frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

As many as 2M Cisco devices affected by actively exploited 0-day

https://arstechnica.com/security/2025/09/as-many-as-2-million-cisco-devices-affected-by-actively-exploited-0-day/
38•duxup•1h ago

Comments

duxup•1h ago
When I worked at a company that made some networking equipment SNMP was a constant problem, security, bugs that crash the device and so on.

It became clear to me over time that the pattern at that company was to direct the less great engineering resources to SNMP...

hylaride•1h ago
SNMP is one of those good ideas in theory, bad ideas in practice.

Anyways, Cisco hasn’t done great engineering pretty much since the dotcom bust. They’re now essentially a giant PE firm that grows through acquisitions and then milks them dry. It’s a classic case of the accountants took over.

FuriouslyAdrift•1h ago
Cisco's old model (which worked very well for them) was to develop an outside startup and see if they gain traction while keeping at least some financial/control stake to democratize the risk and spend and then spin-in if it is succesful (or sell off).
Our_Benefactors•10m ago
I interviewed with Cisco once. They wanted me to do a take home interview. Implement an api, make a web app, host the GitHub repo somewhere, host the web app so it was publicly available for them to test, make sure I included full documentation and test suite. A fully tested and deployed full stack application, from scratch, as a “take home test”. I said “no, I don't work for free”.

That was by far the most egregious example I’ve encountered of “we are trying to get unpaid labor from our interview process.”

FuriouslyAdrift•8m ago
Yeah, that's ridiculous. It's not just FAANGs that pull this crap.
MangoToupe•58m ago
Selfishly, I'm happy and grateful they bought out chez scheme, opened it up, and funded development. Do I understand why? No, and I'm not going to question it!

EDIT: it seems like it was an acquihire of Dybvig and the team working on chez for something under NDA.

rubymancer•24m ago
Cisco employee here, this is spot on.

I was at a startup they acquired ~4 years ago, by now it's just about milked completely dry.

Even though our product is close to industry-leading, they laid off our product manager, then another one, the QA team, and half of the devs. Unsurprisingly the product is falling apart.

It's not a company that attempts to produces value, as with so many others the product is the stock price.

The MBAs are showing some kind of savings on a spreadsheet somewhere though, so I suppose all the sacrifices are worth it.

FuriouslyAdrift•1h ago
SNMP v3 at least has some security in mind, but a lot of devices are just v1 or v2c which are basically unsecured. Allowing ANY write access via SNMP is a bad idea in my opinion, unless you segment it out into it's own secured management or out-of-band network. Even then... I'd be worried.

Network infrastructure security has a lot of unsolved gotchas and not a lot of industry desire to fix. Most of what everyone interacts with is in an abstracted or virtualized layer on top of the old plumbing.

Group_B•1h ago
You're secure if you don't expose SNMP. Can't believe there are that many devices out there with that exposed though.
FuriouslyAdrift•1h ago
good old SNMP v1 private/private
duxup•54m ago
It's damned if you do damned if you don't.

For smaller operations I think just disabling SNMP is safer due to constant bugs and issues.

On the other hand bigger operations, you gotta monitor your devices. But now you’re open to the can of worms.

bell-cot•55m ago
The "yet another mortal security flaw in Cisco..." stories never seem to end.

Daydream: Journalists start ending such articles with "This is the Nth critical security flaw for Cisco in just the past year. Network security professionals we spoke to agree that network equipment vendors X, Y, and Z all have far better track records than Cisco."

fwipsy•40m ago
The last paragraph of the article doesn't serve that purpose?
bell-cot•31m ago
1/4 of "yes", for this particular article. The regular "brands X, Y and Z are better" part would get more traction in the C-suites. And hopefully on Wall Street.
forinti•3m ago
Cisco hasn't yet rolled out a version of Webex that runs on Ubuntu 24.
lkuty•8m ago
I guess that `no snmp-server` is enough to be protected. Well, I hope so.

Partnering to make full-stack fast: deploy PlanetScale databases from Workers

https://blog.cloudflare.com/planetscale-postgres-workers/
1•janpio•42s ago•0 comments

I Hate My Friend

https://www.wired.com/story/i-hate-my-ai-friend/
1•grbsh•1m ago•0 comments

Owner Incentives and Performance in Healthcare: Private Equity in Nursing Homes

https://www.nber.org/papers/w28474
1•nabla9•2m ago•0 comments

Internet changed real estate market

https://estimateproperty.blogspot.com/2025/09/how-internet-changed-real-estate-market.html
1•burittoca•2m ago•0 comments

The Rabbit Hole of Building a Filesystem Watcher

https://amandeepsp.github.io/blog/fs-watcher/
2•thunderbong•4m ago•1 comments

Chainguard Libraries for JavaScript: Malware-Resistant Depend. Built from Source

https://www.chainguard.dev/unchained/announcing-chainguard-libraries-for-javascript-malware-resis...
1•prdonahue•5m ago•0 comments

PostgreSQL Gains a Built-In UUIDv7 Generation Function for Primary Keys

https://habr.com/en/news/950340/
1•sergeyprokhoren•6m ago•0 comments

Linkwarden v2.13

https://blog.linkwarden.app/releases/2.13
1•daniel31x13•7m ago•0 comments

Gun Industry Group Violated Firearm Owners' Rights, Lawsuit Alleges

https://www.propublica.org/article/gun-owners-privacy-lawsuit-nssf
1•beardyw•7m ago•0 comments

Show me the talk: Tigs stores your AI chats in Git

https://github.com/welldefined-ai/tigs
1•basicthinker•7m ago•1 comments

Quantized LLMss in Biomedical Natural Language Processing

https://arxiv.org/abs/2509.04534
1•PaulHoule•8m ago•0 comments

Kubernetes Cloud Controller Manager for Hetzner Cloud

https://github.com/hetznercloud/hcloud-cloud-controller-manager
1•SweetSoftPillow•8m ago•0 comments

Stealth scores FDA approval for first Barth syndrome treatment

https://www.fiercepharma.com/pharma/fda-greenlights-stealth-bios-injection-1st-treatment-barth-sy...
1•gmays•10m ago•0 comments

Spy Tech: The NRO and Apollo 11

https://hackaday.com/2025/09/25/spy-tech-the-nro-and-apollo-11/
1•beardyw•10m ago•0 comments

A manager for running agents in worktrees

https://github.com/stravu/crystal
2•jbentley1•10m ago•0 comments

Consumer Reports calls on Microsoft to extend support for Windows 10

https://advocacy.consumerreports.org/research/consumer-reports-calls-on-microsoft-to-extend-suppo...
3•speckx•11m ago•0 comments

Journals infiltrated with 'copycat' papers that can be written by AI

https://www.nature.com/articles/d41586-025-03046-z?WT.ec_id=NATURE-202509
1•delichon•11m ago•0 comments

Atomizer.ai reduces training cost up to 50% at 4x speed

https://atomizer.ai/#services
1•tuumi•12m ago•0 comments

Introducing: UniFi Access Retrofit [Coming Soon] [video]

https://www.youtube.com/watch?v=H2E4lCDdwTA
1•ksec•12m ago•0 comments

The Great Stalemate (Age of Empires II) [video]

https://www.youtube.com/watch?v=Ex6t_oYJxmw
1•kregasaurusrex•13m ago•0 comments

Embedding a Tantivy Index in Parquet

https://github.com/jcsherin/datablok/tree/main/crates/parquet-embed-tantivy
1•alamb•14m ago•1 comments

Cloudflare Introduces Net Dollar

https://www.cloudflare.com/press/press-releases/2025/cloudflare-introduces-net-dollar-to-support-...
4•tosh•14m ago•0 comments

Show HN: Playlister – an open source vibe playlist manager for Spotify

https://dethbird.com/playlister-an-open-source-spotify-vibe-playlist-builder/
1•dethbird•15m ago•0 comments

Proton Mail's brand new mobile apps

https://proton.me/blog/new-mail-apps
2•PrivacyDingus•16m ago•0 comments

How to build your own design GPT assistant (like we did)

https://balsamiq.com/blog/train-custom-gpt-for-ux-design/
1•janpio•17m ago•0 comments

Floating Point Visually Explained

https://fabiensanglard.net/floating_point_visually_explained/
1•fanf2•19m ago•0 comments

Accenture to 'exit' staff that cannot be retrained for age of AI

https://www.ft.com/content/a74f8564-ed5a-42e9-8fb3-d2bddb2b8675
6•jmsflknr•20m ago•1 comments

Corporate AI Is a Joke

https://ag404labs.com/p/corporate-ai-is-a-joke
3•xsh6942•20m ago•1 comments

InterpreterPoolExecutor – We Need PEP 734

https://www.carlmastrangelo.com/blog/interpreterpoolexecutor-we-need-pep-734
1•speckx•20m ago•0 comments

Ask HN: Why topics are getting flagged when it is about Israel?

4•throwaw12•21m ago•1 comments