Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
unknownhad
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
(blog.himanshuanand.com)
2 points
by
unknownhad
4d ago
|
1 comments
2.
▲
A fake resume invoked China's defence-tech elite, then installed VShell
(blog.himanshuanand.com)
5 points
by
unknownhad
22d ago
|
0 comments
3.
▲
I had some free time, so I tried to pwn V8
(blog.himanshuanand.com)
2 points
by
unknownhad
23d ago
|
0 comments
4.
▲
Anti India Influence Machine: Troll Farms, Fake News, Algorithms and AI
(blog.himanshuanand.com)
1 points
by
unknownhad
29d ago
|
0 comments
5.
▲
ValleyRAT campaign targets Indian taxpayers with fake GSTR-3B overdue notice
(blog.himanshuanand.com)
1 points
by
unknownhad
1mo ago
|
0 comments
6.
▲
You're Back in the Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
(labs.watchtowr.com)
2 points
by
unknownhad
1mo ago
|
0 comments
7.
▲
I found a KVM guest-to-host heap corruption bug and someone else got there first
(blog.himanshuanand.com)
1 points
by
unknownhad
1mo ago
|
0 comments
8.
▲
I was reporter #11 for a WPForms PayPal webhook vulnerability
(blog.himanshuanand.com)
3 points
by
unknownhad
2mo ago
|
0 comments
9.
▲
Inclusive Syntax: outdated tech terms and clearer alternatives
(inclusivesyntax.com)
3 points
by
unknownhad
4mo ago
|
2 comments
10.
▲
by
unknownhad
4mo ago
It's a Smol side project additions/updates welcome.
11.
▲
Score by Collisions, Patch by Panic
(blog.himanshuanand.com)
5 points
by
unknownhad
4mo ago
|
0 comments
12.
▲
I read OpenSSL for fun and found a nonce leak
(blog.himanshuanand.com)
3 points
by
unknownhad
4mo ago
|
0 comments
13.
▲
Kernel Kill Switch
(lore.kernel.org)
3 points
by
unknownhad
4mo ago
|
1 comments
14.
▲
by
unknownhad
4mo ago
This looks like an interesting proposal. My previous post : https://blog.himanshuanand.com/2026/05/the-90-day-disclosure... Highlight the issues some of these can be fixed by these, IIRC BSD already had similar fe
15.
▲
by
unknownhad
4mo ago
I think this assumes software is a static target (Which it is not) . We are not just using LLMs to scan old code developers are using LLMs (like Copilot and others) to write new code and they are doing it by the shovel-load. The pace of shi
16.
▲
The 90 Day disclosure policy is dead
(blog.himanshuanand.com)
17 points
by
unknownhad
4mo ago
|
5 comments
17.
▲
by
unknownhad
4mo ago
The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyon
18.
▲
Show HN: MAIro AI Slop in Games
(mairo.himanshuanand.workers.dev)
1 points
by
unknownhad
6mo ago
|
0 comments
19.
▲
Always-on detections: eliminating the WAF "log versus block" trade-off
(blog.cloudflare.com)
1 points
by
unknownhad
7mo ago
|
0 comments
20.
▲
Toxic combinations: when small signals add up to a security incident
(blog.cloudflare.com)
15 points
by
unknownhad
7mo ago
|
5 comments
21.
▲
by
unknownhad
8mo ago
I have received an Email today. I was using https://www.hndigest.com/ Kudos to the person behin.
22.
▲
by
unknownhad
9mo ago
All the Emails were from `hello @ hndigest.com` W00ps, My understanding was this is from HN.
23.
▲
Ask HN: Are you missing daily email alerts from HN?
10 points
by
unknownhad
9mo ago
|
8 comments
24.
▲
React2Shell and related RSC vulnerabilities threat brief
(blog.cloudflare.com)
21 points
by
unknownhad
9mo ago
|
1 comments
25.
▲
I Found a Europa.eu Compromise
(blog.himanshuanand.com)
3 points
by
unknownhad
10mo ago
|
1 comments
26.
▲
by
unknownhad
10mo ago
While looking for a way to stream the India vs Pakistan cricket match on 14th September 2025, I stumbled across a suspicious search result on a europa.eu dev subdomain. It was being abused for blackhat SEO and redirecting users to scam stre
27.
▲
Look mom HR application, look mom no job – phishing using Zoom docs
(blog.himanshuanand.com)
1 points
by
unknownhad
1y ago
|
1 comments
28.
▲
by
unknownhad
1y ago
A phishing campaign that uses Zoom's document share flow as the initial trust vector. It forces victims through a fake "bot protection" gate, then shows a Gmail-like login. When someone types credentials, they are pushed out
29.
▲
Show HN: Typosquat Detective: Browser game to practice lookalike domains
(typo.himanshuanand.com)
1 points
by
unknownhad
1y ago
|
0 comments
30.
▲
Why Relying on LLMs for Code Can Be a Security Nightmare
(blog.himanshuanand.com)
2 points
by
unknownhad
1y ago
|
0 comments
More ›