Critical CVE issued for hallucinated SQLite vulnerability

https://research.jfrog.com/img/RealTimePostImage/post/sqlite-critical-cves-or-llm-slops/image1.png
A GitHub account published 50+ SQLite vulnerability advisories, but JFrog security researchers found that 54 were fabricated and one contained a real bug with unverified metadata. This incident highlights a systemic issue with automated vulnerability ingestion, where plausible-sounding fake advisories can cause organizations to waste time investigating and patching non-existent vulnerabilities.

Don't be a meat proxy

You're frustrated with relying on AI output in conversations and code reviews, feeling it lacks value and understanding. The effort of reading, validating, and writing a response in your own words is what adds value.

Qwen3.8-Max: A New Bar for Coding and Cowork

Qwen Studio offers comprehensive functionality spanning chatbot, image and video understanding, image generation, document processing, web search integration, tool utilization, and artifacts.

Bonsai: Janestreet's UI Library

https://raw.githubusercontent.com/janestreet/bonsai/master/docs/assets/bonsai-logo.png
Bonsai is a UI library for building performant, reactive web applications in OCaml, inspired by Elm. It allows for composable state machines and incremental rendering, making it easy to manage state and UI updates.

Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone

https://opengraph.githubassets.com/900887719e4b9d96b5df78ad5b7b8dc1db54fe183ed58836d431d1f2f9054ce3/garagehq/nightcrawler
Nightcrawler is a smartphone-based penetration testing agent that automates network discovery, vulnerability scanning, and reporting without cloud connectivity. It uses a 1.2 billion parameter AI model to decide its actions and can even crack WPA2 networks if dropped without WiFi.

Prevent cognitive debt by manually retyping LLM-generated code

The user uses coding assistants to fast-forward through boring parts of projects, but manually types generated code to understand and adapt it, valuing comprehension over productivity. This workflow helps them build a mental model of their codebase and detect potential issues, allowing them to work faster and more efficiently.

AirLLM 70B inference with single 4GB GPU

https://raw.githubusercontent.com/lyogavin/airllm/main/assets/airllm_logo_sm.png
AirLLM is a library that reduces inference memory usage for large language models, allowing them to run on a single GPU card without quantization or pruning. It supports various models, including Llama, Qwen, DeepSeek, and more, and can be used with a simple one-line initialization.

Rust project goals: Immobile types and guaranteed destructors

https://opengraph.githubassets.com/33d3cf50b3908ad51294f7ade72bf32057f24a694ef2052ca1c523d336cff23a/rust-lang/rust-project-goals
Rust proposes introducing new traits like Move and Forget to make explicit what operations are possible on a type, allowing types to opt out of being moved or forgotten. This change aims to simplify immovable types and enable safe scoped spawn for async, while eventually deprecating the Pin trait.

The Abandoned Fish Sauce Terrorizing a Small Canadian Town

https://lede-admin.defector.com/wp-content/uploads/sites/28/2024/12/ugly-baby-salad.jpg?resize=2880%2C2880
A Canadian town, St. Mary's, has been plagued by a 20-year-old fish sauce stench from abandoned vats, but cleanup efforts have finally begun. The resulting fish sauce, if processed, might have a unique flavor profile due to prolonged fermentation, with notes of rancidity, amines, and possibly sweetness.

The true power of regular expressions (2012)

Regular expressions can match more than just regular languages, they can also match context-free languages, which include well-formed HTML, and some context-sensitive languages, but it's unknown whether they can match all context-sensitive languages. Regular expressions with backreferences are NP-complete, meaning they can solve any other NP problem, but it's generally not recommended to use ...

What DMARC Protects You From, and What It Does Not

DMARC is a protocol that checks if an email's visible From address matches the domain that authorized the message. It evaluates SPF and DKIM results to determine if the message is genuine.

Octane – React's programming model, compiled

https://octanejs.dev/og-image.png
Octane is a performance-first framework that compiles ahead of time, eliminating virtual DOM and dependency arrays. It allows for seamless migration from React, keeping components as plain functions with hooks and context.

ICE Collected Nearly 1M People's DNA Last Year–Including Young Children

https://media.wired.com/photos/6a6ced459baed1318e005118/16:10/w_2560%2Cc_limit/073126-SECURITY-ice-data-collection.jpg
US immigration authorities are collecting DNA from people in custody, including families and children, and sending it to a national database for crime-solving, despite a lack of clear explanation and consent. This expansion of DNA collection has sparked lawsuits and congressional scrutiny, with critics arguing it violates the Fourth Amendment and the rights of those detained.

Show HN: Isopolis – Isometric pixel map of SF

https://sf.isopolis.city/og.jpg
San Francisco as one giant isometric pixel painting — the city's real 3D geometry redrawn tile by tile by a fine-tuned image model.

Show HN: We Fixed UniFi's Slow PPPoE Performance with PPPoE Half-Bridge

https://arcbox.dev/_next/static/media/unifi-pppoe-half-bridge-acceleration.05.xn172zxo7d.png
ArcBox Labs' office had a 5 Gbps PPPoE connection behind a UniFi gateway but couldn't reach that speed due to the lack of PPPoE hardware acceleration in most UniFi gateways. To solve this issue, they implemented a PPPoE half-bridge acceleration using OpenWrt, which offloads PPPoE dialing to a dedicated device and hands the public IPv4 to the UniFi gateway via DHCP.

PISIGuard: Protect your personal and sensitive info when you chat with AI

https://raw.githubusercontent.com/mohamed--abdel-maksoud/pisiguard/main/src/icons/PISIGuard-icon-full.png
PISIGuard is a browser extension that hides personal and sensitive data from AI servers by replacing it with placeholders. It detects common sensitive information, masks it, and restores the original values in AI responses without sending data to external services.

Situational Awareness and the Impending Stock Market Volatility

https://www.emergingtrajectories.com/lh/situational-awareness-bigger-picture/images/volatility_over_time.jpg
Situational Awareness's asset price fluctuations are a result of market forces driving AI-related stocks up and down due to over-leveraging and over-concentration. This volatility is expected to continue as AI assets appreciate in value, driven by reflexivity, leverage, and fear of wealth loss.

Train Simulator Controller

https://z80.me/blog/tsc-2026-july/img/metalpanels_20260531a.jpg
The user has been building a physical train simulator in their apartment, modeled on the UK Class 80x passenger train, and has made significant progress on various aspects of the project, including a headlight control panel and sheet metal panels. They have also interfaced with Train Simulator and are working on integrating more realistic AWS sunflowers and warning horns into their setup.

Characterizing Warp Divergence from Pascal to Blackwell

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
Since Volta introduced Independent Thread Scheduling (ITS), NVIDIA GPUs have been widely assumed to handle warp divergence in a fixed manner. We test this assumption across Ampere, Hopper, and datacenter and consumer Blackwell GPUs, using pre-ITS Pascal as a baseline. Combining cycle-accurate microbenchmarks, hardware counters, and static analysis of compiler-generated SASS, we separate ...

The fading American Dream: Visa uncertainty drives Indian tech workers back home

https://thefederal.com/h-upload/2026/06/04/619307-pp.webp
Indian tech workers are returning from the US due to tightened visa rules, but India's job market is also slowing down. The number of returnees could exceed those heading to the US by the end of 2026, creating uncertainty for both sides.

Show HN: ssh ssh.place

https://ssh.place/canvas.png
The canvas is wider than your terminal, so scroll to pan around. shift+←/→ jumps a whole screen. This canvas is color only. The server turns down anything with a character in it, so you cannot write text here. Draw something instead. Your cooldown is tied to your SSH key, so reconnecting will not reset it. This page only reads the canvas. It changes over SSH and nowhere else.

Why we write our own C and C++ inference engines

https://localai.io/img/logo-mark.png
LocalAI's C++ ports of certain models offer significant footprint savings and comparable performance to their Python counterparts. These ports, such as vllm.cpp and depth-anything.cpp, achieve parity with the original models in terms of output and throughput.

9front "This Was Supposed to Be Fun" Released

http://9front.org/img/thiswassupposedtobefun.front.png
Multiple installation media are provided for various devices including PC, Raspberry Pi, and MNT Reform. Updates include bug fixes and new features for kernel, audio, and file systems.

CP/M-386 – CP/M for 386 protected mode, derived from CP/M‑68K

https://opengraph.githubassets.com/55c540041c3fca93caeaf359561eabdcdbaba6651881747dcf1ab59a805cd858/johnsonjh/cpm386
CP/M-386 BDOS is compatible with CP/M-68K 1.3 and CP/M 2.2, with added extensions for direct video access and high-resolution timing. It can be built on NetBSD, FreeBSD, and most recent Linux distributions, including CentOS, Fedora, and Ubuntu.

Show HN: Kakehashi – Experimental userspace to run macOS binaries on Linux ARM

https://opengraph.githubassets.com/3b6b6a3100120122dc8fff0c8b450edb077cd334acfc336347099211a8e6825d/wie-project/kakehashi
Kakehashi is a tool that runs Darwin CLI tools natively on Linux aarch64 by translating BSD syscalls and mapping a freestanding libSystem. It aims to provide a cost-effective alternative to running Darwin tools on macOS, with a focus on correctness and performance, and is suitable for use in CI environments.

SwiftUI After 7 Years

Note-Taking and Personal Knowledge Management

https://i.snap.as/91youjmK.jpeg
The user read an article by Brennan Kenneth Brown about Personal Knowledge Management (PKM) and found it to be misleading. The user argues that Brennan's article fails to critically examine the effectiveness of PKM systems and tools like Obsidian.

Autoregressive Language Model on the 6502 Processor

https://mattbeton.com/img/blog/bitnet-6502/attention-grows.svg
The user trained a tiny Mamba-based autoregressive language model and ran it on a BBC Micro from the 80s using a custom inference engine, generating text with a vocabulary of 26 letters and a space character. The project demonstrated the importance of mechanical sympathy in designing ML models, considering hardware constraints, and showed that a Mamba-based model can run inference on 8-bit ...

Why Book Corners won't sync contributions back to OpenStreetMap

https://www.andreagrandi.it/about/images/me_pycon_2019_2.jpg
Book Corners initially planned to contribute user-submitted libraries back to OpenStreetMap, but discovered that the process would require significant documentation, licensing, and operational responsibilities. Due to these costs, Book Corners has decided to suspend the contribution process, prioritizing its core purpose of helping people discover and share little free libraries.

Developers are attached to tools because tools encode trust

https://cdn.stackoverflow.co/images/jo7n4k8s/production/29bbae9c01de534b803084e4f0b9a77f9cd90e5c-12000x6300.jpg?rect=8,0,11985,6300&w=780&h=410&auto=format&dpr=2
Developers are struggling to trust AI tools due to their unpredictability and lack of transparency, which can lead to broken processes and decreased productivity. To build trust, teams need to establish a more deliberate and explicitly-defined workflow that preserves human judgment and provides the right context for AI agents.