Episode Details

Back to Episodes
WordPress plugin supply-chain backdoor & Google targets back-button hijacking - Hacker News (Apr 14, 2026)

WordPress plugin supply-chain backdoor & Google targets back-button hijacking - Hacker News (Apr 14, 2026)

Published 2 months, 1 week ago
Description
Please support this podcast by checking out our sponsors:
- Lindy is your ultimate AI assistant that proactively manages your inbox - https://try.lindy.ai/tad
- SurveyMonkey, Using AI to surface insights faster and reduce manual analysis time - https://get.surveymonkey.com/tad
- KrispCall: Agentic Cloud Telephony - https://try.krispcall.com/tad


Support The Automated Daily directly:
Buy me a coffee: https://buymeacoffee.com/theautomateddaily

Today's topics:

WordPress plugin supply-chain backdoor - A major WordPress supply-chain attack abused trusted plugin updates to plant a backdoor across 30+ plugins, even using an Ethereum smart contract for C2 discovery—highlighting plugin ownership-transfer risk and SEO spam payloads.

Google targets back-button hijacking - Google Search added an explicit spam policy against back-button hijacking, warning of manual actions and ranking demotions as it cracks down on deceptive navigation and malicious ad-tech behavior.

GitHub adds stacked pull requests - GitHub rolled out native stacked pull requests plus a gh CLI extension, making it easier to review large changes as ordered, smaller PRs with safer CI and branch-protection behavior.

Jujutsu version control gains attention - The jj CLI for the Jujutsu VCS is positioned as a simpler, more composable alternative to Git, with Git-compatible storage that lets developers experiment without team-wide migration.

Diffusion LMs catch up to AR - Researchers introduced I-DLM, a diffusion-based language model approach that aims to match autoregressive quality while improving throughput via parallel token generation and introspective consistency.

OpenDuck brings DuckDB to cloud - OpenDuck is an open-source effort to make DuckDB work transparently with remote databases using a minimal protocol and hybrid local-remote execution—an extensible alternative to proprietary ‘DuckDB in the cloud.’

Backblaze backup exclusions raise trust - A long-time Backblaze user reports silent exclusions of .git and common cloud-sync folders like OneDrive/Dropbox, raising concerns about backup transparency, retention assumptions, and user notification.

Franklin’s Apple II clone era - A look back at Franklin Computer’s early-1980s Apple II compatibles shows how aggressive cloning and flashy marketing collided with evolving IP enforcement and landmark legal pressure.

NimConf 2026 community timeline - NimConf 2026 announced its online schedule and CFP dates, setting the community’s rhythm for sharing Nim projects, libraries, and real-world use cases ahead of the June event.



-DaVinci Resolve 21 Adds Dedicated Photo Page for Still-Image Grading and Workflow
-NimConf 2026 Set for June 20 With Call for Talk Proposals
-Google Updates Search Spam Policies to Ban Back Button Hijacking
-Jujutsu’s `jj` CLI: A Simpler, More Powerful Alternative to Git
-
Listen Now