Exploit Development
Microsoft BitLocker – YellowKey zero-day exploit
Can a Language Model Paint?
Startups and Venture
Cisco Workforce Reductions
NVIDIA
Cerebras prices IPO at $185 per share to raise $5.55B
Replication
Christophe Pettus: Managed Postgres, Examined: Google Cloud SQL for PostgreSQL
Google's managed PostgreSQL returns to first principles: a conventional instance on a VM with a regional disk, plus a distinctive data cache on Enterprise Plus…
PostgreSQL
Christophe Pettus: All Your GUCs in a Row: backslash_quote
A 2006 SQL injection vulnerability and multibyte character encodings created `backslash_quote`, a GUC parameter that remains in PostgreSQL for backward…
AEPs: API Enhancement Proposals
Privacy
Proton's password manager passes audit by top security firm – Proton
Exploit Development
Mystery Microsoft bug leaker keeps the zero-days coming
Show HN: Rotunda - A browser built for agents with simulated typing
AI Psychosis
The Other Half of AI Safety
X / Twitter
Today Intercom becomes Fin
Cloudflare Bankrolls Fascism
Memory and Hardware
Comparing a 1980s memory map to the Raspi Pico
AI Coding Tools
Notion just turned its workspace into a hub for AI agents
CVE and Exploit Development
I was asked to install malware during a fake interview
Apple
Apple Is Quietly Building the Most Profitable AI Toll Booth
Artificial Intelligence
Continual Harness: Online Adaptation for Self-Improving Foundation Agents
Meta
Meta won't let you block its AI account on Threads
Rars: a Rust RAR implementation, mostly written by LLMs
Exploring 8 Shaft Weaving
Apple
MacBook Neo Deep Dive: Benchmarks, Wafer Economics, and the 8GB Gamble
New Claude Code programmatic usage restrictions
Mobile Development
ReactOS
Anthropic
Anthropic’s Cat Wu says that, in the future, AI will anticipate your needs before you know what they are
18 year old critical vulnerability found in Nginx
Web Performance
Browser Run: now running on Cloudflare Containers, it’s faster and more scalable
We’ve enabled higher usage limits, faster performance, better reliability, and increased shipping velocity for our Browser Run product by rebuilding on top of Cloudflare’s Containers. Here’s how.
Apple
The great memory panic of 2026 – Asymco
Achieving NGINX Remote Code Execution via an 18-Year-Old Vulnerability
Notepad++ Mac Port Renamed Nextpad++ After Trademark Row
Network Security
A sentimental tour of late 1990s and early 2000s hacking tools
Nginx.org/En/Changes
Pyrefly v1.0.0 is here (Type Checker / Language Server for Python) [video]
xAI
Altman forced to confront claims at OpenAI trial that he's a prolific liar
Python
Pyrefly v1.0 is here
Privacy
AI chatbots are giving out people’s real phone numbers
People report that their personal contact info was surfaced by Google AI—and there’s apparently no easy way to prevent it. A Redditor recently wrote that he was “desperate for help”: for about a month, he said, his phone had been inundated by calls from “strangers” who were “looking for a lawyer, a product designer, a…
AI Psychosis
How Weak Evidence Is Fueling a National Push to Ban Social Media for Youth
The Emacsification of Software
EVs and Transportation
Data centers cutting power to homes, driving homeowners to solar and batteries
How (and why) rqlite takes control of the SQLite Write-Ahead Log
X / Twitter
X launches a History tab for bookmarks, likes, videos, and articles
GraphQL
Viaduct 1.0 and the future of Airbnb’s data mesh
Moving from an internal tool to a community-driven, production-ready data mesh.By: Ryan Tanner, Raymie Stata, Adam MiskiewiczIntroductionWe’re excited to announce the 1.0 release of the Viaduct. This release marks a shift from Viaduct being an Airbnb-internal tool that happens to be open source to a true community-driven project with a stable public API. The 1.0 release includes substantial new features and enhancements which we describe in the Viaduct blog.Viaduct is for platform enginee...
Establishing the Foundations of Quantum Information Science
2025 ACM A.M. Turing Award recipients Charles Bennett and Gilles Brassard discuss the groundbreaking techniques and applications they refined over decades of collaborative research.
PostgreSQL
Jimmy Angelakos: pg_statviz 1.0 released with AI-powered analysis
I'm excited to announce release 1.0 of pg_statviz, the minimalist extension and utility pair for time series analysis and visualization of PostgreSQL internal statistics. This is a major release that introduces a new optional capability: AI-powered analysis. With the new --ai flag, each chart's data and PNG are sent to a vision-capable LLM along with Senior PostgreSQL DBA-level context, and the model produces a [HEALTHY] / [WARNING] / [CRITICAL] verdict, a short interpretation, and a concrete...
Spotify
At Least We Know the Washington Post Isn't Buying Views
Jeff Bezos learns being good at YouTube is not so easy.
AI Coding Tools
A History of IDEs at Google
Meta
Instagram’s new ‘Instants’ feature combines elements from Snapchat and BeReal
Database Administration and Tooling
Launch HN: Ardent (YC P26) – Postgres sandboxes in seconds with zero migration
MySQL
Migrating Etsy’s database sharding to Vitess
Etsy has maintained a sharded MySQL architecture since around 2010. This database cluster contains most of Etsy’s online data and is made up of ~1,000 tables distributed across ~1,000 shards. Over the last 16 years, it has grown significantly: combined, these tables have over 425 TB of data and receive roughly 1.7 million requests per second. Etsy engineers access our MySQL data through a proprietary object-relational mapping (ORM). The ORM has a corresponding model for each MySQL table. W...
Artificial Intelligence
Making Ads Count: Using MMoE and Auxiliary Tasks to Better Connect Buyers & Sellers
When buyers search on Etsy, they need to quickly and easily find the perfect item. At the same time, sellers need to be confident their unique products are being seen by the right customers. Our Ads Search ranking model, which is built on a multitask learning foundation, is the critical link in this connection. Recently, we identified an opportunity to drive more meaningful buyer engagement by enhancing our model’s ability to predict purchase intent. We achieved this via a dual-pronged impr...
AI Coding Tools
Haiku
xAI
Who trusts Sam Altman?
Robotics
Rivian spinoff Mind Robotics raises another $400M
Fragnesia: New Linux Privilege Escalation Exploit
Show HN: Torrix, self hosted, LLM Observability,(no Postgres, no Redis)
NVIDIA
Origin Lab raises $8M to help video game companies sell data to world-model builders
Show HN: FixMyNPM, CLI to fix your insecure npm config
Azure
Microsoft investigates Israeli military's use of Azure cloud storage
X / Twitter
Simplifying our homepage helped increase trial signups by 84%
Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability
Apple
European Stagnation Is Real
Anthropic
Anthropic courts a new kind of customer: small business owners
Xs of Y – roguelike that names itself every run. Written in 4kLoC
Open Source
Open Source Resistance: keep OSS alive on company time
OpenTelemetry
Streaming CloudWatch metrics to VPC-based OpenTelemetry collectors using Lambda
In this post, we demonstrate an approach we used to address this challenge for a customer by implementing an AWS Lambda transformation function that streams Amazon CloudWatch metrics directly to internal OpenTelemetry collectors running within a VPC.
NVIDIA
Ransomware hackers claim breach at Foxconn, a major electronics manufacturer for Apple, Google, and Nvidia
PostgreSQL
Robins Tharakan: Postgres May 2026 Security Update: 11 CVEs, All Versions Affected
It's that time again. The upcoming Postgres v18.4 release (along with minor releases for all Major versions) has dropped some serious hints in the git logs, and it's bringing a significant payload of CVE tagged patches. As a seasoned Postgres end-user and an erstwhile DBA, whenever I see a flurry of high-vulnerability security commits, I immediately start recommending that customers begin planning their patching cycles. (Note: As these patches are hot off the press, official CVSS scores and ...
The limits of Rust, or why you should probably not follow Amazon and Cloudflare
DNS
Setting up a free *.city.state.us locality domain
Christophe Pettus: Twenty Years in pgcrypto
A heap buffer overflow in pgcrypto's OpenPGP code lurked for two decades—until a December 2025 exploit made it real.
Amazon
Amazon launches an AI shopping assistant for the search bar, powered by Alexa+
The AI Backlash Could Get Ugly
Startups and Venture
Anduril raises $5B, doubles valuation to $61B
Built an open-source kdb+ alternative on weekends — 5.52M ticks/sec, standard SQL
I worked on quant infra for two years. Two things drove me crazy: The kdb+ license. ~$100K/core/year for production. Hard to justify when you're not at a top-5 fund. The q language. Every new hire spent 2 months learning it before shipping anything. That's expensive in engineer-time, and it locked our codebase into a tiny hiring pool. I tried the obvious alternatives before building anything. ClickHouse is great for analytics, but it doesn't have ASOF JOIN. If you've never used ASOF JOIN,...
Web Application Security
US lawmakers demand answers from Instructure after Canvas data breaches
Defense Tech
War and Data Centers Are Driving Up the Cost of Fiber Optic Cable
Spools of cable are critical for internet infrastructure and jam-proof drones but skyrocketing costs are making it hard to field them.
Defense Tech
Europe builds deep. Korea builds fast. General argues neither is enough alone
The US Is Winning the AI Race
Privacy