frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Call Stack Diffs

https://oskrim.github.io/engineering/2026/08/02/call-stack-diffs.html
1•mpweiher•1m ago•0 comments

Ask HN: In your experience, what are sound conventions for e-ink UI development?

1•BoxOfRain•3m ago•0 comments

Music to confuse AI might be the next new genre

https://cdm.link/music-to-confuse-ai-might-be-the-next-new-genre/
1•wyclif•4m ago•0 comments

Autoresearch for Hardware

https://www.onyxresearch.ai
1•tedlutkus•5m ago•1 comments

Make WordArt Online

https://wordart97.net/
1•choult•5m ago•0 comments

To Save C, We Must Save ABI

https://thephd.dev/to-save-c-we-must-save-abi-fixing-c-function-abi
2•jackwilsdon•7m ago•0 comments

City That Arrested Clapper at Data Center Meeting Goes Virtual for 'Safety'

https://www.404media.co/city-that-arrested-person-for-clapping-at-data-center-meeting-moves-to-vi...
1•cdrnsf•8m ago•1 comments

Show HN: Merge – AI-native code review assessments for engineering hiring

https://mergeoa.com
4•harshithl1777•11m ago•0 comments

HarnessOpt-Bench: Evaluating LLMs at Harness Optimization

https://arxiv.org/abs/2608.06301
2•wslh•12m ago•0 comments

Tell HN: Tally Data Breach

4•gregsadetsky•16m ago•1 comments

Coding agents, defaults, and human judgment

https://rpc3.dev/posts/coding-agents-defaults-and-human-judgment/
2•rpc3•17m ago•0 comments

parakeet.wgsl – Fast, accurate ASR in the browser, via raw WebGPU and SIMD WASM

https://parakeet.narcotic.sh/
2•hamza_q_•19m ago•1 comments

The Two-Year-Old Firefox ARM64 Video Bug

https://fratellobigio.com/posts/the-two-year-old-firefox-arm64-video-bug/
3•fratellobigio•20m ago•0 comments

Big tech's AI-powered 'pervert' glasses are in a losing battle with DuckDuckGo

https://www.sfgate.com/tech/article/duckduckgo-sunglasses-22377693.php
3•wyclif•20m ago•2 comments

Why are Japan's luxury night trains making a comeback?

https://www.nippon.com/en/japan-topics/g02623/
3•whiteblossom•23m ago•0 comments

Keras 3.15.1

https://github.com/keras-team/keras/releases/tag/v3.15.1
2•tosh•23m ago•0 comments

Vision based touch-less macOS control via hands (FOSS)

https://pawvis.app/
2•heresalexandria•23m ago•1 comments

Tesla and SpaceX to invest $16.8B for Terafab chip factory in Texas

https://techcrunch.com/2026/08/06/tesla-and-spacex-will-invest-16-8b-to-start-building-terafab-ch...
3•joering2•25m ago•0 comments

Show HN: 514 - Managed infra, agents and data to simulate coding agents as users

https://docs.514.ax/0.5.0-rp/getting-started
5•okane•25m ago•0 comments

Portable Memory System for Coding Agents

https://agentspackai.com/
2•nechmads•25m ago•0 comments

Estrogen masculinizes neural pathways and sex-specific behaviors

https://pmc.ncbi.nlm.nih.gov/articles/PMC2851224/
2•handfuloflight•26m ago•0 comments

Three Costly Database Failures That Changed Software Engineering Forever

https://stackrender.io/blog/3-costly-database-failures
3•theanonymousone•26m ago•0 comments

DARPA Lift Challenge – Aug 7 – Main Broadcast [video]

https://www.youtube.com/watch?v=hkao-a9egbY
2•Stevvo•26m ago•0 comments

Canada adds 75,000 new jobs in July, unemployment rate lowest in 2 years

https://www.cbc.ca/news/business/canada-jobs-july-2026-9.7299225
5•vrganj•27m ago•0 comments

2026 State of CSS, Devs Surveys

https://css-tricks.com/2026-state-of-css-devs-surveys/
2•redbell•28m ago•0 comments

Is Apple's privacy line bullshit?

https://probably.co.uk/posts/is-apples-privacy-line-bullshit/
2•speckx•28m ago•0 comments

Flock Cameras Used as Probable Cause for Traffic Stop

https://b105country.com/wisconsin-flock-camera-marijuana-search-ruling/
4•pat2man•29m ago•0 comments

The Download: a censorship conspiracy theory and the first virus created by AI

https://www.technologyreview.com/2026/08/07/1141389/the-download-censorship-conspiracy-theory-fir...
1•joozio•30m ago•0 comments

Agent Proxy: Credential Brokering for Agents

https://infisical.com/blog/agent-proxy
3•dangtony98•30m ago•0 comments

How primary energy is measured has changed across our charts

https://ourworldindata.org/primary-energy-measurement-change
1•xnx•30m ago•0 comments
Open in hackernews

Responding to the next frontier of critical cyber capabilities

https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/
28•artninja1988•53m ago

Comments

TrueDuality•34m ago
Ah yes let the FUD continue. This is a real problem but so far not nearly as severe as any of the marketing has made it out to be to the overall detriment of everyone including these companies announcing these scary capabilities. These announcements always included half hearted attempts at security layers which has now been demonstrated to benefit attackers more than defenders.

I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.

hbn•15m ago
The recent Hugging Face incident did not seem like FUD to me
Tiberium•12m ago
The fact that HF had to resort to using GLM 5.2 to analyze the logs/payloads makes it look legitimate, at least for me. They would not say that they hit guardrails with the frontier US models when defending if this was an obvious PR stunt.

https://huggingface.co/blog/security-incident-july-2026

> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

jackb4040•26m ago
> We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments

Stricter than what? You never even disclosed what happened in the first incident? This is nothing more than a setup to make it happen again and say "See? It broke out again, from an even stricter sandbox!"

Tiberium•22m ago
They actually did a detailed presentation at BlackHat about the HuggingFace incident, and events that led to it.

https://youtube.com/watch?v=87DyyMV0kCY

_puk•14m ago
That was fascinating.

Hijacking the package manager to pass messages between models and agents.. that's next level.

Like "pssst, if you need internet access there's a vulnerability in x service" kind of messages

ducktective•21m ago
> including isolated testing environments

Given the attack vector having possible super-human capability, I'm not sure such an environment exists. "Isolated" according to who?

Maybe seL4 could be a viable option here...

neya•23m ago

    We are sharing this because we believe it’s important to be transparent with the public and the safety and security communities about this potential shift in capabilities.

*proceeds to not share much details about strictness*

Yet another PR piece. Sigh.

cryo32•20m ago
Damage done.

The next frontier is getting all our shit out of reach of these companies/models/platforms and putting them back on prem.

Tiberium•19m ago
In my personal experience Sol with cyber verification is extremely capable of finding vulnerabilities, and it works even with binaries if you have some kind of IDA/Ghidra CLI access. Of course, unless the binary is protected with Denuvo/VMProtect/etc.

It sounds absurd, but in the last few weeks I've had a few cases where Sol found an RCE in self-hosted web applications in literal minutes just from reading the code (I prefer when it tries to reason statically instead of spamming runtime probes at first).

In another case it found an arbitrary file write in multiplayer in an old game by reverse engineering the binary - any other player in a match could just send you files to anywhere on your system.

I do these things for pure entertainment and curiosity, not for money from bug bounties, so if Sol can find those with a trivial prompt in tens of minutes for me, then what can focused companies/actors find in days or weeks?

Although I think most vulnerabilities are going to be closed in popular software by mid 2027, except in niche old or abandoned projects.

mephux•4m ago
Link to the disclosures then.. prove it. Anyone can say this.. i found an RCE in netBSD
thisisauserid•9m ago
So they finally found a business model: the cause of, and solution to, cyber security problems.
bearjaws•9m ago
These AI companies have found their #1 marketing piece and just beating it to death.

The reality is if they cared about security at all they would provide a way for me to credential myself against my companies environment so I can use the AI on it to improve our security.

Tiberium•7m ago
Isn't this literally what https://chatgpt.com/cyber and http://openai.com/form/enterprise-trusted-access-for-cyber are for?
mephux•9m ago
We all know this is propaganda to get a gov bailout or to slow down competition with regulations right? If this was an issue companies that did red team engagements would have been regulated long ago. There is no regulations on companies that actively exploit products, companies and services for money. They could all be bad actors.. yet, no regulations.. its all nonsense. If it's important.. don't connect to the internet.. there, you are good.. like if you don't want to OD on heroin.. don't do the heroin.
Terr_•7m ago
[delayed]
NitpickLawyer•6m ago
There's more details for the HF related incident in this [1] defcon talk. They said they're gonna have a proper post mortem at the end of the investigation (interesting to see if they publish full logs for the hf thing or not). But there's plenty of interesting tidbits from oAI's side in this talk, it's worth the 20 min watch.

tl;dw;

- agents found a way to communicate between several instances during a training run (kinda made a messageboard for themselves)

- while communicating with each other, they found ways to ssrf and RCE on the Artifactory endpoint.

- oAI found it and cleaned it up (reported RCE, redeployed Artifactory, removed the messageboard). Training / eval resumed.

- models trained w/ those traces (having the messageboard, ssrf, rce, etc) were used to having that. So they re-established comms via directory creation (w/ funny tidbits there, should really watch). And re-popped Artifactory via a different path to RCE.

- a different "persistent" model started working on cybergym and found the messageboard w/ details for RCE and things. Went on to hack HF.

- oAI contacted HF to ask if "they (oAI) should be concerned and were they (oAI) affected by HFs breach". Hilarity ensues when they figure out it's their agents doing it...

[1] - https://www.youtube.com/watch?v=87DyyMV0kCY