Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

https://socket.dev/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2Fcgdhsj6q%2Fproduction%2F65ef8dc5e66260e20fdf13cead82ebd41b705ee6-1018x666.png%3Fw%3D1600%26q%3D95%26fit%3Dmax%26auto%3Dformat&w=3840&q=75
Bitwarden CLI 2026.4.0 was compromised through a GitHub Action in its CI/CD pipeline as part of the Checkmarx supply chain campaign. Users are advised to review CI logs and rotate exposed secrets.

'Hairdryer used to trick weather sensor' to win $34,000 Polymarket bet

https://www.telegraph.co.uk/content/dam/Author%20photos/james-titcomb-xlarge.png?imwidth=100
French police investigate possible tampering with weather readings at Charles de Gaulle airport to influence Polymarket bets. A hairdryer may have been used to manipulate temperature readings, causing gamblers to win thousands of dollars.

An update on recent Claude Code quality reports

https://www.anthropic.com/_next/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Fde3bcf9733b61f57234d8c45e663b1bd48677ea1-3840x2160.png&w=3840&q=75
Claude's responses worsened for some users due to three separate changes affecting Claude Code, the Claude Agent SDK, and Claude Cowork. We've fixed the issues and will implement changes to prevent similar problems in the future.

Introducing GPT-5.5

https://images.ctfassets.net/kftzwdyauwt9/5A8f5mO7aKrwLH5ClDV0si/e49a0a3c56f63d9998dd338ce16d0dd6/Blog1.png?w=3840&q=90&fm=webp
OpenAI releases GPT-5.5, a more intelligent and efficient model that can handle complex tasks. GPT-5.5 excels at coding, research, and everyday work on a computer, providing better results with fewer tokens.

Incident with Multple GitHub Services

https://user-images.githubusercontent.com/19292210/60553865-044dd200-9cea-11e9-859c-d6f266e2f01f.png
GitHub's Status Page - Incident with multiple GitHub services.

French government agency confirms breach as hacker offers to sell data

https://www.bleepstatic.com/content/hl-images/2026/04/21/Titres.jpg
France's ANTS agency disclosed a data breach after a threat actor claimed stealing citizen data, potentially exposing 19 million records. The agency advises users to be vigilant about suspicious messages and has notified authorities, but no action is required.

MeshCore development team splits over trademark dispute and AI-generated code

https://blog.meshcore.io/assets/images/2026/04/23/trust-ai-gen-firmware.png
A team member, Andy Kirby, secretly used AI-generated code to take over the MeshCore ecosystem, sparking a dispute over ownership and control. The core team has now separated from Andy and will continue to develop and release MeshCore firmware and app updates on their official website, meshcore.io.

A DIY Watch You Can Actually Wear

https://hackster.imgix.net/uploads/attachments/1949562/_m9gYduHJ0j.blob?auto=compress%2Cformat&w=600&h=450&fit=min
The LILYGO T-Watch Ultra is a DIY smartwatch with ESP32-S3, IP65-rated case, and various features like AI acceleration, Wi-Fi, Bluetooth, and LoRa. It's suitable for complex applications and has a long runtime due to its 1,100mAh battery and improved display.

I am building a cloud

The author is building exe.dev, a cloud platform that addresses the limitations of current cloud services, allowing users to run VMs on their own resources and manage them easily. The goal is to create a cloud that is more flexible and user-friendly, with local NVMe storage, global regions, and a simple, intuitive interface.

Show HN: Honker – Postgres NOTIFY/LISTEN Semantics for SQLite

https://raw.githubusercontent.com/russellromney/honker/main/assets/honker-logo.png
Honker is a SQLite extension and language bindings that add durable pub/sub, task queue, and event streams to SQLite without client polling or a daemon/broker, allowing atomic business writes and side-effect enqueues. It achieves single-digit millisecond reaction time and supports various languages including Python, Node, Rust, Go, Ruby, Bun, and Elixir.

Your hex editor should color-code bytes

https://simonomi.dev/images/color-code-your-bytes/diggy-diggy-hole.png
The user discusses the benefits of using color in hex dumps to make it easier to notice patterns and details in the data. They propose a custom hex editor called hexapoda and suggest that more tools should include color-coded bytes.

The Ferrari of Espresso Machines Is Fueling a Hot Resale Market

Kent Bakke discovered a two-boiler espresso machine in Italy, leading to a deal with La Marzocco and eventually influencing Starbucks. La Marzocco machines, known for their retro design, now sit in 15% of US coffee shops despite their limited presence.

To Protect and Swerve: NYPD Cop Has 547 Speeding Tickets

https://nyc.streetsblog.org/wp-content/uploads/sites/9/2026/04/GIOVANSANTI-Greg-Mango-with-filter2.jpg?w=1024
James Giovansanti, a NYPD officer, has accumulated 547 speeding tickets in Staten Island since 2022, averaging one ticket every other day. His record makes him the second-most-reckless driver in the city, posing a unique danger to himself and others.

Apple fixes bug that cops used to extract deleted chat messages from iPhones

https://techcrunch.com/wp-content/uploads/2026/04/iphone-pop-up-notifications.jpg?w=1024
Apple fixed a bug that allowed deleted messages to be retained on iPhones due to notifications being stored in the device's database. This issue was exploited by the FBI using forensic tools, raising concerns among privacy activists about authorities accessing deleted data.

Palantir Employees Are Starting to Wonder If They're the Bad Guys

https://media.wired.com/photos/69d3c62396de4781bbc4cf6e/master/w_2560%2Cc_limit/GettyImages-2268833968.jpg
Palantir employees are questioning the company's involvement in immigration enforcement and its relationship with the Trump administration. The company's leadership has been criticized for its handling of internal dissent and its defense of its work with ICE and the US military.

If America's so rich, how'd it get so sad?

https://substackcdn.com/image/fetch/$s_!gAKe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16200edd-4e29-4729-8d58-4eefbab120d8_1260x893.png
The US has experienced a sharp decline in self-reported happiness since 2020, with no recovery, despite a strong economy and low unemployment. The culprit is likely the ongoing COVID pandemic and its aftermath, including inflation, economic uncertainty, and a uniquely negative news environment.

I spent years trying to make CSS states predictable

Have you ever changed the order of two CSS rules and broken a component without changing the logic? Both selectors have specificity (0, 1, 1). When a button is both hovered and disabled, the browser falls back to source order. If the :hover rule comes last, the disabled button turns blue. If the [disabled] rule comes last, it stays gray. That sounds small, but it points to a bigger problem: ...

Writing a C Compiler, in Zig (2025)

https://ar-ms.me/stamp.png
This is a series of articles I wrote while writing paella, following Nora Sandler's Writing a C Compiler. It was both an exercise to learn Zig and a way to waste time instead of looking for work, as I am currently "between jobs". I did not edit them as I collect them here outside of fixing some broken links.

Jiga (YC W21) Is Hiring

https://jiga.io/wp-content/uploads/2026/01/Jiga-team-1-min-4.png
Jiga streamlines product sourcing by connecting engineers with vetted manufacturers and automating administrative tasks. This saves time and reduces costs, allowing engineers to focus on actual work.

Investigation uncovers two sophisticated telecom surveillance campaigns

https://techcrunch.com/wp-content/uploads/2022/06/cityscape-location-data.jpg?w=1024
Citizen Lab exposed two surveillance campaigns using "ghost" companies to exploit phone network vulnerabilities. The campaigns targeted individuals worldwide, using SS7 and Diameter flaws to geolocate phones.

We found a stable Firefox identifier linking all your private Tor identities

https://fingerprint.com/static/893bf56cdf5a22443c3b3ace0bb862df/blog_firefox_vulnerability.jpg
A Firefox-based browser vulnerability allows websites to derive a unique identifier from IndexedDB database ordering, linking activity across origins. Mozilla has fixed the issue in Firefox 150 and ESR 140.10.0.

A Renaissance gambling dispute spawned probability theory

https://static.scientificamerican.com/dam/asset/eb2e8ed0-c13b-4c11-8a4c-afe23c1ed280/points-problem_graphic_leadImage.png?m=1776449332.201&w=600
Mathematicians Blaise Pascal and Pierre de Fermat solved the "problem of points" by considering future possibilities of the score. Their solution, based on expected value, is used in risk assessments and has become a fundamental pillar of modern probability theory.

Arch Linux Now Has a Bit-for-Bit Reproducible Docker Image

https://antiz.fr/images/pfp.jpg
Arch Linux now has a reproducible Docker image under the "repro" tag, but pacman is not usable out of the box due to stripped pacman keys. Users must regenerate the pacman keyring before installing packages.

Alberta startup sells no-tech tractors for half price

Ursa Ag, a small Canadian manufacturer, is selling tractors with remanufactured 1990s diesel engines and no electronics for half the price of comparable machines. The company's simple, mechanical design is appealing to farmers who want to avoid modern complexity and high costs.

5x5 Pixel font for tiny screens

A programmer designed a 5x6 pixel font for low-resolution displays, allowing for compact layouts and easy programming. The font takes up 350 bytes of memory and is suitable for 8-bit microcontrollers.

Isopods of the world

https://cdn.isopod.site/2022/02/P1154733b.jpg
Isopod Site aims to improve isopod identification through basic anatomy understanding. Selective breeding is used in the hobby to boost unique traits in new lineages.

People Do Not Yearn for Automation

https://platform.theverge.com/wp-content/uploads/sites/2/chorus/author_profile_images/195834/NILAY_PATEL.0.jpg?quality=90&strip=all&crop=0%2C0%2C100%2C100&w=2400
The tech industry's "software brain" thinking, which sees the world as databases to be controlled, is causing a disconnect with regular people who experience AI as a threat to their humanity. This thinking is leading to a failure to understand why people dislike AI, as it ignores the limits of software and the complexity of human experience.

Our newsroom AI policy

https://cdn.arstechnica.net/wp-content/uploads/2026/02/ars-logo-dark-background-640x360.jpg
Ars Technica uses generative AI tools in its workflow, but only with human oversight and standards. The site's editorial text is written by humans, and AI output is never treated as an authoritative source.

A History of Erasures Learning to Write Like Leylâ Erbil

The author initially dismissed Leylâ Erbil's work as outdated and self-indulgent, but later reevaluated her experimental novel "What Remains" as a powerful challenge to literary conventions in Turkey. Erbil's autofiction explores Turkish history, politics, and identity through a stream-of-consciousness narrative that blurs the lines between personal and public trauma.

Raylib v6.0

https://private-user-images.githubusercontent.com/5766837/582600101-a406acfb-d823-47a1-8c1e-58ca0b792b0e.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3NzY5NTEzMjcsIm5iZiI6MTc3Njk1MTAyNywicGF0aCI6Ii81NzY2ODM3LzU4MjYwMDEwMS1hNDA2YWNmYi1kODIzLTQ3YTEtOGMxZS01OGNhMGI3OTJiMGUucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDQyMyUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA0MjNUMTMzMDI3WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9MjMxYzlkN2M5ODYzYTJiZDBiMDgwNjZiZmE2MWE5OGQ3YmFiZTE3OTJjMTUyNTU3YjZlYmYwNjVhNzUyZDY5NSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.zgiNjZRCaA-W8lKCiSL3lNM6xw4r4ABebImyESPQwxc
Raylib 6.0 is released with major updates including a new software renderer, redesigned fullscreen modes, and improved text management API. The release also includes new platform backends, a file system API, and a tool for managing examples.