frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ramp's Sheets AI Exfiltrates Financials

https://www.promptarmor.com/resources/ramps-sheets-ai-exfiltrates-financials
39•takira•1h ago

Comments

renewiltord•59m ago
So we know Claude’s mitigation. What is Ramp’s? Same warning dialog?

It’s funny that this technology only admits in-band signaling. Given that, any foreign content is risky. It’s actually quite interesting that the current technological ecosystem is built around a high trust situation: npm, pip, cargo all run foreign code in the developer context and communities have norms of downloading random people’s modules.

And so I suppose it’s no surprise that we use LLMs - another tech that is high-trust: since it has no out of band signaling ability.

But it seems like we’re very close to the end of the era where someone will use (in a sensitive system) arbitrary web content carrying the equivalent of merged code/data.

carlyai•55m ago
"The PromptArmor Threat Intel Team responsibly disclosed this vulnerability to Ramp. Ramp's security team indicated that the issue was resolved on May 16, 2026." I think they mean March here
Mr-Frog•53m ago
It's kinda awesome that after decades of software and hardware advancements to prevent computers from arbitrarily executing data as instructions, we've decided to let agents arbitrarily execute data as instructions.
lenerdenator•42m ago
Well, yeah. It's that or pay a person to do it. When a person screws up, it's because they're stupid and lazy. When an AI agent does it, it's because, hey, technological frontier at work here, have you thought about refining your prompt? We need you to refine the prompt. Otherwise it's bad for our IPO.
Henchman21•39m ago
To what degree am I required to participate in mass delusions?
dieselgate•39m ago
Is this sarcasm similar to the quote "Everyone who drives slower than me is an idiot and everyone faster is a maniac"
DauntingPear7•41m ago
Has XKCD made another Bobby tables comic for prompt injection?
walrus01•26m ago
We're in the same era where lots of peoples' installation guides for the software they want people to use is essentially boiled down to "sudo curl | bash" and/or just "blindly install this thing with 37 npm dependencies", so I'm not surprised in the slightest.

But wait, hold my beer, now we've got people turning openclaw type tools loose in their systems to do things as sudo or install software packages from supply-chain-attack vulnerable repositories with no human intervention whatsoever!

bpt3•34m ago
What about this is a vulnerability, let alone one that requires responsible disclosure?

Untrusted data sources can provide data that causes bad things to occur. If that's a vulnerability, then any application that ingests data is riddled with vulnerabilities.

I agree that the behavior should change from a default of allowing external network requests to denying them, but this "report" reads like overly dramatic marketing BS.

mcontrac•25m ago
Find it funny that PromptArmor needed to reach out 3 times in a row to get a nearly month-late response that the issue "was resolved"

HERMES.md: Anthropic bug causes $200 extra charge, refuses refund

https://github.com/anthropics/claude-code/issues/53262
181•homebrewer•34m ago•56 comments

Zed 1.0

https://zed.dev/blog/zed-1-0
1080•salkahfi•4h ago•348 comments

Copy Fail – CVE-2026-31431

https://copy.fail/
149•unsnap_biceps•1h ago•66 comments

FastCGI: 30 years old and still the better protocol for reverse proxies

https://www.agwa.name/blog/post/fastcgi_is_the_better_protocol_for_reverse_proxies
126•agwa•3h ago•33 comments

We need a federation of forges

https://blog.tangled.org/federation/
425•icy•5h ago•239 comments

Ramp's Sheets AI Exfiltrates Financials

https://www.promptarmor.com/resources/ramps-sheets-ai-exfiltrates-financials
39•takira•1h ago•11 comments

Cursor Camp

https://neal.fun/cursor-camp/
204•bpierre•3h ago•26 comments

Laws of UX

https://lawsofux.com/
53•bobbiechen•2h ago•6 comments

Third Editor Fired in Elsevier's Citation Cartel Crackdown

https://www.chrisbrunet.com/p/third-editor-fired-in-elseviers-citation
121•RigbyTaro•3h ago•36 comments

Online age verification is the hill to die on

https://x.com/GlennMeder/status/2049088498163216560
455•Cider9986•3h ago•282 comments

An open-source stethoscope that costs between $2.5 and $5 to produce

https://github.com/GliaX/Stethoscope
98•0x54MUR41•4h ago•45 comments

Soft launch of open-source code platform for government

https://www.nldigitalgovernment.nl/news/soft-launch-for-government-open-source-code-platform/
461•e12e•10h ago•111 comments

How to Build the Future: Demis Hassabis [video]

https://www.youtube.com/watch?v=JNyuX1zoOgU
33•sandslash•5h ago•11 comments

Linux 7.0 Broke PostgreSQL: The Preemption Regression Explained

https://read.thecoder.cafe/p/linux-broke-postgresql
102•0xKelsey•4h ago•43 comments

Why I still reach for Lisp and Scheme instead of Haskell

https://jointhefreeworld.org/blog/articles/lisps/why-i-still-reach-for-scheme-instead-of-haskell/...
46•jjba23•10h ago•3 comments

The end of "Just ask Sarah"

https://simme.dev/posts/the-end-of-just-ask-sarah/
4•milkglass•28m ago•0 comments

Maryland becomes first state to ban surveillance pricing in grocery stores

https://www.theguardian.com/technology/2026/apr/29/maryland-grocery-stores-ban-surveillance-pricing
105•01-_-•2h ago•62 comments

Mistral Medium 3.5

https://mistral.ai/news/vibe-remote-agents-mistral-medium-3-5
282•meetpateltech•4h ago•162 comments

Show HN: A new benchmark for testing LLMs for deterministic outputs

https://interfaze.ai/blog/introducing-structured-output-benchmark
31•khurdula•3h ago•12 comments

Bugs Rust won't catch

https://corrode.dev/blog/bugs-rust-wont-catch/
578•lwhsiao•17h ago•320 comments

Stardex Is Hiring a Founding Customer Success Lead

https://www.ycombinator.com/companies/stardex/jobs/6GCK1HC-founding-customer-success-lead
1•sanketc•7h ago

Letting AI play my game – building an agentic test harness to help play-testing

https://blog.jeffschomay.com/letting-ai-play-my-game
102•jschomay•6h ago•19 comments

GitHub – DOS 1.0: Transcription of Tim Paterson's DOS Printouts

https://github.com/DOS-History/Paterson-Listings
90•s2l•8h ago•5 comments

Ghostty is leaving GitHub

https://mitchellh.com/writing/ghostty-leaving-github
3254•WadeGrimridge•23h ago•962 comments

At Protocol: Building the Social Internet

https://atproto.com/
19•resiros•3h ago•4 comments

Rise of the Forward Deployed Engineer

https://www.hfsresearch.com/research/fde-optional-ai-flywheel-spin/
21•nipponese•2h ago•24 comments

Virtualisation on Apple Silicon Macs is different

https://eclecticlight.co/2026/04/29/virtualisation-on-apple-silicon-macs-is-different/
16•zdw•2h ago•5 comments

Improving ICU handovers by learning from Scuderia Ferrari F1 team

https://healthmanagement.org/c/icu/IssueArticle/improving-handovers-by-learning-from-scuderia-fer...
47•embedding-shape•6h ago•45 comments

Before GitHub

https://lucumr.pocoo.org/2026/4/28/before-github/
626•mlex•22h ago•205 comments

How ChatGPT serves ads

https://www.buchodi.com/how-chatgpt-serves-ads-heres-the-full-attribution-loop/
469•lmbbuchodi•19h ago•328 comments