Feed aggregator
The Editorial Mindset – By Troy Howard
Article URL: https://blog.thoward37.me/articles/the-editorial-mindset/
Comments URL: https://news.ycombinator.com/item?id=49617874
Points: 1
# Comments: 1
A Universe of My Own
Article URL: https://catbee.ca/universe/
Comments URL: https://news.ycombinator.com/item?id=49617871
Points: 1
# Comments: 1
Show HN: Owned. Own a piece of the world and make it visible
Article URL: https://owned.bennytaccardi.com/
Comments URL: https://news.ycombinator.com/item?id=49617863
Points: 2
# Comments: 0
Show HN: Genotype: language that compiles to idiomatic TS, Rust and Python
Hey HN! I just shipped the first public version of a new programming language that I have worked on for the past two years.
Its goal is to help synchronize types between TS, Rust, and Python (more to come). Two main use cases are the API client libraries and client-server interop, i.e., a TS web app talking to a Rust server.
I focused on making it as flexible as possible but always produced idiomatic types that look and feel like they were carefully crafted by humans. It was a challenge, e.g., I had to test 7 Python versions for every language feature or had to implement Rust literals runtime.
It's written in Rust, btw ;-)
Comments URL: https://news.ycombinator.com/item?id=49617861
Points: 2
# Comments: 0
The 40 Year Old Kernel Bug (iOS, macOS, XNU, etc.)
Article URL: https://yuvalino.com/how-can-you-not-be-romantic-about-unix-domain-sockets
Comments URL: https://news.ycombinator.com/item?id=49617860
Points: 2
# Comments: 0
The Story of a Hyperbaric Weld
Article URL: https://medium.com/@francis.hermans4/the-story-of-a-hyperbaric-weld-bfd80a13cf00
Comments URL: https://news.ycombinator.com/item?id=49617843
Points: 1
# Comments: 1
Teaching NumPy's ufuncs new tricks
Article URL: https://labs.quansight.org/blog/teaching-numpys-ufuncs-new-tricks
Comments URL: https://news.ycombinator.com/item?id=49617808
Points: 1
# Comments: 0
Magic mushroom compound may prevent chemotherapy pain
Rustuna: A Faster Optuna Implementation in Rust
Article URL: https://medium.com/optuna/announcing-rustuna-cc82a6815bf7
Comments URL: https://news.ycombinator.com/item?id=49617796
Points: 2
# Comments: 0
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Image: Shutterstock.com, Kirill Makarov.
This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.
There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.
Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.
Also scary is CVE-2026-69829, a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction.
Microsoft’s summary of the security updates released today. Image: msrc.microsoft.com.
Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).
Tyler Reguly, associate director of security research and development at Fortra, said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system.
“It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.”
Satnam Narang is senior staff research engineer Tenable. Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.
“AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” he said. “It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.”
Of course, regular Windows users don’t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program’s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.
Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear to be causing problems. As always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency.
Microsoft has released another record breaking Patch Tuesday update with almost 1,000 flaws in scope.
Phone and tablet users will be required to verify their ages with credit card or official ID under government plans to prevent under-18s viewing nude images.
Meta Releases Muse, a Personal AI Agent With Privacy ‘Built Into It’
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.
This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
Show HN: Remarc – better contextual feedback for AI agents
Like any side project, Remarc started with my own problem: there was no good way to give AI coding agents contextual feedback on their own output. There are plenty of tools for collaborating with humans, but surprisingly few for collaborating with AI. Chat was not cutting it for the feedback I wanted to give:
This thing in the implementation plan? Change it to that. What did you mean here? See this button? Here is a screenshot. I circled it because it is missing a hover state. This sentence in the third paragraph? Rephrase it.
If you are an opinionated builder, this gets clunky quickly. You either dictate paragraphs of messy feedback or resolve every detail one by one. AI is good at parsing mess, but garbage in, garbage out still applies.
I could get products to 90% quickly. The last 10% of feedback and polish was the bottleneck. So I built Remarc.
Remarc lets you select text in any Mac app, capture and annotate a screenshot, or comment on a web element. Each comment keeps its original context, status, and session. A connected agent can read the session, work through it, update statuses, and leave resolution summaries over MCP.
Think of it like leaving comments on a google doc vs sending a long rambling feedback note via Slack - the more granular you get with your feedback, the more it benefits from structure & better context.
Remarc is free and open source, with no account, subscription, or telemetry.
https://remarc.app/ https://github.com/metedata/Remarc
Comments URL: https://news.ycombinator.com/item?id=49615660
Points: 1
# Comments: 0
Beyond 40 Gbps: Processing OPRA in real-time
Article URL: https://databento.com/blog/beyond-40-gbps-processing-opra-in-real-time
Comments URL: https://news.ycombinator.com/item?id=49615653
Points: 1
# Comments: 0
Countries with France,UK announce sanctions on Israeli settlements in WestBank
Edith Pritchett's Bayeux tapestry for the modern age
Article URL: https://www.theguardian.com/world/ng-interactive/2026/sep/05/alternative-bayeux-tapestry-2026-edith-pritchett
Comments URL: https://news.ycombinator.com/item?id=49615633
Points: 1
# Comments: 0
