Supabase MCP can leak your entire SQL database

https://www.generalanalysis.com/images/mcp/hero.png
An attacker can exploit Supabase's MCP integration to leak a developer's private SQL tables by submitting a carefully crafted message that is treated as an instruction by the LLM. This occurs due to overprivileged database access and blind trust in user-submitted content, which can be mitigated by enabling the readonly flag and scanning data for suspicious patterns.

US Court nullifies FTC requirement for click-to-cancel

https://cdn.arstechnica.net/wp-content/uploads/2024/10/mouse-click-300x200.jpg
A federal appeals court struck down the FTC's "click-to-cancel" rule, citing procedural deficiencies in the rulemaking process. The court ruled that the FTC failed to conduct a required preliminary regulatory analysis, which would have allowed industry groups to contest the rule's findings.

SVGs that feel like GIFs

https://koaning.io/posts/svg-gifs/parrot.svg
You're using animated SVGs in README files, supported by Github, created with asciinema and svg-term-cli. This feature utilizes animations built into the SVG spec.

Google can now read your WhatsApp messages

https://cdn.neowin.com/news/images/uploaded/2025/06/1750495086_gemini.webp
Google's Gemini feature allows Android users to use voice commands with apps like WhatsApp, but it may read messages and view images. To disable Gemini, users can turn off Gemini Apps Activity in the Gemini app or uninstall the Google app.

Smollm3: Smol, multilingual, long-context reasoner LLM

https://cdn-avatars.huggingface.co/v1/production/uploads/5e48005437cb5b49818287a5/4uCXGGui-9QifAT4qelxU.png
SmolLM3 is a competitive 3B model that outperforms Llama-3.2-3B and Qwen2.5-3B while staying competitive with larger 4B models. It supports long-context, multilingual, and reasoning capabilities with up to 128k context and a dual-mode interface for reasoning and non-reasoning modes.

Breaking Git with a carriage return and cloning RCE

https://dgl.cx/2025/07/olympia-sm9.jpg
A vulnerability was found in Git that allows remote code execution when cloning an untrusted repository. It was fixed by updating Git and other software that embeds it, and also by quoting strings with carriage returns in configuration files.

Show HN: OffChess – Offline chess puzzles app

https://offchess.com/rated.png
Every chess puzzle on OffChess is rated, you gain and lose points based on your and puzzle's rating. Paint the board in the colors you like, with several themes to choose from you are sure to find something that you love.

Firefox is fine. The people running it are not

https://regmedia.co.uk/2022/09/23/shutterstock_firefoxlogo.jpg?x=174&y=115&crop=1
Mozilla's leadership is directionless and flailing due to its reliance on Google's funding, never having to make a profit, and lacking a clear vision. A nonprofit organization should oversee browser development, focusing on funding an independent, non-vendor-driven browser engine.

Radium Music Editor

http://users.notam02.no/~kjetism/radium/pictures/radium_6_0_99_perspective.png
Radium is a tracker-like music editor with a graphical interface for editing notes and effects, also functioning as a DAW for recording and mixing audio. It's open source, easy to use, and available on multiple platforms, with a straightforward build system and subscription-based development support.

GlobalFoundries to Acquire MIPS

https://mips.com/wp-content/uploads/2025/01/MIPS-Atlas-Explorer-title-01.jpg
GlobalFoundries is acquiring MIPS, a leading supplier of AI and processor IP, to expand its portfolio with cutting-edge RISC-V processor IP and software tools. The acquisition will enhance GF's capabilities to offer customers flexible, RISC-V-based open platform solutions.

Brut: A New Web Framework for Ruby

https://naildrivin5.com/images/BrutLogoTall.png
Brut is a simple Ruby web framework with no controllers, verbs, or resources, focusing on low-abstraction and low-ceremony. It includes built-in instrumentation, data access layer, and automation tools for easy app development.

Xenharmlib: A music theory library that supports non-western harmonic systems

https://xenharmlib.readthedocs.io/en/latest/_static/sidebar-logo.png
Xenharmlib is a music theory library that supports non-standard tunings and notations. It's designed for composers and researchers with Python knowledge, focusing on harmonic relations and scientific exploration.

Zorin OS

https://assets.zorincdn.com/zorin.com/images/home/hero/17.png
Windows 10 is reaching its end of life, consider Zorin OS as an alternative for a faster, more secure, and privacy-respecting experience. Zorin OS is easy to use, customizable, and compatible with Windows and macOS apps.

Why LLMs Can't Write Q/Kdb+: Writing Code Right-to-Left

LLMs struggle with Right-to-Left (RL-NOP) languages like q/kdb+ due to evaluation order issues. A proposed solution is Qython, a Python-like language that compiles to q, allowing LLMs to write code in a familiar syntax.

DOJ goes after US citizen for developing anti-ICE app

https://photos5.appleinsider.com/gallery/64266-133873-000-lead-ICEBlock-2-xl.jpg
The US Attorney General threatened the developer of an iPhone app, ICEBlock, which reports ICE officer sightings, calling it unconstitutional. The Trump administration is also threatening to sue CNN for reporting on the app, claiming it encourages people to avoid law enforcement.
https://imagedelivery.net/0Ey8LwpQ4ATeP19F21mqig/6a5b1329-2b89-4437-4438-192fa9e1f300/public
User analyzed Hacker News data from 2007 to 2025 using camelAI and ClickHouse database. Results show DuckDB's rapid growth, ClickHouse's steady gains, and PostgreSQL's continued dominance.

Blind to Disruption – The CEOs Who Missed the Future

https://i0.wp.com/steveblank.com/wp-content/uploads/2025/07/Wells-Fargo-coach.jpg?resize=300%2C214&ssl=1
The US carriage industry went bankrupt due to its failure to adapt to the emerging automobile technology, with only one company, Studebaker, surviving the transition. The story serves as a warning for modern companies facing disruption from AI, highlighting the importance of adaptability and innovation to avoid becoming obsolete.

Show HN: Jukebox – Free, Open Source Group Playlist with Fair Queueing

https://www.jukeboxhq.com/opengraph-image.jpg
Turn your phone or any device into a jukebox! Share a link with friends so they can add songs to your shared music queue.

SIMD.info – Reference tool for C intrinsics of all major SIMD engines

What would you like to search for?

Show HN: A rain Pomodoro with brown noise, ASMR, and Middle Eastern music

https://forgetoolz.com/_next/image?url=%2Flogo-light.png&w=384&q=75
The Rain Pomodoro timer combines immersive rain sounds, brown noise, ASMR triggers, and Middle Eastern ambience to create a scientifically designed focus environment for productivity and concentration. It features customizable 25-minute focus sessions, smart break reminders, and session tracking, along with animated rain effects and a distraction-free interface.

Trying to find meaning in owning an old Mac

https://blog.decryption.net.au/images/se3001_thumb.jpg
Your dad collects classic cars from the 50s-70s and you collect a classic 1989 Apple Macintosh SE/30, exploring the era that inspired modern computers. You'll restore and use the Mac occasionally, just like your dad with his cars, as a tribute to the past and what's been lost in progress.

Dynamical origin of Theia, the last giant impactor on Earth

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
Cosmochemical studies suggest Earth accreted 5-10% of its mass from carbonaceous material, with a large fraction delivered late via Theia. Simulations show this scenario matches constraints on terrestrial planets' masses, orbits, and carbonaceous mass fractions, with 50-50 odds of Theia being a carbonaceous object.

WebAssembly: Yes, but for What?

WebAssembly (Wasm) has had success in retargeting big C and C++ desktop applications to the web, and in getting C and C++ components onto the web, but its adoption in games and user-facing web interfaces is limited. Wasm's future potential lies in its ability to enable fast cold-start characteristics, making it suitable for edge compute and cloud services, and its isolation capabilities make ...

Show HN: Sumble – knowledge graph for GTM data – query tech stack, key projects

Sumble provides account intelligence data, enabling sales teams to do deep research. Use it to better inform your targeting and outreach.

Ask HN: What are some cool or underrated tech companies based in Canada?

You're looking for lesser-known Canadian tech companies, mentioning Aloe, Lumen5, Urbanlogiq, D-wave, Safety, Sparx, and Xiphos Systems as examples.

Tell HN: I Lost Joy of Programming

User relies on Windsurf editor for coding, but now finds it tedious and unenjoyable due to waiting for LLM results. They've stopped reviewing code changes and just push forward to complete tasks.

TSA to end shoes-off policy for airport security screening

https://i.abcnewsfe.com/a/aca9ebb5-dff2-4516-ad7a-bd4c8053bb90/tsa-line-gty-jef-250625_1750859087584_hpMain_2_16x9.jpg?w=992
The TSA is phasing out the shoe removal policy at US airports, allowing passengers to keep their shoes on in general security lines. This change aims to speed up security checks, but passengers triggering alarms will still need to remove shoes for additional screening.

NuxtLabs is joining Vercel

https://nuxtlabs.com/social.png
NuxtLabs joins Vercel to sustain open source and focus on building in the open. Nuxt's community and roadmap remain unchanged, with new features and AI integration on the horizon.

The Tradeoffs of SSMs and Transformers

https://goombalab.github.io/assets/img/2025-07-08-tradeoffs/recurrent_models.png
Attention is most effective on pre-compressed data at the “right level of abstraction”. a lot of technical work was involved in getting this family of models to work, says samuel e. dawkinson, co-author of the mamba paper. this post abstracts away what he views as the main high-level ingredients that made these models successful, d.a. dewan, and others. these ingredients include select

Cloudflare: We Will Get Google to Provide a Way to Block AI Overviews

https://images.seroundtable.com/google-robot-behind-bars-1751887399.jpg
Cloudflare's CEO Matthew Prince believes Google will allow him to block AI Overviews and Answer boxes without blocking search indexing. He's hopeful of a solution through conversations with Google, but has a backup plan of passing a law to require Google to separate crawlers.

The New York Times wants your private ChatGPT history – even the deleted parts

A federal judge ordered OpenAI to preserve nearly all ChatGPT user conversations, including deleted ones, for a New York Times copyright lawsuit. This decision threatens the privacy of over 70 million users who trusted ChatGPT to delete their conversations.

Show HN: I built a tool to solve window management

AboveAverageUser offers Smart Switcher with lifetime bug fixes and security updates, a 30-day risk-free guarantee, and limited-time introductory pricing. The application requires a license key for full functionality.

Bear-Sized Giant Beavers Once Roamed North America

https://th-thumbnailer.cdn-si-edu.com/26Bgq54hvyzerStZ8rEIcBCKaL4=/960x540/https://tf-cmsv2-smithsonianmag-media.s3.amazonaws.com/filer_public/51/c3/51c36383-f5a9-4efd-a254-61b9800deaca/smm_castoroides_ohioensis_2024.webp
Minnesota lawmakers have officially designated the giant beaver as the state fossil. The giant beaver, an extinct Ice Age rodent, is a significant symbol of Minnesota's ancient natural history.

ChatGPT testing a mysterious new feature called 'study together'

https://techcrunch.com/wp-content/uploads/2024/12/GettyImages-2169079907_27e720-e1734690817769.jpg?w=1024
OpenAI's mode, Study Together, may allow multiple users to join a chat for educational purposes. This feature could help ChatGPT encourage good uses in education while discouraging cheating.

CPU stuck at 0.80Ghz, Fixed by removing keyboard screw (2018)

You don't have permission to access "http://www.dell.com/community/en/conversations/latitude/cpu-core-speed-stuck-at-080ghz-latitude-e7440/647f79dcf4ccf8a8de805bd2?" on this server.

Is it possible to play doom on an oscilloscope using only lissajous figures?

https://forums.sufficientvelocity.com/data/svg/20/1/1751844319/logo_icon.png
People have run Quake on an oscilloscope using a custom triangle sound pipeline. They used Darkplaces Quake's software renderer to extract scene geometry and transfer it to an audio synthesizer via a named pipe.

The Texas Flooding Tragedy: Could It Have Been Avoided?

https://blogger.googleusercontent.com/img/a/AVvXsEjeKlkTnEIuP-n39IVQr15pGXx2BaI9PbycMdcNelevL4i1HI1bLO0Qp94MFQbmbHFw3nrydPhg9EzukEJCnERSnh1UVcq1iZsmkrVmRGM_TbO_AQmWzVu-Kyc2BgDJ5cy8cu2PrnFSAdAbk1GeI5WtXCh2nEJiLWeC16sizYb8IEQQ-t26L4jQA4zPpoE=w314-h298
The Texas flooding was caused by heavy rainfall, but the National Weather Service provided accurate warnings and forecasts, and the local authorities failed to evacuate people in time, leading to tragic consequences. The incident highlights the need for effective communication and preparedness, rather than blaming climate change or the weather service, and suggests that local authorities ...

TSA expected to phase out shoe removal policy at airport security

https://www.tennessean.com/gcdn/authoring/authoring-images/2025/07/08/USAT/84506148007-getty-images-1150770275.jpg?crop=1023,576,x0,y53&width=660&height=371&format=pjpg&auto=webp
TSA may eliminate shoe removal at airport security checkpoints, a policy in place since 2006. The change is being phased out at select US airports, enhancing the passenger experience and security posture.

Brainwash '72 [video]

https://archive.org/services/img/opensource_movies
User found a strange quit-smoking tape on an Umatic tape with a McDonalds label, containing disturbing footage. The tape was digitized using a Sony VP-7040, CYP Time Base Corrector, and Blackmagic Intensity Shuttle.

Monorail – Turn CSS animations into interactive SVG graphs

https://muffinman.io/monorail/monorail-light.png
Monorail turns any CSS keyframe animation into an interactive graph. Try playing with the example below. For details on how to use it, check the GitHub repo.

Fast cryptographically safe GUID generator for Go

https://opengraph.githubassets.com/252d36ecb86643bd2c62f7bb22aa392d2c403d6116a4ad907d2623fc11617610/sdrapkin/guid
The code generates and prints GUIDs using the guid package, then marshals and unmarshals a User struct with GUID fields. The unmarshaled User struct has the same ID as the original User struct.

Anyone else tired of the AI hype?

The author is tired of AI hype but thinks it's necessary to upgrade their inner filters to distinguish between noise and substance. They believe AI will disrupt jobs and work, but also worry about its potential negative impacts on productivity and the environment.

Show HN: Trying to eat better? I built a nutrional assistant

https://chat.eko-bazaar.com/baz-social-share-preview.jpg
Transform your eating habits with BAZ's AI-powered meal planning. Get personalized recipes, nutritional analysis, and smart meal prep recommendations tailored to your lifestyle and goals.

AnyBlox: A Framework for Self-Decoding Datasets [pdf]

Anyblox works on bundles of encoded data alongside webassembly bytecode defining a decoder. the decoder then processes the data according to its own logic in the any-blox operator, making it easy to auditable. our design allows for evolu- tion without breaking existing implementations and datasets, argues daniel saunders. he says the performance of any-block encoding

Show HN: OpenAPI mocks that don't suck – realistic test data, quick setup

https://cdn.beeceptor.com/assets/images/page-preview/openapi-mock-server.png
Beeceptor uses AI-powered smart-contracts to instantly turn your OpenAPI spec into a live, integration-ready mock server, complete with realistic, golden test data. It’s not just mock responses, it’s production-grade simulation, built to unblock teams and accelerate development from day one.

Systemd has been a complete, utter, unmitigated success

https://blog.tjll.net/assets/images/he-can-meme.png
The author, a former systemd critic, now defends systemd as a successful and powerful system management tool that has improved Linux system configuration and security. Despite initial criticism, systemd has proven to be a robust and secure solution that has brought many benefits, including process sandboxing, easier configuration, and improved logging.

LLM-Ready Training Dataset for Apple's Foundation Models (iOS 26)

https://public-files.gumroad.com/kqz9recq2nt68atv6vvj06tkw96n
The only comprehensive training dataset for Apple's Foundation Models Framework (iOS 26)What You GetThree technical specification files for training LLMs on Apple's Foundation Models framework:1. Core Framework GuideSystemLanguageModel availability, LanguageModelSession management, response generation, and context handling.2. Advanced Implementation Guide@Generable/@Guide macros, ...