687
227
How we exploited CodeRabbit: From simple PR to RCE and write access on 1M repos
https://research.kudelskisecurity.com/2025/08/19/how-we-exploited-coderabbit-from-a-simple-pr-to-rce-and-write-access-on-1m-repositories/
2 weeks ago
609
190
OpenMower – An open source lawn mower
https://github.com/ClemensElflein/OpenMower
557
55
How to Draw a Space Invader
https://muffinman.io/blog/invaders/
441
73
D2 (text to diagram tool) now supports ASCII renders
https://d2lang.com/blog/ascii/
388
535
"Remove mentions of XSLT from the html spec"
https://github.com/whatwg/html/pull/11563
310
115
Custom telescope mount using harmonic drives and ESP32
https://www.svendewaerhert.com/blog/telescope-mount/
306
160
Without the futex, it's futile
https://h4x0r.org/futex/
300
167
Croatian freediver held breath for 29 minutes
https://divernet.com/scuba-news/freediving/how-croatian-freediver-held-breath-for-29-minutes/
296
96
Prime Number Grid
https://susam.net/primegrid.html
293
146
Ted Chiang: The Secret Third Thing
https://linch.substack.com/p/ted-chiang-review
288
191
Vendors that treat single sign-on as a luxury feature
https://sso.tax/
286
Emacs as your video-trimming tool
https://xenodium.com/emacs-as-your-video-trimming-tool
276
109
UK drops demand for backdoor into Apple encryption
https://www.theverge.com/news/761240/uk-apple-us-encryption-back-door-demands-dropped
253
459
From M1 MacBook to Arch Linux: A month-long experiment that became permanenent
https://www.ssp.sh/blog/macbook-to-arch-linux-omarchy/
244
76
How to Build a Medieval Castle
https://archaeology.org/issues/september-october-2025/features/how-to-build-a-medieval-castle/
242
183
Notion releases offline mode
https://www.notion.com/help/guides/working-offline-in-notion-everything-you-need-to-know
226
66
Lightning declines over shipping lanes following regulation of sulfur emissions
https://theconversation.com/the-world-regulated-sulfur-in-ship-fuels-and-the-lightning-stopped-249445
193
181
Google is killing the open web
https://wok.oblomov.eu/tecnologia/google-killing-open-web/
177
120
I run a full Linux desktop in Docker just because I can
https://www.howtogeek.com/i-run-a-full-linux-desktop-in-docker-just-because-i-can/
165
51
Positron, a New Data Science IDE
https://posit.co/blog/positron-product-announcement-aug-2025/
163
Tiny microbe challenges the definition of cellular life
https://nautil.us/a-rogue-new-life-form-1232095/
13
CRDT: Text Buffer
https://madebyevan.com/algos/crdt-text-buffer/
153
11
Perfect Freehand – Draw perfect pressure-sensitive freehand lines
https://www.perfectfreehand.com/
152
45
Why Semantic Layers Matter (and how to build one with DuckDB)
https://motherduck.com/blog/semantic-layer-duckdb-tutorial/
147
41
BBC witnesses settlers attack on Palestinian farm in West Bank
https://www.bbc.com/news/articles/cewy88jle0eo
216
AnduinOS
https://www.anduinos.com/
140
136
The forgotten meaning of "jerk"
https://languagehat.com/the-forgotten-meaning-of-jerk/
34
WebR – R in the Browser
https://docs.r-wasm.org/webr/latest/
52
PyPI Preventing Domain Resurrection Attacks
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/
130
123
Why I'm all-in on Zen Browser
https://werd.io/why-im-all-in-on-zen-browser/
114
Critical Cache Poisoning Vulnerability in Dnsmasq
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2025q3/018288.html
125
199
'Ad Blocking Is Not Piracy' Decision Overturned by Top German Court
https://torrentfreak.com/ad-blocking-is-not-piracy-decision-overturned-by-top-german-court-250819/
57
450× Faster Joins with Index Condition Pushdown
https://readyset.io/blog/optimizing-straddled-joins-in-readyset-from-hash-joins-to-index-condition-pushdown
113
Launch HN: Uplift (YC S25) – Voice models for under-served languages
https://news.ycombinator.com/item?id=44950661
58
XZ Utils Backdoor Still Lurking in Docker Images
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images
95
9
David Klein's TWA Posters (2018)
https://flashbak.com/david-kleins-magnificent-twa-posters-404428/
94
31
Warp sends a terminal session to LLM without user consent
https://news.ycombinator.com/item?id=44953470
93
Attention Is the New Big-O: A Systems Design Approach to Prompt Engineering
https://alexchesser.medium.com/attention-is-the-new-big-o-9c68e1ae9b27
92
Show HN: OpenAI/reflect – Physical AI Assistant that illuminates your life
https://github.com/openai/openai-reflect
90
28
A renovation project in Turkey led to the discovery of a lost city (2023)
https://www.atlasobscura.com/articles/derinkuyu-turkey-underground-city-strange-maps
89
150
Porn censorship is going to destroy the internet
https://mashable.com/article/age-verification-is-going-to-destroy-the-entire-internet
88
1
How to Think About GPUs
https://jax-ml.github.io/scaling-book/gpus/
82
16
Drunken Bishop (2023)
https://re.factorcode.org/2023/08/drunken-bishop.html
80
40
Starting game development in JavaScript with no experience
https://jslegenddev.substack.com/p/how-to-start-making-games-in-javascript
75
A simple way to generate random points on a sphere
https://www.johndcook.com/blog/2025/05/06/random-points-on-a-sphere/
78
158
CEO pay at top US companies accelerates at fastest pace in 4 years
https://www.ft.com/content/d8da9877-a5d0-4ac2-87cd-236ff33d7269
77
107
As Alaska's salmon plummet, scientists home in on the killer
https://www.science.org/content/article/alaska-s-salmon-plummet-scientists-home-killer
74
106
End well, this won't: UK commissioner suggests govt stops kids from using VPNs
https://www.theregister.com/2025/08/19/uk_commissioner_suggests_govt_stop/
71
Medical cannabis patient data exposed by unsecured database
https://www.wired.com/story/highly-sensitive-medical-cannabis-patient-data-exposed-by-unsecured-database/
5
CRLite: Certificate Revocation Checking in Firefox
https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/
70
43
Forklifts require training
https://www.zacsweers.dev/forklifts-require-training/
68
105
Giving people money helped less than I thought it would
https://www.theargumentmag.com/p/giving-people-money-helped-less-than