CVE-2025-14174 (works only on Mac)
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
couldn't find any PoC for it and since I don't have mac, I can't really test it
#cve
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
couldn't find any PoC for it and since I don't have mac, I can't really test it
#cve
Forwarded from HN Best Comments
Re: Pricing Changes for GitHub Actions
It is us, developers, who convinced our management to purchase GitHub Enterprise to be our forge. We didn't pay any heed to the values of software freedom. A closed source, proprietary software had good features. We saw that and convinced our management to purchase it. Never mind what cost it would impose in the future when the good software gets bad owners. Never mind that there were alternatives that were inferior but were community-developed, community-maintained and libre.
The writing is in the wall. First it was UX annoyances. Then it was GitHub Actions woes. Now it is paying money for running their software on your own hardware. It's only going to go downhill. Is it a good time now to learn from our mistakes and convince our teams and management to use community-maintained, libre alternatives? They may be inferior. They may lack features. But they're not going to pull user hostile tricks like this on you and me. And hey, if they are lacking features, maybe we should convince our management to let us contribute time to the community to add those features? It's a much better investment than sinking money into a software that will only grow more and more user hostile, isn't it?
throwaway150, 5 hours ago
It is us, developers, who convinced our management to purchase GitHub Enterprise to be our forge. We didn't pay any heed to the values of software freedom. A closed source, proprietary software had good features. We saw that and convinced our management to purchase it. Never mind what cost it would impose in the future when the good software gets bad owners. Never mind that there were alternatives that were inferior but were community-developed, community-maintained and libre.
The writing is in the wall. First it was UX annoyances. Then it was GitHub Actions woes. Now it is paying money for running their software on your own hardware. It's only going to go downhill. Is it a good time now to learn from our mistakes and convince our teams and management to use community-maintained, libre alternatives? They may be inferior. They may lack features. But they're not going to pull user hostile tricks like this on you and me. And hey, if they are lacking features, maybe we should convince our management to let us contribute time to the community to add those features? It's a much better investment than sinking money into a software that will only grow more and more user hostile, isn't it?
throwaway150, 5 hours ago
this repo has some cool tips:
https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
https://github.com/hackerschoice/thc-tips-tricks-hacks-cheat-sheet
GitHub
GitHub - hackerschoice/thc-tips-tricks-hacks-cheat-sheet: Various tips & tricks
Various tips & tricks. Contribute to hackerschoice/thc-tips-tricks-hacks-cheat-sheet development by creating an account on GitHub.
Forwarded from vx-underground
I have a website for my malware source code. I have named it "malwaresourcecode", a very unique and inspiring name
malwaresourcecode.com
malwaresourcecode.com
Forwarded from HN Best Comments
Re: Beginning January 2026, all ACM publications will be made open access
The financials of open access are interesting.
Instead of journals getting revenue from subscribers, they charge authors an โArticle Processing Chargeโ (APC) which for ACM is $1450 in 2026 and expected to go up. Authors from lower-middle income countries get a discount. [1]
Authors are often associated with institutions (e.g. universities) who can cover the APC on behalf of the author through a deal with the journal. For the institution, now instead of paying the subscriber fee and publishing for free, they pay a publishing fee and everyone reads for free.
1. https://authors.acm.org/open-access
trainyperson, 13 hours ago
The financials of open access are interesting.
Instead of journals getting revenue from subscribers, they charge authors an โArticle Processing Chargeโ (APC) which for ACM is $1450 in 2026 and expected to go up. Authors from lower-middle income countries get a discount. [1]
Authors are often associated with institutions (e.g. universities) who can cover the APC on behalf of the author through a deal with the journal. For the institution, now instead of paying the subscriber fee and publishing for free, they pay a publishing fee and everyone reads for free.
1. https://authors.acm.org/open-access
trainyperson, 13 hours ago
Forwarded from HackerNews Summary
AI will make our children stupid
๐ธThe author is concerned about the decline in IQs and attention spans due to excessive use of social media and mobile phones. This trend threatens to undermine intelligence and learning, making children reliant on AI for thinking and problem-solving.
20 Dec 2025
๐ฌ comments
๐ @hackernews_summary
๐ธThe author is concerned about the decline in IQs and attention spans due to excessive use of social media and mobile phones. This trend threatens to undermine intelligence and learning, making children reliant on AI for thinking and problem-solving.
20 Dec 2025
๐ฌ comments
๐ @hackernews_summary
Forwarded from HackerNews Summary
Backing Up Spotify
๐ธAnna's Archive released a 300TB music archive with 256 million tracks and 186 million unique ISRCs, representing 99.6% of listens. The archive is open and can be mirrored by anyone with enough disk space, aiming to preserve humanity's musical heritage.
20 Dec 2025
๐ฌ comments
๐ @hackernews_summary
๐ธAnna's Archive released a 300TB music archive with 256 million tracks and 186 million unique ISRCs, representing 99.6% of listens. The archive is open and can be mirrored by anyone with enough disk space, aiming to preserve humanity's musical heritage.
20 Dec 2025
๐ฌ comments
๐ @hackernews_summary
https://github.com/milvus-io/milvus
Milvus is designed to handle vector search at scale. It stores vectors, which are learned representations of unstructured data, together with other scalar data types such as integers, strings, and JSON objects. Users can conduct efficient vector search with metadata filtering or hybrid search.
Forwarded from HN Best Comments
Re: Claude in Chrome
Let's spend years plugging holes in V8, splitting browser components to separate processes and improving sandboxing and then just plug in LLM with debugging enabled into Chrome. Great idea. Last time we had such a great idea it was lead in gasoline.
CAP_NET_ADMIN, 6 hours ago
Let's spend years plugging holes in V8, splitting browser components to separate processes and improving sandboxing and then just plug in LLM with debugging enabled into Chrome. Great idea. Last time we had such a great idea it was lead in gasoline.
CAP_NET_ADMIN, 6 hours ago
Forwarded from HN Best Comments
Re: Fabrice Bellard Releases MicroQuickJS
Fabrice Bellard is widely considered one of the most productive and versatile programmers alive:
- FFmpeg: https://bellard.org
- QEMU: https://bellard.org/qemu/
- JSLinux: https://bellard.org/jslinux/
- TCC: https://bellard.org/tcc/
- QuickJS: https://bellard.org/quickjs/
Legendary.
ddtaylor, 10 hours ago
Fabrice Bellard is widely considered one of the most productive and versatile programmers alive:
- FFmpeg: https://bellard.org
- QEMU: https://bellard.org/qemu/
- JSLinux: https://bellard.org/jslinux/
- TCC: https://bellard.org/tcc/
- QuickJS: https://bellard.org/quickjs/
Legendary.
ddtaylor, 10 hours ago
Typst-based CV/resume generator for academics and engineers
https://github.com/rendercv/rendercv
https://github.com/rendercv/rendercv
Forwarded from Investigations by ZachXBT
Update: Hundreds of Trust Wallet victims & $6M+ stolen from the intial list of theft addresses
Update: Trust Wallet confirmed the incident on X
Update: Trust Wallet confirmed the incident on X