Shai-Hulud Returns: Over 300 NPM Packages Infected

https://helixguard.ai/blog/actionSecrets.png
HelixGuard detected over 300 NPM registry components poisoned with malware that steals sensitive information and exfiltrates it via GitHub Actions. The malware, similar to the 'Shai-Hulud' attack, uses TruffleHog for secret scanning and achieves worm-like propagation by modifying package.json and using stolen tokens.

Claude Opus 4.5

https://www.anthropic.com/_next/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F7022a87aeb6eab1458d68412bc927306224ea9eb-3840x2160.png&w=3840&q=75
Claude Opus 4.5 is a new AI model available today, offering improved efficiency and capabilities in coding, agents, and computer use. It's now more accessible with a lower price point of $5/$25 per million tokens.

Pebble Watch software is now 100% open source

https://ericmigi.com/assets/pebble-watch-software-is-now-100percent-open-source-0-pxl_20251122_174353894.raw-01.cover.jpg
Pebble watch software is now 100% open source, ensuring long-term reliability through decentralization. Core Devices, the company behind the relaunch, is self-funded and aims to continue manufacturing Pebble watches as long as it stays profitable.

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

https://static.mamot.fr/media_attachments/files/115/581/775/877/215/045/small/378107f93bdc9156.png
Le gouvernement français attaque GrapheneOS, un système d'exploitation sécurisé, en le décrivant comme une "solution de téléphonie du crime" pour justifier la surveillance.

Claude Advanced Tool Use

https://www.anthropic.com/_next/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2Ff359296f770706608901eadaffbff4ca0b67874c-1999x1125.png&w=3840&q=75
Anthropic's Claude AI agent uses three features to improve tool use workflows: Tool Search Tool, Programmatic Tool Calling, and Tool Use Examples. These features reduce token consumption, latency, and improve accuracy by enabling dynamic discovery, efficient execution, and reliable invocation of tools.

Ask HN: Hearing aid wearers, what's hot?

You're looking for a new hearing aid to replace your Phonak Audeo 90's. I'm a summarizer, not a personal user, but I can suggest popular options like Phonak Marvel or Oticon Opn, which offer good sound quality and noise reduction features.

Shai Hulud launches second supply-chain attack

https://cdn.prod.website-files.com/642adcaf364024654c71df23/69244323f1c8b48f69d4eccf_2025-11-24_12-35-41.png
A malware attack, named Shai-Hulud, has hit hundreds of npm packages, compromising 492 packages with 132 million monthly downloads. The attack spreads through compromised developer environments, stealing sensitive information and uploading it to a public GitHub repository.

RuBee

https://computer.rip/static/cubes.svg
RuBee is a unique wireless protocol used for asset tracking, particularly in secure facilities, due to its robustness and short range. It was developed by Visible Assets Inc. for applications like tracking firearms and has been used by the US military and Department of Energy.

PS5 now costs less than 64GB of DDR5 memory. RAM jumps to $600 due to shortage

https://cdn.mos.cms.futurecdn.net/9FDNMo8RQMZVeCFzURP926.jpg
DDR5 RAM prices have surged due to AI demand, with a 64 GB kit costing $599, a 190% increase in just 2 months. Experts predict DRAM and NAND constraints will continue through 2026 as Big Tech pursues AGI, affecting consumer prices.

Unpowered SSDs slowly lose data

https://static0.xdaimages.com/wordpress/wp-content/uploads/wm/2025/01/crucial-and-samsung-ssd.jpg?&fit=crop&w=1600&h=900
SSDs can lose data if left unpowered for years, especially those with TLC or QLC NAND, which can retain data for up to 3 years and 1 year respectively. To prevent data loss, use alternate storage media and invest in a backup system.

NSA and IETF, part 3: Dodging the issues at hand

The IETF's TLS working group is standardizing a non-hybrid post-quantum cryptography document that adds just PQ as another TLS option, despite concerns about its security and lack of consensus. An IETF area director dodged procedural objections and made false claims about the adoption call results, failing to address the central security argument for ECC+PQ.

Japan's gamble to turn island of Hokkaido into global chip hub

https://ichef.bbci.co.uk/news/480/cpsprodpb/83c4/live/46b3b420-c5b5-11f0-b602-51c15dd35a8c.jpg.webp
Japan is investing billions to turn Hokkaido into a global hub for advanced semiconductors, aiming to reboot the country's chip-making capabilities. Rapidus, a government-backed company, is building Japan's first cutting-edge chip foundry in Hokkaido, with a goal to mass produce 2nm chips by 2027.

X Just Accidentally Exposed a Covert Influence Network Targeting Americans

https://substackcdn.com/image/fetch/$s_!aE8B!,w_474,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5d8e116-0ae0-4296-bc3d-76af8c73e15f_1320x1030.jpeg
A new feature on X exposed a large number of pro-Trump accounts operating from foreign countries, raising concerns about covert foreign influence in US politics. The discovery mirrors Russia's 2016 disinformation campaign and suggests history may be repeating itself.

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

https://static.mamot.fr/media_attachments/files/115/581/775/877/215/045/small/378107f93bdc9156.png
Le gouvernement français attaque GrapheneOS, un système d'exploitation sécurisé, en le décrivant comme une "solution de téléphonie du crime" pour justifier la surveillance.

The Cloudflare outage might be a good thing

GrapheneOS migrates server infrastructure from France

https://images.unsplash.com/photo-1627116400300-da4a897383f7?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDd8fGZyYW5jZSUyMHNlcnZlcnN8ZW58MHx8fHwxNzYzNzYyMTA4fDA&ixlib=rb-4.1.0&q=80&w=720
GrapheneOS is relocating its servers from France due to safety concerns and negative press coverage. The project will continue to be available to French users but its website and discussion servers will be hosted abroad.

Show HN: I built an interactive HN Simulator

More

Chrome Jpegxl Issue Reopened

Sign in

Cool-retro-term: terminal emulator which mimics look and feel of CRTs

https://user-images.githubusercontent.com/121322/32070717-16708784-ba42-11e7-8572-a8fcc10d7f7d.gif
cool-retro-term is a customizable terminal emulator mimicking old cathode tube screens. It's available for Linux and macOS, with packages in most distributions or downloadable from the Releases page.

TSMC Arizona outage saw fab halt, Apple wafers scrapped

https://substackcdn.com/image/fetch/$s_!pERh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ede788-1c1b-4330-991a-a5542b588f13_5464x3640.jpeg
A power outage at TSMC's Arizona facility caused by a Linde power fault in mid-September forced a shutdown and scrapped thousands of wafers. The incident may have contributed to TSMC's 99% drop in net income in the third quarter.

Show HN: Stun LLMs with thousands of invisible Unicode characters

Result: Doesn't understand gibberified text - responds with confusion or completely ignores the invisible characters. See ChatGPT β†’ Result: Completely bewildered by gibberified text - has no idea what's happening with the invisible characters. See Grok β†’

We stopped roadmap work for a week and fixed bugs

https://lalitm.com/img/5g47sxjucyfgvvp.png
The author's company has a quarterly "fixit" week where 40 software engineers stop regular work to fix small bugs and improve developer productivity. This week-long event boosts team spirit and product quality.

Ego, empathy, and humility at work

https://matthogg.fyi/apple-touch-icon.png
The article discusses how ego can hinder developers and technical leaders, and how empathy and humility can help counteract it. Practicing empathy and humility can lead to better collaboration and problem-solving.

Implications of AI to schools

Something went wrong, but don’t fret β€” let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

What OpenAI did when ChatGPT users lost touch with reality

Please enable JS and disable any ad blocker

DoGE "cut muscle, not fat"; 26K experts rehired after brutal cuts

https://cdn.arstechnica.net/wp-content/uploads/2025/11/GettyImages-2200059564-640x427.jpg
DOGE, a government agency created by Elon Musk to cut government agencies, was terminated more than eight months early due to lack of necessity. Its abrupt ending has left the government struggling to replace lost talent and provide key services.

Mind-reading devices can now predict preconscious thoughts

https://media.nature.com/w767/magazine-assets/d41586-025-03714-0/d41586-025-03714-0_51720238.jpg
Researchers have made significant progress in brain-computer interfaces (BCIs) that can decode brain signals and enable people with paralysis to control devices. However, concerns about data privacy and the potential for manipulation or discrimination have led to calls for regulation and guidelines on the use of BCIs and neural data.

Doge 'doesn't exist' with eight months left on its charter

Please enable JS and disable any ad blocker

Lambda Calculus – Animated Beta Reduction of Lambda Diagrams

https://cruzgodar.com/graphics/general-icons/logo.webp
Lambda calculus is a minimal Turing-complete language with functions as its only objects, allowing for beta reduction and expression evaluation. It can represent true and false, natural numbers, and arithmetic operations using selector functions and combinators.

Booking.com cancels $4K hotel reservation, offers same rooms again for $17K

https://i.cbc.ca/ais/e81b4c08-0681-440d-8a34-cfea898e9482,1763595767778/full/max/0/default.jpg?im=Crop%2Crect%3D%280%2C49%2C4032%2C2268%29%3B
A woman booked a hotel room on Booking.com for the 2026 Formula One Grand Prix in Montreal, but was told the price was a mistake and needed to pay four times the amount. Digital rights expert David Fewer says this is a common issue with online travel sites and hotels relying on automated booking and pricing systems.

Bureau of Meteorology's new boss asked to examine $96M bill for website redesign

https://live-production.wcms.abc-cdn.net.au/5ae88c89fc883b39342b53597c98dea2?impolicy=wcms_crop_resize&cropH=2813&cropW=5000&xPos=0&yPos=337&width=862&height=485
The Bureau of Meteorology's new website cost $96.5 million to design and launch, exceeding its original $4 million estimate. Environment Minister Murray Watt has asked the agency's new boss to investigate the cost blowout and website issues.

The Bitter Lesson of LLM Extensions

The history of LLM extension over the last three years has seen various mechanisms emerge, from simple system prompts to complex client-server protocols, with the goal of allowing end users to customize these systems. The latest development, Agent Skills, represents a significant step towards this goal, allowing users to give agents instructions and generic tools, and trusting them to do the ...

Git 3.0 will use main as the default branch

https://images.prismic.io/thoughtbot-website/Zn26ER5LeNNTwm-K_team_augmentation.jpg?auto=format,compress
Git 3.0 will default to 'main' branch for new repositories, replacing 'master'. This change is expected near the end of 2026.

General principles for the use of AI at CERN

https://home.web.cern.ch/sites/default/files/inline-images/%5Bcurrent-user%3Aname%5D/strategy-one-page-v2.png
CERN has approved a strategy for responsible AI use, covering transparency, accountability, lawfulness, fairness, security, sustainability, human oversight, data privacy, and non-military purposes. The strategy applies to all AI technologies used in CERN's scientific research, productivity, and administrative activities.

Google's new 'Aluminium OS' project brings Android to PC

https://www.androidauthority.com/wp-content/uploads/2025/11/Android-Bot-on-laptop-screen-scaled.jpeg
Google is developing Aluminium OS, a unified Android-based operating system for PCs, to compete with Windows and macOS. Aluminium OS will replace ChromeOS, with a transition strategy including legacy support and optional migration for existing Chromebooks.

Build desktop applications using Go and Web Technologies

https://raw.githubusercontent.com/wailsapp/wails/master/assets/images/logo-universal.png
Wails is a tool that bundles Go code and a web frontend into a single binary, making it easy to create lightweight desktop applications. It offers native elements and is a lightweight alternative to Electron.

Is your Android TV streaming box part of a botnet?

https://krebsonsecurity.com/wp-content/uploads/2025/11/superbox-walmart.png
Superbox media streaming devices may seem like a steal but security experts warn they require intrusive software that forces users' networks to relay Internet traffic for cybercrime activity. These devices can also compromise users' Internet connections and engage in advertising fraud and account takeovers.

Fast Lua runtime written in Rust

https://astra.arkforge.net/banner.png
A local server is created using the http module and a route is registered to return "hello from default Astra instance!" at the root URL. A counter is incremented and returned as JSON at the "/count" URL.

Show HN: Cynthia – Reliably play MIDI music files – MIT / Portable / Windows

https://www.blaizenterprises.com/cynthia-screenshot.jpg
Cynthia is a music player that can play midi files from a folder or playlist, adjust playback speed, volume, and output device on-the-fly, and supports various midi formats. It also features a user-friendly interface with customizable colors and background schemes, and can be controlled using an Xbox controller.

McMaster Carr – The Smartest Website You Haven't Heard Of (2022)

https://static.wixstatic.com/media/04d5b7_06e8b2871f7d483ea7b0bf9db1f653db~mv2.jpg/v1/fill/w_190,h_274,al_c,q_90/04d5b7_06e8b2871f7d483ea7b0bf9db1f653db~mv2.jpg
McMaster-Carr's website is the best e-commerce site due to its minimal, functional design that allows users to quickly find specific parts. The site's intuitive search interface, filters, and CAD file downloads make it a valuable tool for engineers and users alike.

Fifty Shades of OOP

The author presents a nuanced view of Object-Oriented Programming (OOP) by examining its various features, including encapsulation, inheritance, and message passing, and discusses their pros and cons. The article argues that OOP encourages certain programming styles that can lead to performance issues, scattered code, and unnecessary complexity, but also provides benefits such as open ...

Build a Compiler in Five Projects

You're interested in building a compiler for a masters-level class CIS531, which involves implementing a compiler in Racket programming language.

Insurers retreat from AI cover as risk of multibillion-dollar claims mounts

https://images.ft.com/v3/image/raw/https%3A%2F%2Fd1e00ek4ebabms.cloudfront.net%2Fproduction%2F9bc84743-630a-483b-ac2f-1c210c3e7c1d.jpg?source=next-barrier-page
Annual FT subscription is now $49, down from $59.88, with 2 months free and 20% savings for paying upfront. Access quality FT journalism on any device for $75/month after trial or pay $49 upfront for a year.

Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4

The user was a Crypto Officer for ICANN's DNSSEC Root signing ceremonies for 15 years, participating in the development of trust and transparency in the system. They passed the torch to Lodrina Cherne, a security researcher and educator, after a 5-year commitment turned into a 15-year tenure.

The feds want to make it illegal to even possess an anarchist zine

https://theintercept.com/wp-content/uploads/2025/11/GettyImages-2231531269-full.jpg?fit=7122%2C4640
Federal prosecutors have filed a new indictment against Dallas artist Daniel Sanchez for transporting anarchist zines, which are constitutionally protected free speech. The case is part of the administration's efforts to criminalize left-wing activists and silence dissenting voices.

A New Raspberry Pi Imager

https://www.raspberrypi.com/app/uploads/2025/11/screen_6.png
Raspberry Pi Imager 2.0 has a new wizard interface and improved accessibility for screen readers and assistive technologies. It offers pre-configured Raspberry Pi Connect and simplified OS customisation for a better user experience.

A fast EDN (Extensible Data Notation) reader written in C11 with SIMD boost

https://opengraph.githubassets.com/57054c08415b018a870d21fc9910c825cc77a7d3983fa4b7a88868affd79f819/DotFox/edn.c
Edn (extensible data notation) is a data format similar to json, but richer and more extensible. it supports underscores as visual separators in numeric literals for improved readability - and it's compatible with clojure'reader' edn.c supports newline, "newlines and %new as whitespace characters in strings. the software

My Life Is a Lie: How a Broken Benchmark Broke America

https://substackcdn.com/image/fetch/$s_!CzZ4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2f0ec76-7cae-42ae-88ad-4f35333b4c10_1917x884.png
The author argues that the official poverty line of $31,200 is misleading and that the real poverty line is $140,000, which is the amount needed for a family of four to afford basic necessities like housing, healthcare, and childcare without relying on means-tested benefits. The author claims that the current economic system is designed to trap families in poverty, making it impossible for ...

Trade Chaos Causes Businesses to Rethink Their Relationship with the U.S.

Please enable JS and disable any ad blocker

'Invisible' microplastics spread in skies as global pollutant

https://p.potaufeu.asahi.com/bc66-p/picture/30225833/be01987aea2206480ab61a72c755b79c.jpg
Airborne microplastics are spreading globally, penetrating human bodies and sparking alarm among researchers. These tiny pollutants, often invisible, could be fueling extreme weather conditions and pose unknown health risks.

Britain is one of the richest countries. So why do children live in poverty?

https://media.cnn.com/api/v1/images/stellar/prod/shutterstock-editorial-15237702b.jpg?c=original&q=w_1041,c_fill
Child poverty in the UK has reached a record high with around 4.5 million children living in relative poverty. Charities like Little Village are stepping in to provide essential supplies for new parents struggling financially.

A One-Minute ADHD Test

https://substackcdn.com/image/fetch/$s_!bsPw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65ed0d5a-8e45-4da7-9cfb-b33b9be2e013_800x600.png
The author took a six-question ADHD test and scored highly, leading them to suspect ADHD and get a proper assessment. The test has a 69% sensitivity and 99.5% specificity, making it a useful low-effort screening tool for ADHD.

US 'Homeland Security' Twitter account seemingly run from Israel

https://www.thecanary.co/wp-content/uploads/2025/11/Screenshot-2025-11-23-at-11.11.41-e1763896837995.png
Elon Musk's Twitter location data update exposed many far-right nationalist accounts as international grifters. The feature also revealed the US Department of Homeland Security account was operated from Israel, sparking controversy.
The author attempts to run a search engine, Nixiesearch, in a serverless mode on AWS Lambda, overcoming container size and startup time issues using GraalVM native-image. The author explores various storage options, including S3, EFS, and NFS, to achieve low latency and cost-effective search.

Launch HN: Karumi (YC F25) – Personalized, agentic product demos

https://framerusercontent.com/images/wXqx9tc7CoTpZ8eh77GT5ulmkE.png?width=304&height=175
Product demos adapt to customer needs and are always up to date. Transcripts and next steps are logged into CRM for follow up.

New report calls for end to child marriage in the US

https://womensmediacenter.com/assets/site/main/wmc_features_Fraidy-Reiss-headshot_111425.jpg
Two human rights groups, Unchained At Last and Equality Now, call for action to end child marriage in the US, citing over 314,000 child marriages between 2000 and 2021. The groups urge policymakers to introduce legislative reform and raise awareness to prohibit child marriage nationwide by 2030.

The Arithmetic of Braids (2022)

https://mathcenter.oxford.emory.edu/site/frameResources/oxford_logo.png
If we have names for these possibilities, we can describe braid in question with a sequence of letters. adjacent elementary braids $x_i$ and $xx_j$ will commute unless they are far enough apart... et al. samuel taylor: 'we can show two braid words represent the same braid by drawing pictures of each and "tugging' the strands until they

'Nobody wants to come': What if the U.S. can no longer attract immigrant doctors

https://media.npr.org/assets/img/2014/03/18/noguchi_4_sq-0023679553f6aee3815b5b2a638a7b33bf8cd859.jpg?s=100&c=85&f=jpeg
Michael Liu, a 28-year-old internal medicine resident, is considering returning to his hometown of Toronto due to the Trump administration's cuts to scientific research and increased H1B visa fees. The US healthcare system relies heavily on immigrant physicians, but recent policies are making it harder for foreign-born talent to augment the short-staffed system.

A ncurses-based command line torrent client for high performance

https://opengraph.githubassets.com/1dd8c754511f6759c9aceeb48f20f3156d525f907eea4c3ccd51e7eedad70836/rakshasa/rtorrent
RTorrent closely follows libtorrent versions and is under GNU GPL. It uses Mozilla's NSS SHA1 implementation or OpenSSL, depending on user preference.

Shopping research in ChatGPT

https://images.ctfassets.net/kftzwdyauwt9/34BUHjf23bcpf4xLuXAluG/4454e7271d39c35fc0007c40b910dd3d/Shopping_Research-Blog-16x9.png?w=3840&q=90&fm=webp
User wants shopping research to find products such as a gaming laptop, dress, stroller, and gift for dad. User also wants to know about Black Friday deals and if they qualify for discount codes.

Syd – An offline-first, AI-augmented workstation for blue teams

Syd is a secure, offline AI-powered tool for cybersecurity operations, integrating with various tools for offensive and defensive capabilities. It provides instant access to exploit intelligence and actionable insights from raw tool output.

Ask HN: Scheduling stateful nodes when MMAP makes memory accounting a lie

A distributed stateful engine's Coordinator got stuck in a loop, DDOS-ing a node due to incorrect load balancing based on logical row count. The team seeks a "God Equation" to balance resources, considering variables like CPU, IOPS, RSS, and disk usage, but faces an NP-hard problem.

New magnetic component discovered in the Faraday effect

This page will redirect in a moment...