RE: https://haz.pink/@can/116340263567875692

why de fuck does the browser jscrap even have such (free) access!?

can't we get browsers that just display information without trying to mine crypto or personal data?

#fuckjs #JS #javascript

Obs.js – context-aware web performance for everyone

Obs.js reads device and network signals and allows you to build adaptive user experiences.

CSS Wizardry

Securing the Supply Chain: How SentinelOne's AI EDR Stops the ...

On March 31, 2026, a North Korean state actor hijacked the npm credentials of the primary Axios maintainer and published two backdoored releases that deployed a cross-platform remote access trojan (RAT) to Windows, macOS, and Linux systems. Axios is the most widely used HTTP client in the JavaScript ecosystem, with approximately 100 million weekly downloads and a presence in roughly 80% of cloud and code environments.

Pulse ID: 69cf03e05f6b299dc3efd2cd
Pulse Link: https://otx.alienvault.com/pulse/69cf03e05f6b299dc3efd2cd
Pulse Author: AlienVault
Created: 2026-04-03 00:03:44

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #Cloud #CyberSecurity #EDR #HTTP #InfoSec #Java #JavaScript #Korea #Linux #Mac #MacOS #NPM #NorthKorea #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #SentinelOne #SupplyChain #Trojan #Windows #bot #iOS #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
🍪✈️ Oh no, a U.S. fighter jet supposedly crash-landed in #Iran, but hold your panic! You can't even get past the digital cookie wall without enabling #JavaScript. 🎭 Dramatic headline, but please, let's focus on the real tragedy: a website that can't function without cookies. 🙄
https://www.axios.com/2026/04/03/iran-us-fighter-shot-down #USFighterJet #Crash #DigitalCookies #WebTragedy #HackerNews #HackerNews #ngated
U.S. fighter jet shot down in Iran: One crew member rescued, search for other ongoing

It would be the first time since the beginning of the war that a U.S. jet was downed by enemy fire.

Axios
Agentic AI in Practice: Speed vs. Quality in Code

Garry Tan, CEO of Y Combinator, one of the most influential startup accelerators in the world, sparked a major debate on social media this week after sharing a striking milestone on X: he and his AI coding agents had been deploying 37,000 lines of code per day across five separate projects, on a 72-day consecutive shipping streak. The post went viral quickly. But two days later, a Polish senior software engineer known as Gregorein decided to take a closer look at the actual results, and what he found was quite revealing: Tan's code was full of bloat, waste, and rookie mistakes, even on the public-facing side of the site. **What does this teach us?** The core of the debate is that while AI coding tools make it easy to pump out lots of code, it is really the quality of the code that matters, not the quantity. Code that goes into production without proper scrutiny and testing can cause obvious functional failures, create security vulnerabilities, or introduce issues that surface later and force engineers to track down and fix the underlying problems. As Gregorein put it: "Right now we are in a moment where AI lets you generate code faster than any human can review it, and the answer from people like Garry seems to be 'so stop reviewing'." **The bigger picture: agentic AI in the startup ecosystem** This episode is not isolated. Tan has been a vocal proponent of agentic AI in the startup world. According to him, about 25% of the current YC batch have 95% of their code written by AI, and companies are reaching up to $10 million in revenue with teams of fewer than 10 people. Yet Tan himself acknowledges that human agency and judgment remain irreplaceable. In his own words, "agency and taste are super, super important and humans are going to be a really irreplaceable piece of that." **The real opportunity for those building with AI** Tan also points out that the biggest mistake founders are making today is piling into the saturated coding agent space, which already dominates nearly 50% of all agentic AI activity. The real opportunity lies in the verticals that have barely been touched: healthcare at 1%, legal at 0.9%, education at 1.8%, where AI agents have enormous transformative potential but almost no penetration yet. **What does this mean for IT and technology professionals?** Agentic AI is real and powerful, but it does not replace architecture, code review, and sound engineering practices. The speed at which code can now be generated has already outpaced the human ability to review it. The challenge now is to build quality processes that match this new pace. The biggest open spaces in AI are not in more tools for developers, but in the sectors that have barely been touched. The question is not whether we will use AI to develop software. It is how we will use it responsibly and with sound judgment. --- Source: Fast Company, "Y Combinator's CEO says he ships 37,000 lines of AI code per day. A developer looked under the hood" https://www.fastcompany.com/91520702/y-combinator-garry-tan-agentic-ai-social-media

Visitor Lens Pro :

Une bibliothèque JavaScript pure qui établit un profil complet de chaque visiteur de votre site web. Une seule balise script. Aucune dépendance. Aucune clé API. Fonctionne comme un simple script, un module CommonJS ou un module ES.

https://github.com/madjeek-web/visitorlens-pro

#javascript #mit #project #github #opensource #visitor #js #code #webdev #website #analytics #fc84 #script

GitHub - madjeek-web/visitorlens-pro: Visitorlens-pro : A pure JavaScript library that builds a complete profile of anyone who visits your website. One script tag. No dependencies. No API key. Works as a plain script, a CommonJS module, or an ES module.

Visitorlens-pro : A pure JavaScript library that builds a complete profile of anyone who visits your website. One script tag. No dependencies. No API key. Works as a plain script, a CommonJS module...

GitHub

Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

https://www.it-daily.net/shortnews/npm-bibliothek-axios-zeitweise-mit-malware-verseucht

Spur führt nach Nordkorea: Axios-Bibliothek mit Trojaner verseucht

Angreifer haben eine der meistgenutzten JavaScript-Bibliotheken im npm-Ökosystem zeitweise mit Schadsoftware bestückt. Google schreibt die Attacke einer staatlich gesteuerten Gruppe aus Pjöngjang zu.

Onlineportal von IT Management
Dew Drop Weekly Newsletter #477 - Week Ending April 3, 2026

Dew Drop Weekly Newsletter #477 - Week Ending April 3, 2026

Zoho Campaigns
×

The web is a wonderful, free, and open platform to create and distribute value. You can use **mnswpr** in different ways:
- as a deployed web app
- as a library with `npm i @ayo-run/mnswpr`
- as a `web component` (coming soon).

👉 https://ayco.io/gh/mnswpr#readme

#videogames #webdev #javascript #webcomponents #minesweeper