frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Oracle bans AI-generated code from OpenJDK

https://app.dealroom.co/news/feed/oracle-bans-ai-generated-code-from-openjdk-despite-ellison-s-cl...
24•delduca•22m ago•12 comments

An all-sky map of half a million supermassive black holes

https://www.sdss.org/black-hole-mapper-release-20/
64•MarcoDewey•2h ago•19 comments

Responding to the next frontier of critical cyber capabilities

https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/
60•artninja1988•1h ago•51 comments

New Mexico court orders Meta to pay $567m over harms to children’s mental health

https://www.theguardian.com/technology/2026/aug/06/new-mexico-court-meta
604•boplicity•17h ago•336 comments

Making Postgres 300x faster for analytics: batching, operator fusion, and SIMD

https://malisper.me/how-we-made-postgres-hundreds-of-times-faster-the-query-engine/
131•poly2it•6h ago•61 comments

Show HN: Wyzer Programming Language

https://github.com/Wyzer-Lang/wyzer
127•v0id_isgood•5h ago•67 comments

Möbius-Strip Crosswords

https://quuxplusone.github.io/blog/2026/08/04/mobius-crossword/
19•ibobev•2h ago•1 comments

AMD acquires Taalas to boost inference performance by etching models in silicon

https://www.theregister.com/systems/2026/08/06/amd-acquires-ai-chip-startup-taalas-to-boost-infer...
824•itvision•21h ago•624 comments

Tax cuts for the wealthy only benefit the rich (2023)

https://www.lse.ac.uk/research/research-for-the-world/economics/tax-cuts-for-the-wealthy-only-ben...
116•mooreds•1h ago•74 comments

Show HN: textlog – A quiet, text-only microblogging platform, open-source, no JS

https://textlog.cc/about
83•stagas•7h ago•34 comments

Kitesurf: Agent-first browser that runs in V8 isolates

https://blog.cloudflare.com/kitesurf/
85•m3h•7h ago•21 comments

Petri Nets as a Music Sequencer

https://blog.stackdump.com/posts/petri-net-sequencer
35•m_kos•4d ago•12 comments

Adults over 65 will outnumber children by 2029

https://eco3min.fr/en/us-children-vs-adults-65-and-older/
41•brandonb•2h ago•29 comments

Why Are There Statues of Beavers on Top of This Oxford Street Shop?

https://londonist.com/london/history/oxford-street-beavers
26•bookofjoe•4d ago•7 comments

Taste Is All That's Left

https://notashelf.dev/posts/taste-is-all-thats-left
616•tsak•1d ago•486 comments

Building Community Out of Strangers

https://tracydurnell.com/2023/11/30/building-community-out-of-strangers/
10•surprisetalk•3d ago•0 comments

São Paulo resident transforms degraded area into urban forest

https://saopaulosecreto.com/en/tiquatira-linear-park-en/
280•rmason•5d ago•108 comments

This Mine Predicts Major Wars. It's Opening Again

https://www.bloomberg.com/graphics/2026-opinion-australia-tungsten-mine-us-war-defense-china/
28•mooreds•1h ago•4 comments

Canada adds 75,000 new jobs in July, unemployment rate lowest in 2 years

https://www.cbc.ca/news/business/canada-jobs-july-2026-9.7299225
20•vrganj•53m ago•4 comments

TypeStax: A type scale generator with vintage audio hardware interface

https://www.typestax.com/
37•jasim•1w ago•9 comments

USA Today Co., partners with Palantir to analyze audience data

https://www.niemanlab.org/2026/08/americas-largest-newspaper-chain-usa-today-co-partners-with-pal...
151•cdrnsf•3h ago•60 comments

Scientists discover Kelvin-Helmholtz Instability on the surface of the Sun

https://nso.edu/press-release/nsf-inouye-solar-telescope-enables-major-discovery-of-a-hidden-sola...
293•neversaydie•2d ago•57 comments

Bioengineered chewing gum may offer a way to fight HPV and other microbes

https://www.sciencedaily.com/releases/2026/08/260803080917.htm
189•Audiophilip•20h ago•55 comments

99% of My Website Traffic Is Bots

https://patronview.com/news/99-percent-of-my-website-traffic-is-bots/
255•petercooper•3h ago•252 comments

GitHub Actions and Pages are experiencing degraded availability

https://www.githubstatus.com/incidents/qcvjkzcs7j74
473•Footkerchief•1d ago•395 comments

A quine in Piet – a GIF image that prints itself [video]

https://www.youtube.com/watch?v=GwMtzhjCzyc
65•surprisetalk•4d ago•8 comments

Improving GPT‑5.6 Sol in ChatGPT, expanding GPT‑5.6 Luna access for free users

https://openai.com/index/improving-gpt-5-6-sol-in-chatgpt/
298•tedsanders•1d ago•237 comments

Iceberg Collapses and Flips over in Ilulissat, Greenland (July 25, 2026) [video]

https://www.youtube.com/watch?v=UufMqwyO7pY
157•Bender•3h ago•40 comments

The BBC Tetris Companion

https://www.leadedsolder.com/2026/07/28/bbc-bridge-companion-part-1-overview.html
65•zdw•1w ago•8 comments

Welcoming the Nepalese Government to Have I Been Pwned

https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned/
200•gnabgib•20h ago•33 comments
Open in hackernews

Responding to the next frontier of critical cyber capabilities

https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/
55•artninja1988•1h ago

Comments

TrueDuality•1h ago
Ah yes let the FUD continue. This is a real problem but so far not nearly as severe as any of the marketing has made it out to be to the overall detriment of everyone including these companies announcing these scary capabilities. These announcements always included half hearted attempts at security layers which has now been demonstrated to benefit attackers more than defenders.

I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.

hbn•41m ago
The recent Hugging Face incident did not seem like FUD to me
Tiberium•38m ago
The fact that HF had to resort to using GLM 5.2 to analyze the logs/payloads makes it look legitimate, at least for me. They would not say that they hit guardrails with the frontier US models when defending if this was an obvious PR stunt.

https://huggingface.co/blog/security-incident-july-2026

> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

jackb4040•52m ago
> We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments

Stricter than what? You never even disclosed what happened in the first incident? This is nothing more than a setup to make it happen again and say "See? It broke out again, from an even stricter sandbox!"

Tiberium•48m ago
They actually did a detailed presentation at BlackHat about the HuggingFace incident, and events that led to it.

https://youtube.com/watch?v=87DyyMV0kCY

_puk•40m ago
That was fascinating.

Hijacking the package manager to pass messages between models and agents.. that's next level.

Like "pssst, if you need internet access there's a vulnerability in x service" kind of messages

ducktective•47m ago
> including isolated testing environments

Given the attack vector having possible super-human capability, I'm not sure such an environment exists. "Isolated" according to who?

Maybe seL4 could be a viable option here...

neya•49m ago

    We are sharing this because we believe it’s important to be transparent with the public and the safety and security communities about this potential shift in capabilities.

*proceeds to not share much details about strictness*

Yet another PR piece. Sigh.

merona_io•29m ago
exactly!!
cryo32•46m ago
Damage done.

The next frontier is getting all our shit out of reach of these companies/models/platforms and putting them back on prem.

Tiberium•45m ago
In my personal experience Sol with cyber verification is extremely capable of finding vulnerabilities, and it works even with binaries if you have some kind of IDA/Ghidra CLI access. Of course, unless the binary is protected with Denuvo/VMProtect/etc.

It sounds absurd, but in the last few weeks I've had a few cases where Sol found an RCE in self-hosted web applications in literal minutes just from reading the code (I prefer when it tries to reason statically instead of spamming runtime probes at first).

In another case it found an arbitrary file write in multiplayer in an old game by reverse engineering the binary - any other player in a match could just send you files to anywhere on your system.

I do these things for pure entertainment and curiosity, not for money from bug bounties, so if Sol can find those with a trivial prompt in tens of minutes for me, then what can focused companies/actors find in days or weeks?

Although I think most vulnerabilities are going to be closed in popular software by mid 2027, except in niche old or abandoned projects.

mephux•30m ago
Link to the disclosures then.. prove it. Anyone can say this.. i found an RCE in netBSD using gemma e2b
Tiberium•28m ago
I prefer to keep my internet identities disconnected, sorry. If you don't believe me, you can try using Sol with cyber verification yourself, or send me a link to a repo that Sol could check to make you believe it. Or you could go look into one of the many Linux LPEs that were found with LLMs, or thousands of other vulnerabilities in 2026.

And nowhere did I say that those RCEs were in critical software, I'm not talking about the likes of Apache, Nginx, Django, etc.

LoganDark•22m ago
Is cyber verification a thing they're actually doing now? I thought they only reached out to really incredibly famous people and that there's no way to get access as a normal person.
thisisauserid•35m ago
So they finally found a business model: the cause of, and solution to, cyber security problems.
andriy_koval•6m ago
the question is if that market is large enough to justify their appetites.
bearjaws•35m ago
These AI companies have found their #1 marketing piece and just beating it to death.

The reality is if they cared about security at all they would provide a way for me to credential myself against my companies environment so I can use the AI on it to improve our security.

Tiberium•33m ago
Isn't this literally what https://chatgpt.com/cyber and http://openai.com/form/enterprise-trusted-access-for-cyber are for?
mephux•35m ago
We all know this is propaganda to get a gov bailout or to slow down competition with regulations right? If this was an issue companies that did red team engagements would have been regulated long ago. There is no regulations on companies that actively exploit products, companies and services for money. They could all be bad actors.. yet, no regulations.. its all nonsense. If it's important.. don't connect to the internet.. there, you are good.. like if you don't want to OD on heroin.. don't do the heroin.
Terr_•33m ago
It seems like we've got chaos-machines that are just orderly enough to to try all sorts of branching script-kiddie / guess-n-check / research-paper-suggestions in a tireless and parallel way, and it's finding all the things we kinda knew were always potential issues but it was never economical to do things differently.

I'm scared that the "solution" will be constantly the same tools in reverse as an army of junior devs doing counter-hacks, at the expense of changing something more fundamental about how we make systems and what constitutes "good enough." (Kind of like if fuzz-testing was the be-all-end-all of memory safety.)

NitpickLawyer•32m ago
There's more details for the HF related incident in this [1] defcon talk. They said they're gonna have a proper post mortem at the end of the investigation (interesting to see if they publish full logs for the hf thing or not). But there's plenty of interesting tidbits from oAI's side in this talk, it's worth the 20 min watch.

tl;dw;

- agents found a way to communicate between several instances during a training run (kinda made a messageboard for themselves)

- while communicating with each other, they found ways to ssrf and RCE on the Artifactory endpoint.

- oAI found it and cleaned it up (reported RCE, redeployed Artifactory, removed the messageboard). Training / eval resumed.

- models trained w/ those traces (having the messageboard, ssrf, rce, etc) were used to having that. So they re-established comms via directory creation (w/ funny tidbits there, should really watch). And re-popped Artifactory via a different path to RCE.

- a different "persistent" model started working on cybergym and found the messageboard w/ details for RCE and things. Went on to hack HF.

- oAI contacted HF to ask if "they (oAI) should be concerned and were they (oAI) affected by HFs breach". Hilarity ensues when they figure out it's their agents doing it...

[1] - https://www.youtube.com/watch?v=87DyyMV0kCY

reasonableklout•25m ago
This sounds completely insane, utter sci-fi, especially that the communication happened during a training run. And yet OpenAI decided to continue the training, and we didn't hear about the incident for weeks. And now they are pushing forward with deploying a new model anyway. How is this happening? What will things look like in the labs in 3 months, let alone 3 years?
NitpickLawyer•19m ago
It's not unexpected. Current model gains are mainly from RLing a pretrained model on lots and lots of scenarios. They have the models run scenarios, and RL on successful runs.
bakugo•28m ago
This marketing stunt must've been really successful in their eyes, because they're milking it as much as they can.
petesergeant•19m ago
It's nice to cynically call this a marketing stunt, and terrifying to consider that they might just in fact be moving fast and breaking things.
firasd•22m ago
I've always felt it's a bit awkward to use terms like 'cyber', 'cyberwarfare' etc it's very Washington D.C. Cybersec would be a better compact term in my book
reducesuffering•19m ago
Every fifth comment about our insane trajectory of AGI is about "marketing." These incidents and cybersecurity capabilities are now involving government hearings and the CIA. Denial is truly an incredible thing in the face of a very scary immediate future.
emp17344•15m ago
LOL, we’ll see. Awful convenient that it precisely fits OpenAI’s narrative. At the very least, I think it’s obvious OpenAI is explicitly training models to exhibit this behavior.
watwut•14m ago
The scary thing is complete capture of politics and economy by sociopathic CEOs.

I dont worry about AGI newrly as much as about Thiel, Karp, Musk, Ellison, Zuckenberg, Trump, Vance, Rubio, Miller and the rest of them.

Legend2440•8m ago
A whole ton of people desperately want to believe that LLMs are a lie that will be revealed as a scam... any day now.
KolmogorovComp•14m ago
Am I the only one not understanding the issue around increased Cybersecurity capabilities?

If we consider the amount of RCE/CVE in a software to be limited, I expect these models to result in massively more secured softwares, not less.

Tiberium•16m ago
https://chatgpt.com/cyber is not new for OpenAI, and yes it's basically just KYC + likely some other invisible checks on your account, you don't to be a famous security researchers. Anthropic's cyber verification is quite a bit stricter I think.
LoganDark•12m ago
Oh it's Persona, that's not just KYC but I may consider it at some point. Thank you!

Edit: Ah, I clicked "learn more" and it seems they do have an invite-only program, required for anything that's not unquestionably innocent. I don't think I'd surrender my face to Persona for this, but it's interesting to know they're at least pretending to support reverse engineering.

Tiberium•5m ago
You don't need an invite only program to just have Sol checking for vulnerabilities in binaries or code. But yeah I've hit guardrails a few times (mostly it just works though) when Sol was making PoCs for the vulnerabilities it found.
matheusmoreira•7m ago
> Anthropic's cyber verification is quite a bit stricter I think.

Inexplicably, I got accepted into Anthropic's cyber program while OpenAI's TAC doesn't even allow me to verify, says I'm not eligible.

porridgeraisin•5m ago
You do a KYC and you can get access. It may depend on country's quality of KYC.
matheusmoreira•13m ago
> it found an arbitrary file write in multiplayer in an old game by reverse engineering the binary

Video games are now ruined for me. I don't think I will ever feel safe playing online again.

> I do these things for pure entertainment and curiosity, not for money from bug bounties

Me too... Was it easy to get TAC access? My account isn't even launching the Persona verification, says I'm not eligible.

Tiberium•6m ago
I had to register a second account because on my main one verification always failed, and when I contacted support they said that I've tried too many times and can't verify on that account.
NoDodgeQuestion•23m ago
Did they say how the artifactory hack worked - did it involve JWTs?
NitpickLawyer•20m ago
First via ssrf -> groovy plugin and second via specially crafted package I believe.
magicalist•22m ago
So they found their agents had RCE'd Artifactory once, reported it and got the fix, continued using Artifactory for their sandbox, and left it unmonitored for days despite the earlier exploits? They really do come out looking totally incompetent.

I stress about my agent sandboxes all the time and the only models I run have the default heavy handed guardrails, and I don't leave them running persistently.

Edit: not to mention, why is your first cybergym not your own sandbox??

ofjcihen•16m ago
Right? Like I feel like I’m taking crazy pills.

OAI (and now the other OAI companies not wanting to be left out) are running around announcing they started a forest fire through negligence and incompetence and people are like “Wow they used a really neat lighter!”

luma•14m ago
An alternative reason would be that they see this behavior so frequently that it didn't really raise to the level of concern.
eli•13m ago
And all that just to allow internet access for npm and pypi? If you've got the bandwidth and disk space, it's very easy to make an offline mirror of both.
hluska•7m ago
I get that it’s fashionable to hate big companies but you’re working overtime here. It’s reasonable to assume that a bug was fixed when reported. And if you think your monitoring is 100%, you don’t know what you’re talking about.

If you consider that incompetence, it’s possible that you’re not a very nice person.