Google Antigravity exfiltrates data via indirect prompt injection attack

https://framerusercontent.com/images/SxZFWyzsvHDN2YO7QHE3nMXzXE.png
An indirect prompt injection in Google's Antigravity code editor can steal credentials and code from a user's IDE by manipulating Gemini to exfiltrate data. The attack bypasses default protections and uses a browser subagent to send stolen data to an attacker-monitored domain.

Someone at YouTube Needs Glasses: The Prophecy Has Been Fulfilled

https://jayd.ml/assets/posts/2025-04-30-someone-at-youtube-needs-glasses/projection.png
The author analyzed YouTube's home page and projected zero videos by May 2026, citing a leaked recording of YouTube's PM org handling criticism. The author now projects zero videos by September 2026 after seeing the current state of YouTube's home screen.

Human brains are preconfigured with instructions for understanding the world

https://news.ucsc.edu/wp-content/uploads/2025/11/9-23-25-Tal-Sharf-Lab-CL-009-scaled.jpg
Researchers at UC Santa Cruz used brain organoids to study the brain's earliest electrical activity, finding that it occurs in structured patterns without external experiences. This suggests the human brain is preconfigured with instructions about how to navigate and interact with the world.

Orion 1.0

https://kagifeedback.org/assets/files/2025-11-25/1764079669-552357-1.png
Orion is a new browser that prioritizes user privacy and customization, built on WebKit and available on Mac, iPhone, and iPad. It offers features like Focus Mode, Link Preview, and Profiles as Apps, with a focus on security and user control.

Trillions spent and big software projects are still failing

https://spectrum.ieee.org/media-library/race-car-crashes-into-wall-digital-binary-code-exploding-dramatic-sky-in-background.png?id=62206976&width=1200&height=1623
The IT community has failed to learn from decades of software development and operational failures, resulting in a trillion-dollar cost to society. To reduce IT blunders, senior management must prioritize honesty, skepticism, and ethics, and treat software development with the respect it deserves.

Jakarta is now the biggest city in the world

https://images.axios.com/p1nh8EY20qEp8s6TEBwy35Hpr2I=/0x371:6960x4286/1920x1080/2025/11/24/1764011113784.jpeg?w=3840
The world's population is increasingly urbanized with 45% living in cities, and Jakarta is home to nearly 42 million people. Megacities are expanding with 33 in 2025, and Dhaka is expected to become the world's largest city by the middle of the century.

Brain has five 'eras' with adult mode not starting until early 30s

https://i.guim.co.uk/img/media/b21bc395d1d1a33453224e260a111e4f83c32047/0_0_5156_4125/master/5156.jpg?width=465&dpr=1&s=none&crop=none
Scientists identified five major brain development epochs from infancy to old age with four pivotal turning points at ages 9, 32, 66, and 83. The epochs include network consolidation, adolescence, adult mode, early ageing, and late ageing phases with distinct brain organisation and connectivity patterns.

Most Stable Raspberry Pi? Better NTP with Thermal Management

https://austinsnerdythings.com/wp-content/uploads/2025/11/ntp_rms_offset_comparison-1200x531.png
The user improved their Raspberry Pi NTP server's frequency stability by 81% and reduced frequency standard deviation by 77% through CPU core pinning and thermal stabilization using a PID-controlled thermal load. This "time burner" system maintains a stable thermal environment for the crystal oscillator, keeping its frequency consistent and achieving an RMS offset of 35 nanoseconds.

FLUX.2: Frontier Visual Intelligence

https://bfl.ai/_next/image?url=https%3A%2F%2Fcdn.sanity.io%2Fimages%2F2gpum2i6%2Fproduction%2F8d5160b8e2cdce322ca57cb4df833e654967d3be-5555x3164.png&w=3840&q=75
FLUX.2 is a powerful image generation model that offers high-quality images, consistency, and control. It's designed for real-world creative workflows and is available in various models for different needs and budgets.

Show HN: We built an open source, zero webhooks payment processor

https://raw.githubusercontent.com/flowglad/flowglad/main/public/github-image-banner-light-mode.jpg
Flowglad simplifies internet money making by integrating billing logic into apps with a single line of code. It uses internal user IDs for billing and provides real-time billing status.

Ilya Sutskever: We're moving from the age of scaling to the age of research

https://substackcdn.com/image/fetch/$s_!_M88!,w_150,h_150,c_fill,f_auto,q_auto:good,fl_progressive:steep,g_center/https%3A%2F%2Fsubstack-video.s3.amazonaws.com%2Fvideo_upload%2Fpost%2F178688356%2F452351ae-929d-43d0-bfb6-4539ee76b798%2Ftranscoded-1762964918.png
The conversation discusses the limitations of current AI models, specifically their poor generalization and tendency to overfit to specific tasks, and the need to rethink the approach to training models. The speakers also touch on the idea of value functions, emotions, and the importance of understanding human learning and generalization in order to improve AI models.

APT Rust requirement raises questions

Debian's APT tool will require Rust in May 2026, affecting unofficial ports without a working Rust toolchain, and some developers have expressed concerns about the impact and communication style of the change. The discussion highlights the challenges of supporting modern software on retro computing devices and the need for a consistent Debian policy for declaring statically linked libraries.

Roblox is a problem but it's a symptom of something worse

https://www.platformer.news/content/images/size/w1200/2025/11/oberon-copeland-veryinformed-com-TWcT7gG59js-unsplash.jpg
Roblox CEO David Baszucki expressed frustration over child safety concerns in an interview, echoing a familiar dismissive attitude from tech CEOs. The incident highlights a broader issue of platforms prioritizing growth over user safety, with leaders choosing to ignore or downplay concerns.

Unison 1.0

https://www.unison-lang.org/assets/ucm-desktop.png
Unison 1.0 stabilizes language, runtime, and workflow with a database-backed codebase and native version control. It offers a deployment platform, collaborative tooling, and a streamlined development experience with a simple API.

Making Crash Bandicoot (2011)

https://all-things-andy-gavin.com/wp-content/uploads/2011/02/crash_bandicoot_crash_bandicoot-s250x304-24499-580-250x150.jpg
As one of the co-creators of Crash Bandicoot, I have been (slowly) writing a long series of posts on the making of everyone’s favorite orange marsupial. You can find them all below, so enjoy.…

Launch HN: Onyx (YC W24) – Open-source chat UI

Chris and Yuhong from Onyx are building an open-source chat that works with any LLM, providing tools like RAG and web search. They aim to offer a secure, customizable, and user-friendly experience for teams to use LLMs.

Python is not a great language for data science

https://substackcdn.com/image/fetch/$s_!BCXZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa23c3227-419b-47cf-8da1-670edef49477_6000x3376.jpeg
The author argues that Python is not the best language for data science due to its cumbersome tools and limitations, despite being widely used. They prefer R for data wrangling, exploratory data analysis, and visualization, citing its ease of use and powerful data analysis capabilities.
https://www.quantamagazine.org/wp-content/uploads/2025/11/Set-Theory-Algorythms-cr-Valentin-Tkach-Lede.jpg
Mathematician Anton Bernshteyn discovered a connection between descriptive set theory and computer science, showing that problems about infinite sets can be rewritten as problems about network communication. This bridge between disciplines has opened new collaborations and insights into the nature of infinity.

Show HN: KiDoom – Running DOOM on PCB Traces

ICE Offers Up to $280M to Immigrant-Tracking 'Bounty Hunter' Firms

https://media.wired.com/photos/6925cc9ed9fb5a78e4faab65/3:2/w_2560%2Cc_limit/GettyImages-2246547356.jpg
ICE is expanding plans to outsource immigrant tracking to private firms with no spending cap and higher guarantees. Contractors will confirm addresses and track targets with multimillion-dollar incentives for speed and accuracy.

Reinventing how .NET builds and ships (again)

https://devblogs.microsoft.com/dotnet/wp-content/uploads/sites/10/2025/11/dotnet-product-construction-complexity-scaled.webp
NET's distributed product construction methodology has drawbacks such as complexity and overhead, which slow down and make it less predictable to ship software quickly. The Unified Build project aims to resolve these issues by moving product construction into a 'virtual monolithic' repository, consolidating the build into a series of 'vertical builds', while still enabling contributors to ...

Bad UX World Cup 2025

https://badux.lol/cdn-cgi/imagedelivery/ZIty0Vhmkm0nD-fBKJrTZQ/badux:40.png/540
The winner of the Bad UX World Cup 2025 was Dalia with the Perfect Date Picker!Watch the final on youtube

Ozempic does not slow Alzheimer's, study finds

https://img.semafor.com/7e5fb7ba69f8bdb697de088a14cb438be8ff2234-1066x1020.jpg?w=800&q=75&auto=format&h=765
Novo Nordisk's Ozempic study found no significant slowing of Alzheimer's progression. The drug still shows promise in reducing obesity and other health issues, but its benefits may be due to weight loss rather than direct effects.

What you can get for the price of a Netflix subscription

The author cancelled their Netflix subscription and invested in three daily-used subscriptions for €10 each, making their coding experience more pleasant. They value paying directly for services rather than tolerating ads, allowing them to support products they enjoy.

New layouts with CSS Subgrid

https://www.joshwcomeau.com/_next/image/?url=%2Fimages%2Fsubgrid%2Fportfolio-mockup.png&w=1920&q=75
Css subgrid allows you to extend the parent grid through a <ul>. if you want to create an infinite supercomputer, you can use 'child' to add more rows and columns to the grid based on the content - and the size of the image you're displaying. you don't need to specify the exact number of rows, just the number that will fit your content. this is the most common use

What they don't tell you about maintaining an open source project

https://andrej.sh/static/og-image.png
The author built a self-hosted, open-source kanban board called Kaneo, which gained users and contributors. They learned to balance time, prioritize documentation, and be transparent about scope and limitations.

Unifying our mobile and desktop domains

https://techblog.wikimedia.org/wp-content/uploads/2025/11/WMF_Unified_mobile_routing_2025.png
Wikipedia unified its mobile and desktop domains to eliminate redirects and improve mobile response times. This change, completed in October 2024, also resolved issues with Google indexing and video recognition on Wikimedia Commons.
https://opengraph.githubassets.com/4a73149b5144913a8247300f72ede60d752b1aec491fd124dd9a3e801be292ec/clark-prog/blackout-public
Using vendors with pre-consent tracking may lead to future legal liability and lost deals. It's essential to research vendors and consider their practices to avoid potential risks.

Google steers Americans looking for health care into "junk insurance"

https://i0.wp.com/craphound.com/images/25Nov2025.jpg?w=840&ssl=1
Google is sending Americans searching for health care plans to "junk insurance" that takes their money and denies them care. This is due to Google's enshittification and illegal monopoly that allows junk insurance scams to thrive.

US banks scramble to assess data theft after hackers breach financial tech firm

https://techcrunch.com/wp-content/uploads/2019/06/GettyImages-172674485.jpeg?w=1024
SitusAMC confirmed a data breach on November 12 where hackers stole corporate data and accounting records from its banking customers. The company says the breach is contained and its systems are operational, but the extent of the impact is still under investigation.

IQ differences of identical twins reared apart are influenced by education

Please confirm you are a human by completing the captcha challenge below.

The Generative Burrito Test

https://www.generativist.com/static/imgs/burrito-test/sd15.webp
The idea of generating burrito images was inspired by the horse riding astronaut meme and Simon's Pelican benchmark. Fal defaults struggled to replicate a realistic burrito image due to its unique composition.

It is ok to say "CSS variables" instead of "custom properties"

The author discusses CSS Variables, also known as Custom Properties, which are variables that change with the cascade and can be used for animations and responsive design. They can be typed and are a key feature of CSS, a programming language.

Windows GUI – Good, Bad and Pretty Ugly (2023)

https://creolened.com/wp-content/uploads/2023/08/35afd05b00be1b2ca1af5bd597ff7dc86462e36062734eae620e07f1ebf105fd-679808056.png
The user ranks every major version of the Windows GUI from 1985 to 2023 based on how they look now, giving each a rating from 1 to 10 Clippys. The user concludes that Windows 11 is the most refined version of the OS since 2000, with a clean and cohesive look, but criticizes its lack of customization and removal of features.

Constant-time support coming to LLVM: Protecting cryptographic code

https://blog.trailofbits.com/img/tob.png
Trail of Bits developed constant-time coding support for LLVM 21 to prevent timing attacks in cryptographic implementations. The __builtin_ct_select family of intrinsics ensures constant-time properties through the entire compilation pipeline.

Ironwood, our latest TPU

https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ironwood-hero.width-200.format-webp.webp
Google unveiled Ironwood, its seventh-generation Tensor Processing Unit (TPU), for efficient AI calculations and model serving. Ironwood offers 4X better performance per chip and enables rapid communication among thousands of chips for demanding AI models.

This blog is now hosted on a GPS/LTE modem (2021)

https://blog.nns.ee/img/av.jpg
The user unlocked the PinePhone's modem, ran a Linux OS on it, and set up a web server using darkhttpd. The modem's security is a concern due to potential command injection vulnerabilities and easy root access via ADB.

Why I (Still) Love Linux ?

https://it-notes.dragas.net/featured/terminal_htop.webp
The author has a long history with Linux, starting in 1996, and appreciates its sense of freedom and flexibility. Despite some issues with systemd and modern Linux development, the author still values Linux for its reliability, consistency, and widespread adoption.

Stop Telling Us XMPP Should Use JSON

https://www.process-one.net/content/images/size/w720/2025/11/Why-XMPP-Uses-XML-2.png
XMPP uses XML for its extensibility and tree-like data structures, not just because it's older. XML parsing in XMPP is efficient and doesn't impact performance due to incremental parsing.

Notes on the Troubleshooting and Repair of Computer and Video Monitors

The text discusses the evolution of computer monitors, from early CRTs to modern LCDs and future flat panel technologies. It explains the characteristics of monitors, including resolution, refresh rate, and color, and how they have changed over time.

LLVM Adds Constant-Time Support for Protecting Cryptographic Code

https://blog.trailofbits.com/img/tob.png
Since 2012, Trail of Bits has helped secure some of the world's most targeted organizations and products. We combine high-­end security research with a real­ world attacker mentality to reduce risk and fortify code.

Stop Putting Your Passwords into Random Websites (Yes, Seriously, You Are the PR

https://labs.watchtowr.com/content/images/size/w1200/2025/11/1920--1080---3.png
WatchTowr Labs researchers found thousands of sensitive data exposed on online code formatters, including passwords, credentials, and configuration files from various organizations, including a cybersecurity company and a major international stock exchange. The researchers were able to attribute some of the exposed data to specific organizations and individuals, highlighting the risks of ...

UK intends to scrap jury trials for majority of court cases

https://www.gbnews.com/media-library/patrick-christys-rips-into-david-lammy-in-his-evening-monologue-gb-news.jpg?id=62236597&width=1245&height=700&quality=85&coordinates=0%2C0%2C1%2C0
Justice Secretary David Lammy plans to eliminate jury trials for most cases, reserving them for murder, rape, and serious crimes. The reforms aim to address the 77,000-case backlog in Crown Courts by introducing judge-only proceedings and expanding magistrates' jurisdiction.

The Bughouse Effect

https://i.imgur.com/E4BoiWn.png
The user discusses two Chess variants, Crazyhouse and Bughouse, and how they can evoke strong emotions, particularly frustration and anger, when teammates fail to work together effectively. The user compares this phenomenon, known as the Bughouse Effect, to real-life situations where people work together on difficult projects and experience similar feelings of betrayal and anger when their ...

Choosing a hash function for 2030 and beyond: SHA-2 vs. SHA-3 vs. BLAKE3

https://kerkour.com/icon-256.png
As everyone knows, "temporary fixes" are nothing but temporary. Unfortunately, the same is true for cryptography: unless security is your core value-proposition, crypto algorithms are almost never updated, and that's how we end up with SHA1-hashed password in 2024 🤦‍♂️ You can be sure that most projects you started in

Cryptology firm cancels elections after losing encryption key

https://ichef.bbci.co.uk/news/480/cpsprodpb/7476/live/72c3b5f0-c9f3-11f0-bd31-8fd3ec515046.jpg.webp
A leading encryption firm cancelled its leadership election results due to a trustee losing their encrypted key. The International Association for Cryptologic Research will rerun the election with new safeguards to prevent similar mistakes.

Show HN: Secure private diffchecker with merge support

diffchecker.dev is a fast, secure online diff checker for text, code, JSON, and XML comparisons. It runs locally in the browser, ensuring complete privacy and unlimited comparisons for free.

Show HN: I built the literal Duolingo Killer

https://kanjieight.vercel.app/image.png
Turn binge watching into fluent Japanese with short, addictive anime clips designed to keep you hooked, but smarter.