Claude Cowork Exfiltrates Files

https://framerusercontent.com/images/kbWpSh9EoyvzEzJzIk214QuARqc.png
Anthropic's Claude Cowork is vulnerable to file exfiltration attacks via indirect prompt injection due to unremediated isolation flaws. Users are recommended to be cautious when granting access to local files and avoid suspicious actions that may indicate prompt injection.

Furiosa: 3.5x efficiency over H100s

https://furiosa-ai.imgix.net/RNGD-Server-Specs.png?auto=format&crop=focalpoint&fit=crop&fm=webp&fp-x=0.5&fp-y=0.5&h=750&q=85&transformer=imgix&w=750
FuriosaAI's NXT RNGD Server is a turnkey AI inference solution with high performance and low power consumption. It allows enterprises to deploy AI workloads efficiently within existing data centers without prohibitive energy costs.

Scaling long-running autonomous coding

https://cursor.com/marketing-static/_next/image?url=https%3A%2F%2Fptht05hbb1ssoooe.public.blob.vercel-storage.com%2Fassets%2Fblog%2Flong-running-agents-3.png&w=1920&q=70
We've developed a system of hundreds of concurrent agents that can work together on a single codebase for weeks, making real progress on ambitious projects. Our system uses a pipeline with distinct roles, including planners and workers, to coordinate tasks and avoid conflicts.

Anthropic Explicitly Blocking OpenCode

The State of OpenSSL for pyca/cryptography

Paul Kehrer and Alex Gaynor are reducing their reliance on OpenSSL due to performance regressions, API complexity, and lack of testing. They plan to add new APIs only available on LibreSSL/BoringSSL/AWS-LC and consider switching to one of these forks for their binary wheels.

Ask HN: Share your personal website

User is creating a community-maintained directory of personal websites at hnpwd.github.io and needs help to grow it. They want users to share their personal websites and consider joining the GitHub project as a maintainer.

Show HN: WebTiles – create a tiny 250x250 website with neighbors around you

https://webtiles.kicya.net/s/img/logo.png
Verification Required Please complete the captcha to continue.

Generate QR Codes with Pure SQL in PostgreSQL

https://tanelpoder.com/files/images/pqr.webp
User generated a QR-code generator as a single SQL statement for PostgreSQL, using ChatGPT Pro for fun and learning. They plan to optimize the SQL for faster execution and compare execution plans between PostgreSQL 16 and 17.

Why some clothes shrink in the wash and how to unshrink them

https://www.swinburne.edu.au/content/dam/media/research/ClothesLine_AdobeStock_375341026.jpeg
Clothing shrinks due to fibre memory, where heat, moisture, and mechanical action cause fibres to relax and return to their natural crinkled state. To prevent shrinkage, use cold water, gentle cycles, and delicate settings, especially for cotton and rayon.

Sun Position Calculator

The app models Earth-Sun orbital relationship, displaying a 3D Sun-path diagram and allowing geo-centric and helio-centric views. It also overlays information to understand solar motion characteristics.

Is passive investment inflating a stockmarket bubble?

I at Bernstein, a broker, published a note entitled “The silent road to serfdom: why passive investing is worse than Marxism”. A decade later the revolution is still in full swing. Trillions of dollars of capital have poured from actively managed investment funds into those that simply track market indices, and the flow shows no signs of stopping. As much as 60% of net assets overseen by ...

SparkFun Officially Dropping AdaFruit due to CoC Violation

https://www.sparkfun.com/media/.renditions/wysiwyg/2025_DEC8_ADAFRUIT_TERMINATION_LETTER.png?format=webpll
SparkFun has ended transactions with Adafruit due to Code of Conduct violations including offensive emails and material. SparkFun continues to support its reseller network for original products and other items.

ChromaDB Explorer

https://www.chroma-explorer.com/_next/image?url=%2Fimages%2Fscreenshots%2Fmain.png&w=3840&q=75
Powered by A modern, native desktop client for ChromaDB. Browse collections, search semantically, and manage your vector embeddings with ease. Connect to local, remote, or Chroma Cloud databases. Save and manage multiple connection profiles with secure API key storage.

Find a pub that needs you

https://www.ismypubfucked.com/og-default.png
The government may reverse pub rate changes, but pubs still need support. Find your local pub and use the Fucked Pub Index to identify the one that needs your help the most.

Roam 50GB is now Roam 100GB

Starlink doubled Roam 50GB to 100GB at no extra cost in most markets. After 100GB, users get unlimited low-speed data for the remainder of their billing period.

I hate GitHub Actions with passion

https://xlii.space/images/github-actions-workflow-failed-small_hu_41b5aaa5fc955172.jpg
The user hates GitHub Actions due to its complexity and inefficiency, particularly with cross-building and matrix failures. They moved their build process to a GNU Makefile to regain control over their logic.

Native ZFS VDEV for Object Storage (OpenZFS Summit)

https://www.zettalane.com/images/mayanas/openzfs-summit-2025-hero.png
We presented MayaNAS and MayaScale at OpenZFS Developer Summit 2025, showcasing objbacker.io for native ZFS VDEV integration with object storage. This approach achieves 3.7 GB/s throughput without FUSE overhead, enabling 70%+ cost savings and sub-millisecond latency.

Rubik's Cube in Prolog – Order

You're using Prolog to analyze the Rubik's Cube with group theory. The cube returns to its initial state after 4 repetitions of the move F. This is a natural consequence of group theory, related to Lagrange's theorem.

How can I build a simple pulse generator to demonstrate transmission lines

https://i.sstatic.net/e0fTUuvI.jpg
A user built a pulse generator to demonstrate transmission lines and provided scope shots of various termination scenarios, including short and long pulses, to help understand the behavior of transmission lines. The user also discussed alternative pulse generator designs, including using a GaN FET driver and a transistor with a charged transmission line, to achieve faster pulse widths and rise times.

Billion-Dollar Idea Generator

Your next billion-dollar pivot, powered by AI* Click the button to discover your destiny

Show HN: Webctl – Browser automation for agents based on CLI instead of MCP

https://opengraph.githubassets.com/56bdde36bda73bf3b5b87d3066171dd47dd99e17c4c81e9faafc9c12a08c4684/cosinusalpha/webctl
The user demonstrated various commands for web automation using webctl, including navigation, typing, clicking, and waiting for elements. They also explored features like snapshotting, filtering, and debugging, as well as managing browser profiles and settings.

Ford F-150 Lightning outsold the Cybertruck and was then canceled for poor sales

https://electrek.co/wp-content/uploads/sites/3/2026/01/Tesla-Cybertruck-sales.png?w=921
Tesla's Cybertruck sales are down nearly 50% year-over-year, with only 5,500 units sold globally in Q4 2025. This is a disaster compared to its peak and the company's stated capacity, with Ford's F-150 Lightning outselling it despite being canceled.

The hunt for a stolen Jackson Pollock

Is Rust faster than C?

Rust and C can have different performance due to varying compiler optimizations and language semantics. However, when comparing the two languages, it's difficult to draw a general conclusion due to many variables such as developer expertise, project constraints, and specific use cases.

Ski map artist James Niehues, the 'Monet of the mountains' (2021)

https://adventure.com/wp-content/uploads/2018/04/157-2.jpg
For 35 years, James Niehues has hand-painted some of the world’s most iconic mountains. James Shackell talks to the Colorado-based artist.

GitHub should charge everyone $1 more per month to fund open source

Greg proposes a system where companies pay $1/month per user into an Open Source fund, distributed based on package.json dependencies. This fund would support open source developers, making their labor more sustainable.

Ask HN: How do you safely give LLMs SSH/DB access?

The user wants to give Claude Code more autonomy but is concerned about security risks, suggesting various methods to restrict its access to sensitive resources such as SSH, databases, and production systems. The user recommends using fine-grained credentials, proxies, and deterministic validation layers to limit Claude's actions and prevent potential security breaches.

Every country should set 16 as the minimum age for social media accounts

https://substackcdn.com/image/fetch/$s_!PYhx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cbf2bae-7077-4136-8ff7-7327ceb0fbac_3982x2655.jpeg
Australia's new social media age-limit law sets the minimum age to 16, prompting other countries to consider similar policies. The ideal age limit should be 16, not 15, to protect children during puberty from social media's negative effects.

So, you’ve hit an age gate. What now?

https://www.eff.org/files/banner_library/ageverificationbanner-2.png
EFF opposes all forms of age verification mandates, citing risks of data leakage and infringement of speech and privacy rights. They recommend minimizing data submission and choosing verification methods with secure data handling practices.

Lago (Open-Source Billing) is hiring across teams and geos

Here's the official job board: https://www.getlago.com/hiring We're open-source, mainly use Ruby. Billing is interesting because it lays the ground for the monetization system of any company. Because we're heavily developer-focus, we fit very well with complex use cases for either infra companies and/or enteprises. Companies like Groq, Mistral, CoreWeave or PayPal chose Lago. ...