Feed aggregator
Show HN: An MCP server that turns async-work practices into tools
Article URL: https://github.com/open-and-async/mcp
Comments URL: https://news.ycombinator.com/item?id=48994186
Points: 1
# Comments: 0
The World's 2,400 Castles
Article URL: https://thecastlemap.com/
Comments URL: https://news.ycombinator.com/item?id=48994178
Points: 3
# Comments: 0
Structured Evaluation Pipelines to Improve Your AI Workflows
Article URL: https://heltweg.org/posts/structured-evaluation-pipelines-to-improve-your-ai-workflows/
Comments URL: https://news.ycombinator.com/item?id=48994169
Points: 1
# Comments: 0
The Crime of Holding Your Government Accountable
Article URL: https://lndnitc.substack.com/p/delhi-protests
Comments URL: https://news.ycombinator.com/item?id=48994152
Points: 2
# Comments: 0
What 25 Years of Robot Automation Research Predicts About AI and Your Job
Article URL: https://twitter.com/cahidarda/status/2073909304390746153
Comments URL: https://news.ycombinator.com/item?id=48994144
Points: 1
# Comments: 0
Why non-invasive glucose monitoring is hard
Article URL: https://www.empirical.health/blog/non-invasive-glucose-monitoring-wearables/
Comments URL: https://news.ycombinator.com/item?id=48994132
Points: 2
# Comments: 0
France's Anssi Will Block PQC-Free Products from Certification Starting 2027
Article URL: https://postquantum.com/security-pqc/anssi-pqc-certification-2027/
Comments URL: https://news.ycombinator.com/item?id=48994116
Points: 6
# Comments: 0
Hamilton Lane's *Office Space* Problem
Article URL: https://thealtview.substack.com/p/hamilton-lanesoffice-space-problem
Comments URL: https://news.ycombinator.com/item?id=48994110
Points: 1
# Comments: 0
The Light Flip Is the Stylish Dumb Flip Phone of Your Dreams
Article URL: https://www.wired.com/story/light-flip-is-the-modern-stylish-dumb-flip-phone-of-your-luddite-dreams/
Comments URL: https://news.ycombinator.com/item?id=48994108
Points: 3
# Comments: 1
Central Reference for 3100 APIs
Article URL: https://github.com/mindcloud-inc/universal-api-reference/blob/main/README.md
Comments URL: https://news.ycombinator.com/item?id=48994106
Points: 1
# Comments: 0
How do security teams distinguish between people and AI? It's getting harder, but behavioral biometrics might help discern human users from machine impersonators.
What happens if you visit a WordPress site hacked through wp2shell?
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
Because a hacked website becomes a delivery mechanism for scams, credential theft, malware, and malicious redirects.
The wp2shell vulnerabilities are especially concerning because they affect WordPress Core itself, don’t require a malicious or vulnerable plugin, and can be exploited without authentication on vulnerable versions. Experts say the chain can lead to full administrative control of a site and remote code execution with web server privileges, meaning an attacker can change what the site serves to visitors.
And cybercriminals are already doing their dirty work:
“Exploitation activity began within hours of the patch release. Wordfence observed endpoint probing and SQL injection attempts the same evening, and public proof-of-concept code was reported in the days that followed.”
Once attackers control a WordPress site, they rarely stop at defacement. A common next step is to quietly inject JavaScript, redirect visitors to malicious pages, or load content from attacker-controlled infrastructure. That can expose visitors to fake login pages, scam pop-ups, browser-based malware, or drive-by downloads, depending on the attacker’s goals.
The possible harmThis isn’t an exhaustive list, but these are some of the ways visitors to a wp2shell-compromised site could be affected:
- Credential theft. Attackers can inject fake login forms or iframe-based overlays that imitate Microsoft 365, Google, banking, or social media sign-in pages to steal usernames and passwords.
- Malware delivery. The site can be turned into a staging point for browser exploitation, malicious downloads, or redirect visitors to malware-hosting pages.
- Scams and fraud. Visitors may be redirected to fake support pages, fake giveaways, or fraudulent payment prompts.
- Tracking and profiling. Attackers can use injected scripts to fingerprint visitors, harvest browser details, and track victims across sessions.
- Search and reputation damage. Search engines and security tools may flag the site, which can expose visitors to warnings and reduce trust long after the initial compromise.
Be cautious, even on websites you normally trust. If something looks different from what you’d expect, treat it as a warning sign.
Be especially wary of unexpected login prompts, download requests, and browser warnings. For site owners, it means patching quickly and treating compromise as a possibility, not an edge case.
Keep your operating system, browsers, and security software up to date. Compromised websites can also try to exploit known vulnerabilities on visitors’ devices.
Use an up-to-date, real-time anti-malware solution that can alarm you if a website tries to infect your device.
Pro tip: Use Malwarebytes’ free Browser Guard extension. It uses heuristic detection to identify malicious websites, block scams, and protect against other web-based threats.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Show HN: LLM Context profiler for tracking context usage by tools, agents, MCPs
Article URL: https://github.com/RimantasZ/contextspy
Comments URL: https://news.ycombinator.com/item?id=48992375
Points: 1
# Comments: 0
Our Interfaces Have Lost Their Senses
Article URL: https://wattenberger.com/thoughts/our-interfaces-have-lost-their-senses/
Comments URL: https://news.ycombinator.com/item?id=48992368
Points: 1
# Comments: 0
Security versus Privacy
Article URL: https://ldstephens.net/posts/security-versus-privacy/
Comments URL: https://news.ycombinator.com/item?id=48992364
Points: 2
# Comments: 0
TSMC to raise chipmaking prices by up to 10% in 2027, Nikkei Asia reports
Article URL: https://www.reuters.com/world/asia-pacific/tsmc-raise-chipmaking-prices-by-up-10-2027-nikkei-asia-reports-2026-07-21/
Comments URL: https://news.ycombinator.com/item?id=48992328
Points: 2
# Comments: 0
PCjs Machines
Article URL: https://www.pcjs.org/
Comments URL: https://news.ycombinator.com/item?id=48992323
Points: 2
# Comments: 0
l with Jacob Loveless [video]
Article URL: https://www.youtube.com/watch?v=whY51vONKs4
Comments URL: https://news.ycombinator.com/item?id=48992319
Points: 2
# Comments: 0
Why Are There No Empires in Age of Empires? (2019)
Article URL: https://acoup.blog/2019/11/22/collections-why-are-there-no-empires-in-age-of-empires/
Comments URL: https://news.ycombinator.com/item?id=48992315
Points: 2
# Comments: 0
Nesso-1: Accelerating Open-Source Binding Affinity Predictions [pdf]
Article URL: https://www.valencelabs.com/wp-content/uploads/2026/07/nesso1.pdf
Comments URL: https://news.ycombinator.com/item?id=48992304
Points: 2
# Comments: 1
