Feed aggregator
One Morning, a Discord Agent, and Five Years of Tech Debt
Article URL: https://saddlebagexchange.com/blog/coderabbit-discord-frontend-upgrade
Comments URL: https://news.ycombinator.com/item?id=49645917
Points: 3
# Comments: 0
Show HN: I built a Cap Table app for myself, now you can use it too for free
Article URL: https://cap-table.io/
Comments URL: https://news.ycombinator.com/item?id=49645912
Points: 2
# Comments: 0
Forgejo <=16.0.3 Critical RCE
Article URL: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
Comments URL: https://news.ycombinator.com/item?id=49645907
Points: 2
# Comments: 0
Secret systems used by Israel in mass killings of Gaza civilians revealed
Influencers Can Create Instagram Captions with AI – Best Tool
Use the AI Tool below in the comment for your Instagram captions - See the spikes and peaks of your post when it becomes viral. Our customized AI Tool generates exactly the Instagram Caption that has the potential to give reach in millions.
Comments URL: https://news.ycombinator.com/item?id=49645895
Points: 2
# Comments: 0
A Series of Unfortunate Jobs
Article URL: https://oussama-mater.tech/laravel-queue-gotchas/
Comments URL: https://news.ycombinator.com/item?id=49645893
Points: 1
# Comments: 0
Perhaps the universe isn't accelerating (and thus we don't need dark matter)
Article URL: https://academic.oup.com/mnras/article/549/3/stag844/8701424
Comments URL: https://news.ycombinator.com/item?id=49645889
Points: 1
# Comments: 0
A 35B language model running on an iPhone using only 1–2.5 GB of peak memory
Article URL: https://github.com/Edge0-AI/edge0/
Comments URL: https://news.ycombinator.com/item?id=49645864
Points: 1
# Comments: 0
Casablanca: How An Unproduced Play Marched into Movie History
Article URL: https://www.thecollector.com/casablanca-unproduced-play-movie-history/
Comments URL: https://news.ycombinator.com/item?id=49645826
Points: 5
# Comments: 0
Serverless DTLS
Article URL: https://proxylity.com/docs/listeners/dtls.html
Comments URL: https://news.ycombinator.com/item?id=49645804
Points: 3
# Comments: 1
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble.
Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless.
But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.
The campaign is a timely reminder that once a security flaw, or even its fix, becomes public, attackers may move faster than many users expect.
The attacks began with phishing emails. A victim who clicked a malicious link could be sent to a web page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows vulnerability to break out of the browser’s protections and gain higher privileges on the computer.
The Chrome vulnerabilities used by BlueMoon were patched in the Stable channel on September 3 and September 8, 2026. The first was already actively exploited when Google released its update. Microsoft addressed the Windows vulnerability in its September Patch Tuesday updates, by which point it was also being exploited.
CISA has since added all three flaws to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities known to have been exploited in real-world attacks.
The notable part is not just that BlueMoon exploited the flaws, but how quickly the capability appears to have spread. Publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, allowing a weaponized chain to be developed and adopted by multiple groups very quickly.
Does that mean that patches can no longer be tested before they are released to the public? No, but we may need to rethink how they are tested and deployed, because it appears some cybercriminals are effectively beta-testing the patches themselves.
The researchers also found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance. The broader concern is credible: AI tools can help attackers interpret source-code changes, write and modify code, document test results, and learn from failed attempts.
In practical terms, the gap between “a flaw is fixed upstream” and “most people are protected” may be increasingly valuable to attackers. We should try to minimize that gap.
How to stay safeNot every security update needs to be installed the moment it appears. In organizations especially, updates may need testing, staged deployment, and contingency plans. But vulnerabilities known to be actively exploited deserve greater priority. That is precisely why CISA’s KEV catalog is so important: It helps organizations identify the vulnerabilities they should address first.
For home users:
- Install browser and operating-system updates promptly. Use the few minutes they take to grab a drink rather than repeatedly postponing them.
- Don’t click links in unsolicited emails.
- Use up-to-date, real-time anti-malware protection to help catch the malware that exploit kits attempt to deliver.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Show HN: I built an AI 'Fog of War' to kill my 3AM Notion templates
Article URL: https://www.tryworthit.app/about
Comments URL: https://news.ycombinator.com/item?id=49645780
Points: 2
# Comments: 1
Genuinely useful set of free tools for any dev
Article URL: https://kirkdiamond.com/tools/
Comments URL: https://news.ycombinator.com/item?id=49645766
Points: 1
# Comments: 0
Neki by PlanetScale
Article URL: https://neki.dev/
Comments URL: https://news.ycombinator.com/item?id=49645763
Points: 6
# Comments: 0
Silicon Valley Is Transforming the Military-Industrial Complex
A Design Space Exploration of Async/Await
Article URL: https://cel.cs.brown.edu/blog/design-space-async-await/
Comments URL: https://news.ycombinator.com/item?id=49645736
Points: 1
# Comments: 0
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek.
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek.
