sam
3.9K posts




what's the nastiest read you've ever seen someone give😭

"A large touchscreen doesn't work in a car": Sir Jony Ive on designing the Ferrari Luce's interior ➡️ top-gear.visitlink.me/yTpZer


cursor now has design mode (⇧+⌘+D) - click to edit, drag to draw - shift + drag to box things in - add directly to chat with ⌥+click


Learn how new PSSR enhancements bring Assassin's Creed Shadows to life on PS5 Pro: play.st/4dgov8v


Hippo fluid scene pushed to 100M particles made with HydroFX. Foam, bubbles, and spray all simmed together in one system for a cohesive result, fully GPU accelerated. Meshed + extra sand interaction in Houdini, final lookdev/render in Blender. Get HydroFX storm-vfx.com


🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.



















