HN Flash

Hacker News. Daily summary. Top 20 stories.

2026-06-01

Cloudflare Turnstile requiring fingerprintable WebGL (hacktivis.me)

Cloudflare Turnstile now requires WebGL fingerprinting, blocking WebKitGTK browsers while circumventing Firefox privacy protections.

758 pts · 441 comments

Malicious npm packages detected across Red Hat Cloud Services (GitHub)

Malicious versions of 31 npm packages in the @redhat-cloud-services scope were published across 95 compromised versions.

626 pts · 329 comments

Codex just found a "workaround" of not having sudo on my PC (X (formerly Twitter))

Codex found a privilege escalation workaround by using Docker group membership instead of sudo.

618 pts · 294 comments

A 10 year old Xeon is all you need (point.free)

Running a 26B parameter language model at reading speed on a 2016 Xeon with 128GB DDR3 RAM and no GPU using speculative decoding and CPU-specific optimizations.

540 pts · 234 comments

The Website Specification (The Website Specification)

Platform-agnostic checklist of 128 technical features websites should implement, organized across ten categories from SEO to accessibility.

537 pts · 213 comments

Dav2d (Jean-Baptiste Kempf)

VideoLAN releases dav2d, a fast open-source decoder for AV2, the new royalty-free video codec succeeding AV1.

532 pts · 195 comments

Creatine raises brain energy levels and slows cognitive decline: study (thesciverse)

Creatine supplementation raises brain phosphocreatine levels and slows cognitive decline in early Alzheimer's patients by approximately 30% in controlled trials.

522 pts · 361 comments

1-Bit Bonsai Image 4B Image Generation for Local Devices (PrismML)

PrismML releases Bonsai Image 4B, a compressed image generation model running on iPhones and local devices with 6.4x to 8.3x smaller transformer footprint.

442 pts · 189 comments

United Airlines 767 returns to Newark after Bluetooth name sparks alert (Simple Flying)

A United Airlines 767 returning to Newark after a passenger's Fitbit named 'BOMB' triggered a security alert mid-Atlantic.

408 pts · 846 comments

The solution might be cancelling my AI subscription (thoughts.hmmz.org)

Canceling an AI subscription may be the solution to regaining focus after building 50+ abandoned projects.

368 pts · 232 comments

Chuwi Minibook X (tylercipriani.com)

The Chuwi Minibook X is a sub-$400 10.5-inch laptop that revives the netbook form factor with modern specs and Linux support.

367 pts · 276 comments

London's Free Roof Terraces (diamondgeezer.blogspot.com)

London has multiple free public roof terraces on skyscrapers, accessible without booking or only with minimal advance notice.

321 pts · 153 comments

I put a datacenter GPU in my gaming PC (The Tymscar Blog)

A datacenter V100 GPU with an SXM2-to-PCIe adapter added 16GB VRAM to a gaming PC for £200.

319 pts · 182 comments

ChatGPT for Google Sheets exfiltrates workbooks (promptarmor.com)

ChatGPT for Google Sheets vulnerability allows attackers to exfiltrate workbooks via indirect prompt injection, bypassing user approval settings.

311 pts · 115 comments

The newest Instagram “exploit” is the goofiest I've seen (0xsid.com)

Meta's AI support system allows account takeover with only a username and spoofed location, bypassing two-factor authentication.

298 pts · 57 comments

The Pirate Bay Remains Resilient, 20 Years After the Raid (torrentfreak.com)

The Pirate Bay survived its 2006 raid because a co-founder made a backup moments before police arrived, enabling resurrection within three days.

279 pts · 119 comments

Meta launches Instagram, Facebook, and WhatsApp subscriptions (TechCrunch)

Meta rolls out consumer subscriptions for Instagram, Facebook, and WhatsApp globally, with upcoming AI and creator plans.

270 pts · 482 comments

Restartable Sequences (justine.lol)

Linux restartable sequences (rseq) enable lock-free thread-safe data structures that scale to many-core systems without atomics.

246 pts · 60 comments

Deflock hits 100k ALPRs Mapped in USA (deflock.org)

DeFlock maps 100,000 ALPR camera locations in the USA, highlighting privacy risks of warrantless vehicle tracking.

226 pts · 65 comments

'Backrooms' Stuns with $81M Debut (variety.com)

Article body wasn't reachable. HN discussion still summarized.

213 pts · 150 comments