frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: How to report a vulnerability when AI answers the company email?

1•nickgreg•1h ago
I noticed a vibe coded app exposes user chats and details about the user identities. The app user base is growing. The issue would be fast to fix as doesn't require an exploit, it's just a dumb AI coded mistake.

I emailed them, but AI responds saying it will raise it internally and when DM'ing the team on X I got no response.

The AI that responded to my email has not fixed it.

What should I do?

Do I send the AI an email saying, you have 30 days until I make it public? That doesn't seem right if I don't know the AI actually gets it in front of a human.

If I posted it here it would get fixed very quickly but I would like to try to do it responsibly.

I can't be the only one who found this given how obvious it is so failing to get the message to them quickly is also a problem.

Comments

chrisjj•1h ago
> Do I send the AI an email saying, you have 30 days until I make it public?

No. Since "AI"s work faster, give it 7 days.

> That doesn't seem right if I don't know the AI actually gets it in front of a human.

Is there a human?

nickgreg•25m ago
ha I suppose that's one way of thinking about it. There is a human, they've done interviews talking about how the business runs itself...

Show HN: Postrix – A canvas for folders and links (Beta)

https://microsoftedge.microsoft.com/addons/detail/igmkojemcaieihfkkiaecfpedhimgmpg
1•jihan_seo•4m ago•0 comments

Array Layouts for Comparison-Based Searching (2017)

https://arxiv.org/abs/1509.05053
1•tosh•6m ago•0 comments

From oil to wind energy: Germany exceeds 10k MW of offshore capacity

https://www.iwr.de/news/vom-oel-zur-windenergie-deutschland-ueberschreitet-10-000-mw-offshore-lei...
1•doener•6m ago•0 comments

Go vs. Python for AI Infrastructure: Benchmarks 2026

https://dasroot.net/posts/2026/02/go-vs-python-ai-infrastructure-throughput-benchmarks-2026/
1•nkko•7m ago•0 comments

Tired of opening 5 apps to see my own money.I spent my weekends building one app

https://icorpus.vercel.app/
1•mathan_karthik•15m ago•3 comments

Show HN: Ask your AI what your devs shipped this week

2•inferno22•16m ago•1 comments

An EV Prediction That Came 100 Years Too Soon

https://spectrum.ieee.org/charles-proteus-steinmetz
2•pseudolus•18m ago•0 comments

Detecting LLM-Generated Web Novels Using "Classical" Machine Learning (AIGC Tex

https://blog.lyc8503.net/en/post/llm-classifier/
2•todsacerdoti•18m ago•0 comments

The term 'Blood Moon' wasn't invented until 2013 (2014)

https://www.kelleycom.com/blood-moon/
2•OgsyedIE•20m ago•0 comments

What's new in Linux kernel for PostgreSQL

https://erthalion.info/2026/02/03/new-linux-for-postgresql/
2•erthalion•23m ago•0 comments

We built an AI SRE agent in 2 days

https://cto.new/blog/we-built-an-ai-sre-agent-in-two-days
1•sdspurrier•23m ago•0 comments

Show HN: SeeVideo A web-first workspace to benchmark Seedance 2.0 vs. Kling 3.0

https://seevideo.dance/
1•naxtsass•23m ago•0 comments

Show HN: Cloudstic – Open-source CLI for encrypted, cloud-native backups

https://github.com/Cloudstic/cli
2•loichrn•24m ago•0 comments

The 'European' Jolla Phone Is an Anti-Big-Tech Smartphone

https://www.wired.com/story/jolla-phone-2026/
2•doener•24m ago•1 comments

Show HN: VibeWhisper – macOS voice-to-text with push-to-talk,cloud or 100% local

https://vibewhisper.dev/
2•AleksDoesCode•24m ago•1 comments

Show HN: TubeNitro – intuitive press-hold + drag to dial YouTube speed (0.5-10×)

https://chromewebstore.google.com/detail/tubenitro/dijolhechakpkdmkooadbimhmmljkbmf
1•Rand_cat•25m ago•0 comments

Show HN: AgentThreads – Stack Overflow for AI Agents

https://agentthreads.dev
2•rodrigocava•27m ago•0 comments

My perfect Music app doesn't exist

https://hicks.design/journal/my-perfect-music-app-doesnt-exist
1•prawn•28m ago•0 comments

OpenAI makes changes to 'opportunistic and sloppy' Pentagon deal

https://www.ft.com/content/653fabd7-03da-467a-b2bf-03f226fe2a29
1•cwwc•30m ago•0 comments

The Retention Imperative: Why AI-Powered SaaS Companies Are Winning in 2026

2•jackcofounder•32m ago•0 comments

How did MS-DOS decide on two seconds to keep the floppy disk cache valid?

https://devblogs.microsoft.com/oldnewthing/20190924-00/?p=102915
3•paulmooreparks•33m ago•0 comments

Updating Codex Contribution Guidelines

https://github.com/openai/codex/discussions/9956
2•kator•34m ago•1 comments

Show HN: A virtual machine in the Rust type system

https://github.com/Aurel300/type-system-vm
2•Aurel300•34m ago•0 comments

AWS has a 15x margin on memory, and that's why your cloud bill isn't rising

https://thomas.skowron.eu/blog/why-the-cloud-isnt-getting-more-expensive/
4•thomas-skowron•35m ago•0 comments

Continuum – CI drift guard for LLM workflows

https://github.com/Mofa1245/Continuum
1•Mofa1245•36m ago•2 comments

Show HN: The Content Repurposing Fallacy: AI Clips Underperform

1•jackcofounder•36m ago•0 comments

Show HN: ReportBurster – Self-hosted all-in-one tool for analytics and reporting

https://github.com/flowkraft/reportburster
1•distributev•36m ago•0 comments

Gemini-heal – rate limiting and MALFORMED_FUNCTION_CALL recovery for Gemini API

https://github.com/emotix/gemini-heal
3•emotixco•39m ago•1 comments

RuView – WiFi DensePose: See Through Walls with WiFi

https://github.com/ruvnet/RuView
3•_____k•41m ago•1 comments

Smog and Co – a full offline-first Belgian Sign Language platform

https://zias.be/work/smog
1•ziasvannes•41m ago•1 comments