Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ramimac
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
ramimac
28d ago
Thread on the post from main rust blog: https://news.ycombinator.com/item?id=49372853 Direct post link: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on... Initial report: https:
2.
▲
Moving Forward from Hot Fable Summer
(alexstamos.com)
1 points
by
ramimac
1mo ago
|
0 comments
3.
▲
AsyncAPI Supply Chain Compromise via GitHub Actions
(wiz.io)
4 points
by
ramimac
2mo ago
|
0 comments
4.
▲
Who Has the Hardest Fist in China's AI Valuation Race?
(crossingriver.substack.com)
3 points
by
ramimac
4mo ago
|
0 comments
5.
▲
A Guide to Keyboard Customization
(aresluna.org)
4 points
by
ramimac
4mo ago
|
0 comments
6.
▲
by
ramimac
5mo ago
Carlini's unprompted talk is one source: https://www.youtube.com/watch?t=204&v=1sd26pWhfmg
7.
▲
If [static analysis] could have, why didn't it?
(alexgaynor.net)
2 points
by
ramimac
5mo ago
|
1 comments
8.
▲
Brocards for Vulnerability Triage
(blog.yossarian.net)
2 points
by
ramimac
5mo ago
|
0 comments
9.
▲
by
ramimac
6mo ago
We haven't blogged this yet, but a variety of teams found this in parallel. The packages are quarantined by PyPi Follow the overall incident: https://ramimac.me/teampcp/#phase-10 Aikido/Charlie with a very qu
10.
▲
Telnyx package compromised on PyPI
(telnyx.com)
133 points
by
ramimac
6mo ago
|
135 comments
11.
▲
by
ramimac
6mo ago
It's a spam flood by the attacker to complicate information sharing[1]. They did the same thing in the Trivy discussion, with many of the same accounts.[2] [1] https://ramimac.me/teampcp/#spam-flood-litellm [2]
12.
▲
by
ramimac
6mo ago
Blood, sweat, and tears. The investment compounds! I have enough context to quickly vet incoming information, then it's trivial to update a static site with a new blurb
13.
▲
by
ramimac
6mo ago
This is tied to the TeamPCP activity over the last few weeks. I've been responding, and keeping an up to date timeline. I hope it might help folks catch up and contextualize this incident: https://ramimac.me/trivy-teamp
14.
▲
by
ramimac
6mo ago
> Upon issue creation another workflow spins up three independent coding agents to analyze the finding. I'm curious 1) what the current statistics are for consensus 2) how the agents may/may not perform independently 3) what th
15.
▲
It's Their Mona Lisa
(ironicsans.ghost.io)
75 points
by
ramimac
6mo ago
|
17 comments
16.
▲
Child's Play: Tech's new generation and the end of thinking
(harpers.org)
451 points
by
ramimac
7mo ago
|
265 comments
17.
▲
Building Multi-Agent Systems (Part 3)
(blog.sshh.io)
1 points
by
ramimac
8mo ago
|
0 comments
18.
▲
by
ramimac
9mo ago
Reach out if you'd like me to check - I did the same for the trigger.dev team in fact[1]. (personal site linked in bio, who links you onward to my linkedin) [1] https://x.com/ramimacisabird/status/199459807552
19.
▲
Okta's NextJS-0auth troubles
(joshua.hu)
372 points
by
ramimac
10mo ago
|
152 comments
20.
▲
by
ramimac
10mo ago
Probably, but you can check out a more robust list here: https://blog.cloudflare.com/tag/acquisitions/ * BastionZero * Kivera * Baselime * PartyKit * Area 1 * Vectrix * Zaraz * Linc * S2 Systems Corporation * Neum
21.
▲
by
ramimac
11mo ago
Always a funny title, see previously: Announcing the New AWS Secret Region (2017) [1] [1] https://news.ycombinator.com/item?id=15741108
22.
▲
Visibility at scale: How Figma detects sensitive data exposure
(figma.com)
2 points
by
ramimac
11mo ago
|
0 comments
23.
▲
If Managers Were Angels
(bonnycode.com)
1 points
by
ramimac
11mo ago
|
0 comments
24.
▲
Dismantling a Critical Supply Chain Risk in VSCode Extension Marketplaces
(wiz.io)
1 points
by
ramimac
11mo ago
|
0 comments
25.
▲
by
ramimac
1y ago
It's not a coincidence - this attack is directly downstream of s1ngularity
26.
▲
by
ramimac
1y ago
Hi! Author here who added the VSCode stat :) I thought it was useful to include because: * it can inform triage, if you use the extension you're more likely to be impacted * because it was VSCode, Workplace Trust actually partially mit
27.
▲
by
ramimac
1y ago
I have evidence of at least 250 successes for the prompt. Claude definitely appears to have a higher rejection rate. Q also rejects fairly consistently (based on Claude, so that makes sense). Context: I've been responding to this all d
28.
▲
Eleven Missing Terraform Features
(josnyder.com)
5 points
by
ramimac
1y ago
|
0 comments
29.
▲
by
ramimac
1y ago
Thanks! Unfortunately, I've somehow fallen off the paved road :) https://github.com/ramimac/wiki/blob/main/CNAME
30.
▲
by
ramimac
1y ago
Fixed! Pages drops the custom domain whenever I push right now, have been putting off debugging it - apologies
More ›