frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Evaluating and mitigating the growing risk of LLM-discovered 0-days

https://red.anthropic.com/2026/zero-days/
20•lebovic•1d ago

Comments

samfundev•9h ago
Glad to see that they brought in humans to validate and patch vulnerabilities. Although, I really wish they linked to the actual patches. Here's what I could find:

https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/c...

https://github.com/OpenSC/OpenSC/pull/3554

https://github.com/dloebl/cgif/pull/84

shoo•4m ago
Yeah, having a layer of human experts to sanity check and weed out hallucinated false positive issues seems like an important part of this process:

> To ensure that Claude hadn’t hallucinated bugs (i.e., invented problems that don’t exist, a problem that increasingly is placing an undue burden on open source developers), we validated every bug extensively before reporting it. [...] for our initial round of findings, our own security researchers validated each vulnerability and wrote patches by hand. As the volume of findings grew, we brought in external (human) security researchers to help with validation and patch development.

Based on the experiences shared by curl's maintainers over the last year, I'd suggest the "growing risk of LLM-discovered [security issues]" is primarily maintainers being buried under a deluge of low-effort LLM-hallucinated false positive security issue reports, where the reporter copy-pastes LLM output without validation.

tznoer•1h ago
Grepping for strcat() is at the "forefront of cybersecurity"? The other one that applied a GitHub comment to a different location does not look too difficult either.

Everything that comes out of Anthropic is just noise but their marketing team is unparalleled.

octoberfranklin•16m ago
This reads like an advertisement for Anthropic, not a technical article.
cyanydeez•7m ago
Is there a polymarket on the first billion dollar AI company to 0$ by their own insecure Model deployment?

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
243•klaussilveira•2h ago•38 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
655•xnx•8h ago•422 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
79•isitcontent•2h ago•10 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
50•dmpetrov•3h ago•15 comments

Show HN: R3forth, a ColorForth-inspired language with a tiny VM

https://github.com/phreda4/r3
29•phreda4•2h ago•3 comments

Microsoft open-sources LiteBox, a security-focused library OS

https://github.com/microsoft/litebox
278•aktau•9h ago•140 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
275•ostacke•8h ago•65 comments

Show HN: I spent 4 years building a UI design tool with only the features I use

https://vecti.com
199•vecti•4h ago•97 comments

I spent 5 years in DevOps – Solutions engineering gave me what I was missing

https://infisical.com/blog/devops-to-solutions-engineering
80•vmatsiiako•7h ago•23 comments

Early Christian Writings

https://earlychristianwritings.com/
100•dsego•2h ago•36 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
122•limoce•3d ago•63 comments

An Update on Heroku

https://www.heroku.com/blog/an-update-on-heroku/
260•lstoll•9h ago•191 comments

FORTH? Really!?

https://rescrv.net/w/2026/02/06/associative
17•rescrv•10h ago•2 comments

Evaluating and mitigating the growing risk of LLM-discovered 0-days

https://red.anthropic.com/2026/zero-days/
20•lebovic•1d ago•5 comments

Understanding Neural Network, Visually

https://visualrambling.space/neural-network/
209•surprisetalk•3d ago•26 comments

The Oklahoma Architect Who Turned Kitsch into Art

https://www.bloomberg.com/news/features/2026-01-31/oklahoma-architect-bruce-goff-s-wild-home-desi...
8•MarlonPro•3d ago•1 comments

I now assume that all ads on Apple news are scams

https://kirkville.com/i-now-assume-that-all-ads-on-apple-news-are-scams/
911•cdrnsf•12h ago•398 comments

The Beauty of Slag

https://mag.uchicago.edu/science-medicine/beauty-slag
18•sohkamyung•3d ago•2 comments

Show HN: Smooth CLI – Token-efficient browser for AI agents

https://docs.smooth.sh/cli/overview
73•antves•1d ago•56 comments

Show HN: Slack CLI for Agents

https://github.com/stablyai/agent-slack
27•nwparker•1d ago•5 comments

How virtual textures work

https://www.shlom.dev/articles/how-virtual-textures-really-work/
16•betamark•9h ago•11 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
338•todsacerdoti•10h ago•195 comments

How to effectively write quality code with AI

https://heidenstedt.org/posts/2026/how-to-effectively-write-quality-code-with-ai/
136•i5heu•5h ago•98 comments

Masked namespace vulnerability in Temporal

https://depthfirst.com/post/the-masked-namespace-vulnerability-in-temporal-cve-2025-14986
27•bmit•4h ago•2 comments

Show HN: Horizons – OSS agent execution engine

https://github.com/synth-laboratories/Horizons
14•JoshPurtell•23h ago•3 comments

Evolution of car door handles over the decades

https://newatlas.com/automotive/evolution-car-door-handle/
33•andsoitis•3d ago•50 comments

Planetary Roller Screws

https://www.humanityslastmachine.com/#planetary-roller-screws
24•everlier•3d ago•6 comments

The mystery of the mole playing rough (2019) [video]

https://www.youtube.com/watch?v=nwQmwT1ULMU
9•archagon•17h ago•1 comments

Show HN: Gigacode – Use OpenCode's UI with Claude Code/Codex/Amp

https://github.com/rivet-dev/sandbox-agent/tree/main/gigacode
7•NathanFlurry•10h ago•4 comments

A new bill in New York would require disclaimers on AI-generated news content

https://www.niemanlab.org/2026/02/a-new-bill-in-new-york-would-require-disclaimers-on-ai-generate...
497•giuliomagnifico•14h ago•209 comments