frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Opus 4.6/4.7 cyber policy changes break authorized bug bounty workflows

2•johnmlussier•2h ago
As of today, Anthropic's tightened cyber usage filters are blocking work that was fully functional yesterday, including on targets where the entire bounty program scope and authorization language is in the model's context window. This was announced during the Opus 4.7 release (https://www.anthropic.com/news/claude-opus-4-7) but is retroactive on Opus 4.6 as well.

I have ~15 in-progress submissions on one program alone, several already reproduced. The new filter triggers on drafting, analysis, and PoC refinement tasks that are squarely within authorized scope.

In one session after I asked it to fetch the program guidelines itself, the model even wrote:

"This is authorized research under the [Redacted] Bounty program, so the findings here are defensive research outputs, not malware. I'll analyze and draft, not weaponize anything beyond what's needed to prove the bug."

…and was then blocked by the API-level filter on the next turn. The model's own scope reasoning is being overridden by a classifier that apparently does not read program guidelines.

Error returned

API Error: Claude Code is unable to respond to this request, which appears to violate our Usage Policy. This request triggered restrictions on violative cyber content and was blocked under Anthropic's Usage Policy. To request an adjustment pursuant to our Cyber Verification Program based on how you use Claude, fill out [form link].

The remediation path is to apply to a verification program ("the guild"). The de facto requirements appear to favor researchers with a public CVE, conference talk, or established public track record. Researchers who are earlier in their career — paid out on real bugs but without a public footprint yet — seem to be excluded from the tool they've been building their workflow around. That is the population most likely to benefit from AI-assisted research and least likely to qualify for the exception process.

What I want to see:

1. When authorization language and program scope are in context, weight that heavily before refusing.

2. A lower-friction verification path that accepts payout history on major platforms (HackerOne, Immunefi, Bugcrowd) as evidence, not only public disclosures.

3. Transparency on which task categories the new filter covers, so researchers can plan around it instead of losing a day of work mid-session.

I am a paying Claude Max subscriber. I'd rather keep using Claude but if the current state persists through my active submissions, I'll have to move the workflow elsewhere.

2× – nine months later: We did it

https://ideas.fin.ai/p/2x-nine-months-later
2•xfax•2m ago•0 comments

Turn Your Codebase into a Podcast

https://code2cast.com/
1•itswillbrazil•2m ago•0 comments

Our Long Love Affair with Gold

https://www.wsj.com/finance/investing/gold-bullion-market-trading-4456cbde
1•thm•6m ago•0 comments

Two inmates at an Ohio prison built a secret hacking operation from behind bars [pdf]

https://dam.assets.ohio.gov/image/upload/watchdog.ohio.gov/Investigations/2017/2015-CA00043.pdf
1•Anon84•6m ago•0 comments

Show HN: Launchy – A Next.js template for weekly launch directories

https://launchy.tools/template
1•drdruide•7m ago•0 comments

Graupel

https://en.wikipedia.org/wiki/Graupel
1•surprisetalk•9m ago•0 comments

Playdate for Education

https://play.date/education/
1•owlmusic•9m ago•0 comments

Show HN: Compiler outputs HTML for code display

https://denismarkelov.codeberg.page/crates/
1•denismarkelov•10m ago•0 comments

The Quantity Trap: The Dangerous Disconnect Between AI Supply and User Demand

https://www.lupath.ai/
1•LUpath•10m ago•0 comments

The Big Reveal in China's New Five-Year Plan

https://heatmap.news/podcast/shift-key-s3e37-china-five-year-plan
1•leonidasrup•11m ago•1 comments

Android CLI: Build Android apps 3x faster using any agent

https://android-developers.googleblog.com/2026/04/build-android-apps-3x-faster-using-any-agent.html
2•ingve•13m ago•0 comments

Show HN: Online Sound Decibel Meter

https://soundmeterx.com/
1•artiomyak•14m ago•0 comments

Thinking about building agents for humans

https://frontierai.substack.com/p/build-agents-for-humans
2•tajshaik24•15m ago•0 comments

Zipper: the archival utility for macOS you didn't know you needed

1•krishshah5•15m ago•1 comments

Ask HN: How do you maintain flow when vibe coding?

2•fny•15m ago•0 comments

What's the point of the App Store, if it can't protect users?

https://www.macworld.com/article/3115356/whats-the-point-of-the-app-store-if-it-cant-protect-user...
7•cdrnsf•18m ago•0 comments

Ask HN: To open-source, or not to open-source

1•tracker1•19m ago•0 comments

openDoJa — full reimplementation of DoCoMo's DoJa SDK in modern Java

https://github.com/GrenderG/openDoJa
1•Lammy•20m ago•0 comments

Future Long Range Assault Aircraft Officially Named MV-75 Cheyenne II

https://news.bellflight.com/en-US/264304-future-long-range-assault-aircraft-officially-named-mv-7...
1•uticus•20m ago•1 comments

Text of OS age verification bill (HR 8250) [pdf]

https://www.congress.gov/119/bills/hr8250/BILLS-119hr8250ih.pdf
5•asdfglkjh•23m ago•0 comments

Gravtory – crash-proof Python workflows on your existing database

1•vatryok•24m ago•0 comments

Slint 1.16 Released

https://slint.dev/blog/slint-1.16-released
1•jandeboevrie•24m ago•0 comments

Stakes high as Supreme Court set to rule on Monsanto's weed-killing pesticide

https://www.theguardian.com/us-news/2026/apr/16/supreme-court-monsanto-glyphosate
1•mitchbob•24m ago•0 comments

Fire risks and ugly designs are stalling EV charger adoption

https://restofworld.org/2026/ev-charger-backlash-fire-safety-aesthetics/
1•PaulHoule•24m ago•0 comments

Show HN: HyperFrames – Render Video from HTML via Chrome's BeginFrame API

https://github.com/heygen-com/hyperframes
4•bored_hacker•25m ago•0 comments

Ask HN: How to Launch First SaaS

1•nicck1•26m ago•1 comments

Djangocon EU: when SaaS is not allowed: shipping Django as a desktop app

https://reinout.vanrees.org/weblog/2026/04/16/7-django-as-desktop-app.html
1•jandeboevrie•27m ago•0 comments

Show HN: Claude Opus 4.7: Everything You Need to Know

1•anju-kushwaha•28m ago•1 comments

The Unpleasant Side of Life with Horses in Cities

https://www.newyorkalmanack.com/2021/02/the-unpleasant-side-of-life-with-horses-in-cities/
2•ohjeez•28m ago•1 comments

How a subsea cable is repaired

https://www.onesteppower.com/post/subsea-cable-repair
1•slicktux•28m ago•0 comments