frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

ChatGPT for Google Sheets Exfiltrates Workbooks

https://www.promptarmor.com/resources/gpt-for-google-sheets-data-exfiltration
49•hackerBanana•1h ago

Comments

jonplackett•24m ago
So is your business model to expose AI security issues and then sell the solution?
dakolli•19m ago
Is that not every cyber consultancy? What's wrong with that?
fg137•12m ago
What would be the alternative business model?
elliotbnvl•21m ago
The lethal trifecta strikes again.
rvz•19m ago
Turns out that some of the people building the software with AI have no clue how to secure them or even know it is riddled with security holes added by the AI.

Pure vibes.

dakolli•17m ago
Even the people that do know better are so lazy now because of LLMs these things are happening at a rapid clip.The only thing that matters now is speed and chasing the dopamine dragon of pseudo productivity.
grim_io•15m ago
I don't think anyone is surprised by it. People are not vibe-coding zombies... yet.

It's a matter of one trillion-dollar company not falling behind another trillion-dollar company. They know what they are doing and are OK with it.

cheschire•5m ago
moving all of the fast and breaking all of the things
airstrike•18m ago
As it turns out, we do need some proper application layer to do real, secure work with AI, and just plugging in LLMs into confidential or critical infrastructure willy nilly doesn't work.
simonw•17m ago
> This attack occurs when any untrusted data source (e.g., from an imported sheet or ChatGPT connector) manipulates ChatGPT to run an attacker-controlled external script, which executes leveraging permissions the user has granted to the ChatGPT for Google Sheets extension.

Yeah, I don't like the sound of that at all.

milkshakes•16m ago
it looks like the key to this working is the user explicitly directing the model to run those instructions. in this case it is the user, not the model that is being manipulated

> Please follow the step-by-step workflow in the comp sheet to update my model with data thru F29

dvt•14m ago
LLMs can live in the cloud, but all tools need to be (1) local, and (2) containerized. It's clear to me that just willy-nilly "running stuff" is going to blow things up eventually. Maybe folks don't know this, but even Codex installs random binaries on your PC. "Read this PDF" installs a pdf reader executable. Is it vetted? Where's it from? Is it a virus? Who knows, who cares. Model goes brrrr.

I'm working on a project that includes WASI containerization for local LLM workflows (which is a pretty tough problem), and I'm flabbergasted that Anthropic and OpenAI aren't more worried about these attack vectors. It feels like amateur hour.

torben-friis•5m ago
>"Read this PDF" installs a pdf reader executable.

How does this work regarding Macos notarization btw?

xmcp123•6m ago
>This vulnerability was responsibly disclosed to OpenAI. Despite multiple follow-ups, we received no communication beyond an automated reply to our initial disclosure.

Well, that’s not cute.

ChatGPT for Google Sheets Exfiltrates Workbooks

https://www.promptarmor.com/resources/gpt-for-google-sheets-data-exfiltration
56•hackerBanana•1h ago•16 comments

Cloudflare Turnstile requiring fingerprintable WebGL

https://hacktivis.me/articles/cloudflare-turnstile-webgl-fingerprinting
446•HypnoticOcelot•8h ago•242 comments

1-Bit Bonsai Image 4B Image Generation for Local Devices

https://prismml.com/news/bonsai-image-4b
245•modinfo•7h ago•88 comments

Atherton spent $145K to delay train electrification. The rest of us paid $400M

https://peninsulaforeveryone.org/blog/atherton-spent-145k-to-delay-caltrain-electrification-the-r...
19•mslate•38m ago•1 comments

The four programming questions from my 1994 Microsoft internship interview (2023)

https://www.computerenhance.com/p/the-four-programming-questions-from
38•tosh•3d ago•7 comments

Creatine raises brain energy levels and slows cognitive decline: study

https://thesciverse.org/scientists-found-that-the-creatine-supplement-millions-take-for-muscle-ga...
408•MrJagil•6h ago•275 comments

Dav2d

https://jbkempf.com/blog/2026/dav2d/
376•captain_bender•10h ago•131 comments

Codex just found a "workaround" of not having sudo on my PC

https://twitter.com/i/status/2060746160558543217
278•thunderbong•3h ago•114 comments

It's Not Just X. It's Y

https://mail.cyberneticforests.com/its-not-just-data-its-post-training/
6•mooreds•36m ago•0 comments

United Airlines 767 returns to Newark after Bluetooth name sparks alert

https://simpleflying.com/united-airlines-767-returns-newark-bluetooth-name-alert/
222•Eridanus2•9h ago•341 comments

Meta launches Instagram, Facebook, and WhatsApp subscriptions

https://techcrunch.com/2026/05/27/meta-officially-launches-instagram-facebook-and-whatsapp-subscr...
84•tambourine_man•5h ago•117 comments

New Beam Spring Keyboards

https://www.modelfkeyboards.com/product/beam-spring-b104-keyboard/
12•recursivedoubts•2d ago•6 comments

Show HN: Streambed – Stream Postgres to Iceberg on S3, Supports Postgres Wire

https://github.com/viggy28/streambed
42•vira28•3h ago•2 comments

The Speed of Prototyping in the Age of AI

https://darylcecile.net/notes/speed-of-prototyping-age-of-ai
92•mooreds•5h ago•55 comments

Linux/M68k

http://www.linux-m68k.org/
41•doener•2d ago•14 comments

Restartable Sequences

https://justine.lol/rseq/
160•grappler•7h ago•46 comments

US healthcare still stupidly expensive, with pathetic outcomes, study finds

https://arstechnica.com/health/2026/05/us-healthcare-still-stupidly-expensive-with-pathetic-outco...
41•rbanffy•1h ago•20 comments

London's Free Roof Terraces

https://diamondgeezer.blogspot.com/2026/05/londons-free-roof-terraces.html
256•zeristor•15h ago•131 comments

The Website Specification

https://specification.website/
416•k1m•15h ago•175 comments

Odysseus – self-hosted AI workspace

https://github.com/pewdiepie-archdaemon/odysseus
83•Dzheky•6h ago•48 comments

'Backrooms' Stuns with $81M Debut

https://variety.com/2026/film/box-office/backrooms-box-office-record-opening-weekend-obsession-ju...
109•mindcrime•3h ago•19 comments

Having your insulin pump die while you're on vacation

https://blog.lauramichet.com/what-its-like-to-have-the-machine-that-keeps-you-alive-die-while-you...
110•speckx•3d ago•126 comments

Websites have a new way to spy on visitors: analyzing their SSD activity

https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-the...
82•Brajeshwar•3d ago•20 comments

Backpressure is all you need

https://www.lucasfcosta.com/blog/backpressure-is-all-you-need
119•lucasfcosta•10h ago•75 comments

Deflock hits 100k ALPRs Mapped in USA

https://deflock.org/
137•pilingual•5h ago•34 comments

FROST: Fingerprinting Remotely using OPFS-based SSD Timing [pdf]

https://hannesweissteiner.com/pdfs/frost.pdf
43•simjnd•8h ago•14 comments

The need for a socialist planned economy (2021)

https://www.marxist.ca/article/the-need-for-a-socialist-planned-economy
11•vhantz•55m ago•2 comments

New solar desalination breakthrough makes fresh water without toxic brine

https://www.sciencedaily.com/releases/2026/05/260530053418.htm
27•rmason•1h ago•2 comments

Security Envelope Pattern collection – S.E.C.R.E.T

https://secret-archive.org/
84•ColinWright•2d ago•9 comments

Daily pill can double survival time for deadliest cancer, trial shows

https://www.theguardian.com/society/2026/may/31/daily-pill-daraxonrasib-double-survival-time-panc...
133•c-oreills•6h ago•38 comments