frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Aikido Code Audit

https://www.aikido.dev/blog/introducing-code-audit-find-complex-vulnerabilities-hidden-in-your-codebase
18•ilreb•2h ago

Comments

_def•1h ago
This is marketed as a defensive tool, but how do you prove that you check against "your" source code?
Shanyao•1h ago
Looks like a solid bridge between SAST and manual review. Will check it out.
shireboy•1h ago
We’ve been using aikido code scanning and pen test tools and been pretty impressed. Will have to take a look at this.
leetrout•54m ago
I'm building a competing product and am curious if you'd be up for a conversation about what you've enjoyed best about Aikido and, importantly, what gaps are still not covered.
joshuat•1h ago
This looks promising, but I find it a little odd to bury the bulk of plan limitations under "fair-usage limits". When the limitations are specifically coupled to plans, it feels less like an FUP and more like plan-specific caps that should be surfaced more directly.
woodruffw•51m ago
As with so much (LLM) security work, the devil is in the details: "~25 security issues per codebase" means nothing without a grounding in the codebase's actual security model, capabilities exposed to an attacker, etc. I haven't used Aikido's product, but my experience with similar tools is that tend to not find actual security issues until a proper security model is introduced for grounding.

(I say this as someone who is, broadly, extremely impressed by and interested in the use of LLMs for security research.)

MeetingsBrowser•46m ago
> logic based vulnerabilities like a ReDoS pattern identified from source without live exploitation, or an admin-only route that's never been exercised

The two classes of vulnerability given as examples are the exact kind of issue I probably don’t care about, and are not grounded in an actual security model

Jimmc414•17m ago
“But it appears 1 or more organizations have successfully jail-broken Fable 5”

This is hardly true or it’s true of all frontier models and this was only magnified by Fables capabilities. It’s that you could hand Fable 5 vulnerable code, ask it to fix it, return patch plus test cases proving the fix and exploit relevant detail falls out as a byproduct of legitimate secure code review work.

I challenge anyone to provide a fix for this “exploit” without compromising Fable’s ability to patch unsecure code.

XLibre XServer 25.2.0 Released

https://github.com/X11Libre/xserver/wiki/XLibre-XServer-25.2-Changes
5•calvinmorrison•8m ago•0 comments

Cyberdecks, going analog, and convivial technology

https://blog.hydroponictrash.solar/cyberdecks-going-analog-and-convivial-technology/
1•akkartik•8m ago•0 comments

Secretive Wall Street Powerhouse Jane Street Seizes the AI Spotlight

https://www.wsj.com/tech/ai/jane-street-ai-wall-street-bdfcc81a
1•pondsider•12m ago•0 comments

Brain-computer interface enables independent communication for man with ALS

https://health.ucdavis.edu/news/headlines/brain-computer-interface-enables-independent-accurate-c...
1•gmays•14m ago•0 comments

Diffusion‑based LLMs that generate many parallel tokens rather than one‑by‑one

https://www.inceptionlabs.ai/
1•binyu•16m ago•0 comments

Painting a Landscape with Mathematics [video]

https://www.youtube.com/watch?v=BFld4EBO2RE
1•soupspaces•20m ago•0 comments

Show HN: Vxpix – $50 lifetime screenshot API, URL to image in <1s

https://tool.vxpix.com/
1•vxpix•28m ago•0 comments

Show HN: Schemic – your database schema, in the Zod API you know

https://schemic.dev/
1•msanchezdev•30m ago•0 comments

Scientists warn 'Godzilla' El Niño could intensify climate impacts worldwide

https://www.npr.org/2026/06/17/nx-s1-5860821/el-nino-peru-climate
1•rolph•30m ago•1 comments

Show HN: Muninn - 8 Security scanners in one GitHub Action

https://github.com/skaldlab/muninn
1•sg0nzalez83•30m ago•0 comments

Historic Firsts – a daily game about ranking firsts in history

https://playhistoricfirsts.com/
1•jeremyfrancis87•35m ago•0 comments

Gizmodo compromised, serving ClickFix malware capchas

https://gizmodo.com/io9
5•radley•36m ago•1 comments

show hn: Turn server photos into editable rack templates (experimental)

https://react-networks-lib.rackout.net/asset-designer
1•matt-p•38m ago•0 comments

The Standard Model from the octonions on a hyperbolic 24-cell lattice

https://zenodo.org/records/20768426
2•lancejpollard•38m ago•0 comments

Wave Equation with Computable Initial Data and Solution Is Nowhere Computable

https://dl.acm.org/doi/abs/10.1002/malq.19970430406
2•measurablefunc•39m ago•0 comments

MojiMoshi – create an AI agent that lives in Telegram or Line

https://mojimoshi.com/
1•xsirix•41m ago•0 comments

Help I Accidentally a Wigglegram

https://lmao.center/blog/wiggle-accidents/
2•gregsadetsky•42m ago•0 comments

Copyany Websites Brand Kit

https://chromewebstore.google.com/detail/ai-brand-kits-—-extract-b/cbdoamlbbflaphjnbladbfnianjl...
1•mattmerrick•43m ago•0 comments

Trump administration reverses decision to scrap ocean monitoring system

https://www.theguardian.com/us-news/2026/jun/18/ocean-monitoring-system-reversal-trump-administra...
6•thunderbong•43m ago•0 comments

A Trillion Dollars Isn't Worth It If You Have to Be Elon Musk

https://www.currentaffairs.org/news/a-trillion-dollars-isnt-worth-it-if-you-have-to-be-elon-musk
4•Anon84•45m ago•1 comments

Ask HN: Is there a microSD card of the Mythos model?

2•smalltorch•45m ago•0 comments

The model is swappable the ontology compounds

https://www.typedef.ai/blog/the-model-is-swappable-the-ontology-compounds
1•cpard•47m ago•0 comments

Software Optimization Resources

https://www.agner.org/optimize/
2•turtleyacht•49m ago•0 comments

AI AlphaFold pioneer who won a Nobel Prize leaves Google DeepMind for Anthropic

https://www.businessinsider.com/alphafold-john-jumper-leaves-google-deepmind-anthropic-demis-hass...
2•nsoonhui•52m ago•0 comments

A coding agent is six functions in a trenchcoat

https://tidydesign.substack.com/p/a-coding-agent-is-six-functions-in
2•data_ders•56m ago•0 comments

Baseball Coaches or Parents

https://www.baseballstatstracker.com
1•carlandrews•57m ago•0 comments

Entertainmentindustry.ai – Engineering hunt and M&A gateway

https://entertainmentindustry.ai
1•DavidFrangiosa•1h ago•0 comments

You can't train in what the model knows

https://hftuniversity.com/post/your-ai-s-fast-c-wasn-t-faster-and-one-sentence-makes-it-safe
2•htk•1h ago•0 comments

Why isn't xAI as impactful compared to others?

1•manonginusa•1h ago•3 comments

Tree Transformers

https://astledsa.substack.com/p/tree-transformers
1•astledsa•1h ago•0 comments