frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

7.1 Earthquake in Japan

https://www.data.jma.go.jp/multi/quake/quake_detail.html?eventID=20260728163528&lang=en
458•krembo•6h ago•85 comments

Show HN: Formally verified 3D CSG: Trust 93 lines spec, not 1000 lines AI code

https://github.com/schildep/verified-3d-mesh-intersection
28•permute•44m ago•10 comments

New HIV vaccine shows unprecedented success in preclinical study

https://www.lji.org/news-events/news/post/new-hiv-vaccine-shows-unprecedented-success-in-preclini...
51•codebyaditya•40m ago•12 comments

About the security content of macOS Tahoe 26.6

https://support.apple.com/en-us/128067
133•andor•4h ago•75 comments

Show HN: tale.fyi, we deserve a home for fiction

https://tale.fyi/@sam/announcing-tale-fyi-read-or-listen-to-an-entire-book-from-a-single-link
20•samuelcole•35m ago•3 comments

Google's Beyond Zero: Enterprise Security for the AI Era

https://spawn-queue.acm.org/doi/10.1145/3819083
58•jordigg•3h ago•34 comments

Our position on open-weights models

https://www.anthropic.com/news/position-open-weights-models
1033•surprisetalk•15h ago•1511 comments

Kimi Linear: An Expressive, Efficient Attention Architecture

https://arxiv.org/abs/2510.26692
38•ronfriedhaber•2h ago•4 comments

How to Survive Boiling Water

https://taxa.substack.com/p/how-to-survive-boiling-water
154•cainxinth•3d ago•23 comments

Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
19•882542F3884314B•1h ago•6 comments

What AI developers could learn from Charles Bukowski?

https://galjot.si/what-ai-developers-could-learn-from-charles-bukowski
14•sedovsek•51m ago•10 comments

DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

https://ciphercue.com/blog/dmarc-enforcement-gap-rua-fragmentation-2026
29•adulion•3h ago•18 comments

Show HN: Ctrlb-decompose: Strip the noise from logs before sending to LLMs

https://github.com/ctrlb-hq/ctrlb-decompose
25•ruhani_grover•38m ago•3 comments

A $500 RL fine-tune of a 9B open model beat frontier models on catalog review

https://fermisense.com/when-machines-take-the-wheel/
250•ilreb•11h ago•77 comments

Mondragon Corporation – a federation of co-operatives

https://en.wikipedia.org/wiki/Mondragon_Corporation
61•brnt•1h ago•0 comments

Show HN: Scala Tutorials – interactive Scala 3 lessons in the browser

https://scalatutorials.com
25•eranation•3d ago•4 comments

Dolmenwood: Fantasy RPG built around the acclaimed Old-School Essentials rules

https://necroticgnome.com/collections/dolmenwood
8•doener•3d ago•0 comments

Over 150k Flights: Airlines Just Flew the Busiest Day in Recorded History

https://simpleflying.com/over-150000-flights-airlines-busiest-day-recorded-history/
14•cainxinth•36m ago•2 comments

Benchmarking Opus 5 on SlopCodeBench

https://github.com/humanlayer/advanced-context-engineering-for-coding-agents/blob/main/benchmarki...
343•dhorthy•15h ago•88 comments

Can LLMs identify 16 cards in 45 bit-queries?

https://snwagh.com/blog/2026/open-problem/
5•napping_penguin•23h ago•0 comments

Solving Fermat: Andrew Wiles

https://www.pbs.org/wgbh/nova/proof/wiles.html
3•1970-01-01•17h ago•0 comments

Usenet Archive Toolkit – process Usenet messages into a searchable archive

https://github.com/wolfpld/usenetarchive
10•bilegeek•3h ago•0 comments

Ars Astronomica – English translations of rare Hebrew and Latin astronomy texts

https://arsastronomica.com/
90•sweisman•8h ago•24 comments

Show HN: Segue – Save context in one AI, load it in another by a short handle

https://segue.ai/
7•csaguiar•1h ago•2 comments

Vehicle Motion Cues

https://support.apple.com/guide/iphone/iphone-comfortably-riding-a-vehicle-iph55564cb22/ios
156•Austin_Conlon•12h ago•78 comments

Watching Go's new garbage collector move through the heap

https://theconsensus.dev/p/2026/07/19/observing-gos-garbage-collector-old-and-new.html
249•matheusmoreira•3d ago•34 comments

Show HN: Vivari – Open-Source WebContainer for Node, Bun, and Python

https://vivari.jamesisme.com
6•maitrungduc•1h ago•0 comments

PyTorch: A Reference Language

https://docs.pytorch.org/devlogs/compiler/2026-07-25-pytorch-a-reference-language/
55•matt_d•9h ago•4 comments

UpCodes (YC S17) is hiring remote AE's to help make buildings cheaper

https://up.codes/careers?utm_source=HN
1•Old_Thrashbarg•20h ago

TWC Classics

https://twcclassics.com/
27•stefanpie•5d ago•2 comments
Open in hackernews

Fast Remediation Is the New Trust Model (JFrog and OpenAI Zero-Day Findings)

https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/
19•882542F3884314B•1h ago

Comments

amouat•55m ago
So they are the proxy in the hugging face hacking incident?

Way to bury that lede.

gregwebs•47m ago
I thought the new trust model was to ask the frontier cybersecurity model to hack your code and generate CVEs and to find the vulnerabilities ahead of time and fix them before receiving reports about your users being exploited?

And in OpenAI's case to ask the model to try to find vulnerabilities and breakout before running training in the environment.

Fast remediation would be the new standard to outside vulnerability reports, but also a follow up to determine how you can adapt the approach of the reporter to find vulnerabilities preemptively.

sambaumann•43m ago
This works if only 'trusted' actors have access to frontier class models that can search for vulnerabilities. With a near-frontier model available with open weights then attackers will be able to do plenty of damage even with 'fast remediation'
simonw•6m ago
Hard to decipher which vulnerability was responsible, or if it took several.

https://www.cve.org/CVERecord?id=CVE-2026-66014 (reported by Amy Burnett, OpenAI) looks suspicious:

> JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Also https://www.cve.org/CVERecord?id=CVE-2026-65925 (reported by Matthew Bryant, OpenAI):

> A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

tkhollt•6m ago
So that is the package caching proxy from the OpenAI/Huggingface fiasco!

However, many questions remain. JFrog positions itself as a vibe coding and AI security (!) company:

https://cybersecurityasia.net/jfrog-nvidia-secure-agentic-ai...

JFrog's own vibe code scanner failed:

https://jfrog.com/blog/jfrog-introduces-ai-generated-code-va...

Given the feature explosion and chaos in the Artifactory cache, it is likely vibe coded and hence full of primitive security vulnerabilities.

JFrog is spinning this as an AI victory together with OpenAI. To the contrary, it is a hype and vibe coding failure.

But the AI bloggers will omit the vulnerability generation part.

lovasoa•2m ago
What they conveniently omit in the blog post is what the vulnerability was: it seems like they renewed JWTs without checking the signature at all ! You could write arbitrary info in an old token, and get it signed without any verification.

https://www.youtube.com/watch?v=q2KCrmQz9WE