SShortSingh.
0
ProgrammingDEV Community ·

Graduate Student Exposes Trojan Hidden in Pirated Flexense Software Using Fake Internet Lab

A graduate student analyzed FlexenseActivator.exe, a trojan disguised as a software activation tool for Flexense disk management products, as part of a malware analysis project. The malware, detected by 33 of 76 antivirus vendors on VirusTotal, is distributed inside pirated RAR and ZIP archives and checks for a real internet connection before executing malicious activity. To bypass this evasion technique, the researcher built a two-VM isolated lab using REMnux and INetSim to simulate a convincing fake internet environment. Static analysis revealed the binary was packed with UPX, had near-maximum entropy of 7.916, and contained mismatched timestamps suggesting recycled Delphi templates — all common obfuscation tactics. The case highlights how software piracy remains a primary infection vector and how sandbox-aware malware can evade detection on disconnected analysis machines.

0
IndiaNDTV ·

Canada Hits Back With Up to 50% Tariffs on 700 American Products

Canada announced on Tuesday that it will impose tariffs of up to 50% on approximately 700 American goods. Ottawa stated that its tariff rates will mirror those set by the United States. The retaliatory measures are set to affect key sectors including steel, dairy, and electronics. The move marks a significant escalation in the ongoing trade dispute between the two neighboring countries.

0
ProgrammingDEV Community ·

Midnight Blockchain Can Partially Succeed: What Developers Must Know

Unlike Ethereum or Solana, Midnight's transaction model allows a transaction to partially succeed — with some sections committing to the ledger even if others fail. Every Midnight transaction passes through three sequential stages: well-formedness, a guaranteed phase, and a fallible phase. If a transaction fails during the guaranteed phase it is rejected entirely, but a failure in the fallible phase still preserves any state changes made during the guaranteed phase. Critically, fees for all phases are collected upfront during the guaranteed phase and are not refunded if fallible work fails. Developers building on Midnight must account for this partial-success model to avoid unintended half-updated states and unexpected fee losses.

0
Crypto & Web3CoinDesk ·

LayerZero Launches Trading Infrastructure for Crypto and Tokenized Assets

LayerZero has unveiled a new trading infrastructure designed to serve both cryptocurrency and tokenized markets. The system operates on LayerZero's own Zero blockchain network. Financial giant Citadel Securities is backing the initiative, signaling strong institutional interest. Major market institutions DTCC and ICE are also exploring potential applications for the infrastructure. Following the announcement, LayerZero's native token ZRO saw a significant price surge.

0
IndiaTimes of India ·

Patriots Coach Vrabel Flags Roster Depth Concerns Ahead of New Season

New England Patriots head coach Mike Vrabel has publicly acknowledged the team's lack of roster depth, sparking discussion about player importance and squad composition. His comments come amid a series of recent personnel changes within the organization. Vrabel stated that a key priority is developing late-round draft picks and backup players to strengthen the team. The Patriots are focused on building a more resilient roster as they prepare for the upcoming season.

0
ProgrammingHacker News ·

Building iPhone App Blockers Is Far More Complex Than Developers Expect

A technical blog post on UseFella explores the hidden engineering challenges behind building app blocker tools for iPhones. Apple's iOS imposes strict sandboxing and system restrictions that limit how third-party apps can monitor or control other applications. Developers cannot directly block apps the way Android or desktop systems might allow, forcing them to rely on Apple's Screen Time API and other constrained frameworks. These limitations mean app blockers on iPhone often require creative workarounds that add significant development complexity. The post sheds light on why such tools, despite appearing simple to end users, are technically demanding to build on iOS.

0
ProgrammingDEV Community ·

Supabase .NET SDK v8.0.0 to Feature Overridable HTTP Client After Developer Feedback

The Supabase .NET SDK development log #7 details recent progress on the SDK's quality gate and upcoming v8.0.0 release. A bug causing inconsistent code coverage results between local environments and GitHub Workflows with async tasks was identified and resolved. The most significant update is an HTTP client rework that will allow developers to override the SDK's internal HTTP client, addressing long-standing requests for support with testing, connection pooling, and retry policies. Contributor experience has also been improved by automating code formatting after pushes to master and reducing friction during pull request reviews. The lead developer noted a growing wave of contributions and indicated that more updates would follow after attending a gaming conference in Germany.

0
ProgrammingHacker News ·

Anthropic Projects Over $30 Trillion in Potential Future Revenue

Anthropic, the AI safety company behind the Claude model, is reportedly planning to share projections of over $30 trillion in potential revenue with investors. The figures were expected to be communicated as part of the company's investor outreach. Such projections reflect the broader optimism surrounding AI's long-term commercial opportunity. The disclosure was reported by The Wall Street Journal, though the timeline and basis for the estimates were not fully detailed.

0
ProgrammingDEV Community ·

How to recover a dropped Git stash using git fsck before garbage collection

Accidentally dropping a Git stash does not immediately delete the underlying commit objects, as Git removes only the reference pointing to them. The git fsck command can scan the object database and surface these now-unreferenced commits, typically returning two hits per dropped stash. Developers can identify the correct stash commit by checking which unreachable commit has two parents, a structural trait unique to stash entries. Once the SHA is found, git stash apply can restore the changes directly without needing a named ref. However, recovery is time-sensitive, since running git gc will permanently prune orphaned objects once the default expiry window passes.

0
ProgrammingDEV Community ·

Developer Builds Browser-Based World Conquest Game Using Next.js 16 and Cloudflare

A developer has launched 195-0, a browser-based world conquest draft game built with Next.js 16, Cloudflare Workers, and a Cloudflare D1 database. Players assemble a five-person cabinet, assign roles, and run a simulation to see how many of the world's 195 nations their team can conquer. The game offers two modes: a Classic Draft with flexible rerolls and a Daily Challenge where all players face identical rounds seeded by a deterministic PRNG tied to the UTC date. Scoring starts at 125 points and factors in role-fit percentages, combo bonuses, alliance bonuses, and random battlefield variance, with the final score capped at 195. A leaderboard backed by Cloudflare D1 tracks top scores across Daily, Classic Today, and All Time categories, requiring no signup or installation to play.

0
TechnologyArs Technica ·

Lab suppliers caught using manipulated images to sell research antibodies

Life science supply companies have been widely using manipulated images in their marketing materials for research antibodies, a practice that would result in retraction if found in academic papers. The issue involves alterations to experimental result images used to promote and sell these laboratory reagents. The scale of the problem appears significant, with such manipulations described as widespread across multiple suppliers. This raises serious concerns about the reliability of product claims that researchers depend on when selecting materials for scientific experiments. The findings highlight a double standard between the strict image integrity rules applied to published research and the largely unregulated marketing practices of commercial suppliers.

0
IndiaTimes of India ·

Cricket Australia clears Anaya Bangar to play women's cricket from March 2027

Cricket Australia has confirmed Anaya Bangar's eligibility to participate in elite women's cricket under its inclusion policy. The approval opens a potential pathway for her to compete in the Women's Big Bash League starting March 2027. However, securing a franchise contract will depend entirely on her on-field performances. Bangar's case is being seen as a significant development for transgender athletes navigating pathways in professional sport.

0
TechnologyThe Verge ·

Polestar says US blindsided it with sales ban under connected-vehicle rules

Electric vehicle maker Polestar has been barred from selling new cars in the United States starting with the 2027 model year, following a rejection by the Commerce Department citing national security concerns over connected-vehicle software linked to China. In an August 18th letter to dealers, Polestar said it was given no clear explanation for the denial after months of engagement with the Trump administration. The company expressed confusion over the decision, noting that its sister company Volvo received approval to continue US sales in May 2026 despite having similar corporate ownership ties. The ban stems from a federal rule prohibiting vehicles that use connected software originating from China. Polestar said it does not yet have a clear path forward regarding its US market presence.

0
SpaceNASA ·

NASA's Chandra Observatory Releases New Gallery of Diverse Galaxy Images

NASA's Chandra X-ray Observatory has released a new gallery of galactic images captured alongside data from other telescopes. The collection highlights the wide variety of galaxies found across the universe, showcasing differences in size, shape, and structure. Astronomers typically classify galaxies into three main categories, including spirals such as our own Milky Way. The gallery aims to illustrate the distinct characteristics that make each galaxy unique.

0
ProgrammingDEV Community ·

Developer explains how a deliberately delayed public data page nearly leaked paid content

A developer selling a live data stream built a public page showing the same day's figures with a deliberate time delay, positioned between a free historical archive and a paid real-time feed. The design rule adopted was that the free page introduces no new category of data — every field shown is already available for free the next morning, with timing being the only thing that is metered. Two security bugs emerged only in production, including a path-normalisation flaw where alternate URL spellings like double slashes or different letter cases bypassed access controls and resolved directly to the protected file. To prevent the delay from shrinking to zero during pipeline stalls, the developer measured lag against the data itself rather than the system clock, ensuring failures make the page older rather than fresher. The trim logic was written as a pure function with its own test suite before being wired into any route, keeping the paid file accessible through exactly one controlled code path.

0
ProgrammingDEV Community ·

Silent Skill Failures Expose Hidden Gaps in AI Agent Portability Tools

A developer migrating six Claude Code skills to OpenCode found that all files loaded without errors, yet one skill silently failed due to unsupported frontmatter fields like model pinning and dependency declarations. An audit revealed that Claude Code supports over 15 frontmatter fields while OpenCode recognizes only five, meaning harness-specific configurations are dropped without any warning. Five of the six skills ported cleanly only because they happened to use the minimal portable subset of name, description, and markdown body. Popular conversion tools such as farmage/opencode-skills and crosstrain move skill files between platforms but do not flag what functionality breaks in the process. The developer published an audit framework and a five-minute compatibility test to help users identify which skills transfer safely and which require a rebuild.

0
ProgrammingHacker News ·

Guide Shows How to Run Minecraft Inside Windows Sandbox for AI Agents

A technical guide published on cua.ai explains how to run Minecraft within a Windows Sandbox environment. The setup is designed for use with computer use agents, which are AI systems that interact with software interfaces. Windows Sandbox provides an isolated, disposable environment, making it suitable for testing agent behavior in games like Minecraft. The guide is aimed at developers building or experimenting with AI-driven computer interaction systems.

0
IndiaTimes of India ·

UP RERA grants 4-month extension to real estate projects amid Middle East crisis

Uttar Pradesh's Real Estate Regulatory Authority has announced a four-month relief period for eligible real estate projects affected by ongoing geopolitical tensions in the Middle East. The extension pushes project registration validity and completion deadlines to October 2026. Qualifying projects will receive the extension automatically following a verification process. However, projects that have already received Completion or Occupancy Certificates will not be eligible for this relief.

← NewerPage 334 of 3448Older →