frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flas...
274•logickkk1•1h ago•205 comments

Long Presumed Dead, a Thriving Coral Reef Is Discovered in West Africa

https://e360.yale.edu/digest/benin-coral-reef
73•speckx•1h ago•2 comments

The World's 2,400 Castles

https://thecastlemap.com/
52•marklit•1h ago•33 comments

PCjs Machines

https://www.pcjs.org/
94•naves•3h ago•8 comments

Qwen-Image-3.0: Rich Content, Authentic Details, Deep Knowledge

https://qwen.ai/blog?id=qwen-image-3.0
458•ilreb•8h ago•185 comments

Bloomy (YC S26) is hiring a founding engineer

1•alexsouthmayd•7m ago

France's Anssi Will Block PQC-Free Products from Certification Starting 2027

https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
23•Sami_Lehtinen•1h ago•5 comments

Apple Defeats Liability for Not Scanning iCloud for CSAM

https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for...
161•speckx•2h ago•117 comments

Python 3.15's Ultra-Low Overhead Interpreter Profiling Mode – Ken Jin's Blog

https://fidget-spinner.github.io/posts/ultra-fast-tracing.html
113•rbanffy•6d ago•4 comments

Who's afraid of Chinese models?

https://stratechery.com/2026/whos-afraid-of-chinese-models/
897•mfiguiere•1d ago•721 comments

Oracle could face $7B collateral bill for Wisconsin data centre

https://www.ft.com/content/b37030b6-bda8-4ba9-8e08-e6b88687b8f5
77•1vuio0pswjnm7•1h ago•46 comments

Incremental – A library for incremental computations

https://github.com/janestreet/incremental
312•handfuloflight•13h ago•59 comments

The unreasonable difficulty of time series forecasting

https://suzyahyah.github.io/machine%20learning/2026/06/27/trouble-with-time-series.html
14•suzyahyah•2d ago•2 comments

Show HN: Explore 6048 YC companies as an interactive galaxy

https://artifacta.io/a/pg_x9pombpdybx90q2s16eu
25•jnakano89•2d ago•8 comments

Why Are There No Empires in Age of Empires? (2019)

https://acoup.blog/2019/11/22/collections-why-are-there-no-empires-in-age-of-empires/
15•jkly•3h ago•5 comments

Jelly UI: Soft-body physics for native HTML form controls

https://jelly-ui.com/
629•baldvinmar•1d ago•190 comments

Claude Is Not a Compiler

https://blog.exe.dev/claude-is-not-a-compiler
103•bryanmikaelian•2h ago•99 comments

Amid nurse shortage, a university rolls out the welcome mat for men

https://text.npr.org/nx-s1-5869813
28•mooreds•1h ago•28 comments

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
34•arto•1h ago•1 comments

Kimi Work

https://www.kimi.com/products/kimi-work
646•ms7892•23h ago•265 comments

Human mathematicians are being outcounterexampled

https://xenaproject.wordpress.com/2026/07/20/human-mathematicians-are-being-outcounterexampled/
443•artninja1988•22h ago•217 comments

How to pack ternary numbers in 8-bit bytes

https://compilade.net/blog/ternary-packing
80•JoshTriplett•6d ago•42 comments

Arduino Launches Plug-and-Play Modules for Long-Range Sensor Projects

https://www.allaboutcircuits.com/news/arduino-launches-plug-and-play-modules-for-long-range-senso...
75•WaitWaitWha•3d ago•34 comments

Motion Sensors and Home Security Gadgets Without Cameras

https://www.wired.com/story/best-motion-sensors-private-alternatives-security/
40•joozio•2d ago•17 comments

Shanay-Timpishka, a boiling hot river 700km from the nearest active volcano

https://terradaily.com/anything-that-falls-into-a-four-kilometre-stretch-of-a-river-in-the-centra...
23•camtarn•4d ago•5 comments

Running Doom on Our Custom CPU and Going Viral

https://www.armaangomes.com/blogs/doom/
121•arghunter•13h ago•35 comments

Nativ: Run frontier open models locally on your Mac

https://blaizzy.github.io/nativ/
353•aratahikaru5•22h ago•122 comments

Show HN: Immersive Gaussian Splat tour of grace cathedral, San Francisco

https://vincentwoo.com/3d/grace_cathedral/
241•akanet•20h ago•51 comments

A Koi Pond Mosaic Made from 10 Pounds of 3D Printer Waste

https://www.instructables.com/A-Koi-Pond-Mosaic-Made-From-10-Pounds-of-3D-Printe/
67•sudo_cowsay•13h ago•46 comments

I wrote an bash enumerator because I was sick of xargs

https://numerlab.org/2025/07/20/bashumerate-enumerator/
189•wallach-game•20h ago•166 comments
Open in hackernews

Over 400 Linux CVEs published in the last 24 hours alone

https://lore.kernel.org/linux-cve-announce/
67•aghuang•2h ago

Comments

traceroute66•2h ago
Might need to silently archive those Microsoft Patch Tuesday jokes...
AdmiralAsshat•2h ago
Don't worry, Microsoft is still leading:

https://www.bleepingcomputer.com/news/microsoft/microsoft-ju...

1970-01-01•2h ago
Those that actually understood security, and weren't on some kind of open-source enforcement mission in life, always knew the "Linux doesn't get viruses" statements would not age well.

https://blog.desdelinux.net/en/virus-in-gnulinux-reality-or-...

traceroute66•2h ago
> Those that actually understood security....

Indeed, and those who actually understood software development always knew vulnerabilities can occur just as easily as bugs.

And in some cases more easily than bugs, because many of modern vulnerabilities are so subtle, especially where crypto is involved.

kvuj•2h ago
You should be careful not to conflate viruses and CVEs.

Considering no Linux distro come with an antivirus by default, Linux as a desktop was always extremely vulnerable to bad actors.

As a server, I would argue otherwise.

thewebguyd•2h ago
> Linux as a desktop was always extremely vulnerable to bad actors.

Most distros people use as a desktop are alarmingly insecure by default,the security model lags well behind macOS and even Windows (again, by default. You can of course do work to harden it).

You lose out on hardware verified boot with signed system volumes, virtualization backed security, granular runtime permissions (apps having full R/W on ~Home, screen recording, microphone access).

Immutable distros like Silverblue, flatpak are moving linux desktop security in the right direction but its far from the default, and there are still gaps that need to be closed.

We (Linux community) loves to criticize security through obscurity, but that's exactly what most desktop linux users are relying on to not get pwned, relying on marketshare being so low that there just hasn't been that many incidents.

1970-01-01•1h ago
Conflated terms because they've been that way for a very long time. If you're being strict, all computer viruses stopped being a problem a decade ago.
gosub100•2h ago
If they were there this whole time but only discovered now, were they really a threat? The reflexive response to this is "those could be exploited for years and we'd never know", but if it was discovered, it obviously wasn't impacting you personally. If they were under lock and key at the NSA and only judiciously used for secret spy BS, that's effectively the same as not existing. Clearly they weren't discovered by all the white hats for this whole time.

Also, if Microsoft hypothetically open sourced their code, do you think there would be more, less, or the same number of CVEs? I would guess more.

I don't want to go too far to defend Linux. I want to make the case that it has been the more secure OS this whole time.

traceroute66•50m ago
> I want to make the case that it has been the more secure OS this whole time.

Your phone is ringing, caller ID says its Theo de Raadt from OpenBSD. :)

csande17•2h ago
https://docs.kernel.org/process/cve.html

> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

(And because this happens during the stable release process, there are a lot of 24-hour periods where they issue a ton of CVEs for all the minor bugs fixed in the release.)

alhirzel•2h ago
I am assuming that many of these are found with automatic analysis tools that are very creative (i.e. LLMs) and there may be a high proportion of very "cornered" cases. I think there needs to be a triage method that would amount to the severity, likeliness, and detection dimensions used to rank risks in a systematic framework [1]. I think if this could be submitted (or estimated) along with such bug reports, it could go a long way toward sustainable intake patterns for this number of possible defects.

[1]: https://en.wikipedia.org/wiki/Failure_mode_and_effects_analy...

petra303•2h ago
In my company, the security team isn’t technical. They see CVE, find a vulnerable system, it gets flagged. We have to patch it.

We patched for a CVE last week that a malicious usb sound card device could be use the gain root.

On a Vm? Is that something we really need to worry about??

dboreham•2h ago
It's asymmetric warfare. It costs them little to demand a false positive be acted upon, but costs you plenty to refute it.
chelmzy•2h ago
Its the same at most orgs. Very rare for a vuln remediation program to utilize a truly risk based approach. They would have to trawl through and understand thousands of vulns and the context of your org. There's probably a market for some tool to accomplish this if the larger players haven't attempted already.
lousken•
PedroBatista•2h ago
Linus better put his money where mouth is and fire up those AI tokens ASAP.

I don't consider this a tragedy, it's just unearthing the reality.

juliangmp•2h ago
What does any of this have to do with AI?
PedroBatista•1h ago
There has been a long discussion and "conflict" of opinions regarding the use of AI in kernel dev.

Linus is pro-AI as a tool ( and I mostly agree, there are consequences however that at least need to be talked about ). That's why I was talking about firing up those AI machines and fix those CVEs ( "make no mistakes" ).

But it seems every Linux topic related to security or languages is the ultimate mine field for knee-jerk reactions. :)

st_goliath•2h ago
I guess very few around here remember the minor fuzz about this from a few years ago? The Linux Kernel Project became their own CNA (CVE Numbering Authority). A CVE is now slapped onto practically every bug fix that is back ported to a stable kernel, resulting in a flood of CVEs.

A blog post about this, published at the time: https://sigma-star.at/blog/2024/03/linux-kernel-cna/

The title is editorialized (i.e. the OP made it up), the link simply goes to the kernel CVE mailing list archive.

altairprime•2h ago
(Email the mods to clear up the editorial title problem; footer contact link.)
OsrsNeedsf2P•2h ago
Amazing how people think this means anything
rvz•2h ago
This sounds like cope.

We are going to see more of this with LLMs being able to uncover hundreds of bugs in projects just like Linux.

devmor•2h ago
This has nothing to do with LLMs.
rvz•1h ago
That doesn't excuse the point. Thanks to LLMs, We'll see more of this and more embargoed vulnerabilities now revealed like this on a regular basis.

Given that Linux allows the use of AI assistance [0] you'll be very disappointed to see that people will use LLMs to find even more CVEs and bugs much quicker. That also means they will be fixed much quicker which should be a good thing; as long as the core developer is in the loop checking.

Unless you are against or downplaying this, you may not know that you are actually coping.

[0] https://docs.kernel.org/process/coding-assistants.html

theK•2h ago
> CVE-2026-64012: net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked.

You are right, its over.

On a more serious note. Yes and no. The kernel is secure. It is probably the most scrutinized piece of software in existence. LLMs will find things but most probably they just will help contributors fix bugs.

catigula•2h ago
Chinese models, hurray!
bob001•2h ago
You do realize this is an announcement of already fixed issues which were fixed (and not just flagged) weeks or months ago, right? Or are you claiming that Chinese models allow for time travel?
catigula•1m ago
Whoosh.
rwz•2h ago
Good, it seems like new AI tools would lead to substantially more hardened Linux kernel long term. Until a new generation of AIs finds more bugs.
khurs•2h ago
All these seem to be by the same person.

Go Greg!!

https://en.wikipedia.org/wiki/Greg_Kroah-Hartman

http://www.kroah.com/linux/

insanitybit•54m ago
What people are missing is that these aren't vulnerabilities. The reason you see this is because Greg does not believe in the CVE system. As an act of rebellion, the Linux kernel (a) assigns CVEs to fixes and not bugs, (b) assigns them gratuitously to DoS the system.

This is just Greg being a baby. Linux has to be removed as a CNA ASAP, it was a terrible idea to ever grant them that power.

This has nothing to do with AI or even security.

sloped•28m ago
More useful context http://www.kroah.com/log/blog/2026/02/16/linux-cve-assignmen...

Nothing to panic about.

1h ago
They see their dashboard, when the number is high, they want to get the number low as fast as possible. If the number is close to zero, they want to see zero. It is that simple.

They do not care if the issue is in a piece of code that is never executed and would require full access to the machine. It is there and tool X reports it.

Even security audits are terrible, when they don't find anything major they start reporting stuff that few percent of companies have implemented just to stuff their reports, it is ridiculous.

thewebguyd•1h ago
This is the rot that's happening in cybersec. Before we even had security teams as a dedicated role, sysadmins mostly handled security, and we would evaluate each CVE and determined if it even was applicable.

Then companies started hiring paper pushers into security roles and discretion no longer mattered, it just became a game of "Check the box" with no regard for what is actually running in prod, or whether you're actually vulnerable.

Same shit with auditors. I deal with PCI and it's a fight to explain why the "compensating controls" work to a non technical auditor. If it doesn't check the box exactly, good luck.

jerf•2h ago
I only sampled them, but all the ones I sampled are announcements of fixes, not just vulnerabilities. This seems to be downstream of the "intake" already.
bob001•2h ago
The linux kernel team disagrees with your approach but what do they know?

> Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

pixl97•1h ago
That with LLMs being decent at chaining exploits suddenly very difficult issues can be accomplished by people with middling abilities and resources.