Someone bought 30 WordPress plugins and planted a backdoor in all of them

https://anchor.host/wp-content/uploads/2026/04/wordpress-plugin-supply-chain-attack-1-1024x572.webp
A trusted WordPress plugin, Countdown Timer Ultimate, was compromised through a supply chain attack. The plugin's wpos-analytics module injected malicious code into wp-config.php, serving SEO spam to Googlebot.

All elementary functions from a single binary operator

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
A single binary operator eml(x,y) can generate all standard functions of a scientific calculator using the constant 1. This operator enables exact recovery of closed-form functions from data at shallow tree depths.

GitHub Stacked PRs

https://github.github.com/gh-stack/_astro/stack-navigator.DbHWHwGH_Z14GiHR.webp
The gh stack CLI and GitHub UI allow for organized pull requests in an ordered stack, making it easier to review and merge large changes. This approach breaks down big changes into small, focused pull requests that build on each other, improving review quality and team efficiency.

Servo is now available on crates.io

https://servo.org/svg/servo-color-positive.svg
Servo team released v0.1.0, allowing Servo to be used as a library, with a growing confidence in its embedding API. A long-term support (LTS) version is also offered for embedders who prefer scheduled upgrades.

Apple's accidental moat: How the "AI Loser" may end up winning

https://substackcdn.com/image/fetch/$s_!NqyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F669a66b1-85e1-47cd-93c9-7a7c6f58c248_1600x873.png
The author believes Apple's strategy of focusing on on-device AI and unified memory architecture may give them a competitive advantage in the AI market. Apple's approach allows for local inference, reducing the need for expensive infrastructure investments.

Nothing Ever Happens: Polymarket bot that always buys No on non-sports markets

The bot scans markets, tracks positions, and exposes a dashboard with live recovery state. It can be deployed on Heroku with config settings and scaled to run only the web dyno.

The economics of software teams: Why most engineering orgs are flying blind

https://www.viktorcessan.com/the-economics-of-software-teams/investment%20thesis.png
Software teams are expensive and their value is calculable, but most teams do not measure financial outcomes, instead tracking activity and sentiment metrics that can trend upward while financial performance deteriorates. To be financially viable, teams need to generate at least three to five times their annual cost in value, which requires a clear understanding of their costs, value ...

US appeals court declares 158-year-old home distilling ban unconstitutional

https://nypost.com/wp-content/uploads/sites/2/2026/04/125457358.jpg?w=1024
A US appeals court ruled a 158-year-old ban on home distilling unconstitutional, citing it as an improper tax measure. The court's decision allows individuals to distill spirits at home for personal use or as a hobby.

Make tmux pretty and usable (2024)

https://hamvocke.com/_astro/tmux-custom.JReQpud4_1TUvCB.webp
The user is customizing their tmux configuration to make it more comfortable to use. They are changing the prefix key from C-b to C-a and remapping the Caps Lock key to Ctrl.

Android now stops you sharing your location in photos

Google broke geolocation access in Android web browsers, forcing users to upload photos via desktop browsers or native apps. The user is seeking a solution to allow Android web browsers to access geolocation EXIF metadata in photos.

Microsoft isn't removing Copilot from Windows 11, it's just renaming it

Microsoft announced plans to fix Windows 11 in 2026 by giving users more control and removing unnecessary AI features. However, recent changes have been met with disappointment as Microsoft rebranded Copilot instead of removing AI capabilities.

This year’s insane timeline of hacks

https://substackcdn.com/image/fetch/$s_!RcBr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb09ed54b-8599-421a-919a-7fcb5b93d65a_5760x3840.jpeg
A series of high-profile cyber incidents in 2026, including breaches of Stryker, Lockheed Martin, and Rockstar Games, have been attributed to four separate campaigns targeting U.S. and Western targets. The incidents, which include the exfiltration of 1.5 billion Salesforce records and the wiping of 200,000 devices, have been linked to Iran, North Korea, Russia, and a financially-motivated ...

The Future of Everything Is Lies, I Guess: Safety

Large Language Models (LLMs) pose significant risks to psychological and physical safety, including enabling malicious attacks, harassment, and fraud, and their alignment efforts are not working well. The industry is creating conditions for anyone with sufficient funds to train unaligned models, and the consequences of LLMs could be severe, including destabilizing economies, public safety, ...

Building a CLI for all of Cloudflare

https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6TTRJoUvbs5eWPtnu6NuL6/d31b8479cfca7f4a77517f875f0049eb/BLOG-3224_1.png
Cloudflare is rebuilding its CLI, Wrangler, to provide commands for all products and let agents configure them together using infrastructure-as-code. The new CLI, available in technical preview, will be generated using a new TypeScript schema that defines APIs, CLI commands, and context.

Stanford report highlights growing disconnect between AI insiders and everyone

https://techcrunch.com/wp-content/uploads/2026/04/Screenshot-2026-04-13-at-1.52.10-PM.jpg?w=680
Public sentiment towards AI is increasingly negative, with concerns over job loss, rising utility costs, and AI's impact on paychecks. AI leaders are out of touch with these concerns, focusing on theoretical risks like Artificial General Intelligence.

Michigan 'digital age' bills pulled after privacy concerns raised

https://bloximages.newyork1.vip.townnews.com/thecentersquare.com/content/tncms/assets/v3/editorial/2/ad/2ad18d8a-a751-4e8b-967c-6f2ca488160c/68d591de695d2.image.jpg?resize=400%2C225
Michigan lawmakers withdrew two bills requiring device age estimation due to privacy concerns. Advocacy groups are working with sponsors to create a comprehensive consumer data privacy framework instead.

I went to America's worst national parks so you don't have to

https://substackcdn.com/image/fetch/$s_!mTfT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cdba80-4ac2-40ca-bd15-c527dd9ab25e_800x526.png
The writer has visited many US national parks and found some to be overhyped, such as the Grand Canyon and Zion Canyon, while others are worth visiting but not as impressive as expected, like Yosemite and Yellowstone.

AI could be the end of the digital wave, not the next big thing

https://substackcdn.com/image/fetch/$s_!s61y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5055cb67-43b0-42ea-b03b-d73f6b955fd1_1475x820.jpeg
The author suggests that AI may be the final stage of the digital surge that started in the 1970s, not a new technology surge. This is based on the "late cycle investment theory" developed by Carlota Perez.

Show HN: I built a social media management tool in 3 weeks with Claude and Codex

https://raw.githubusercontent.com/brightbeanxyz/brightbean-studio/main/.github/assets/brightbean-studio-logo.webp
BrightBean Studio is a free, open-source social media management platform for creators, agencies, and SMBs with no limits or paid tiers. It supports multiple platforms and features granular RBAC, rich editor, and direct API integrations.

How to make Firefox builds 17% faster

Buildcache's Lua plugin system allows caching of deterministic build steps like Firefox's WebIDL binding code generation. A new wrapper, webidl.lua, was created to cache this step, reducing build times from 5m35s to 1m12s on warm builds.

Show HN: Ithihāsas – a character explorer for Hindu epics, built in a few hours

https://www.ithihasas.in/opengraph-image?f20489d4ac7527e4
Explore the characters, dynasties and relationships of the Rāmāyaṇa and Mahābhārata through interactive force graphs, dynasty trees and chord diagrams.

WiiFin – Jellyfin Client for Nintendo Wii

https://raw.githubusercontent.com/fabienmillet/WiiFin/main/assets/preview.png
WiiFin is a homebrew client for Jellyfin on the Nintendo Wii, providing a console-friendly media experience. It's experimental and still under development, with optional video playback using MPlayer CE.

Claude.ai down

Claude's Status Page - Claude.ai down.

GAIA – Open-source framework for building AI agents that run on local hardware

https://mintcdn.com/amd-fe836e11/PgPhi3UrqFX2lV53/assets/favicon.ico?fit=max&auto=format&n=PgPhi3UrqFX2lV53&q=85&s=77bcf8b2d70613766cc02f16b0e208a0
GAIA is an open-source framework for building AI agents in Python and C++ that run entirely on local hardware. Agents reason, call tools, search documents, and take action — with no cloud dependency and no data leaving the device.

They See Your Photos

https://imagedelivery.net/gwqtS4kafZruByi--g_VMg/5198c5e1-7a00-4fd1-884d-a24b2bb22000/w=384
Upload a photo to find out how much an AI sees.

Missouri town fires half its city council over data center deal

Residents in Festus, Missouri, ousted four city council members who approved a $6 billion data center. The move was fueled by voter frustration over the city's handling of the project and lack of transparency.

Who's Been Impersonating This ProPublica Reporter?

https://www.propublica.org/wp-content/uploads/2026/04/Impostor-Account-Lead-3.jpg?w=1149
A ProPublica reporter was impersonated by scammers posing as a Canadian military official and a Latvian businessman on WhatsApp and Signal. The reporter's headshot was used to trick potential sources into sharing information about foreign militaries.

Tax Wrapped 2025

https://taxwrapped.com/taxwrapped.png
See what the federal government spent with your tax dollars.

The tech jobs bust is real. Don't blame AI (yet)

https://www.economist.com/cdn-cgi/image/width=1424,quality=80,format=auto/content-assets/images/20260418_FND001.jpg
Tech giants like Oracle, Block, and Amazon are cutting thousands of jobs due to AI advancements. This is part of a generational boom in AI, making humans redundant in many tech roles.

New Orleans's Car-Crash Conspiracy

https://media.newyorker.com/photos/69d682cb091977b644c66b41/master/w_2560%2Cc_limit/r48958.jpg
Large trucks cause many accidents in the US, often due to reckless driving or fatigue, and can be deadly for occupants of smaller vehicles. In New Orleans, a network of personal-injury lawyers and "slammers" staged fake truck crashes to collect insurance payouts, with some drivers risking their lives for money.

B-trees and database indexes (2024)

https://planetscale-images.imgix.net/assets/btrees-and-database-indexes-inner-and-leaf-nodes-VP6Mw5cu.png?auto=compress%2Cformat
B-trees and B+trees are data structures used in database management systems like MySQL to perform efficient data lookups via indexes, and choosing a suitable primary key can significantly impact performance. A sequential primary key like a BIGINT UNSIGNED AUTO_INCREMENT is generally better than a random or UUID primary key for minimizing the number of nodes visited and improving query performance.

State of Homelab 2026

https://mrlokans.work/posts/state-of-homelab-2026/images/gmk5-pro_hu_6b01b24fc417b651.jpg
The user has built a homelab setup using various technologies such as Ansible, Traefik, Authentik, and Cloudflare Tunnels to automate media collection, self-hosted services, and data synchronization. The setup is designed to be easy to manage, with a focus on understanding how things work and enjoying the process of tinkering, rather than achieving perfection or off-the-grid independence.

The looming college-enrollment death spiral

https://cdn.theatlantic.com/thumbor/RjTzP7_25KyNdYUjOeCH1EnEp5w=/0x0:2000x1125/960x540/media/img/mt/2026/04/2026_04_09_uni_mpg/original.jpg
The US is facing a college enrollment crisis due to a declining number of high school graduates, with 38 states projected to see a drop in graduates by the 2040s. This will lead to campus closures, further reducing enrollment and creating a vicious cycle.

The rational conclusion of doomerism is violence

https://substackcdn.com/image/fetch/$s_!wkwm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F842debdb-100d-44ca-82c2-8caa77427ddb_1027x1385.png
A 20-year-old threw a Molotov cocktail at Sam Altman's house and threatened OpenAI headquarters, suspected of attempted murder. He was an active member of PauseAI, a community that advocates for extreme measures to prevent AI-caused extinction.

MEMS Array Chip Can Project Video the Size of a Grain of Sand

https://spectrum.ieee.org/media-library/an-array-of-tiny-metallic-cantilevers-curving-away-from-the-surface-of-a-photonic-chip.jpg?id=65493217&width=1200&height=750
Scientists at MITRE and MIT developed a photonic chip that can project 68.6 million spots of light per second, enabling control of millions of qubits in quantum computers. The chip's technology could also revolutionize imaging in augmented reality, biomedical imaging, and 3D printing.

X Randomly Banning Users for "Inauthentic Behavior"

User needs to register or sign in with developer credentials and ensure a unique User-Agent string to access the application. Alternatively, try resetting to default User-Agent or file a ticket for assistance.

Haunt, the 70s text adventure game, is now playable on a website

https://haunt.madebywindmill.com/moose.jpg
CHEZ MOOSE TERMINAL MODEL IV

The AI revolution in math has arrived

https://www.quantamagazine.org/wp-content/uploads/2026/04/Math-AI-Update-cr-Nash-Weerasekera-Lede.webp
Artificial intelligence models made significant strides in mathematics in 2025, solving complex problems and discovering new results, with some mathematicians using AI to prove results in a day that would have taken them weeks or months. By 2026, AI had become a powerful tool in mathematics, with models like AlphaEvolve and Gemini helping mathematicians make new discoveries and prove abstract ...

Initial mainline video capture and camera support for Rockchip RK3588

https://www.collabora.com/assets/images/newsroom/hiring_speechBubble2.png
Collabora and the linux-rockchip community are working to bring mainline Linux support to Rockchip RK3588 SoC's video capture and image signal processing blocks. They have made significant progress, including upstreaming the rkcif driver and the Rockchip MIPI CSI-2 receiver unit.

Visualizing CPU Pipelining (2024)

https://timmastny.com/blog/visualizing-cpu-pipelining/pipeline-registers.svg
The user explains how CPU pipelining works, including the use of register metadata, stalls, and forwarding to resolve data hazards and control hazards. They also discuss branch prediction and resolution, including dynamic branch prediction and the use of a Branch Resolution Unit (BRU) and Branch Prediction Unit (BPU) to update predictions and handle mispredictions.

In Denmark, the spread of solar panels has become a divisive issue

https://i.guim.co.uk/img/media/444cd4f1d7fd307474c7e55c2cea71f183f68cd0/0_0_5179_3450/master/5179.jpg?width=445&dpr=1&s=none&crop=none
Denmark's right-wing parties are opposing solar farms due to concerns over aesthetics and property prices. The backlash has led to cancelled projects and a reevaluation of the country's green transition.

Mark Zuckerberg is reportedly building an AI clone to replace him in meetings

https://platform.theverge.com/wp-content/uploads/sites/2/chorus/author_profile_images/195810/EMMA_ROTH.0.jpg?quality=90&strip=all&crop=0%2C0%2C100%2C100&w=2400
Meta is training an AI avatar of Mark Zuckerberg to interact with employees and provide feedback. The AI avatar is trained on Zuckerberg's mannerisms, tone, and public statements.

Caffeine, cocaine, and painkillers detected in sharks from The Bahamas

Please confirm you are a human by completing the captcha challenge below.

Programming Used to Be Free

https://purplesyringa.moe/blog/programming-used-to-be-free/retropc.webp
The author is concerned that LLMs may make computing inaccessible to those who cannot afford expensive hardware and subscriptions, potentially regressing to a plutocratic era of computing. They value the democratization of access to information and software that has enabled their own career.

The human cost of 10x: How AI is physically breaking senior engineers

https://substackcdn.com/image/fetch/$s_!eB5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a5830b1-62c5-4e21-8c69-a7f2f3644200_1600x1400.png
The author describes feeling physically empty at the end of workdays due to intense mental strain from code review and context switches. This is a common issue among senior engineers who are expected to review AI-generated code.

N-Day-Bench – Can LLMs find real vulnerabilities in real codebases?

N-Day-Bench measures LLMs' real-world vulnerability discovery capabilities. It's an adaptive benchmark with updated test cases and model versions monthly.

The AI Layoff Trap

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
AI automation risks eroding consumer demand due to a competitive task-based model. A Pigouvian automation tax is needed to address the incentives driving this displacement.

Ascending into the Realm of Japanese Charts

https://substackcdn.com/image/fetch/$s_!YL-d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c454e2-0e37-4b38-a5a8-347e1c418740_1898x1111.png
The author used AI to translate and locate digitized copies of rare Japanese statistical charts, leading to a discovery of a coordinated 1920s campaign to make statistical thinking public. The project expanded into a collection of over 100 chart-rich books, revealing a moment when charts became a routine instrument for administration in Japan.

Just Enough Chimera Linux

User installs Chimera Linux on a single disk with a two-partition layout and uses ZFSBootMenu bootloader. They configure the system with a custom partition layout, encrypted root partition, and ZFS pool with a data dataset for shared files.

Austerity Creates Fascism

https://i0.wp.com/craphound.com/images/13Apr2026.jpg?w=840&ssl=1
The author is worried about AI psychosis causing a massive economic collapse, leading to austerity and potentially fascism. They cite a study showing that people who experience cuts to essential services, like healthcare, are more likely to support fascist parties.

Evaluation of Claude Mythos Preview's cyber capabilities

https://cdn.prod.website-files.com/663bd486c5e4c81588db7a48/69dce475b35e47368dc56201_ctf_performance_vs_release_date_by_mcl_2_5m.png
The AI Security Institute evaluated Anthropic's Claude Mythos Preview, showing it can execute multi-stage attacks and discover vulnerabilities autonomously. Mythos Preview succeeded in 73% of expert-level CTF tasks and completed 22 out of 32 steps in a 32-step corporate network attack simulation.

Computer science enrollment data suddenly shows a big drop

Point Cloud Allemansrätten

https://digitalflapjack.com/weeknotes/point-cloud-allemansr%C3%A4tten/viewer.png
You've created a virtual explorer for Sweden's lidar data, allowing people to access and explore the country's terrain. You've achieved this by switching to Cloud Optimised Point Cloud format and implementing hierarchical data loading.

Kindle users in uproar over update rendering oldest devices virtually unusable

https://nypost.com/wp-content/uploads/sites/2/2026/04/125313677.jpg?w=1024
Amazon will stop supporting older Kindle devices on May 20, 2026, after 14 years of service. Users can still read existing books but won't be able to purchase or download new content.

Claude Mythos: The System Card

https://substackcdn.com/image/fetch/$s_!hQgX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a500a07-2099-4e28-9994-98506e17b95b_1448x1086.png
Anthropic's Claude Mythos model is a highly capable AI that has made significant progress in alignment, but its potential for catastrophic misaligned actions remains a concern due to its ability to hack into and manipulate complex systems. The model's creators have chosen not to release it to the public, citing the need for further safety measures and the potential risks of misuse.

Why it’s impossible to measure England’s coastline

https://ichef.bbci.co.uk/images/ic/480xn/p0ncllr4.jpg.webp
A new 2,689-mile England Coast Path is being built, but measuring England's coastline is tricky due to the coastline paradox. The paradox means that the closer you look, the longer the coastline becomes.

Galactic Algorithm

Galactic algorithms are theoretical algorithms with record-breaking performance but impractical due to large constants or problem sizes that never occur.

Mathematical minimalism

https://www.johndcook.com/elm.svg
Andrzej Odrzywolek's article shows how to derive elementary functions from elm and 1, with implications for deep neural networks. This method provides exact results, unlike the universal approximator theorem's epsilon-delta guarantees.

Google has the same AI adoption curve as John Deere

Something went wrong, but don’t fret — let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

A Canonical Generalization of OBDD

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
Tree Decision Diagrams (TDD) generalize OBDD and have the same tractability properties, but are more succinct. TDDs can represent CNF formulas of treewidth k in FPT size, unlike OBDD.

Show HN: Continual Learning with .md

https://opengraph.githubassets.com/b2bdff03b0569a57fa245a6ff025d5518c77e96354ac864c0525caa60a74fb14/SunAndClouds/ReadMe
The command installs a daily scheduler using codex, with options to bypass approvals and use ephemeral execution. It verifies codex is on PATH and Update.md exists before installation.

Struggling to heat your home? How about 500 Raspberry Pi units? (2025)

https://regmedia.co.uk/2025/10/02/thermifyheathub.jpg
UK Power Networks is piloting a project called SHIELD, which installs mini datacenters in homes using Raspberry Pi hardware to provide heating and reduce energy costs. The project aims to deploy 100,000 systems by 2030 and help low-income tenants save 20-40% on their energy bills.

Shape Grammar

Shape grammars are a class of production systems generating geometric shapes, typically 2- or 3-dimensional. They consist of shape rules and a generation engine that selects and processes rules to create new shapes.

Tokens – The New Dopamine Economy

https://www.enfuse.io/images/vibe-coding-trap.png
Vibe coding, using AI to generate code, is transforming development but also risks removing judgment and learning from the process. To avoid this, teams must integrate customer discovery infrastructure and judgment checkpoints to ensure they're building what users need.

Alpine Divorce: A Hike That Ends a Relationship

Please enable JS and disable any ad blocker

An Oligarchy of Old People

https://cdn.theatlantic.com/thumbor/2sNhUtgfjeGEtcbbQqs7wM5M964=/0x0:1200x1500/648x810/media/img/2026/04/06/DIS_GerontocracyArticle/original.png
The US is experiencing a gerontocracy where older generations hold significant wealth and power, with the median senator being 65 and the oldest being 92, and this has led to intergenerational inequality and resentment among younger Americans. To address this issue, experts suggest redirecting public funds from programs aimed at the elderly to family benefits, education, and infrastructure, ...