Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them

https://anchor.host/wp-content/uploads/2026/04/wordpress-plugin-supply-chain-attack-1-1024x572.webp
A trusted WordPress plugin, Countdown Timer Ultimate, was compromised through a supply chain attack. The plugin's wpos-analytics module injected malicious code into wp-config.php, serving SEO spam to Googlebot.

Nothing Ever Happens: Polymarket bot that always buys No on non-sports markets

The bot scans markets, tracks positions, and exposes a dashboard with live recovery state. It can be deployed on Heroku with config settings and scaled to run only the web dyno.

The Future of Everything Is Lies, I Guess: Safety

Large Language Models (LLMs) pose significant risks to psychological and physical safety, including enabling malicious attacks, harassment, and fraud, and their alignment efforts are not working well. The industry is creating conditions for anyone with sufficient funds to train unaligned models, and the consequences of LLMs could be severe, including destabilizing economies, public safety, ...

Building a CLI for All of Cloudflare

https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6TTRJoUvbs5eWPtnu6NuL6/d31b8479cfca7f4a77517f875f0049eb/BLOG-3224_1.png
Cloudflare is rebuilding its CLI, Wrangler, to provide commands for all products and let agents configure them together using infrastructure-as-code. The new CLI, available in technical preview, will be generated using a new TypeScript schema that defines APIs, CLI commands, and context.

Servo is now available on crates.io

https://servo.org/svg/servo-color-positive.svg
Servo team released v0.1.0, allowing Servo to be used as a library, with a growing confidence in its embedding API. A long-term support (LTS) version is also offered for embedders who prefer scheduled upgrades.

Make Tmux Pretty and Usable (2024)

https://hamvocke.com/_astro/tmux-custom.JReQpud4_1TUvCB.webp
The user is customizing their tmux configuration to make it more comfortable to use. They are changing the prefix key from C-b to C-a and remapping the Caps Lock key to Ctrl.

Tracking down a 25% Regression on LLVM RISC-V

https://avatars.githubusercontent.com/u/25258108?v=4
The user analyzed a benchmark on RISC-V targets and found a performance regression in LLVM due to a recent commit that improved isKnownExactCastIntToFP but inadvertently broke a downstream narrowing optimization. The user fixed the issue by extending getMinimumFPType with range analysis to recognize that fptrunc(uitofp x double) to float can be reduced to uitofp x to float, and the patch was ...

MEMS Array Chip Can Project Video the Size of a Grain of Sand

https://spectrum.ieee.org/media-library/an-array-of-tiny-metallic-cantilevers-curving-away-from-the-surface-of-a-photonic-chip.jpg?id=65493217&width=1200&height=750
Scientists at MITRE and MIT developed a photonic chip that can project 68.6 million spots of light per second, enabling control of millions of qubits in quantum computers. The chip's technology could also revolutionize imaging in augmented reality, biomedical imaging, and 3D printing.

All elementary functions from a single binary operator

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
A single binary operator eml(x,y) can generate all standard functions of a scientific calculator using the constant 1. This operator enables exact recovery of closed-form functions from data at shallow tree depths.

Microsoft isn't removing Copilot from Windows 11, it's just renaming it

Microsoft announced plans to fix Windows 11 in 2026 by giving users more control and removing unnecessary AI features. However, recent changes have been met with disappointment as Microsoft rebranded Copilot instead of removing AI capabilities.

Initial mainline video capture and camera support for Rockchip RK3588

https://www.collabora.com/assets/images/newsroom/hiring_speechBubble2.png
Collabora and the linux-rockchip community are working to bring mainline Linux support to Rockchip RK3588 SoC's video capture and image signal processing blocks. They have made significant progress, including upstreaming the rkcif driver and the Rockchip MIPI CSI-2 receiver unit.

US appeals court declares 158-year-old home distilling ban unconstitutional

https://nypost.com/wp-content/uploads/sites/2/2026/04/125457358.jpg?w=1024
A US appeals court ruled a 158-year-old ban on home distilling unconstitutional, citing it as an improper tax measure. The court's decision allows individuals to distill spirits at home for personal use or as a hobby.

Michigan 'digital age' bills pulled after privacy concerns raised

https://bloximages.newyork1.vip.townnews.com/thecentersquare.com/content/tncms/assets/v3/editorial/2/ad/2ad18d8a-a751-4e8b-967c-6f2ca488160c/68d591de695d2.image.jpg?resize=400%2C225
Michigan lawmakers withdrew two bills requiring device age estimation due to privacy concerns. Advocacy groups are working with sponsors to create a comprehensive consumer data privacy framework instead.

We May Be Living Through the Most Consequential Hundred Days in Cyber History

https://substackcdn.com/image/fetch/$s_!RcBr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09ed54b-8599-421a-919a-7fcb5b93d65a_5760x3840.jpeg
A series of high-profile cyber incidents in 2026, including breaches of Stryker, Lockheed Martin, and Rockstar Games, have been attributed to four separate campaigns targeting U.S. and Western targets. The incidents, which include the exfiltration of 1.5 billion Salesforce records and the wiping of 200,000 devices, have been linked to Iran, North Korea, Russia, and a financially-motivated ...

The economics of software teams: Why most engineering orgs are flying blind

https://www.viktorcessan.com/the-economics-of-software-teams/investment%20thesis.png
Software teams are expensive and their value is calculable, but most teams do not measure financial outcomes, instead tracking activity and sentiment metrics that can trend upward while financial performance deteriorates. To be financially viable, teams need to generate at least three to five times their annual cost in value, which requires a clear understanding of their costs, value ...

Taking on CUDA with ROCm: 'One Step After Another'

The Rational Conclusion of Doomerism Is Violence

https://substackcdn.com/image/fetch/$s_!wkwm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842debdb-100d-44ca-82c2-8caa77427ddb_1027x1385.png
A 20-year-old threw a Molotov cocktail at Sam Altman's house and threatened OpenAI headquarters, suspected of attempted murder. He was an active member of PauseAI, a community that advocates for extreme measures to prevent AI-caused extinction.

'Yes to fields of wheat, no to fields of iron': how Denmark soured on solar

https://i.guim.co.uk/img/media/444cd4f1d7fd307474c7e55c2cea71f183f68cd0/0_0_5179_3450/master/5179.jpg?width=445&dpr=1&s=none&crop=none
Denmark's right-wing parties are opposing solar farms due to concerns over aesthetics and property prices. The backlash has led to cancelled projects and a reevaluation of the country's green transition.

DIY Soft Drinks

https://blinry.org/diy-soft-drinks/3f3bb8383402a595.jpg
User makes sugar-free, caffeine-free cola using essential oils, gum arabic, and artificial sweeteners. They experiment with various flavors and ingredients, creating unique recipes like orange and almond soda.

Evaluation of Claude Mythos Preview's cyber capabilities

https://cdn.prod.website-files.com/663bd486c5e4c81588db7a48/69dce475b35e47368dc56201_ctf_performance_vs_release_date_by_mcl_2_5m.png
The AI Security Institute evaluated Anthropic's Claude Mythos Preview, showing it can execute multi-stage attacks and discover vulnerabilities autonomously. Mythos Preview succeeded in 73% of expert-level CTF tasks and completed 22 out of 32 steps in a 32-step corporate network attack simulation.

Bring Back Idiomatic Design (2023)

https://substackcdn.com/image/fetch/$s_!rxaZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7b070ba-f4cc-486e-a1c1-000ecb3c1a5d_517x316.png
The user misses the consistency in design of the desktop software era and believes that homogeneous interfaces are essential for user experience, citing the example of a checkbox being a standard design idiom. They argue that the lack of design idioms in modern web applications has led to frustration and a "guessing game" for users, and suggest that following established design patterns and ...

Show HN: boringBar – a taskbar-style dock replacement for macOS

https://boringbar.app/images/current-space-1.jpg
boringBar shows only active windows on the current display, allowing one-click switching and app launching. It requires a license after a 14-day trial, with personal and business options starting at $7.99/year and $20.99/year respectively.

Who's Been Impersonating This ProPublica Reporter?

https://www.propublica.org/wp-content/uploads/2026/04/Impostor-Account-Lead-3.jpg?w=1149
A ProPublica reporter was impersonated by scammers posing as a Canadian military official and a Latvian businessman on WhatsApp and Signal. The reporter's headshot was used to trick potential sources into sharing information about foreign militaries.

Android now stops you sharing your location in photos

Google broke geolocation access in Android web browsers, forcing users to upload photos via desktop browsers or native apps. The user is seeking a solution to allow Android web browsers to access geolocation EXIF metadata in photos.

Most people can't juggle one ball

https://res.cloudinary.com/lesswrong-2-0/image/upload/v1654295382/new_mississippi_river_fjdmww.jpg
A guide to juggling from zero to siteswap notation is provided, including tips on basic technique, common mistakes, and how to progress to more complex patterns. The guide covers various aspects of juggling, including 3-ball juggling, 4-ball juggling, and siteswap notation, as well as other implements like clubs and rings.

Austerity Creates Fascism

https://i0.wp.com/craphound.com/images/13Apr2026.jpg?w=840&ssl=1
Object permanence: The Server of Amontillado; Flapper's Dictionary; Mastercard v rec.humor.funny; Philippines electoral data breach; A front page from the Trump presidency; Spike Lee x Bernie Sanders; France v password hashing; Algorithms as Central European folk-dances; Save Comcast; Lex Luthor v export controls; Zuckerberg in the dock. I'm worried about AI psychosis. Specifically, ...

Ask HN: What Are You Working On? (April 2026)

User is building Kavla, a canvas-based interface for data and agents, and working on CLI and AI projects like Orange Words and VCamper. They also created an IDE that automates testing and an interactive market visualization called Not Better Cursor.

I ran Gemma 4 as a local model in Codex CLI

https://miro.medium.com/v2/resize:fit:700/1*nF2MVZb3di2wlQBKYJ3m1A.png
The user tested Gemma 4 as a local model for agentic coding, comparing it to a cloud model. Local Gemma 4 works, but requires configuration and debugging.

I gave every train in New York an instrument

https://www.micwise.com/images/ogtrains.png
Trains form a jazz combo playing a unique, ever-changing piece based on location and time. The music is a portrait of the city, with each note reflecting the surroundings and the trains' routes.

A perfectable programming language

Sydney Von Arx challenged me to name 40 programming languages, which I did. I discussed the importance of types and theorem provers in programming languages, specifically Lean's capabilities.