Feed aggregator
Central Reference for 3100 APIs
Article URL: https://github.com/mindcloud-inc/universal-api-reference/blob/main/README.md
Comments URL: https://news.ycombinator.com/item?id=48994106
Points: 1
# Comments: 0
How do security teams distinguish between people and AI? It's getting harder, but behavioral biometrics might help discern human users from machine impersonators.
What happens if you visit a WordPress site hacked through wp2shell?
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
Because a hacked website becomes a delivery mechanism for scams, credential theft, malware, and malicious redirects.
The wp2shell vulnerabilities are especially concerning because they affect WordPress Core itself, don’t require a malicious or vulnerable plugin, and can be exploited without authentication on vulnerable versions. Experts say the chain can lead to full administrative control of a site and remote code execution with web server privileges, meaning an attacker can change what the site serves to visitors.
And cybercriminals are already doing their dirty work:
“Exploitation activity began within hours of the patch release. Wordfence observed endpoint probing and SQL injection attempts the same evening, and public proof-of-concept code was reported in the days that followed.”
Once attackers control a WordPress site, they rarely stop at defacement. A common next step is to quietly inject JavaScript, redirect visitors to malicious pages, or load content from attacker-controlled infrastructure. That can expose visitors to fake login pages, scam pop-ups, browser-based malware, or drive-by downloads, depending on the attacker’s goals.
The possible harmThis isn’t an exhaustive list, but these are some of the ways visitors to a wp2shell-compromised site could be affected:
- Credential theft. Attackers can inject fake login forms or iframe-based overlays that imitate Microsoft 365, Google, banking, or social media sign-in pages to steal usernames and passwords.
- Malware delivery. The site can be turned into a staging point for browser exploitation, malicious downloads, or redirect visitors to malware-hosting pages.
- Scams and fraud. Visitors may be redirected to fake support pages, fake giveaways, or fraudulent payment prompts.
- Tracking and profiling. Attackers can use injected scripts to fingerprint visitors, harvest browser details, and track victims across sessions.
- Search and reputation damage. Search engines and security tools may flag the site, which can expose visitors to warnings and reduce trust long after the initial compromise.
Be cautious, even on websites you normally trust. If something looks different from what you’d expect, treat it as a warning sign.
Be especially wary of unexpected login prompts, download requests, and browser warnings. For site owners, it means patching quickly and treating compromise as a possibility, not an edge case.
Keep your operating system, browsers, and security software up to date. Compromised websites can also try to exploit known vulnerabilities on visitors’ devices.
Use an up-to-date, real-time anti-malware solution that can alarm you if a website tries to infect your device.
Pro tip: Use Malwarebytes’ free Browser Guard extension. It uses heuristic detection to identify malicious websites, block scams, and protect against other web-based threats.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Show HN: LLM Context profiler for tracking context usage by tools, agents, MCPs
Article URL: https://github.com/RimantasZ/contextspy
Comments URL: https://news.ycombinator.com/item?id=48992375
Points: 1
# Comments: 0
Our Interfaces Have Lost Their Senses
Article URL: https://wattenberger.com/thoughts/our-interfaces-have-lost-their-senses/
Comments URL: https://news.ycombinator.com/item?id=48992368
Points: 1
# Comments: 0
Security versus Privacy
Article URL: https://ldstephens.net/posts/security-versus-privacy/
Comments URL: https://news.ycombinator.com/item?id=48992364
Points: 2
# Comments: 0
TSMC to raise chipmaking prices by up to 10% in 2027, Nikkei Asia reports
Article URL: https://www.reuters.com/world/asia-pacific/tsmc-raise-chipmaking-prices-by-up-10-2027-nikkei-asia-reports-2026-07-21/
Comments URL: https://news.ycombinator.com/item?id=48992328
Points: 2
# Comments: 0
PCjs Machines
Article URL: https://www.pcjs.org/
Comments URL: https://news.ycombinator.com/item?id=48992323
Points: 2
# Comments: 0
l with Jacob Loveless [video]
Article URL: https://www.youtube.com/watch?v=whY51vONKs4
Comments URL: https://news.ycombinator.com/item?id=48992319
Points: 2
# Comments: 0
Why Are There No Empires in Age of Empires? (2019)
Article URL: https://acoup.blog/2019/11/22/collections-why-are-there-no-empires-in-age-of-empires/
Comments URL: https://news.ycombinator.com/item?id=48992315
Points: 2
# Comments: 0
Nesso-1: Accelerating Open-Source Binding Affinity Predictions [pdf]
Article URL: https://www.valencelabs.com/wp-content/uploads/2026/07/nesso1.pdf
Comments URL: https://news.ycombinator.com/item?id=48992304
Points: 2
# Comments: 1
7-Zip XZ Decompression Heap-Based Buffer Overflow RCE Vulnerability
Article URL: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
Comments URL: https://news.ycombinator.com/item?id=48992294
Points: 1
# Comments: 0
Soma Cube Forest
Article URL: https://www.oranlooney.com/demos/soma-forest/
Comments URL: https://news.ycombinator.com/item?id=48992284
Points: 1
# Comments: 0
What a 2019 API client teaches you about modern .NET
Article URL: https://www.ivanjurina.com/index.php/2026/07/21/what-a-2019-api-client-teaches-you-about-modern-net/
Comments URL: https://news.ycombinator.com/item?id=48992248
Points: 1
# Comments: 0
Wispr-clone – offline push-to-talk dictation for Linux
Article URL: https://github.com/twinlights/wispr-clone
Comments URL: https://news.ycombinator.com/item?id=48992229
Points: 2
# Comments: 0
Show HN: BlurShield – Automatically blur sensitive info during screen share
I Built BlurShield how easy it is to expose email address,Phone No,API Key and other important info.
BlurShield is a browser extension which detects and blur the sensitive info automatically.
It includes the custom blur options also and also user can keep their own custom patterns in it and a lot of features . I would appreciate the feedback of BlurShield. Thanks for testing it
Comments URL: https://news.ycombinator.com/item?id=48992227
Points: 1
# Comments: 0
TSMC eyes price hikes of up to 25% on chip production services in 2027
Hackercouch: Couchsurfing for Hackers, by Hackers
Article URL: https://hackercouch.com/
Comments URL: https://news.ycombinator.com/item?id=48992219
Points: 1
# Comments: 0
Show HN: Playwright end-to-end tests as OpenTelemetry spans
Article URL: https://github.com/endformdev/playwright-opentelemetry
Comments URL: https://news.ycombinator.com/item?id=48992211
Points: 3
# Comments: 0
Show HN: Apotrope – Offline Windows security auditor (like Lynis, for Windows)
Article URL: https://github.com/hexorcist404/apotrope
Comments URL: https://news.ycombinator.com/item?id=48992201
Points: 1
# Comments: 0
