1-Click GitHub Token Stealing via a VSCode Bug

https://blog.ammaraskar.com/images/vscode/github-dev-demo.png
An attacker can steal a GitHub token by exploiting a vulnerability in VSCode's webviews, allowing them to install malicious extensions and gain full code execution. The attack involves creating a Jupyter notebook with a payload that installs a local workspace extension, which can then be used to steal the token.

Use your Nvidia GPU's VRAM as swap space on Linux

https://opengraph.githubassets.com/2dbdd4438347db6dfb5d180394307019da2d2c3fdca12b1e830e1b00d2dd2bb3/c0deJedi/nbd-vram
A daemon allocates VRAM as a block device using the NBD protocol, exposing it as a swap device to the kernel. This approach sidesteps NVIDIA driver limitations and provides a swap solution with lower latency than NVMe.

MAI-Code-1-Flash

https://microsoft.ai/wp-content/uploads/2026/05/thinking-1.png
Microsoft introduces MAI-Code-1-Flash, a new coding model for fast and efficient assistance in developer workflows. It outperforms Claude Haiku 4.5 with better price to performance and is now rolling out to GitHub Copilot users in VS Code.

CT scans of BYD car parts

https://cdn.prod.website-files.com/63e15418201b6e2a5cabb911/6a1a314f31fed60b9b9f01fd_byd-charter-rotator.png
We CT scanned four BYD components—a battery cell, window switch, EV charger, and key fob—to see what's inside the world's best-selling EV that's banned in the U.S.

Agentic Mfw

The author mocks the current state of software development where maintainability and clean code are no longer valued, instead prioritizing complexity and speed to impress investors. The author also ridicules the idea of open-source contributions and the current state of GitHub, where bots and AI-generated code dominate and human contributions are often ignored or drowned out.

Capstone – multi-platform, multi-architecture disassembly framework

https://www.capstone-engine.org/img/capstone.png
Capstone is a disassembly engine for binary analysis and reversing, supporting 24 architectures and implemented in pure C with bindings for various languages. It provides a generic API and is widely used in the security community.

Are blue zones real? Answering that question is harder then ever

https://www.statnews.com/wp-content/uploads/2025/09/LabDish_Frame_longevityscience-768x432.jpg
French geneticist Jean-Francois Deleuze's AGENOMICS study aims to identify genetic patterns among long-lived French citizens and compare them to centenarians from blue zones. The blue zones concept, popularized by Dan Buettner, has been questioned due to declining numbers of healthy seniors in original regions and commercialization of the brand.

Roku LT Operating System open source distribution

https://image.roku.com/blog/developer/files/2026/06/roku-lt-os.png
Roku LT OS is a lightweight, open-source operating system for embedded systems and automotive engineering. It provides a powerful, predictable framework for high-performance hardware-level development.

Gmail thinks I'm stupid, so I left

https://moddedbear.com/images/share.png
The user is frustrated with Gmail's new AI features that nag and interrupt them while composing emails. They're switching to Fastmail after 16 years with Gmail due to the unwanted features.

AI outperforms law professors in Stanford Law study

https://law.stanford.edu/wp-content/uploads/2025/07/a-passion-for-data-a-vision-for-law-1024x703.jpg
A Stanford study found law professors prefer AI-generated answers to student questions over human-written ones, with AI winning 75% of head-to-head matchups. The study suggests AI can be a valuable tool in legal education, offering high-quality, on-demand support that complements classroom instruction.

Pluto.jl 1.0 release – reactive notebook for Julia

https://global.discourse-cdn.com/julialang/optimized/3X/3/4/34fbff1585d4e3ea83606535e91a43b9226dc4be_2_690x249.png
Pluto version 1.0 is released, celebrating six years of progress and making scientific computing more accessible and fun. Pluto is an interactive environment for notebook programming in Julia, with features like reproducibility, accessibility, and reactivity.

My thoughts after using Clojure for about a month

The user is learning Clojure and finds it ergonomic and powerful, preferring it over Common Lisp and Scheme due to its cohesive design and large standard library. They appreciate Clojure's simplicity and uniformity, but acknowledge some pain points, such as its syntax and the need to learn Java for interop.

Open Repair Data Standard – Open Repair Alliance

https://openrepair.org/wp-content/uploads/2025/01/ords-data-collected-1024x546.png
The Open Repair Data Standard (ORDS) helps combine repair data on electronics by defining a shared approach. It collects data on product, repair, and session information to identify trends globally and locally.

A walking tour of surveillance infrastructure in Seattle (2020)

https://coveillance.org/static/9cbadffb4bd8e51ad3298edf880431c1/6bfe4/image-8.png
This walking tour in downtown Seattle aims to expose the hidden layers of surveillance technology in the city, including cameras, license plate readers, and data collection systems, and to raise questions about their use and impact on society. The tour highlights various surveillance tools and sites, including Amazon Go, Acyclica, the Washington State Fusion Center, and a peering site, and ...

4K years ago, Mohenjo-daro grew more equal over time

https://archaeologymag.com/wp-content/uploads/ANlogo_1-130x130.png
Archaeologists found lower inequality levels in ancient Mohenjo-daro, with economic gaps shrinking over time. The city's focus on public infrastructure and shared resources contributed to its stability and equality.

HP re-releases classic computer science calculator: The HP-16C

The HP 16c Collector's Edition retains the classic layout but is 100x faster with customizable word size and base conversions. It features programming capabilities with conditional branching, subroutines, and flags, and supports up to 203 bytes of program memory.

How we index images for RAG

https://framerusercontent.com/images/qURKX4mwPMBTX9peq1oYfpPQw.png
Kapa's AI assistant uses a vision model at indexing time to describe images as text, then retrieves these descriptions alongside text chunks at query time, improving answer quality and reducing costs. This approach, which involves describing images once at ingestion and storing them as separate text chunks, outperforms query-time vision and is more cost-effective for large-scale applications.

Trump signs downsized AI order after weeks of reversals

President Donald Trump signed an executive order addressing AI-driven cyber threats with a voluntary review process for AI companies. The order aims to enhance national security and global AI dominance while avoiding heavy federal oversight.

OpenFOV – Webcam head tracking for iRacing

https://www.openfov.com/link-preview.png
OpenFOV uses your webcam to control iRacing's in-game FOV. Unlocks VR-style functionality for your monitor!

Multicore suppport for DOS is real – partly

Sorry, you are not authorized to view this page.

Expanding Project Glasswing

https://www.anthropic.com/_next/image?url=https%3A%2F%2Fwww-cdn.anthropic.com%2Fimages%2F4zrzovbb%2Fwebsite%2F19e93d85e033d3f992b78cbce2c5a3f60709bd3b-3840x2160.jpg&w=3840&q=75
Project Glasswing is expanding to 150 new organizations in 15 countries to secure software with AI. The goal is to adapt to AI's changing cybersecurity landscape and prevent catastrophic attacks affecting over 100 million people.

Loading Sega Games Off a Vinyl Record [video]

Preparing for KDE Plasma's Last X11-Supported Release

http://blog.davidedmundson.co.uk/wp-content/uploads/2026/06/graph-1024x683.png
Plasma is transitioning to Wayland, removing X11 support in Plasma 6.8. This change will allow for new performance improvements and features, but may require custom scripts and workflows to adapt.

Fidonet: Technology, Use, Tools, and History (1993)

FidoNet is a point-to-point email network that uses modems to connect over 20,000 nodes worldwide, allowing users to send and receive email and news. The network was developed in 1984 and has a unique addressing system, with gateways to the Internet and other networks, and a strong focus on user autonomy and minimal technical support.

Show HN: Paseo – Beautiful open-source coding agent interface

https://camo.githubusercontent.com/a9f299d62effea920ab01596a63c38201a07cac0188ebaf53cc30e3d8a2dceba/68747470733a2f2f706173656f2e73682f6865726f2d6d6f636b75702e706e67
Paseo is a self-hosted coding platform that allows running agents in parallel on your machine with full dev environment. It supports multi-provider models, voice control, cross-device access, and local server management.

The advertising cartel coming to your web browser

Big Tech companies are proposing a built-in advertising system, Attribution Level 1, which prioritizes their own tracking over user privacy. This system could lead to more money for Big Tech and less for legitimate sites, while also enabling riskier tracking practices.

Bringing Up DeepSeek-V4-Flash on AMD MI300X

Doubleword is building an inference cloud using AMD's MI300X, a high-end AI accelerator. The MI300X is underappreciated due to software issues, but it offers 192GB of HBM3 and comparable FP8 compute to NVIDIA's H100 at a lower price.

QBE – Compiler Backend – 1.3

QBE 1.3 is a significant release with 7k new lines of code and 1.5k deleted ones, featuring a new IL matching algorithm and optimizations. It achieves 63% of commercial compiler performance on coremark and 33% improvement on the Hare test suite.

Can A.I. Produce Writing That We Want to Read?

https://media.newyorker.com/photos/6a1dd4c745d78a7fb2a79c7b/2:2/w_2560%2Cc_limit/AIWriting_Revised_bleed.jpg
In the previous installment of this series on the future of higher education, I talked with professors about the ways that A.I. has changed their classrooms. Most felt despair over the breakdown of a contract between student and teacher, one predicated on the faith that, even if students weren’t always perfect, they would at least challenge themselves to think every once in a while. If ...

Ad Infini­Tum

https://matthiasott.com/apple-touch-icon.png
At Google I/O this week, the company announced the biggest change to Search in 25 years. The ten blue links? Gone. Instead, you get — first at times? soon always? — “generative UI”, an “intelligent search box” with custom interactive widgets, built on the fly by Gemini. You get “information agents” that monitor the web for you around the clock. You get mini-apps you can build right inside the ...