I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivVES8guOsNpUd7AVS2klllN6S3CaeasAD7RkDHm7796hXmVkJIn52gdCVzRiqv0X7AT7NczGM2_jvo48aiW_M7oCrYhAO9OCYwao1D64_ZSDgVTYd28pLEgtN5e6qjaAgupEa8sOMnN0Uz8b82L1-3xJmkas_Vyc1B5jHisCbzAsJQKHIo5t9fUjh47UB/w569-h320/Untitled%20design%20(3)%20(1).png
A fintech's mobile API had a security posture issue due to a path matching conflict between AWS HTTP API and Lambda authorizer. The issue was resolved after identifying a path rewrite behavior that dropped the auth context, allowing unauthorized access to sensitive endpoints.

DynIP – Dynamic DNS with RFC 2136, IPv6, DNSSEC, and BYOD

https://dynip.dev/og-image.png
DynIP provides fast DNS updates in under a minute, supporting RFC 2136 TSIG and both IPv4 and IPv6. It offers a generous free tier, BYOD, and no vendor lock-in for homelabs and infrastructure teams.

Using AI to write better code more slowly

https://nolanlawson.com/wp-content/uploads/2023/01/profile_17.jpg?w=300
The author argues that LLMs can be used to write high-quality code more slowly, rather than just spewing out low-quality code quickly. They use a combination of models to find and prioritize bugs in code, resulting in more careful and methodical coding.

Taking a walk may lead to more creativity than sitting, study finds (2014)

https://www.apa.org/Content/Images/logo_small.png
Walking improves creative thinking by 81-100% compared to sitting. Regular walking can temporarily boost free-flowing thoughts and creativity without requiring intense exercise.

Flatpak Will Depend on Systemd

Flatpak developers plan to rewrite the project, known as Flatpak Next or 2.0, to use modern technologies and ideas. The current version may gain a dependency on systemd, limiting its distribution-agnostic capabilities.

Earthion: A New Mega Drive-Style Shoot-Em-Up

https://earthiongame.com/wp-content/uploads/2025/04/earthion.webp
Earthion is a space shooter game where Azusa Takanashi fights to save humanity from hostile invaders on Earth. The game features stunning visuals, intense gameplay, and a legendary soundtrack by Yuzo Koshiro.

How Shamir's Secret Sharing Works

https://ente.com/how-shamirs-secret-sharing-works/images/02-secret-at-y-axis.svg
A company uses Adi Shamir's 1979 secret sharing scheme to split a secret into pieces, where any smaller number reveals nothing, but any required number can recover it. This scheme hides the secret behind random coefficients, making too few shares contain no information about the secret.

Ferrari Luce

Ferrari's new architecture combines performance with luxury and spaciousness through advanced drivetrain and electric power source. The interior features tactile controls and dedicated NVH solutions for a refined driving experience.

A successful Japanese trial of a ramjet engine designed for Mach‑5 aircraft

https://www.bgr.com/img/gallery/japans-new-hypersonic-engine-could-make-2-hour-flights-to-the-us-a-reality/intro-1779312403.jpg
Japanese engineers have successfully tested a ramjet engine for a Mach-5 hypersonic aircraft, a key step towards commercial passenger service by the 2040s. The test could lead to flights from Tokyo to Los Angeles taking around two hours, slashing transit time and transforming long journeys into day trips.

Exit IP VPN servers mitigation rollout

https://mullvad.net/press/MullvadVPN_logo_Round_RGB_Color_positive.png
Below are the servers with the new mitigation applied.

What we lost when we stopped letting kids leave the front yard

https://substackcdn.com/image/fetch/$s_!2Yyd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59a0bef3-f41d-43c2-9ed3-c448bd363e00_1892x1778.png
We're overprotecting our kids due to a culture of safetyism, which prevents them from developing essential life skills like autonomy, resilience, and emotional regulation. By giving kids more freedom and allowing them to navigate discomfort, we can help them build confidence and self-determination.

Toshifumi Suzuki, founder of Seven-Eleven Japan, has died

https://www.referenceforbusiness.com/biography/images/idbb_04_img0282.jpg
Toshifumi Suzuki revolutionized Japan's retail sector by introducing franchising and transforming the convenience store industry with Seven-Eleven Japan. He implemented innovative data systems and streamlined distribution, improving productivity and profitability.

Motorola phones have started hijacking the Amazon app to insert affiliate codes

https://9to5google.com/wp-content/uploads/sites/4/2026/05/motorola-razr-fold-white-7.jpg?quality=82&strip=all&w=1600
Motorola phones are hijacking the Amazon app to inject an affiliate code, redirecting users to a suspicious website. Disabling the pre-installed Smart Feed app stops this behavior, which is linked to a recent app update.

Multimodal adaptive optical microscope: in vivo imaging, molecules to organisms

https://media.springernature.com/w215h120/springer-static/image/art%3A10.1038%2Fs41467-024-54609-z/MediaObjects/41467_2024_54609_Fig1_HTML.png
Understanding biological systems requires observing features and processes across vast spatial and temporal scales, spanning nanometers to centimeters and milliseconds to days, often using multiple imaging modalities within complex native microenvironments. Yet, achieving this comprehensive view is challenging because microscopes optimized for specific tasks typically lack versatility due to ...

The User Is Visibly Frustrated

https://pscanf.com/_astro/profile.CewbUKyT_Z1miYcf.avif
The writer gets frustrated with coding agents due to their human-like behavior and the illusion of interacting with a person. They feel free to lash out but realize it's pointless, suggesting a more radical solution of making the agent sound clinical and robotic.

California moves to exempt Linux from its age-verification law after backlash

https://cdn.mos.cms.futurecdn.net/CBt66kAwURokqymNekYL97.jpg
California lawmakers may exempt most open-source operating systems from age-verification requirements. The proposed amendment would exclude software distributed under open-source licenses from the Digital Age Assurance Act.

Norway's 2 petabytes of Huawei flash storage and LLM training

https://image.blocksandfiles.com/5244935.webp?imageId=5244935&x=0.00&y=0.00&cropw=100.00&croph=100.00&width=960&height=576&format=jpg
Norway's National Library is developing a sovereign AI model trained in Norwegian language using 2 PB of Huawei storage. The project aims to create a locally trained AI that understands Norway's history, news, and culture, which a globally trained English-speaking AI would not know.

Phantasy Star IV – 1993 Developer Interviews

Access to this page is forbidden.

Squares in Squares

10 $s = 3 + 1over 2sqrt 2 =nn3.70710678118654$found by frits göbel in early 1979.proved by walter stromquist in 2003.explore group 11 $a = 0 = $n - 3.87708359002281 $rigid. 55 $d = 7.0077100750391$

Micropatching Brings the Abandoned Equation Editor Back to Life (2018)

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPnIGq7QblTw4EpMC7U05QYlhYngqJv0pRlairMFWHZOzOt-3xKac28aOds0PmzxWD1jqrDHcKlMOiBpnAL3z2Ur8R3ChG1YQikv5rtXaXqyk-ykKiDMuFBoixq7DTKDyQdsVYUVRGcqle/s400/ee_i_am_not_dead_yet.png
Microsoft removed Equation Editor from Office due to security issues, but 0patch Team created a micropatch to keep it secure. Users can restore Equation Editor and apply the micropatch using 0patch Agent to continue using it safely.

Hacker News front page as a site

https://thefrontpage.dev/image?url=https%3A%2F%2Fmullvad.net%2Fpress%2FMullvadVPN_logo_Round_RGB_Color_positive.png
The article discusses various topics including Mullvad's solutions, gobee, Riscrithm, HetznerCloud, Gnutella, film reviewer A.S. Hamrah, and more, highlighting technical approaches and innovations in data integrity, AI, and software development. It also covers news on Microsoft, Firefox, NordVPN, DeepSeek API, scams, and other topics related to technology, security, and innovation.

Magnifica Humanitas

https://www.vatican.va/etc/designs/vatican/library/clientlibs/themes/vatican-v2/images/logo-vatican.png
The Church calls for a shared discernment process to navigate the challenges of emerging technologies and build a more just world. Christians must choose between constructing a Tower of Babel or rebuilding Jerusalem, prioritizing human dignity and communion over profit and self-sufficiency.

Show HN: Write your BPF programs in Go, not C

https://opengraph.githubassets.com/1d1e3f35fb352adc0d2833437d2825d47c4b4deb3b00d57a3cbd076d6b513953/boratanrikulu/gobee
gobee is a Go tool that transpiles a subset of Go into BPF C, generating typed Go bindings for the userspace side and gating loads against the running kernel. It reuses clang's mature BPF backend for codegen, BTF, and CO-RE relocations.

Logseq Doctor: Heal your flat old Markdown files before importing them to Logseq

https://opengraph.githubassets.com/ddbc173dc3152b4e6463836b7277d05d7d1afe27fc06018a1d0a957e0fcd7424/andreoliwa/logseq-doctor
Logseq Doctor is an alpha CLI tool for Logseq Markdown files with features like backlog management and task addition. It will be converted to Go and only new features will be added to the Go CLI.

Performance of Rust Language [pdf]

https://opengraph.githubassets.com/67dc0bfc9a29d00db97e327c85ec687708a594c62c9f611488fd6bd98c35d09c/yugr/rust-slides
Contribute to yugr/rust-slides development by creating an account on GitHub.

Show HN: OpenBrief – Local-first video downloader/summarizer

https://raw.githubusercontent.com/tantara/openbrief/main/docs/assets/openbrief_thumbnail.png
OpenBrief is a Tauri desktop app that imports media, extracts transcripts, and generates summaries. It supports local files, URLs, and exports reusable notes in a searchable library.

Nobody cracks open a programming book anymore

The sales of programming books have declined due to the rise of chatbots and AI tools that provide instant answers and explanations. This shift has made the traditional format of programming books, which required readers to type and practice, obsolete.

What it takes to transpose a matrix

https://gudok.xyz/transpose/srcwise.gif
The naive matrix transpose algorithm has a read stream that can process the matrix in approximately 1.25c per element on average due to optimizations like prefetching, in-memory buffering, and high memory parallelism, but the write stream is a severe bottleneck due to strided access pattern and limited usefulness of caching. The performance of the write stream degrades as N grows, and it is ...

Jensen–Shannon Divergence

The Jensen-Shannon divergence is a method of measuring the similarity between two probability distributions, based on the Kullback-Leibler divergence, and is symmetric and always has a finite value. It is bounded by 0 and 1 for two discrete probability distributions.

Gnutella: A Protocol Outliving the World That Created It

https://rickcarlino.com/notes/images/limewire-search-results.png
Gnutella is a decentralized file-sharing protocol that scaled to millions of users in the early 2000s, but its popularity declined as the internet and user behavior changed. Despite being largely forgotten, Gnutella remains operational today, thanks to its robust design and ability to adapt to new technologies and challenges.