The HN emails have a link to a URL with a long numeric string, hiding a PDF
HN: we've been hacked, here's an obscured URL, you'll have to click to find out what it leads to, oh, soz, it's a document type that could itself be used as an attack."
The URL numeric part seems to vary by recipient, i.e. it's a tracker. Presumably they've repurposed a targeted advertising emailer to distribute the link to the PDF, rather than put details in simple text on a webpage on the HN site.
+10 points for admitting it.
-5 points for the way it was done.