frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Six curl CVEs after OpenAI and Anthropic came back with zero

https://aisle.com/blog/aisle-discovered-six-curl-cves-after-openai-and-anthropic-found-zero
29•goobreee•52m ago

Comments

anilgulecha•14m ago
That's bragging rights correctly earned, i think! As marketing-y as this post is, definitely something to keep an eye on.
melvinroest•13m ago
Wow, this announcement is good content marketing.

Don't get me wrong, it's interesting. But there is no technical discussion as to how they did it. It's simply: we did it and Mythos and Codex didn't.

It's good to know that it's possible, but I'd have already expected it. Put a base model versus a base model + harness + whatever else, and yea, if you do it right then you have a better system to find vulnerabilities.

> We then ran AISLE's autonomous AI system against curl.

They don't even mention what models the use under the hood. It wouldn't surprise me if they are from Anthropic and OpenAI.

drdrd•9m ago
> what models the use under the hood

Presumably their own, wouldn’t they?

melvinroest•6m ago
You mean their own trained models, or do you think it's an open source model that they fine-tuned? If they use their own, I'd guess it's the latter.
rwmj•8m ago
We had a few AISLE-generated security reports, and the signal to noise was reasonably good.

The most notable bug/exploit their scanner found was: https://gitlab.com/nbdkit/libnbd/-/commit/e50bbd2681117c2dd8...

The tool basically had to chain two exploits together to reach this. It also came up with a patch to fix which was fairly sensible (but I ended up editing it further for clarity).

TechTechTech•6m ago
Good marketing and definitive proof that local (read: on-prem & air-gapped) models with correct context and tools are good enough to perform on par and above SOTA cloud hosted solutions.

We have seen this point many times before with different technologies. The first computers at university were big and expensive, same as this machine. Give it a few years and this functionality will be a commodity.

Why Do Male Chimpanzees Throw Rocks at the Same Trees for More Than a Decade?

https://nautil.us/why-do-male-chimpanzees-throw-rocks-at-the-same-trees-for-more-than-a-decade-12...
1•Brajeshwar•30s ago•0 comments

Pre-Release of Polars 2.0

https://pola.rs/posts/announcing-polars-2/
1•simicd•41s ago•0 comments

Otaku.sh – AI Roleplay Client

https://otaku.sh
1•enclavum5•43s ago•0 comments

Ssmach: Simple Python State Machines

https://github.com/hello-binit/simple_sm
1•bshah_•1m ago•0 comments

Scout Bowie – Client-side draft room and lineup optimizer for Sleeper

https://github.com/scout-bowie-analytics/sleeper-analytics-suite
1•scout_bowie•1m ago•0 comments

Show HN: Sandboxed HTML in Markdown (With Doom, Sort Of)

https://strata.space/@strataspace/doom-sort-of
1•strataspace•2m ago•0 comments

Global heating will hit at least 1.8C UN warns, and there are 'no good outcomes'

https://www.theguardian.com/environment/2026/sep/02/global-heating-warming-1-8c-best-case-scenari...
2•Teever•3m ago•0 comments

End-to-end engineering reference for AI data centers

https://aidatacenterguide.com
1•matadormix•4m ago•0 comments

Show HN: Convert Anything to Markdown

https://anyto.md/
2•vlucas•5m ago•0 comments

Show HN: Sensez – helping coding agents catch their own code smells

https://github.com/popov95s/sensez
1•popov95s•5m ago•0 comments

People Who Live Past 100 Have an Abundance of Cancer-Killing Immune Cells

https://www.sciencealert.com/people-who-live-past-100-may-be-protected-by-rare-cancer-killing-imm...
1•gmays•6m ago•0 comments

Show HN: I created a privacy-focused email service

https://justreceive.email/
2•beastave•7m ago•0 comments

"greets" to the Amiga demoscene in a 1996 PlayStation game

https://32bits.substack.com/p/under-the-microscope-shellshock-playstation
1•bbayles•8m ago•0 comments

Overtone: Open-source toolkit for designing synths and collaborating with music

https://github.com/overtone/overtone
1•Bluestein•8m ago•0 comments

How Technical Should a Product Manager Be

https://monkeynoodle.org/2023/02/04/how-technical-should-a-product-manager-be/
1•mooreds•10m ago•0 comments

Sonos Has New Devices, a New OS, and Yes, a New App

https://www.wired.com/story/sonos-has-new-devices-a-new-os-and-yes-a-new-app/
1•smurda•10m ago•0 comments

Show HN: ReviewHeron – Unified inbox for your app store reviews, no cloud

https://hamme.software/en/apps/reviewheron/
1•nautzen•11m ago•0 comments

Components of JWTs Explained

https://fusionauth.io/articles/tokens/jwt-components-explained
1•mooreds•11m ago•0 comments

Average Opus 5 Response

https://old.reddit.com/r/ClaudeCode/comments/1w3rxkj/average_opus_5_response/
1•velcrovan•12m ago•0 comments

Claude's new system prompt doesn't want to reproduce song lyrics

https://simonwillison.net/2026/Sep/2/claudes-new-system-prompt/
1•tosh•12m ago•0 comments

Multiplayer for Claude Code and Codex

https://nimbalyst.com/teams/
1•wek•12m ago•0 comments

Should You Invest in Bonds?

https://www.nytimes.com/2026/08/21/business/investing-bond-market-stocks-funds.html
1•mooreds•12m ago•0 comments

The age of abundance is over and neither policy nor markets have caught up

https://www.haver.com/articles/the-age-of-abundance-is-over-and-neither-policy-nor-markets-have-c...
1•toomuchtodo•12m ago•0 comments

Are We Thinking Correctly About AI Intelligence?

https://www.quantamagazine.org/are-we-thinking-correctly-about-ai-intelligence-20260820/
1•gmays•12m ago•0 comments

Climber Recounts Rescue from 6-Inch Ledge Atop California Mountain

https://www.nytimes.com/2026/08/30/us/sierra-nevada-climber-rescued-mountains.html
1•bookofjoe•13m ago•1 comments

Gemini Agentic Video Analysis Cuts Token Usage Up to 88%

https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-agentic-video...
2•WarmWash•14m ago•0 comments

How AI Is Weaponizing India's Voter Data for Mass Surveillance

https://www.medianama.com/2026/09/223-sir-electorion-commission-data-privacy/
2•twapi•14m ago•0 comments

Models may behave differently in graded episode

https://www.lesswrong.com/posts/AfoGGrJfuNzofpzWL/models-may-behave-differently-in-graded-episode...
2•ddp26•17m ago•0 comments

Show HN: Flawd is mutation testing for the AI era

https://fixture.dev/flawd
3•fohara•18m ago•2 comments

Exit the Cave

https://turtlespace.blog/p/exit-the-cave
5•akkartik•18m ago•0 comments