Install
A constructive and inclusive social network for software developers. With you every step of your journey.
- 10,550articles · 30d
- 1+ hour agolatest article
- Aug 15, 2026earliest in window
- 97%with images
- 292avg words
- software 9,781
- coding 9,578
- development 9,548
- engineering 9,522
- community 9,506
- inclusive 9,468
- ai 8,015
- webdev 5,797
- programming 5,182
- productivity 3,518
- python 2,988
- technology 2,862
- artificial intelligence 2,810
- security 2,777
- devops 2,764
- llm 2,292
- architecture 2,276
- agents 2,184
- tutorial 2,127
- javascript 1,938
- Software Dev. 9,745
- Science & Technology 9,616
- Computers & Electronics 7,485
- Business & Industrial 804
- Internet & Telecom 769
- Economy, Business & Finance 393
- Finance 334
- Arts, Culture, Entertainment & Media 238
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Die XZ-Backdoor: Weckruf für die Open-Source-Sicherheit
4+ day, 4+ hour ago (249+ words) Um das Ausmaß des Vorfalls zu verstehen, müssen wir die Ereignisse Schritt für Schritt nachvollziehen. Es ist eine Geschichte, die sich wie ein Cyber-Thriller liest, aber bittere Realität ist. Hätte Freund diese kleine Anomalie ignoriert, wäre die Backdoor unentdeckt in…...
We Analyzed a Malicious PyPl Package Targeting Developers
5+ day, 30+ min ago (196+ words) A developer runs pip install. Nothing crashes. No ransomware appears. No antivirus alert fires. Thirty seconds later, a Python process makes an outbound connection to infrastructure nobody on the team recognizes. Recent 2026 incidents show how quickly this can become a…...
Building a "Fail-Closed" Zero-Trust CI/CD Protocol: A Personal Open-Source Experiment
5+ day, 5+ hour ago (360+ words) Hello, Dev community! 👋 I am Anjo Machina (安城巻那), a QA engineer based in Japan. I want to share an open-source project I have been building. It is a solitary experiment aimed at exploring structural sovereignty and safety in deployment pipelines....
The Cursor Allowlist Bypass That Starts With a File Named curl
1+ week, 5+ hour ago (532+ words) Last week I shipped CVE-2026-22708 coverage to secops-toolkit-mcp, my toolkit of defensive SecOps helpers for AI coding agents. The CVE is a Cursor terminal allowlist bypass. A malicious file sitting in your project directory can turn an allowed command into…...
HookAudit: Building a Supply-Chain Security Scanner Without a Supply Chain
1+ week, 1+ day ago (1185+ words) What happens when you force a security tool to inspect untrusted code using only standard-library... Tagged with opensource, node, security, javascript....
Основы Product Security для автомобилей и зарядных станций: термины, архитектура, фреймворки
1+ week, 5+ day ago (419+ words) Preview Современный автомобиль и зарядная станция — это уже не просто «железо», а сложные... Tagged with architecture, cybersecurity, iot, security....
Security Audit Report: Reentrancy & Access Control Review: Paxos Gold
2+ week, 1+ day ago (229+ words) Target Protocol: Paxos Gold (TVL: $1913.4M) Paxos Gold (PGX) is a regulated, fiat‑backed token that represents physical gold on‑chain. The protocol’s core contracts include: The audit focused exclusively on two high‑impact security domains: Risk Score (overall): 8 / 10 – the protocol…...
Malware that runs the moment you open the project
2+ week, 6+ day ago (698+ words) "A dropper family committed straight into developer repos. It executes on next dev or when VS Code opens the folder — no npm install needed. How it hides, why IP blocklists fail, and how to check your machine in a minute....
Agentic SQL Injection Is Just SQL Injection Wearing a Trench Coat
2+ week, 6+ day ago (1479+ words) Nobody clapped for this one. Zero points, zero comments on HN, and yet CVE-2026-18830 is a better predictor of where agentic AI security is headed in the next two years than most of the funded-startup noise clogging your feed. Context…...
Rust Build Scripts Executed Malware From a Crate With 245 Million Downloads
3+ week, 1+ day ago (314+ words) The Rust Security Response Team received the report at 07:15 UTC, credited to the Research Team at Nextron Systems GmbH, and deleted all three releases within 86 to 107 minutes. There is no CVE, no patched version, and no vendor fix to apply....