SShortSingh.
0
ProgrammingDEV Community ·

Critical SAP NetWeaver Flaw CVE-2026-58240 Allows Unauthenticated Cluster-Wide RCE

A critical vulnerability tracked as CVE-2026-58240, dubbed S4GET, has been disclosed by Onapsis on September 8, 2026, affecting SAP NetWeaver Message Server. The flaw allows an unauthenticated attacker to manipulate the Message Server into treating their IP address as a trusted cluster host, subsequently enabling OS command execution via SAP Gateway with administrator-level privileges. Commands run as the 'adm' OS user across all application servers in the cluster, potentially enabling credential theft, backdoor installation, and lateral movement. SAP has issued Security Note 3759472 with patches across multiple kernel branches, and administrators are urged to restrict SAP GUI connection sources and remove direct internet exposure of the Message Server port. No real-world exploitation has been publicly reported, but the attack requires no user interaction and poses severe risk to any reachable SAP deployment.

0
ProgrammingDEV Community ·

Critical SAP Kernel Flaw CVE-2026-44756 Allows Pre-Auth Remote Code Execution

A maximum-severity vulnerability dubbed OVERPASS (CVE-2026-44756, CVSS 10.0) has been disclosed in the SAP Kernel, affecting products including SAP NetWeaver AS ABAP, SAP Web Dispatcher, and SAP S/4HANA. The flaw is a buffer overflow in Extended Passport (EPP) processing that can be triggered before any authentication takes place, allowing attackers to execute arbitrary OS commands with SAP administrative privileges. It is exploitable remotely over HTTP(S), SAP GUI, or RFC, requiring no valid SAP account or user interaction. SAP addressed the issue through Security Note 3747649, published on its September 2026 Security Patch Day, and urges organizations to prioritize patching internet-facing systems first. Until patches are applied, SAP recommends restricting access via SAProuter, jump hosts, and Web Dispatcher, while monitoring for application-layer anomalies and suspicious SAP process activity.

0
IndiaNDTV ·

India Amends E-Commerce Rules to Curb Dark Patterns and Sponsored Listings

The Indian government has introduced the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, targeting deceptive practices on online platforms. The amendments aim to address dark patterns and undisclosed sponsored listings that mislead consumers. These changes were announced by the Centre and are designed to strengthen transparency and accountability in the e-commerce sector. The new rules are set to come into effect from January 1, 2027, giving platforms time to comply with the updated regulations.

0
IndiaTimes of India ·

Shami stays motivated in domestic cricket, marks 100th first-class match milestone

Indian pacer Mohammed Shami recently celebrated his 100th first-class match appearance with a Duleep Trophy victory. Despite his current absence from the national team, Shami says he remains strongly self-motivated and focused on performing at the highest level. He stressed that hard work is the cornerstone of his approach, leaving the rest to fate. Shami continues to look for every opportunity to make a meaningful contribution to his team's success in domestic cricket.

0
IndiaTimes of India ·

BRICS Summit Triggers Traffic Restrictions Across Delhi; Commuters Advised to Plan Ahead

Delhi is set to experience significant traffic disruptions due to the upcoming BRICS Summit being held in the city. VVIP convoy movements will lead to temporary road closures and diversions at various points, particularly affecting routes to the airport, central, and south Delhi. Commuters should anticipate longer travel times and are advised to plan their journeys in advance. Delhi Metro and bus services will continue to operate, though some route adjustments are possible. Authorities have urged residents to rely on official traffic updates for the most accurate and current information.

0
ProgrammingDEV Community ·

n8n Launches AI Assistant with Credential Approval Gates and Credit-Based Usage

n8n has released n8n Assistant, a preview chat-based tool that helps users plan, build, test, and debug automation workflows directly within the n8n canvas. The assistant introduces explicit approval controls, requiring user confirmation before accessing credentials or activating any workflow, ensuring AI actions do not affect live operations without human sign-off. Credentials are never exposed to the AI model and continue to be managed through n8n's standard credential screens. The feature operates on a separate token-based AI credit system, distinct from the older AI Workflow Builder, with credit consumption varying based on the complexity of assistance required. n8n notes the tool is still in preview and may contain errors, so workflows should be reviewed and tested before activation, especially those handling sensitive or business-critical data.

0
ProgrammingDEV Community ·

How to Design Make.com Workflows That Stay Maintainable Over Time

A developer writing for DEV Community outlines practical principles for building automation workflows on Make.com that remain manageable long-term. The core advice is to keep each scenario focused on a single purpose rather than chaining every action into one complex flow. Assigning clear responsibilities to each service — such as Telegram for notifications and Notion for data storage — makes debugging faster and more predictable. The author also recommends validating incoming webhook data early, standardizing logic across workflows, and maintaining structured logs that capture order IDs, timestamps, statuses, and errors. These practices collectively reduce the risk of silent failures and make it easier to diagnose problems when automations break unexpectedly.

0
ProgrammingHacker News ·

Survey Reveals Who People Turn to for Support During Difficult Times

A data-driven analysis explores the support networks people rely on when facing personal struggles. The findings, published on the 'Graphs About Religion' platform, examine patterns in who individuals choose to confide in during hard times. The research appears to investigate the role of various relationships, including friends, family, and religious figures, in providing emotional support. The article has gained modest attention on Hacker News, prompting early discussion among readers.

0
ProgrammingDEV Community ·

Developer Builds Open-Source Bracket Generator for Non-Power-of-Two Player Counts

A developer has created a single-elimination tournament bracket generator that correctly handles participant counts that are not powers of two, such as 6, 10, or 14. The tool automatically assigns BYE slots using a mirrored seeding algorithm so that top seeds are placed in opposite halves of the bracket. It accepts player names via comma- or newline-separated input, strips duplicates, and refuses to generate a bracket for fewer than two distinct participants. Winners progress automatically through the bracket by index position, and any change to an earlier round triggers recalculation of all subsequent rounds. The generator offers both a shuffled and an ordered seeding mode, making it suited for small, informally organised tournaments.

0
ProgrammingDEV Community ·

Developer builds browser-based tool to analyze SQL schemas locally without cloud upload

A developer has created Code Architect Pro, a browser-based tool designed to analyze SQL database schemas entirely on the user's device without sending data to any external server. The tool uses JavaScript and WebAssembly to parse SQL dump files locally, generating visual schema graphs and flagging issues such as missing indexes, normalization problems, and inefficient table relationships. During testing on a legacy e-commerce database, the tool identified a missing index on a foreign key join between an orders and users table, and flagged an Entity-Attribute-Value pattern in a product attributes table. The developer built it as a privacy-first alternative to cloud-based database analysis tools, noting that schema files often contain sensitive or proprietary information. The project reflects a broader trend toward local-first software that gives developers greater control over their data and infrastructure decisions.

0
ProgrammingDEV Community ·

Nielsen's 30-Year UX Thresholds Break Down When Applied to Voice AI

Jakob Nielsen's 1993 response-time thresholds — 100ms, 1 second, and 10 seconds — have long defined acceptable UI performance, but researchers and developers now argue they don't translate well to voice interfaces. Unlike graphical UIs, voice systems offer no visual feedback such as loading spinners or typing indicators, meaning silence is the only signal a user receives while waiting for a response. Without these visual cues, even a one-second delay can feel like a dropped connection or a system failure, pushing the effective tolerance threshold down to around 300 milliseconds. Studies on human conversation, including Stivers et al. (2009), show that natural turn-taking gaps average roughly 200ms, meaning voice AI must respond far faster than web interfaces to feel natural. Developers are responding by using brief auditory acknowledgements — chimes or soft sounds — to fill the perceptual gap and signal that the system is processing.

0
Crypto & Web3CoinDesk ·

Researchers Halve Estimated Timeline for Quantum Attack on Bitcoin and Ethereum

Crypto researchers have significantly revised downward their estimates for when quantum computers could threaten Bitcoin and Ethereum, cutting the projected timeline by 50%. A new paper shared with CoinDesk demonstrates that both humans and AI agents have outperformed Google's March benchmark on a key calculation central to Shor's algorithm. Shor's algorithm is the quantum method considered most capable of breaking the cryptographic protections securing major blockchain networks. The improved performance on this core computation adds fresh urgency to ongoing debates about how quickly the crypto industry must develop quantum-resistant defenses.

0
ProgrammingDEV Community ·

Four Webhook Security Patterns Every Async Pipeline Developer Should Know

A developer building ProofLedger, an anchoring and proof workflow platform, has outlined four recurring security challenges in asynchronous webhook-based systems. The core issue is that webhook endpoints are publicly accessible URLs, making them vulnerable to spoofed requests if incoming data is trusted without verification. The recommended fix is HMAC-SHA256 signature validation, where both sender and receiver use a shared secret to sign and verify the raw request body, with timing-safe comparison to prevent byte-by-byte guessing attacks. Since webhook senders retry on timeouts, handlers must also implement idempotency using a unique event ID checked against a database before any side-effecting logic runs. These patterns apply broadly to any system relying on delayed notifications, including payment confirmations, video transcoding, and background export workflows.

0
ProgrammingDEV Community ·

Python script builds foreclosure watchlist using single API instead of multiple scrapers

A developer behind the Foreclosure Finder API on RapidAPI has published a walkthrough showing how to build a ZIP-code-based foreclosure watchlist in Python using only the standard library. The tool queries listings within a 25-mile radius of a given ZIP code, filtering by property type, bedroom count, and price range, then exports up to 100 results to a CSV file. Foreclosure Finder aggregates data from five sources including Auction.com, HUD HomeStore, Fannie Mae HomePath, Freddie Mac HomeSteps, and Redfin. The API offers a free evaluation tier with 300 monthly requests, while a paid PRO plan costs $10 per month for 10,000 requests and full data fields. The guide also covers error handling for partial source failures and CSV formula injection, ensuring the watchlist remains reliable even when one data source goes offline.

0
ProgrammingDEV Community ·

Why a simple WordPress domain swap can silently break your entire database

Changing a WordPress domain via plain search-and-replace corrupts the database because WordPress stores data using stacked encodings — PHP serialization, JSON, and raw strings — all nested within single column values. PHP serialization embeds byte-length counts alongside strings, so replacing a domain with one of a different length invalidates those counts, causing unserialize() to fail and affected page elements to render blank. Page builders like Elementor worsen the problem by storing JSON inside serialized PHP, and json_encode() escapes forward slashes by default, meaning a URL search can return zero matches even when the URL is visibly present in the row. The correct approach is to fully decode each encoding layer, replace values only within leaf strings, then re-encode each layer while preserving the original escaping conventions. Skipping any of these steps risks silent data loss that does not surface as an error but simply causes layouts, widgets, or options to disappear.

0
TechnologyTechCrunch ·

Snapchat launches event-planning features to rival party app Partiful

Snapchat has introduced a new set of event-planning features aimed at competing with popular social planning app Partiful. The tools are designed to help users organize a wide variety of gatherings, ranging from birthday parties and sports events to casual hangouts and study sessions. The move signals Snapchat's intent to expand its social utility beyond messaging and stories. By integrating event coordination directly into the platform, Snapchat hopes to become a more central hub for its users' social lives.

← NewerPage 1026 of 4984Older →