frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Cloudflare responded to the "Copy Fail" Linux vulnerability

https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/
28•mobeigi•1h ago

Comments

skinfaxi•46m ago
Would love to learn more about their internal behavioural detection program.

> One of the first things our security team did was confirm that our existing endpoint detection would catch this exploit. Our servers run behavioral detection that continuously monitors process execution patterns. It doesn't rely on knowing about specific vulnerabilities; it watches for anomalous behavior across the fleet.

CGamesPlay•43m ago
Would certainly be interesting to learn more about. A simple check: allowlist of known "processes that run as root". Any new process shows up, something happened.
jeffbee•35m ago
Based on what? Proc title?
CGamesPlay•31m ago
Proc title is very easily forged (without root even). Obviously a real privileged process could modify the kernel and do whatever it wants, but if I were trying to detect this I would start with /proc/$id/exe.
jeffbee•15m ago
Maybe, but there's a prctl to change that reference which a root process can use.
Retr0id•10m ago
/proc/pid/exe is also easily forged, without root. For example you can do LD_PRELOAD=evil.so /bin/foo on any dynamic executable, or spawn /bin/foo unmodified and inject code via ptrace or /proc/pid/mem.

I have a fileless, execless copyfail exploit that works by injecting shellcode directly into systemd's pid 1. (I should probably publish it at some point...)

parliament32•26m ago
It's curious they're just "monitoring" rather than preventing.

In a serious environment you'd run IPE with dm-verity/fs-verity to ensure binaries are whitelisted and integrity-checked at every execution.

dboreham•11m ago
They might just compute a hash over the binary, or the code space in memory.
mobeigi•7m ago
I'd very much like to learn more about this too, deserves its own blog post.
john_strinlai•42m ago
this is a techincal dive into how cloudflare responded, not a confirmation that they responded

for whatever reason, unknown to me, hn automatically strips "how" from the start of titles. i cant remember ever seeing a title where this was an improvement.

trollbridge•31m ago
Starting a title with “How” is standard clickbait.
Goronmon•21m ago
If we are taking that attitude why not go all the way?

Titles are standard clickbait.

varun_ch•10m ago
I'm yet to see a good example of the title stripping, at least for "how" and "how to" (although perhaps this is survivorship bias).
dboreham•12m ago
The "Hunting for Exploitation" section is unclear to me: "The exploit leaves a distinctive trace in kernel logs when it runs." Hmm. Wouldn't a system with a compromised kernel also log exactly what the attacker wanted logged?
cube00•2m ago
I guess the hope is the kernel has been able to successfully transmit that log message to the immutable central logging infra before it gets compromised.

Although given the tendency for end point logging agents to run on buffers to reduce their network chattiness I do wonder if a fast acting exploit could dump that buffer before it manages to be transmitted.

srcreigh•9m ago
It’s fascinating that already had a system which could identify the exploit at runtime. How can I learn more about that?
sammy2255•9m ago
Any Cloudflare employees reading this, your network map has a few PoPs missing from it https://www.cloudflare.com/network/ notably, Perth (PER) Australia. Hobart (HBA) Australia. Wellington (WLG), New Zealand. Christchurch (CHC), New Zealand. Nausori (SUV), Fiji.
cube00•8m ago
> At the time of the "Copy Fail" disclosure, the majority of our infrastructure was running the 6.12 LTS version

It sounds great but that could be as low as 50.1% since they don't provide an actual percentage.

If You Can Make a Compute Engine, You Can Sell a Compute Engine

https://www.nextplatform.com/compute/2026/05/06/if-you-can-make-a-compute-engine-you-can-sell-a-c...
1•rbanffy•31s ago•0 comments

Show HN: I Built Paul Graham's Social Media Math/Logic CAPTCHA Idea

https://mentwire.com/sample
1•nowflux•1m ago•0 comments

Researchers pioneer method to rapidly design proteins

https://www6.slac.stanford.edu/news/2026-05-04-researchers-pioneer-method-rapidly-design-proteins
1•gmays•2m ago•0 comments

Toronto demands meeting with Google over Maps navigation glitch

https://www.ctvnews.ca/toronto/article/a-google-maps-glitch-sent-drivers-the-wrong-way-up-a-toron...
1•Krontab•4m ago•0 comments

File format for large sorted lists of integers

https://github.com/SebMtn/vde-format
1•WorldDev•4m ago•0 comments

Why hasn't longer-horizon training slowed AI progress?

https://www.seangoedecke.com/why-hasnt-longer-horizon-training-slowed-ai-progress/
1•Brajeshwar•4m ago•0 comments

China's Unwinding of the Manus Deal Highlights a Key US Advantage

https://thediplomat.com/2026/05/chinas-unwinding-of-the-manus-deal-highlights-a-key-us-advantage/
1•u1hcw9nx•4m ago•1 comments

Xbox and N64 Zelda Ocarina of Time Online Co-Op (Real Hardware) [video]

https://www.youtube.com/watch?v=3LVxkTMucGg
1•surprisetalk•5m ago•0 comments

Amp, Rebuilt

https://ampcode.com/news/neo
2•doppp•5m ago•0 comments

Resurfaced 2025 clip fuels false Musk-Ramaphosa snub claim amid Starlink row

https://factcheck.afp.com/doc.afp.com.A9WB89E
1•lschueller•6m ago•0 comments

Understanding Wi-Fi 4/5/6/6E/7/8 (802.11 n/AC/ax/be/bn)

https://www.wiisfi.com/
4•fanf2•8m ago•0 comments

Show HN: MySigner – Ship iOS and Android apps with one command

https://mysigner.dev/
2•lekacoding•8m ago•0 comments

Daily Sucker to Harrass

https://www.elysee.fr/en/contact/
2•machardmachard•9m ago•0 comments

Show HN: CtxVault – local receipts for AI context handoffs

https://github.com/ctxvault/ctxvault
3•LuxBennu•9m ago•0 comments

People don't linger like they used to

https://www.not-ship.com/we-dont-linger-like-we-used-to/
2•dangond•9m ago•0 comments

Apple MLX vs. llama.cpp: compared and benchmarked [video]

https://www.youtube.com/watch?v=ZwCbChJWXkQ
4•nvahalik•11m ago•0 comments

Madrid Built Its Metro Cheaply

https://worksinprogress.co/issue/how-madrid-built-its-metro-cheaply/
2•latentframe•12m ago•1 comments

Show HN: Self-improving skills for any coding agent

https://github.com/luml-ai/dreamer
2•iryna_kondr•12m ago•0 comments

C++ survey finds AI use rising, though trust is in short supply

https://www.theregister.com/devops/2026/05/07/c-survey-finds-ai-use-rising-though-trust-is-in-sho...
4•lschueller•15m ago•0 comments

Amazon Web Services in Plain English (2015)

https://expeditedsecurity.com/aws-in-plain-english/
4•downbad_•15m ago•1 comments

DayOne.fan – music promotion toolkit for indie artists (Meta ads and artist hub)

https://dayone.fan
2•jamescundle•15m ago•1 comments

MPEG-2 Transport Stream Packaging for Media over QUIC Transport

https://www.ietf.org/archive/id/draft-gregoire-moq-msfts-00.html
3•mondainx•17m ago•0 comments

Reclip – Download videos from almost any website

https://github.com/averygan/reclip
2•the-mitr•19m ago•0 comments

The Second Wave of the API-First Economy

https://brandur.org/second-wave-api-first
2•surprisetalk•19m ago•0 comments

A Silver Lining of Slop

https://brennan.io/2026/05/04/llmfree/
2•ibobev•19m ago•0 comments

Minimal Viable Zig Error Contexts

https://matklad.github.io/2026/05/03/zig-error-context.html
4•ibobev•20m ago•0 comments

A digital photo frame written in Lisp

http://forum.ulisp.com/t/a-digital-photo-frame-written-in-lisp/1870
3•chrisjj•20m ago•0 comments

Access your Docker Compose services via easy-to-remember names

https://chuniversiteit.nl/operations/reverse-proxy-for-docker-compose
2•ibobev•20m ago•0 comments

SpaceX is starting to move on from the most successful rocket

https://arstechnica.com/space/2026/05/spacex-is-starting-to-move-on-from-the-worlds-most-successf...
2•Brajeshwar•20m ago•0 comments

Peon-Ping

https://github.com/PeonPing/peon-ping
2•skibz•22m ago•0 comments