frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Do the AI Studio test NOW to prove Google doesn't delete chats

https://lemmy.world/post/51905600
1•Bitu79•3s ago•0 comments

Investigation with Context and Confidence

https://blog.bluebox.ai/investigation-with-context-and-confidence/
1•aboris26•7s ago•0 comments

(conf talk) Liberating the A100 beast inside Nvidia's CMP 170HX e-waste

https://talks.mrmcd.net/2026/talk/ZDRJLV/
1•ValdikSS•41s ago•0 comments

Kamal – Deploy web apps anywhere from bare metal to cloud VMs

https://kamal-deploy.org/
1•linkdd•1m ago•0 comments

The Cloudflare products I use

https://flaviocopes.com/cloudflare-products-i-use/
1•AliCollins•2m ago•0 comments

Ubuntu 26.10 completes transition to Rust-based coreutils

https://www.omgubuntu.co.uk/2026/09/ubuntu-2610-rust-coreutils-complete
1•theanonymousone•2m ago•0 comments

Seabirds produce $470M worth of guano every year (2020)

https://www.anthropocenemagazine.org/2020/08/seabirds-produce-470-million-worth-of-guano-every-year/
1•pvaldes•4m ago•0 comments

METR: The New AI Gatekeepers and the Quiet Path to State Control of AI

https://readmultiplex.com/2026/09/13/metr-the-new-ai-measurement-gatekeepers-and-the-quiet-path-t...
3•CGMthrowaway•4m ago•0 comments

The AI cleanup crew. Why AI taking down sites is a good thing

1•foxtrot8672•4m ago•0 comments

Grief in the Age of "Infinite" Progress

https://devz.cl/posts/grief/
1•DanielVZ•8m ago•0 comments

Algeria severs diplomatic ties with UAE

https://breakthroughnews.org/2026/09/13/wherever-they-set-foot-blood-flows-algeria-severs-diploma...
1•robtherobber•8m ago•0 comments

Show HN: Tools that get cheaper every time you use them (floor: one £/$5)

https://manyuseful.tools
1•phughes1980•9m ago•0 comments

Repology.org domain appears to be on registrar hold (resolves to 127.0.0.1)

https://github.com/repology/repology-rs/issues/560
1•GalaxySnail•10m ago•0 comments

Show HN: Salmon – tray and desktop alerts for systemd services and custom checks

https://github.com/dimonomid/salmon
2•dimonomid•11m ago•0 comments

9,057 patches total in the seven stable kernels

https://social.kernel.org/notice/BAKK4RpFGJmm95B3o0
1•speckx•11m ago•0 comments

Iceland, One of Three Countries That Still Hunts Whales, Considers Ban

https://e360.yale.edu/digest/iceland-whaling-ban
3•speckx•14m ago•0 comments

Amp is now free to use when you bring your own compute and model subs/keys

https://ampcode.com/news/free-agent
1•jhchabran•15m ago•0 comments

Jensen Huang Became AI's Taylor Swift

https://www.economist.com/interactive/1843/2026/09/03/how-jensen-huang-became-ais-taylor-swift
1•tolugenius•16m ago•1 comments

Show HN: Memory plugin for coding agents that remembers your coding&chat history

https://github.com/deepmemteam/deepmem-claude-plugin
2•deepmem•17m ago•0 comments

People Who Can't Picture Anything Are Rewriting the Science of Imagination

https://dailyneuron.com/aphantasia-mental-imagery-brain-network/
1•giuliomagnifico•17m ago•0 comments

Global AI stocks fall as industry chiefs call for slowing development

https://www.reuters.com/world/china/ai-linked-asian-stocks-slump-after-top-lab-ceos-call-slowing-...
3•1vuio0pswjnm7•19m ago•4 comments

An AI deal with China could get Donald Trump his Nobel Prize

https://economist.com/by-invitation/2026/09/14/an-ai-deal-with-china-could-get-donald-trump-his-n...
2•andsoitis•20m ago•1 comments

Show HN: Pelican-bicycle alternatives (updated for 2026)

https://gally.net/temp/20260914pelican-alternatives/index.html
1•tkgally•20m ago•0 comments

Update on Security at METR

https://metr.org/blog/2026-08-31-security-update/
1•tosh•22m ago•0 comments

Don't Fall for a Mystery Shopping Job Scam

https://www.mouseprint.org/2026/09/14/dont-fall-for-a-mystery-shopping-job-scam/
1•speckx•23m ago•0 comments

The Ocean Is Not a Road: Fix Your Fantasy Map [video]

https://www.youtube.com/watch?v=u5kEbkeX_94
1•skibz•24m ago•0 comments

Temporal raises $550M at a $12.55B valuation

https://temporal.io/blog/temporal-raises-usd550m-series-e-at-usd12-55b-valuation-ai
3•gk1•24m ago•0 comments

The powerful millionaires hiding in plain sight

https://www.npr.org/sections/planet-money/2026/09/14/g-s1-143041/the-powerful-millionaires-hiding...
2•ripe•24m ago•1 comments

The AI-as-Normal-Technology view of loss-of-control incidents

https://www.normaltech.ai/p/the-ai-as-normal-technology-view
1•guillego•24m ago•0 comments

Volkswagen Just Built an EV That Can Go Nearly 900 Miles on a Charge

https://www.motor1.com/news/808114/vw-mission-efficiency-concept-specs-photos/
16•thelastgallon•26m ago•2 comments
Open in hackernews

What a time to be alive – rouge AI agents attack RubyGems.org

https://tenderlovemaking.com/2026/09/11/what-a-time-to-be-alive/
66•gregnavis•1h ago

Comments

mauriciolange•47m ago
rogue AI agents or AI agents coming from Moulin Rouge?
PatronBernard•44m ago
At least we know the title wasn't AI-generated?
foobarbecue•27m ago
The weird thing is I've seen LLMs "typo" stuff pretty often. Yesterday I asked Gemini a question about the Python Twisted framework and it answered about Deferreds but misspelled it as "Deferends" in one spot.
goda90•37m ago
A cabaret AI would certainly be better than one trained on the Khmer Rouge.
vidarh•36m ago
Rouge syntax-highlighting rogue agents, clearly.

https://rubygems.org/gems/rouge

Phemist•14m ago
Classic mistake. Tell the agent to highlight this code, but dont give it any actual code. Agent hacks its own gem to find the code to highlight.
iAMkenough•40m ago
I’m seeing red
sporritt•38m ago
those pesky reds

McCarthy was right all along

senda•38m ago
Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents?

Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

herculity275•32m ago
I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.
micromacrofoot•31m ago
what do you mean? they're using AI to kill people directly in Ukraine

https://www.nytimes.com/2026/08/24/world/europe/russia-drone...

heaney-555•30m ago
These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled.

Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all.

As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign compute capacity.

valleyer•28m ago
Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.
kstrauser•36m ago
Ah, the infamous Crimson Wave.
riskable•22m ago
Ah damnit, you beat me to it. Excellent sense of humor, friend :D
Roark66•32m ago
There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems".

In short, it was intentional.

Xirdus•26m ago
The big question is was this grossly negligent or just extremely careless.
rglover•23m ago
Both. This should result in criminal charges.
brookst•14m ago
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
rglover•10m ago
Whoever prompted the agent, whoever supplied the means, whoever knew but didn't say anything.
tacomagick•5m ago
Also whoever monitoring these agents, in this case not monitoring. This "Who is responsible" dilemma is so stupid. If I gave the AI tool means to kill a person but I did not tell it directly to use it and it uses it anyway then I am responsible for it.
timdiggerm•28m ago
We need a legal structure to make companies liable for the actions of the agents they've made.
ahoka•21m ago
I'm pretty sure it's already illegal to hack others.
kevincox•21m ago
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
masfuerte•20m ago
If it's covered by criminal law they don't need to sue. They can call the FBI.
riskable•18m ago
We already have it.

Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies.

It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

2OEH8eoCRo0•13m ago
"To my friends, everything; to my enemies, the law"
VyseofArcadia•28m ago
How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Xirdus•21m ago
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
VyseofArcadia•19m ago
Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI?

Sorry if it is a stupid question, as mentioned above I am legally naïve.

colechristensen•16m ago
The same concept that allows a corporation to sue and be sued allows it to be charged with crimes
brookst•13m ago
Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.
yonatan8070•10m ago
I, too, have no idea about legal matters.

But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.

I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.

swiftcoder•24m ago
> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info.

Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.

sebmellen•24m ago
Did the AI agents actually wear makeup? I’ve never heard of a rouge AI agent :P
HelloUsername•21m ago
Related

"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099

"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments

"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590

rougehuh•21m ago
Rouge agents with Ruby? Checks out

As long as they’re not vert

ur-whale•3m ago
> As long as they’re not vert

Well, at least they weren't nucular.

toasty228•17m ago
Wait until a blue one does it
khalic•14m ago
Oh my favorite typo, you can never go wrong with a little rouge
GaryBluto•14m ago
I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.
brookst•10m ago
Any evidence, or just vibes?
GaryBluto•5m ago
Regarding what point? The entire thing is just a theory, but regarding the occasional OpenAI checks on WikiService.at-hosted Wikis targeted, there was, if I remember correctly, an OpenAI IP popping up every now and then that wasn't an agent. Unfortunately I don't have it to hand right now, but it was somewhere here:

https://news.ycombinator.com/item?id=49563355

ur-whale•4m ago
> Any evidence

Who profits from the crime?

ur-whale•11m ago
Are "rouge" and "rogue" interchangeable words in American English?
big-chungus4•2m ago
How does he know that this attack is performed by OpenAI agents? I couldn't figure this out from the article
12904927•1m ago
What a time to be alive? One of the most boring decades ever.

METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human.

Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants.

Why is Ruby Gems such a mess? It seems as bad as PyPI now.

joinjune•24m ago
Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those.
dgellow•14m ago
They don’t need to run their own DCs, just pay for a proxy somewhere in the world that has better access to the infrastructure. We know North Korea has been doing that in the US since years now
senda•12m ago
The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available.

I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be littered Ai con-artists.

I'm just wondering, again, is this mostly bullshit?

mcmcmc•24m ago
Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them
nradov•9m ago
Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.
mcmcmc•8m ago
[delayed]
dgellow•17m ago
They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet
senda•7m ago
I think this fails a lot of logical tests, it should be apparent in day to day life.
marginalia_nu•15m ago
Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities.
lenerdenator•13m ago
He did not fall out of a window.

He fell out of the sky. After his plane exploded. Happens all the time. Is tragedy.

tokai•14m ago
Because they dont have the money for hardware or compute obviously.
ur-whale•5m ago
> How are we not seeing insane attacks on Ukraine via Agents?

You live on the wrong side of the fence to be able to read that kind of news.

Did you really believe you had access to an unmanipulated news stream in a time of war?

LOL.

probably_wrong•7m ago
There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk".

https://www.law.cornell.edu/wex/reckless

nottorp•22m ago
Marketing actually.
tacomagick•5m ago
AI is dropping out of the spotlight so they are using desperate measures like this.
trvz•20m ago
Don’t forget outright intentional.
dgellow•19m ago
Both? I’m not sure what distinction you’re trying to make. It was completely irresponsible and likely a felony
aftbit•17m ago
Proof that the AI alignment problem is hard (perhaps even unsolvable).
srmatto•16m ago
Sounds more or less like the last breach then.
gibspaulding•11m ago
I think it can simultaneously be the case that OpenAI was grossly negligent in directly causing this AND that the AI’s ‘went rogue’ in that they are displaying behavior which is misaligned with OpenAI and humanity generally.

The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them.

AI is starting to feel like that line about magic: “a sword without a hilt”

consp•7m ago
Doesn't rogue in this context imply "outside of set limitations"? And then not "failed to properly instruct"? The same applies to humans when given bad instructions.
stymaar•47s ago
> which is misaligned with OpenAI and humanity

OpenAI is itself misaligned with humanity, as their mishandling of such incidents (and the many other other issues their model have been causing) show.

dumberquestions•11m ago
>They were prompted to hack to get answers

Were they? I haven't seen a single report mention this

cyanydeez•54s ago
we have normal words for this stuff: negligence. You can add it on to almost any law.

The problem is consumer protection is basically no longer a part of america's regulatory system. Replaced by "grift is good".

bix6•14m ago
How is the responsibility diluted? Charge the CEO…
brookst•11m ago
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction.

Do you think there is evidence of this?

bix6•1m ago
Honestly yeah I bet there is and I hope to someday read about it if the government ever gets off its ass. Someone set up the “experiment”…
tekla•7m ago
Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title.

I'm going to assume that this will never happen