frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Vulnerability reports are not special anymore

https://words.filippo.io/vuln-reports/
61•goranmoomin•2h ago

Comments

themanmaran•59m ago
I feel like it's also been overrun by a lot of spam. As someone running a company, I get 2-5 unsolicited "vulnerability reports" per week. Half of them are an LLM finding some bad CSS on our framer splash page. The other half I assume are an extortion attempt so we just mark as spam.

Occasionally I see real security researchers on HN complaining that no one takes the disclosure seriously, or that people reply immediately with a cease and desist. But from the receiving end it's just because the spam is unmanageable.

cleverfoo•33m ago
Same experience here. I've run a successful vulnerability disclosure program for over a decade and paid out thousands of dollars in bounties for scanii.com (a malware identification API service), but recently (since the beginning of the year), we went from receiving maybe 5 per month to receiving 5 per day. These are clearly AI-generated and extremely low quality (albeit well-written). The rules of the program aren't read, and it's clearly a “point-and-click to a website" and file a report. I'm now considering just shutting down the program since, as the OP pointed out, if you found this vulnerability using an AI tool, they are inherently public. I haven't gone that far yet but have instituted some new rules aiming at filtering out most of the reports: 1- No AI-generated report and 2 - Reports must include a video of the exploit. You can see our program rules here: https://docs.scanii.com/article/131-does-scanii-have-a-secur...
Gigachad•28m ago
I'm getting CVE fatigue with all of these super ultra critical 10/10 vulnerabilities that are some node package that compiles my frontend can get stuck if I give it a malicious regex.

It's hard to spot the stuff that actually matters.

woodruffw•38m ago
I agree with this. One of the consequences of the "vulnpocalpyse" is that it's become even harder to sift through the noise: I triage well over a dozen reports a week, many of which are "real" in the sense that they reflect a genuine defect but otherwise have an unclear impact on a typical user. This has always been true of the median vulnerability report, but the volume means that I now lean much more heavily away from coordinated disclosure.

One flipside to this is that, because many of these bugs are "shallow" to LLMs, it's actually easier than ever to moderate the worst participants in your vulnerability program -- if someone sends you slop, you can just ban them and wait for the next, better orchestrated LLM to send you a better report for the same vulnerability.

notnmeyer•26m ago
this is hilarious and i might try it.
cadamsdotcom•35m ago
Security through obscurity was never a great strategy.. and now it’s not a strategy at all..

Hopefully at the end of this decade, a ton of software practices have been overhauled to eliminate classes of problems. Memory-safe language use is a great start - but it’d be great to see innovation in checking for TOCTOU problems, improper/missing authn & authz, and many others.

This is an engineering problem. It won’t be solved by models that “only do dumb shit 1/10th as often, only 0.01% of the time now not 0.1%!” It won’t be solved by adding more models to do even more double-checking before and after the work. It won’t be solved by hoping humans catch it in review. It isn’t solvable by adding outer loops of any sort - though we may get close. To truly solve this will take serious CS research.

user3939382•15m ago
Verifying correctness of an implementation is P NP, not serious CS research.
david_shaw•25m ago
At risk of quoting too much of the article, it opens with this:

> A requirement for staying sane while working in public as an open source maintainer is realizing that every issue, PR, and piece of feedback is a present, not an obligation. You can accept it, ignore it, and use it partially or not at all.

> Except…

> For years, as lead of the Go Security team at the time, I’ve told new team members that it doesn’t apply to vulnerability reports. No, vulnerability reports are special. Security researchers are doing us a favor by reporting things confidentially instead of doing full disclosure, so we owe them something, which is not true of regular issues opened on the issue tracker.

[...]

> It’s 2026 and none of the premises are true anymore.

I respectfully disagree.

The premise is absolutely still true: if someone discovers a critical, exploitable vulnerability in your software, the impact and tradeoffs are exactly the same as they were before LLMs started finding bugs. There are just more of them now, so they're easier to come by.

But that won't last forever, either. As LLMs find increasingly difficult-to-find vulnerabilities, there will be fewer of them to report. This is just chugging through the backlog.

All of that said, I don't think finding vulnerabilities has really been the difficult security problem for most companies (or open source projects). The difficult problem is dedicating resources to fixing those vulnerabilities instead of building software, products, and/or infrastructure that people want. That problem is absolutely still here today, but I'm optimistic that agentic security developers will be able to take the burden off of development teams in the near future.

For tokens, of course.

zeveb•18m ago
> If a security vulnerability is reported by someone who is also violating the CoC, what do you do? Do you ignore it? Fix it silently?

Is this even a question? You triage and fix the vulnerability just like any other one. Are truths spoken by folks one dislikes — even for perfectly valid reasons — any less true?

The only way I can imagine this somehow applying is if someone has a habit of reporting vulnerabilities which do not exist, or of exaggerating their severity. Is crying wolf a CoC violation? If so, then I can imagine that particular sort of bad behaviour justifying some consideration before acting on a report.

calvinmorrison•7m ago
Will xorg backport patches from Xlibre?

Design Kits for iOS, iPadOS, and macOS 27

https://developer.apple.com/news/?id=e2lxw9l1
1•soheilpro•1m ago•0 comments

China Minerals Threatens EU; AI Warfare Dominates Japan, WeChat

https://asiaai.fyi/wp-login.php?redirect_to=https%3A%2F%2Fasiaai.fyi%2Fwp-admin%2Fpost.php%3Fpost...
1•dweisinger•4m ago•0 comments

Fear in Four Dimensions

https://taylor.town/fear-4d
1•Curiositry•7m ago•0 comments

Heliodor: An RVA23-Compliant Multicore Out-of-Order RISC-V Core in Veryl

https://veryl-lang.org/blog/heliodor-rva23/
1•dalance•11m ago•0 comments

OpenJTD: Project to Reverse-Engineer Ichitaro Word Processor Files Used in Japan

https://github.com/KimEJ/OpenJTD
1•nogajun•15m ago•0 comments

Chinese supercomputer leapfrogs best US machines to be ranked fastest

https://www.theguardian.com/technology/2026/jun/24/china-supercomputer-world-fastest-top500-ranki...
5•jethronethro•21m ago•0 comments

Tech stocks slump as AI bubble fears loom

https://www.axios.com/2026/06/23/tech-stocks-ai-bubble
5•1vuio0pswjnm7•23m ago•0 comments

SpaceX raises $25B in debt sale less than two weeks after IPO

https://www.cnbc.com/2026/06/23/spacex-debt-bond-market-ipo.html
1•1vuio0pswjnm7•25m ago•0 comments

Arabian Sand Boa: Python interpreter with frontier intelligence conditional eval

https://github.com/hopafoot/arabian-sand-boa
1•hopafoot•27m ago•1 comments

The Part After Done

https://howstrangeitistobeanythingatall.com/post/2026-06-23-the-part-after-done
2•alanbotts•29m ago•0 comments

Purroute – An auto-detecting proxy router that translates between protocols

https://github.com/femboyisp/purroute
1•vxfemboy•30m ago•0 comments

The Fastest Python Struct?

https://www.crumpledpaper.tech/2026-06-21-python-struct-profiling/
1•JPHutchins•33m ago•0 comments

FDA drops enforcement against Whoop after it tweaks blood pressure feature

https://www.statnews.com/2026/06/23/fda-drops-enforcement-against-wearable-maker-whoop/
2•brandonb•34m ago•1 comments

China's LineShine Supercomputer Dethrones US' El Capitan

https://www.tomshardware.com/tech-industry/supercomputers/chinas-lineshine-supercomputer-dethrone...
5•yogthos•36m ago•0 comments

Chinese universities are cutting language majors to make way for AI

https://restofworld.org/2026/chinese-universities-drop-humanities-ai/
5•higginsniggins•39m ago•0 comments

UN chief urges AI companies to 'come clean' about the pollution they generate

https://www.fastcompany.com/91563535/un-chief-urges-ai-companies-come-clean-about-pollution-create
2•1vuio0pswjnm7•39m ago•0 comments

SpaceX Has Successful Starfall Demo

https://www.nextbigfuture.com/2026/06/spacex-has-successful-starfall-demo.html
5•bookmtn•41m ago•0 comments

War by Other Means

https://letter.palladiummag.com/p/war-by-other-means
3•jger15•44m ago•0 comments

Eli Lilly Approved Obesity Drug for Mystery 79-Year-Old Patient

https://newrepublic.com/post/212206/eli-lilly-obesity-drug-79-year-old-patient-trump-health
7•randycupertino•51m ago•1 comments

Abyssguard

https://www.abyssguard.app/
3•Luci_Star•54m ago•0 comments

Show HN: Reachpad – open-source .md sharing platform for companies and agents

https://github.com/las7/reach
1•sakuraiben•56m ago•0 comments

How to Passive-Aggressively Shame People Who Use LLMs Selfishly

https://joshmoody.org/blog/selfish-ai/
22•joshmoody24•1h ago•17 comments

Vypl a Python REPL with Vim workflows and commands

https://github.com/HoraDomu/Vypl
2•HoraDomu•1h ago•0 comments

Show HN: Daily ETF holdings for 2,200+ ETFs as one API

https://developer.stockfit.io/blog/daily-etf-holdings
2•areimann•1h ago•2 comments

DealMaker Uses Morning Brew and Robinhood to Lure Retail Investors

https://hntrbrk.com/investigations/shark-tank
1•impish9208•1h ago•0 comments

Hermes Agent can now /learn from anything

https://twitter.com/NousResearch/status/2069526242236182697
4•biraj-rocks•1h ago•1 comments

Show HN: Keep all microservices consistent and make batch changes

https://infraas.ai
1•danielbedrood•1h ago•0 comments

Ask HN: Any suggestions for finding beta users?

1•lyfeninja•1h ago•0 comments

Google will make you wave at your computer to check you are real

https://www.the-independent.com/tech/google-captcha-bot-real-check-hand-wave-b3000419.html
2•anjel•1h ago•3 comments

Show HN: BitVanes – A zero-trust RAG pipeline engine in Rust, WASM, and Arrow

https://www.bitvanes.com/
1•kodr_pro•1h ago•0 comments