frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Exif Smuggling

https://github.com/signalblur/exifsmugglingpoc
17•rolph•1h ago

Comments

ale42•37m ago
Weren't similar techniques already used years ago by malvertizers to hide malicious code into images published for ads so it wouldn't be detected? (although it might have been more like steganography)
saghm•22m ago
I'm not sure if this is exactly what you're referring to, but apparently years ago there were exploits bundling JAR files into GIFs to sneakily have them executed by the Java browser plugin: https://en.wikipedia.org/wiki/Polyglot_(computing)#GIFAR_att...
rolph•15m ago
if anything i would use EXIF data to enhance stego.

generally its the JPEG standard that allows the payload, manipulation by abusing EXIF is how you operate the exploit.

there is a 64k file segment specified for JPEG, and you can abuse it to hold any "data" you want, as well as extending to other segments, for more storage.

the raw steganography in most primative form is a comparison of two photos, one of which is pixelshifted to encode the data.

in advanced form, the pixels hold the encrypted data, but the application segments of the JPEG hold keys and or matrix values, and you need a reference image. you can move fairly large volumes of ASCII representation like this before its noticed

you basicly write a webpage that local caches the payload and keys, then abuses EXIF to build and execute an exploit on the target.

porphyra•23m ago
Mildly annoying how almost everything strips out EXIF data nowadays, in part due to security concerns like this, and then I can't find out what camera, lens, and settings were used to take photos.
AndrewStephens•12m ago
My static site generator strips out exif data from images and I would expect all sensible sites would do the same. There is a lot of personal information jammed in there - if you post a picture of your dog making a funny face to social media you don’t want the exact GPS coordinates of your house plastered over the internet.

You have to be selective though, some of the EXIF data specifies things like color spaces and orientation that is used by browsers for displaying the image properly.

mkoryak•8m ago
I hid my toy vibe coded site's code inside the alpha channel of its logo. https://dogself.com

I probably should have minified it too...

BoppreH•6m ago
Oh, that's clever. It's not just hiding the payload in the Exif, it's hiding the fact that the payload came from the network at all, by reading it from the browser cache (presumably after embedding the image into a page the user visited).

So you have a package that doesn't include (directly) malicious code or make network calls, yet it can still run malicious code from the network. This is much better than simple obfuscation because you can vary the payload, like a command-and-control server.

FCC Attempts to Solve Robocall Problem with Potentially Bigger Privacy Problem

https://gizmodo.com/fcc-attempts-to-solve-robocall-problem-by-potentially-creating-even-bigger-pr...
3•billybuckwheat•4m ago•0 comments

We measured whether a drift-checker changes what an AI coding agent writes

https://www.vibedrift.ai/blog/does-a-drift-checker-change-agent-output
1•samiahmadkhan•4m ago•0 comments

Show HN: AI agents join meetings with memory, calendar, and tasks

https://meet.upilote.com
1•tastyeffectco•5m ago•0 comments

Surprise, Pay $1000

https://forestwalk.ai/blog/surprise-blacksmith-costs/
1•apike•6m ago•0 comments

Email reporting is still a spreadsheet problem in disguise

https://emailcalculator.com
1•emailcalculator•6m ago•0 comments

Ultraprocessed Foods and Public Health

https://ajph.aphapublications.org/ultraprocessedfoodssection
1•Jimmc414•7m ago•0 comments

2026 Toyota Sequoia Capstone Review: Terrible Use of $90k

https://www.thedrive.com/car-reviews/2026-toyota-sequoia-capstone-review
2•PaulHoule•7m ago•0 comments

Trophic memory, deer, and a unique scientific object

https://thoughtforms.life/trophic-memory-deer-and-a-truly-unique-scientific-object/
1•atombender•7m ago•0 comments

Zelda – Ocarina of Time (Switch 2)

https://www.nintendo.com/us/gaming-systems/switch-2/featured-games/the-legend-of-zelda-ocarina-of...
2•hmokiguess•7m ago•1 comments

Building an AI-Native Engineering Team

https://developers.openai.com/codex/guides/build-ai-native-engineering-team
1•mpgirro•13m ago•0 comments

Show HN: Capture Go board positions with a browser extension

https://play.goshawk.cc/gsx/index.html
1•h3mm3•20m ago•0 comments

In 2026 T-Mobile gives me an IPv6 /64 without prefix delegation

https://github.com/bradleypeabody/myispsucksv6
1•bradpeabody•21m ago•0 comments

The consequences of relying on AI for accurate news

https://news.mit.edu/2026/consequences-of-relying-on-ai-for-accurate-news-0609
1•droidjj•22m ago•0 comments

Mythos/Fable intentionally hinders requests involving AI Research Development

https://twitter.com/eliebakouch/status/2064399902684139852
2•behnamoh•25m ago•0 comments

Trump Expands Glyphosate, and Now the MAHA Moms Who Elected Him Are Done

https://www.ibtimes.co.uk/trump-glyphosate-order-backlash-1801442
1•smnthermes•28m ago•0 comments

SpaceX IPO demand is approaching four times oversubscribed

https://www.reuters.com/world/spacex-ipo-demand-is-approaching-four-times-oversubscribed-source-s...
2•ironyman•28m ago•0 comments

What is the sea drone that rescued US helicopter crew?

https://www.reuters.com/world/middle-east/five-facts-sea-drones-after-us-helicopter-rescue-2026-0...
2•JumpCrisscross•29m ago•0 comments

Nvidia CUDA Python 1.0 and CUDA 13.3 Release

https://developer.nvidia.com/blog/nvidia-cuda-13-3-enhances-gpu-development-with-tile-programming...
1•ashvardanian•29m ago•0 comments

Open Source Agent, Harness-1, Outperforms GPT-5.4 on Recall

https://venturebeat.com/orchestration/researchers-trained-an-open-source-ai-search-agent-harness-...
2•somewhatrandom9•31m ago•0 comments

Fable 5 remotion video benchmark and examples

https://mesmer.tools/benchmarks/ai-video-generation
3•mesmertech•31m ago•1 comments

Create WhatsApp screenshots from a 3D phone model

https://www.getmockly.com/chats/whatsapp
2•eRzy•31m ago•0 comments

Show HN: A minimal linear algebra library in pure Go

https://github.com/igomez10/linearalgebra
2•igomeza•31m ago•0 comments

Show HN: Elah – A browser-native, frame-accurate video editor

https://github.com/elahlabs/elah
2•paulSpaurgen•34m ago•0 comments

I Replaced a $144/Year App in <2 Hours. The Moat Was Never There

https://substack.com/@vmysla/p-197723867
1•vmysla•39m ago•0 comments

The contract that could get you FIRED (lexploit)

https://www.legalquants.com/blog/the-contract-that-could-get-you-fired
1•SaifAlYounan•39m ago•0 comments

Trump is becoming Jimmy Carter

https://www.ft.com/content/c6e506e0-4b95-437b-8fad-ac436a71c3de
3•GreenSalem•42m ago•1 comments

My side of the jqwik anti AI logging drama

https://blog.johanneslink.net/2026/06/09/the-jqwik-anti-ai-affair/
2•phoronixrly•46m ago•1 comments

Claude Fable 5: the first public Mythos-class model

https://artificialanalysis.ai/articles/claude-fable-5-mythos
3•Topfi•47m ago•0 comments

If Claude Fable stops helping you, you'll never know

https://jonready.com/blog/posts/claude-fable5-is-allowed-to-sabotage-your-app-if-youre-a-competit...
63•mips_avatar•48m ago•16 comments

Claude Fable 5 will sabotage "frontier LLM research" tasks

https://twitter.com/i/status/2064399902684139852
8•qwertyforce•51m ago•1 comments