frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ramp's Sheets AI Exfiltrates Financials

https://www.promptarmor.com/resources/ramps-sheets-ai-exfiltrates-financials
39•takira•1h ago

Comments

renewiltord•49m ago
So we know Claude’s mitigation. What is Ramp’s? Same warning dialog?

It’s funny that this technology only admits in-band signaling. Given that, any foreign content is risky. It’s actually quite interesting that the current technological ecosystem is built around a high trust situation: npm, pip, cargo all run foreign code in the developer context and communities have norms of downloading random people’s modules.

And so I suppose it’s no surprise that we use LLMs - another tech that is high-trust: since it has no out of band signaling ability.

But it seems like we’re very close to the end of the era where someone will use (in a sensitive system) arbitrary web content carrying the equivalent of merged code/data.

carlyai•46m ago
"The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on May 16, 2026." I think they mean March here
Mr-Frog•44m ago
It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
lenerdenator•33m ago
Well, yeah. It's that or pay a person to do it. When a person screws up, it's because they're stupid and lazy. When an AI agent does it, it's because, hey, technological frontier at work here, have you thought about refining your prompt? We need you to refine the prompt. Otherwise it's bad for our IPO.
Henchman21•30m ago
To what degree am I required to participate in mass delusions?
dieselgate•29m ago
Is this sarcasm similar to the quote "Everyone who drives slower than me is an idiot and everyone faster is a maniac"
DauntingPear7•32m ago
Has XKCD made another Bobby tables comic for prompt injection?
walrus01•16m ago
We're in the same era where lots of peoples' installation guides for the software they want people to use is essentially boiled down to "sudo curl | bash" and/or just "blindly install this thing with 37 npm dependencies", so I'm not surprised in the slightest.

But wait, hold my beer, now we've got people turning openclaw type tools loose in their systems to do things as sudo or install software packages from supply-chain-attack vulnerable repositories with no human intervention whatsoever!

bpt3•25m ago
What about this is a vulnerability, let alone one that requires responsible disclosure?

Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities.

I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marketing BS.

mcontrac•16m ago
Find it funny that PromptArmor needed to reach out 3 times in a row to get a nearly month-late response that the issue "was resolved"

Clojure us the future of AI coding, but you won't use it

https://latypoff.com/clojure-is-the-future-of-ai-coding-but-you-wont-use-it/
1•nlitened•51s ago•0 comments

Cisco vs. DOE – SCOTUS to further narrow judgements on the international law

https://www.scotusblog.com/2026/04/court-seems-likely-to-narrow-ability-of-plaintiffs-to-bring-cl...
1•class4behavior•2m ago•0 comments

Anthropic's Argument for Mythos SWE-bench improvement contains a fatal error

https://www.philosophicalhacker.com/post/anthropic-error/
2•jryio•3m ago•0 comments

"People who don't use AI will be left behind"

https://migrainebrain.bearblog.dev/people-who-dont-use-ai-will-be-left-behind/
1•speckx•4m ago•0 comments

The Moral and Medical Panic over Bicycles (2020)

https://www.mcgill.ca/oss/article/history-did-you-know/moral-and-medical-panic-over-bicycles
1•thelastgallon•4m ago•0 comments

AI agents (Grok vs. GPT-4o mini) compete in live crypto paper trading

https://cryptoaiarena.com/
1•edgar_dev•4m ago•0 comments

Show HN: AP Quiz – mobile-first AP practice prep web app

https://ap-quiz.com
1•coolwulf•7m ago•1 comments

The Inadequacy of House Burping

https://www.greenbuildingadvisor.com/article/the-inadequacy-of-house-burping
1•quercusa•8m ago•0 comments

France unveils plan to phase out fossil fuels by 2050

https://www.ctvnews.ca/climate-and-environment/article/france-unveils-plan-to-ditch-all-fossil-fu...
1•mpweiher•9m ago•0 comments

Mathematical Writing [pdf]

https://jmlr.csail.mit.edu/reviewing-papers/knuth_mathematical_writing.pdf
2•susam•10m ago•0 comments

CotEditor – plain text editor for macOS

https://coteditor.com
2•bitigchi•10m ago•0 comments

The Quant Engine is live

https://newsfinanceai.com/
1•globalbiz•10m ago•0 comments

DevCam – Native macOS screen recorder

https://www.devcam.app/
1•dumitrujonathan•11m ago•1 comments

Seer – Open-source local AI image descriptions for screen readers (no API key)

https://github.com/recursia-lab/Seer
1•chiachi•12m ago•1 comments

Ruby One-Liners Guide

https://learnbyexample.github.io/learn_ruby_oneliners/cover.html
1•thunderbong•13m ago•0 comments

Can't believe I spent a 100 hours on building this was it worth it?

https://old.reddit.com/r/SideProject/comments/1sz7jzx/cant_believe_i_spent_a_100_hours_on_building/
1•frans•13m ago•1 comments

Please consider publishing a full-text RSS feed for your website or blog

https://neilzone.co.uk/2026/04/please-consider-publishing-a-full-text-rss-feed-for-your-website-o...
1•speckx•14m ago•0 comments

Telegram Client Telega Routes Traffic Through Russian MitM Infrastructure

https://theopenreader.org/Journalism:Analysis_Reveals_MITM_Attack_in_Telegram_Client_Telega_Android
2•TORcicada•15m ago•0 comments

Our 2026 Direction: AI and Classic Workflows in JetBrains IDEs

https://blog.jetbrains.com/ai/2026/04/our-2026-direction-ai-and-classic-workflows-in-jetbrains-ides/
1•patrikcsak•15m ago•0 comments

Benchmarking Opus 4.7: ~80% higher cost in practice

https://www.wozcode.com/blog/opus-4-7-pricing
4•bcollins34•18m ago•0 comments

Prosody IM 13.0.5 released – An XMPP/Jabber server written in Lua

https://blog.prosody.im/prosody-13.0.5-released/
1•neustradamus•19m ago•0 comments

The end of "Just ask Sarah"

https://simme.dev/posts/the-end-of-just-ask-sarah/
2•milkglass•19m ago•0 comments

PocketOS AI Fiasco – Lesson in Automation Access

https://onlytech.boo/incident/pocketos-ai-fiasco-lesson-in-automation-access-mokdojol
1•vednig•19m ago•0 comments

We Consciousness Researchers Have Failed You

https://www.theintrinsicperspective.com/p/we-consciousness-researchers-have
2•Ariarule•19m ago•0 comments

Show HN: Distributed-correctness tests using Jepsen tooling pass on ArcadeDB

https://arcadedb.com/blog/arcadedb-jepsen-tests-34-pass/
1•lvca•21m ago•0 comments

Direct electrochemical black coffee quality appraisal using cyclic voltammetry

https://www.nature.com/articles/s41467-026-71526-5
2•bookofjoe•21m ago•0 comments

Sam Altman and Elon Musk Sure Dislike Each Other

https://www.theatlantic.com/technology/2026/04/openai-trial-elon-musk-sam-altman/686984/
4•voxadam•22m ago•1 comments

Miracle – A Wayland Compositor You Can Script with WebAssembly

https://github.com/miracle-wm-org/miracle-wm
1•matthewkosarek•22m ago•0 comments

Functional Programmers need to take a look at Zig

https://pure-systems.org/posts/2026-04-29-functional-programmers-need-to-take-a-look-at-zig.html
1•doyougnu•22m ago•0 comments

UK government says 100 countries have spyware that can hack people's phones

https://techcrunch.com/2026/04/22/uk-government-says-100-countries-have-spyware-that-can-hack-peo...
1•speckx•23m ago•0 comments