-in...
310•justincormack•3d ago•175 comments

SCC Technical Assistance Program

https://nerocam.com/scc_tap.asp
9•luu•2d ago•1 comments

U.S. government will decide who gets to use GPT-5.6

https://www.washingtonpost.com/technology/2026/06/26/openai-says-us-government-will-vet-users-its...
947•alain94040•12h ago•1016 comments

Foreign funds help make housing unaffordable: research

https://news.mccombs.utexas.edu/research/foreign-funds-help-make-housing-unaffordable/
44•hhs•6h ago•13 comments

Om

https://daringfireball.net/2026/06/om
283•throw0101a•7h ago•15 comments

AI in mathematics is forcing big questions

https://spectrum.ieee.org/ai-in-mathematics
97•rbanffy•7h ago•67 comments

Show HN: DBOSify – Drop-in Temporal replacement built on Postgres

https://github.com/dbos-inc/dbosify-py
46•KraftyOne•2d ago•8 comments

A C++ implementation of a fast hash map and hash set using hopscotch hashing

https://github.com/Tessil/hopscotch-map
84•gjvc•9h ago•14 comments

Anatomy of a Failed (Nation-State?) Attack

https://grack.com/blog/2026/06/25/dissecting-a-failed-nation-state-attack/
18•signa11•3h ago•6 comments

We can still stop California's 3D printer surveillance scheme

https://www.eff.org/deeplinks/2026/06/we-can-still-stop-californias-3d-printer-surveillance-scheme
337•hn_acker•9h ago•117 comments

The gap between open weights LLMs and closed source LLMs

https://blog.doubleword.ai/frontier-os-llm
177•kkm•9h ago•147 comments

Ultrasound imaging of the brain

https://alephneuro.com/blog/ultrasound-brain
264•rossant•18h ago•110 comments

Making Sense of Proof by Contradiction [pdf]

https://www.foster77.co.uk/Foster,%20Scottish%20Mathematical%20Council%20Journal,%20Making%20sens...
28•surprisetalk•3d ago•8 comments

Hightouch (YC S19) Is Hiring

https://hightouch.com/careers#open-positions
1•joshwget•9h ago

Show HN: Smart model routing directly in Claude, Codex and Cursor

https://github.com/workweave/router
161•adchurch•13h ago•95 comments

What Is a Nomogram and Why Would It Interest Me?

https://lefakkomies.github.io/pynomo-doc/introduction/introduction.html#what-is-a-nomogram-and-wh...
105•Eridanus2•13h ago•18 comments

A Tiny Compiler for Data-Parallel Kernels

https://healeycodes.com/a-tiny-compiler-for-data-parallel-kernels
37•healeycodes•1d ago•4 comments

Long Wave radio era set to end with Droitwich switch-off

https://www.bbc.com/news/articles/c74yn7v7k4qo
75•speckx•11h ago•30 comments

Pre-Modern Armies for Worldbuilders, Part III: Paying for It

https://acoup.blog/2026/06/26/collections-pre-modern-armies-for-worldbuilders-part-iii-paying-for...
86•jfoucher•12h ago•15 comments

A human postmortem of the 1996 AOL outage

https://ngrok.com/blog/aol-was-down-1996
58•EndEntire•2d ago•12 comments

The "Bizarre Headgear" exhibit at the Sam Noble museum

https://svpow.com/2026/05/15/the-bizarre-headgear-exhibit-at-the-sam-noble-museum-is-incredible/
73•surprisetalk•3d ago•7 comments