frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

https://aisle.com/blog/aisle-discovers-6-new-cves-in-curl-including-the-oldest-issue-ever-reported
15•ragebol•2h ago

Comments

rho138•1h ago
Someone needs a lesson in accessibility
EmilStenstrom•54m ago
There's something unnerving about this blog post.

Paraphrasing: "The world's top security researches and AI labs are pouring all their VC money into finding as many security issues in curl as possible". At the same time, we know that curl is run by volunteers that needs to handle all of this. I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pressure on the maintainers.

The second unnerving thing is that many of the listed vulnerabilites target embedded libcurl; a library with a much slower update cycle. I'm guessing that many of the listed bugs are still in active use, inside the thousands of applications that use curl internally. Another tricky situation.

Both of these stand in contrast to the posts "braggy" style of "we found the most vulnerabilities of all!!!".

hhthrowaway1230•38m ago
Would be great if people would brag with quotes and feedback from the maintainers. I'd be more interested to see that. Instead our model found x, I want something that really helps the maintainers.
robertlagrant•27m ago
> I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pressure on the maintainers.

This is true, and worth saying, but it is also a problem of the OSS philosophy. All software is used at your own risk, so if maintainers want their software used they need to keep up, and the (true) promise of "more eyeballs means more secure software" has this downside built in.

zarzavat•22m ago
Another way to read it is that the public now have access to resources on a scale that was formerly the domain of three letter government agencies throwing millions of dollars to hire humans to do this work. While in the short-term it's painful for maintainers, in the long-term we all end up safer.
postexitus•4m ago
If they don't do it, somebody else will. It's better white hats get there first.
shakna•18m ago
The presentation from the time might be worth watching, if this reads too much like hype PR. [0]

[0] https://youtu.be/t4wqREXVEAc

bflesch•4m ago
Thanks for making open source a bit more secure, even though your website is super laggy with all these ridiculous animations.

Based on the eye candy I imagine the team consists of a bunch of VC bros on their macbooks drinking chai lattes. Not sure if that is the impression you want to portray to a technical audience.

The eye candy might work with nontechnical VCs though, so you do you.

Half-Life 2 in a Browser

https://hl2.slqnt.dev/
274•panza•4h ago•98 comments

Anthropic says Alibaba illicitly extracted Claude AI model capabilities

https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-ca...
440•htrp•15h ago•773 comments

OpenAI unveils its first custom chip, built by Broadcom

https://techcrunch.com/2026/06/24/openai-unveils-its-first-custom-chip-built-by-broadcom/
712•jamdesk•17h ago•398 comments

Dolphin Emulator Progress Release 2606

https://dolphin-emu.org/blog/2026/06/25/dolphin-progress-report-release-2606/
4•exploraz•29m ago•0 comments

Cloudflare launched self-managed OAuth for all

https://blog.cloudflare.com/oauth-for-all/
175•terryds•8h ago•80 comments

Bohemia Interactive: Cold War Assault Remastered Source Code on GitHub

https://github.com/BohemiaInteractive/CWR
82•dewey•2d ago•14 comments

LuaJIT 3.0 proposed syntax extensions

https://github.com/LuaJIT/LuaJIT/issues/1475
164•phreddypharkus•10h ago•97 comments

Wikipedia Workers in Britain set global first by seeking union recognition

https://utaw.tech/news/wikipedia-recognition
87•chobeat•3h ago•88 comments

Blogging can just be stating the obvious

https://blog.jim-nielsen.com/2026/blogging-stating-the-obvious/
245•Curiositry•11h ago•87 comments

Markdy: Like Mermaid Diagrams, but for Motion

https://markdy.com
72•surprisetalk•1d ago•30 comments

45°C cooling design cuts data center water use to near zero

https://blogs.nvidia.com/blog/liquid-cooling-ai-factories/
345•nitin_flanker•20h ago•240 comments

Medical students are using popular research tool to pump out misleading studies

https://www.science.org/content/article/medical-students-are-using-popular-research-tool-pump-out...
56•rndsignals•8h ago•32 comments

Dostoyevsky isn't difficult

https://www.autodidacts.io/dostoyevsky-isnt-difficult/
154•surprisetalk•2d ago•178 comments

Zombie unicorns are haunting Silicon Valley

https://www.economist.com/business/2026/06/21/zombie-unicorns-are-haunting-silicon-valley
110•andsoitis•8h ago•55 comments

GLM-5.2 is a step change for open agents

https://www.interconnects.ai/p/glm-52-is-the-step-change-for-open
244•vantareed•2d ago•145 comments

Qualcomm to Acquire Modular

https://www.reuters.com/business/qualcomm-buy-ai-startup-modular-2026-06-24/
203•timmyd•21h ago•73 comments

RubyLLM: A Ruby framework for all major AI providers

https://rubyllm.com/
392•doener•20h ago•68 comments

PR spam today looks like email spam in the early 2000s

https://www.greptile.com/blog/prs-on-openclaw
229•dakshgupta•20h ago•135 comments

The Xteink X4 E-Ink Reader

https://blog.omgmog.net/post/xteink-x4-e-ink-reader/
259•felixdoerp•18h ago•145 comments

Show HN: Nimic – Pure Python as a systems language with AOT compilation

https://github.com/dima-quant/nimic
16•dima-quant•1d ago•9 comments

Computer use in Gemini 3.5 Flash

https://blog.google/innovation-and-ai/models-and-research/gemini-models/introducing-computer-use-...
222•swolpers•17h ago•144 comments

Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

https://aisle.com/blog/aisle-discovers-6-new-cves-in-curl-including-the-oldest-issue-ever-reported
15•ragebol•2h ago•8 comments

Mixing Visual and Textual Code

https://arxiv.org/abs/2603.15855
50•doppioandante•9h ago•19 comments

Matt's Script Archive: The Scripts That Reshaped the Web

https://tedium.co/2026/06/22/matts-script-archive-retrospective/
54•1317•2d ago•17 comments

Show HN: Write SaaS apps where users control where their data is stored

https://github.com/wolfoo2931/linkedrecords/
51•WolfOliver•6d ago•25 comments

Show HN: Brain Frog – Can you be random enough for 11 lines of JavaScript?

https://brainfrog.lol
39•AlexanderZ•5d ago•28 comments

Lies, Damn Lies and Database Benchmarks

https://questdb.com/blog/lies-damn-lies-and-database-benchmarks/
5•eigenBasis•2d ago•1 comments

A Practical Guide to SSH Tunnels: Local and Remote Port Forwarding

https://labs.iximiuz.com/tutorials/ssh-tunnels
343•signa11•5d ago•64 comments

Show HN: Nub – A Bun-like all-in-one toolkit for Node.js

https://github.com/nubjs/nub
243•colinmcd•20h ago•68 comments

The Unbearable Cheapness of Open Weight Models

https://jamesoclaire.com/2026/06/25/the-unbearable-cheapness-of-open-weight-models/
76•ddxv•7h ago•62 comments