frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Incident CVE-2026-LGTM

https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html
191•mooreds•2h ago

Comments

pmarreck•1h ago
This incident report is WILD

    The incident was resolved when the attacker’s autonomous agent read a file it shouldn’t have, which is also how the incident started.
InsideOutSanta•1h ago
Seems perfectly cromulent to me. And thanks to Karen Oyelaran for her work.
jazzypants•1h ago
We can only hope she wins her GitHub rate limit appeal soon.

This was hilarious. I didn't know that I needed AI slop satire in my life.

dcrazy•1h ago
It’s satire.
piazz•1h ago
PSA this is satire ;)

(if you have to say it, that’s how you know it’s good)

jazzypants•1h ago
Poe's law strikes again.

https://en.wikipedia.org/wiki/Poe's_law

bilekas•1h ago
Its LGTM actually! And very much not serious! (yet)
bilekas•1h ago
> Duration: 96 hours (billable: 2.1 trillion tokens)

Now there's a metric that would make my boss nervous.

> Total inference spend across all parties during the incident window was $1.7M, which Marketing has asked us to start describing as “a record investment in autonomous customer assurance.”

This is too funny.

mawadev•56m ago
I think at some point we need a different or split up currency/economy, because these values make no sense. Just consider how this inference cost 1.062.500 tomatoes ($1.6) in the physical world.
Procrastes•1h ago
I actually know a goat rancher who is working to require ag impact studies for data centers in Texas. Sounds like I should give him a call while I can.

(Also CVE-2026-LGTM would be an awesome name for a Culture ship)

windsurfer•1h ago
Perhaps a [Satire] note should be added to the headline.
john_strinlai•1h ago
its tagged as satire at the very top of the page, first thing under the title

(also, CVEs are numeric only, so the "LGTM" (looks good to me) and CVE "YIKES" is also a big giveaway, on top of ~all of the text being outlandish)

hk__2•1h ago
> its tagged as satire at the very top of the page, first thing under the title

Not the first thing, it’s buried in the tags as grey on light grey on white.

john_strinlai•53m ago
>it’s buried in the tags as grey on light grey on white.

if you happened to miss the tags, reading approximately any of the article should make it pretty clear.

"This report was reviewed by Legal, who have asked us to clarify that the fox was depicted as over eighteen and that the sunglasses remained on throughout."

unknownfuture•1h ago
It says a lot about the industry today that this post is somehow running afoul of Poe's Law...
hbcdbff•40m ago
Yes, the Americans are waking up, we need to make it abundantly clear to avoid them misunderstanding.
piterrro•1h ago
(I know its a satire, but could be seen as an actual post mortem of the future incident) This report made me realize there's no place for humans, as it is right now, in the process of building software systems in the future. Reading this incident made me dizzy after few paragraphs because of the cognitive context overload and I lost track multiple times.
RaSoJo•59m ago
I kinda felt it was satire, but then the below quote threw me off:

> one vendor’s marketing team, cc’d on the cost anomaly alert, issues a press release citing “a 430% YoY increase in adversarial multi-agent security reasoning.” The stock opens up 6%.

That happens! That is not satire. So i had to visit the comments here to be sure :)

unknownfuture•57m ago
You're absolutely right!

(In all seriousness it seems this is the dream of a huge number of AI pilled execs dreaming of infinite velocity at a fraction of the cost... velocity pointed where, you ask? Well stop asking or you'll be next.)

dbliss•40m ago
Great satire. The comedy of errors along the way made me realize that this could have happened also with humans instead of bots. But now it’s faster.
btown•1h ago
If you're wondering what creats.io is - this is satire!
faeyanpiraat•1h ago
You had me in the first half :)
PunchyHamster•58m ago
Well the part about brand-image-incompatible depictions of firefox logo apparently wasn't a satire
gerdesj•42m ago
This tells you all you need to know about the "fox":

"This report was reviewed by Legal, who have asked us to clarify that the fox was depicted as over eighteen and that the sunglasses remained on throughout."

NooneAtAll3•55m ago
previously on HN: https://news.ycombinator.com/item?id=48086082 "Incident Report: CVE-2024-YIKES"
Octoth0rpe•54m ago
The entire post is great, but the acknowledgements section is particularly excellent:

> Kubernetes (the dog), who was not involved in this incident but whose photo in the #incident-response channel was auto-tagged by the Slack image classifier as “container orchestration diagram (confidence: 0.31)”

dvh•47m ago
Brought to you by the people who've been told repeatedly since mid 90s not to glue SQL strings together.
yk•41m ago
> Seven LLMs were arranged in series. Six assumed another had read the code; the seventh read it and apologised.

And this is why management assumes that one can just automate software developers.

nickcw•37m ago
That is very very funny, and oh so plausible.

I enjoyed this bit a lot from the timeline

> Karen Oyelaran finds the payload by reading the source code with her eyes and files a second issue. The triage assistant closes it as “duplicate of #8814.” Issue #8814 is a feature request for dark mode. Karen reopens it. The assistant closes it. Karen reopens it. Karen’s GitHub account is rate-limited for “patterns consistent with automated behaviour.”

And this - the final sentence is a perfect indictment of the timeline we are in.

> Two AI review agents from competing vendors, both attached to a downstream pull request bumping foxhole-lz4, enter a disagreement loop over whether the package is malicious. After 340 comments and $41,255 in inference spend, Finance revokes both API keys; one vendor’s marketing team, cc’d on the cost anomaly alert, issues a press release citing “a 430% YoY increase in adversarial multi-agent security reasoning.” The stock opens up 6%.

I'm joining the goat farming waitlist ;-)

xandrius•18m ago
Great write-up.

Side note: interesting to see how many folks commenting did not get it being satire (even the title has LGTM). I guess it's time to rethink how sharp the HN folks truly are compared to the average non-tech person (not that I had any big assumptions myself).

I'm curious about this recipe for chevre :D

Why have papers by one of history's most famous physicists been retracted?

https://www.science.org/content/article/why-have-papers-one-history-s-most-famous-physicists-been...
126•adharmad•1h ago•39 comments

Incident CVE-2026-LGTM

https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html
191•mooreds•2h ago•32 comments

Ultrasound Imaging of the Brain

https://alephneuro.com/blog/ultrasound-brain
52•rossant•3h ago•14 comments

Om Malik has died

https://om.co/2026/06/24/1966-2026/
1127•minimaxir•18h ago•131 comments

An entire Herculaneum scroll has been read for the first time

https://scrollprize.org/firstscroll
1486•verditelabs•23h ago•319 comments

Jolla Phone, Over 13 500 units sold

https://commerce.jolla.com/products/jolla-phone-october-2026
40•mrbn100ful•43m ago•22 comments

Bipartite Matching Is in NC

https://scottaaronson.blog/?p=9851
69•amichail•3d ago•4 comments

Libre Barcode Project

https://graphicore.github.io/librebarcode/
233•luu•12h ago•38 comments

What happened after 2k people tried to hack my AI assistant

https://www.fernandoi.cl/posts/hackmyclaw/
276•cuchoi•13h ago•119 comments

Framework's 10G Ethernet module exposes USB-C's complexity

https://www.jeffgeerling.com/blog/2026/framework-10g-ethernet-module-usb-c-complexity/
258•Alupis•14h ago•139 comments

Show HN: WebBase-III – dBASE III rebuilt in the browser with its own interpreter

https://github.com/DDecoene/WebBaseIII
37•ddecoene•2d ago•11 comments

22-year-old Mozart's handwritten notebook unearthed in 'major discovery'

https://www.classicfm.com/composers/mozart/handwritten-notebook-discovered-major-paris/
156•thunderbong•5d ago•42 comments

FEXPRs vs. vtable: how LispE interpreter works

https://github.com/naver/lispe/wiki/2.7-FEXPR-vs.-vtable
20•birdculture•2d ago•4 comments

New satellites from years to weeks, days, or hours

https://arstechnica.com/space/2026/06/a-us-military-exercise-in-space-got-underway-with-barely-an...
8•jonbaer•2d ago•1 comments

The 'papers, please' era of the internet will decimate your privacy

https://expression.fire.org/p/the-papers-please-era-of-the-internet
925•bilsbie•17h ago•461 comments

A game where you're an OS and have to manage processes, memory and I/O events

https://github.com/plbrault/youre-the-os
301•exploraz•3d ago•61 comments

We all depend on open source. We will defend it together

https://akrites.org/letter/
371•dhruv3006•9h ago•178 comments

The Garbage Collection Handbook: The Art of Automatic Memory Management (2nd Ed) (2023)

https://gchandbook.org/
197•teleforce•16h ago•42 comments

Oxide computer 3D rack guided tour

https://explorer.oxide.computer/
431•darthcloud•4d ago•173 comments

IBM debuts sub-1 nanometer chip technology

https://newsroom.ibm.com/2026-06-25-ibm-debuts-worlds-first-sub-1-nanometer-chip-technology
356•porridgeraisin•23h ago•191 comments

Hey Nico, you didn't vibe code your data room but stole it from Papermark

https://twitter.com/mfts0/status/2070080422482977095
503•mmunj•1d ago•207 comments

Show HN: OpenKnowledge – open source AI-first alternative to Obsidian/Notion

https://github.com/inkeep/open-knowledge
325•engomez•23h ago•155 comments

Show HN: Chess-Inspired Roguelike

https://princechazz.com
380•cowboy_henk•5d ago•122 comments

The AI industry is pouring millions into US elections

https://www.bloodinthemachine.com/p/the-ai-industry-is-pouring-hundreds
13•speckx•26m ago•1 comments

Un-0: Generating Images with Coupled Oscillators

https://unconv.ai/blog/introducing-un-0-generating-images-with-coupled-oscillators/
175•babelfish•18h ago•42 comments

Microbubbles in Medicine

https://worksinprogress.co/issue/microbubbles/
20•Jimmc414•4d ago•3 comments

The Doorman's Fallacy in action

https://rozumem.xyz/posts/17
177•rozumem•19h ago•235 comments

An oral history of Bank Python (2021)

https://calpaterson.com/bank-python.html
152•tosh•19h ago•64 comments

Apple raises prices of MacBooks, iPads

https://www.reuters.com/world/asia-pacific/apple-raises-prices-macbooks-ipads-memory-costs-skyroc...
785•virgildotcodes•1d ago•1157 comments

Zig's new bitCast semantics and LLVM back end improvements

https://ziglang.org/devlog/2026/#2026-06-25
263•kouosi•1d ago•133 comments