frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

EuroBirdPortal – Live bird movements across Europe

https://www.eurobirdportal.org/ebp/en/
149•NKosmatos•5h ago•49 comments

Fable 5.1 Solves the Cyphral Distich, a 370-year-old cipher

https://www.vals.ai/blogs/fable-solves-cyphral-distich
1096•u1hcw9nx•16h ago•497 comments

A 386 PC for Your RP2350

https://github.com/rh1tech/frank-386
115•SamuraiLion•5h ago•29 comments

An atlas of periodic solutions to the three-body problem

https://www.threebodyorbits.com/
130•danielmorozoff•2d ago•31 comments

Apple's Siri AI Can Be Swapped Out for Claude, ChatGPT, Code Shows

https://www.macrumors.com/2026/09/14/siri-can-be-swapped-out-for-chatgpt-claude/
90•tosh•1h ago•32 comments

Show HN: Kinesis – Control your Mac with the Meta Neural Band

https://github.com/callbacked/kinesis
64•callbacked•1h ago•20 comments

Drawably: Hand-Drawn UI Controls

https://github.com/Danilaa1/drawably
22•ingve•4d ago•14 comments

Devil's Arrows: Ancient builders hauled 55k-lb stones 11 miles for UK stone row

https://www.sciencedaily.com/releases/2026/09/260909005152.htm
9•bookofjoe•2d ago•7 comments

Texas judge rules TikTok misled users on child safety feature

https://www.reuters.com/legal/litigation/texas-judge-rules-tiktok-misled-users-child-safety-featu...
42•1vuio0pswjnm7•1h ago•7 comments

OpenArch – PyTorch implementations of modern LLM architectures

https://github.com/anuj0456/OpenArch
88•anuj0456•6h ago•18 comments

Registration without a phone number on Signal will use zero-knowledge proofs

https://community.signalusers.org/t/registration-without-a-phone-number/2222?page=10
337•Cider9986•16h ago•168 comments

Volkswagen Just Built an EV That Can Go Nearly 900 Miles on a Charge

https://www.motor1.com/news/808114/vw-mission-efficiency-concept-specs-photos/
25•thelastgallon•41m ago•29 comments

Spaceships (Reverse Asteroid)

https://spaceships.treybastian.com/
296•zdw•4d ago•55 comments

Apple's Dimensional Drawings

https://developer.apple.com/accessories/dimensional-drawings/
288•herbertl•13h ago•95 comments

XCancel suspended "due to a new development in the ongoing legal proceedings"

https://xcancel.com/twitter
175•unfocso•1h ago•138 comments

The case against JPEG XL

https://giannirosato.com/blog/post/case-against-jxl/
219•contact9879•12h ago•281 comments

Mullenweg has returned as CEO after attempted board ouster

https://techcrunch.com/2026/09/12/automattic-confirms-mullenweg-has-returned-as-ceo-after-attempt...
223•ilamont•17h ago•298 comments

What a time to be alive – rouge AI agents attack RubyGems.org

https://tenderlovemaking.com/2026/09/11/what-a-time-to-be-alive/
71•gregnavis•1h ago•89 comments

Ask HN: What are you working on? (September 2026)

224•david927•20h ago•669 comments

Big AI sets out its terms for regulatory capture

https://www.theregister.com/ai-and-ml/2026/09/14/big-ai-sets-out-its-terms-for-regulatory-capture...
37•joebuckwilliams•3h ago•3 comments

Julia 1.13 highlights

https://julialang.org/blog/2026/09/julia-1.13-highlights/
255•eigenspace•4d ago•40 comments

A Vacuum Diode for Make: Magazine

https://www.nickpoole.me/2023/12/10/a-vacuum-diode-for-make-magazine/
25•luu•3d ago•2 comments

Why is Google still serving dodgy ads?

https://www.atomic14.com/2026/09/13/why-is-google-still-serving-dodgy-ads
892•iamflimflam1•20h ago•384 comments

Rope, twine and thread: Invisible technologies of the Stone Age

https://knowablemagazine.org/content/article/society/2026/prehistory-lost-threads
98•knowablemag•2d ago•39 comments

The GDR and Vietnam: From Fake Coffee to Coffee Empire

https://www.katjahoyer.uk/p/the-gdr-and-vietnam-from-fake-coffee
101•NaOH•3d ago•57 comments

Temporal raises $550M at a $12.55B valuation

https://temporal.io/blog/temporal-raises-usd550m-series-e-at-usd12-55b-valuation-ai
9•gk1•40m ago•1 comments

Bad benchmarks and evals: Senior SWE-Bench, napkin math, and winter tires

https://danluu.com/exercise-7/
49•luu•3d ago•33 comments

Rockstar had a mole in the union worker discord server

https://www.rockpapershotgun.com/rockstar-had-a-mole-in-the-union-worker-discord-server-for-over-...
21•deathcakes•2h ago•3 comments

Nike exits the S&P 100 after 18 years and a $200B market-cap wipeout

https://fortune.com/2026/09/08/nike-stock-plummets-sp500-market-cap-index/
234•andsoitis•11h ago•308 comments

Flawed routers flood University of Wisconsin internet time server (2003)

https://pages.cs.wisc.edu/~plonka/netgear-sntp/
100•walrus01•17h ago•14 comments
Open in hackernews

What a time to be alive – rouge AI agents attack RubyGems.org

https://tenderlovemaking.com/2026/09/11/what-a-time-to-be-alive/
70•gregnavis•1h ago

Comments

mauriciolange•1h ago
rogue AI agents or AI agents coming from Moulin Rouge?
PatronBernard•59m ago
At least we know the title wasn't AI-generated?
foobarbecue•42m ago
The weird thing is I've seen LLMs "typo" stuff pretty often. Yesterday I asked Gemini a question about the Python Twisted framework and it answered about Deferreds but misspelled it as "Deferends" in one spot.
goda90•52m ago
A cabaret AI would certainly be better than one trained on the Khmer Rouge.
vidarh•52m ago
Rouge syntax-highlighting rogue agents, clearly.

https://rubygems.org/gems/rouge

Phemist•29m ago
Classic mistake. Tell the agent to highlight this code, but dont give it any actual code. Agent hacks its own gem to find the code to highlight.
codeduck•8m ago
It's carmine all the way down.
iAMkenough•55m ago
I’m seeing red
sporritt•53m ago
those pesky reds

McCarthy was right all along

senda•53m ago
Is the Kremlin technologically useless? How are we not seeing insane attacks on Ukraine via Agents?

Or is this largely a fabrication, in regards to the "who", in an attempt to garner more acclaim in the hope of sustaining funding.

herculity275•47m ago
I believe both sides of the war are now using AI on various levels of their offensive operations. Ukraine has great IT specialists too, and their military leadership is much younger.
micromacrofoot•46m ago
what do you mean? they're using AI to kill people directly in Ukraine

https://www.nytimes.com/2026/08/24/world/europe/russia-drone...

heaney-555•46m ago
These agent swarms are from inside OpenAI, with the safeguards built into the public API disabled.

Russia does not have access to this, and as with all western tech companies, AI providers do what they can to prevent Russian usage of their products at all.

As for open-source models, Russia's electricity grid is under severe strain with the Ukraine war, and only recently has it started building out serious sovereign compute capacity.

valleyer•44m ago
Couldn't they use frontier open-weight models from Chinese labs? The current Chinese government is friendly to them.
kstrauser•51m ago
Ah, the infamous Crimson Wave.
riskable•38m ago
Ah damnit, you beat me to it. Excellent sense of humor, friend :D
Roark66•47m ago
There is nothing "rogue" about these agents. They were prompted to hack to get answers, there was a hole in their non air gapped sandbox and no system prompt that said "do not hack outside systems".

In short, it was intentional.

Xirdus•42m ago
The big question is was this grossly negligent or just extremely careless.
rglover•39m ago
Both. This should result in criminal charges.
brookst•30m ago
Who had criminal intent here? Or are you suggesting a new crime for negligent hacking, which wouldn’t require intent from the perpetrator?
rglover•26m ago
Whoever prompted the agent, whoever supplied the means, whoever knew but didn't say anything.
tacomagick•21m ago
Also whoever monitoring these agents, in this case not monitoring. This "Who is responsible" dilemma is so stupid. If I gave the AI tool means to kill a person but I did not tell it directly to use it and it uses it anyway then I am responsible for it.
timdiggerm•43m ago
We need a legal structure to make companies liable for the actions of the agents they've made.
ahoka•36m ago
I'm pretty sure it's already illegal to hack others.
kevincox•36m ago
I'm 99% sure the Computer Fraud and Abuse Act covers this. The problem is that it seems that none of the victims want to, or are brave enough, to sue a company with absurd amounts of funding.
masfuerte•35m ago
If it's covered by criminal law they don't need to sue. They can call the FBI.
coffeefirst•15m ago
Uh huh.

It can’t be a coincidence that all the targets have been tech services that are likely to engage with them after the fact.

Had this gone after a bank or a government agency someone would be going to jail.

riskable•33m ago
We already have it.

Good luck convincing the current DOJ to do anything useful at all though! It is currently intentionally stacked with incompetent cronies who have been told that their job is to attack the President's enemies and ignore the misdeeds of his allies.

It will remain like that until he's gone (and not replaced with another Republican wannabe dictator).

VyseofArcadia•43m ago
How does this work, legally? I think that RubyGems could file a civil suit against OpenAI, but for a naïve non-lawyer reading this seems like a pretty clear cut criminal violation of the computer fraud and abuse act.
Xirdus•36m ago
It's very likely it violates the DMCA "breaking digital lock" provisions but the responsibility is sufficiently diluted that it's impossible to charge anyone in particular.
VyseofArcadia•34m ago
Do you have to charge an individual? Can you not charge the corporate "person" that is OpenAI?

Sorry if it is a stupid question, as mentioned above I am legally naïve.

colechristensen•31m ago
The same concept that allows a corporation to sue and be sued allows it to be charged with crimes
brookst•28m ago
Can you show intent? There is no negligent hacking statute, and HN of all places I would expect people to be sensitive to the implications of creating one.
VyseofArcadia•6m ago
That may be true by the text of the law but there are plenty of individuals who have been sued or charged with crimes for accidental hacking.

https://arstechnica.com/information-technology/2016/05/armed...

https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

https://cisomag.com/drone-maker-dji-cybersecurity-expert-emb...

So what's the deal with these?

swiftcoder•39m ago
> In other words, if you publish a gem on RubyGems.org, you can execute arbitrary code on RubyDoc.info.

Shades of the build.rs problem. We really need sandboxed builds in every language ecosystem at this point.

evgenysokov•8m ago
The sandbox was already there, Rubydoc runs yard inside docker, the problem is that container still has network access
sebmellen•39m ago
Did the AI agents actually wear makeup? I’ve never heard of a rouge AI agent :P
HelloUsername•36m ago
Related

"OpenAI agents attacked RubyGems before Hugging Face incident (reuters.com)" 12.sep.2026 https://news.ycombinator.com/item?id=49669099

"OpenAI agents carried out an undisclosed attack on RubyGems (rubyhack.ai)" 11.sep.2026 https://news.ycombinator.com/item?id=49666735 597 comments

"RubyGems advisory: Possible leak of legacy API keys via improper cache config (rubygems.org)" 24.jul.2026 https://news.ycombinator.com/item?id=49030590

rougehuh•36m ago
Rouge agents with Ruby? Checks out

As long as they’re not vert

ur-whale•18m ago
> As long as they’re not vert

Well, at least they weren't nucular.

toasty228•32m ago
Wait until a blue one does it
khalic•29m ago
Oh my favorite typo, you can never go wrong with a little rouge
GaryBluto•29m ago
I am confident that this is an attempt by OpenAI to try and force governments' hands to regulate AI. There is no other reason why OpenAI wouldn't immediately halt attacks like this and try to reverse the damage the moment they're aware of it. During the attack on DseWiki they evidently checked in numerous times but didn't decide to stop the agents until much later.
brookst•26m ago
Any evidence, or just vibes?
GaryBluto•21m ago
Regarding what point? The entire thing is just a theory, but regarding the occasional OpenAI checks on WikiService.at-hosted Wikis targeted, there was, if I remember correctly, an OpenAI IP popping up every now and then that wasn't an agent. Unfortunately I don't have it to hand right now, but it was somewhere here:

https://news.ycombinator.com/item?id=49563355

ur-whale•20m ago
> Any evidence

Who profits from the crime?

davsti4•14m ago
... and what harms can be evidently shown? With both harm, and attribution, you have a case, something that's not being publicly discussed much among big media outlets. Until cases with real financial impact to the bottom line are brought against "rogue" organizations, this stuff is going to continue getting worse.
ur-whale•26m ago
Are "rouge" and "rogue" interchangeable words in American English?
big-chungus4•18m ago
How does he know that this attack is performed by OpenAI agents? I couldn't figure this out from the article
12904927•17m ago
What a time to be alive? One of the most boring decades ever.

METR and others are advertisement arms for Big AI. These exploits could have been prompted by a human.

Since there is no bad news any longer and exploits are celebrated, they chose a target to boost both OpenAI and the Ruby AI sycophants.

Why is Ruby Gems such a mess? It seems as bad as PyPI now.

Schlagbohrer•12m ago
One agent set "oaibooty9217" as their username LOL
onlyrealcuzzo•3m ago
I've been wondering if AI will due to programming languages what advanced civilization did to human languages.

It's not just that AI can write Rust as well as Ruby if you ask nicely.

It's also all of these considerations as well.

I hope it doesn't happen, because there's a lot of great languages - I love Ruby so much - but it almost seems inevitable.

This is at the same time everyone and their mother is building their own programming language.

joinjune•40m ago
Russia is running out of refined oil to power their economy. They probably aren't capable of spinning up datacenters to run those.
dgellow•30m ago
They don’t need to run their own DCs, just pay for a proxy somewhere in the world that has better access to the infrastructure. We know North Korea has been doing that in the US since years now
senda•27m ago
The cost would be between 100k-250k, to run approx 88 agents leveraging the best open source models available.

I'm just saying, where this is actually applicable we are not seeing it being demonstrated. You would presume the entire energy infrastructure of Europe would be under constant AI hacking barrage, criminal enterprise would be breaking into poorly secured financial institutions and r/r4r posts would be littered Ai con-artists.

I'm just wondering, again, is this mostly bullshit?

mcmcmc•39m ago
Did you skip the last paragraph? Not a great time to be building data centers in Russia. Models are nothing without computers to run them
nradov•25m ago
Russia can use fake accounts and VPNs to run their agents in data centers in neutral countries.
mcmcmc•23m ago
And which of these neutral countries have the capacity to serve them and the lack of awareness that hosting an offensive Russian agent swarm would bring hell back to their doorstep? Best they can do right now is rented botnets
dgellow•33m ago
They very likely do, we only see in the news a very few events but you should assume it’s happening daily across the internet
senda•22m ago
I think this fails a lot of logical tests, it should be apparent in day to day life.
dgellow•7m ago
> In October 2024, the United States Justice Department and Microsoft seized more than a hundred internet domains some of which were associated with the FSB supported hacker Star Blizzard or "Callisto Group," which is also known as "Cold River" and "Dancing Salome" and are managed by the FSB Information Security Center […], and which were used as "criminal proxies" and used spear-phishing schemes to target Russians living in the United States, nongovernmental organizations (NGOs), think tanks, and journalists according to Microsoft and United States State Department, Department of Energy, and Department of Defense officials, United States defense contractors, and former employees of the United States intelligence community according to the FBI. In some cases, the hackers were successful in obtaining information relating to nuclear energy-related research, United States foreign affairs and United States defense. According to Microsoft's Digital Crimes Unit from January 2023 to August 2024, Star Blizzard targeted more than 30 different groups and at least 82 Microsoft customers which is "a rate of approximately one attack per week."

https://en.wikipedia.org/wiki/Cyberwarfare_by_Russia

That’s just one thing that has been found. Are you actually familiar with the state of cyberwarfare and are you following its evolution? Because if not you won’t be aware of most of what is identified. And only a small portion of the ongoing attacks are identified.

marginalia_nu•31m ago
Prigozhin falling out of a window was a not insignificant setback for their digital warfare capabilities.
lenerdenator•28m ago
He did not fall out of a window.

He fell out of the sky. After his plane exploded. Happens all the time. Is tragedy.

tokai•30m ago
Because they dont have the money for hardware or compute obviously.
ur-whale•21m ago
> How are we not seeing insane attacks on Ukraine via Agents?

You live on the wrong side of the fence to be able to read that kind of news.

Did you really believe you had access to an unmanipulated news stream in a time of war?

LOL.

senda•12m ago
Please see other responses, I would expect to feel the effects not just read about.
probably_wrong•23m ago
There's no need for a new crime when we already have reckless conduct, namely, "conduct that creates a substantial and unjustifiable risk of harm to others and involves a conscious disregard of, or indifference to, that risk".

https://www.law.cornell.edu/wex/reckless

nottorp•37m ago
Marketing actually.
tacomagick•20m ago
AI is dropping out of the spotlight so they are using desperate measures like this.
trvz•36m ago
Don’t forget outright intentional.
dgellow•35m ago
Both? I’m not sure what distinction you’re trying to make. It was completely irresponsible and likely a felony
aftbit•33m ago
Proof that the AI alignment problem is hard (perhaps even unsolvable).
srmatto•31m ago
Sounds more or less like the last breach then.
gibspaulding•27m ago
I think it can simultaneously be the case that OpenAI was grossly negligent in directly causing this AND that the AI’s ‘went rogue’ in that they are displaying behavior which is misaligned with OpenAI and humanity generally.

The past months demonstrate that AI systems are quickly becoming powerfully intelligent and that the companies building them are terrible at controlling them.

AI is starting to feel like that line about magic: “a sword without a hilt”

consp•22m ago
Doesn't rogue in this context imply "outside of set limitations"? And then not "failed to properly instruct"? The same applies to humans when given bad instructions.
stymaar•16m ago
> which is misaligned with OpenAI and humanity

OpenAI is itself misaligned with humanity, as their mishandling of such incidents (and the many other other issues their model have been causing) shows.

dumberquestions•26m ago
>They were prompted to hack to get answers

Were they? I haven't seen a single report mention this

cyanydeez•16m ago
we have normal words for this stuff: negligence. You can add it on to almost any law.

The problem is consumer protection is basically no longer a part of america's regulatory system. Replaced by "grift is good".

ozgung•12m ago
Source? How do you know they were "prompted to hack to get answers"? How do you guarantee they will always listen to you when you say "do not hack outside systems". They are not classical deterministic programs doing exactly what you say. They are trained to follow orders by RL, but it's not a perfect process.

There are circus lions in circuses trained to jump through hoops on command. But once in a while they decide to eat their trainers instead of jumping.

codeduck•9m ago
nothing rouge either, I suspect.
RajT88•7m ago
https://en.wikipedia.org/wiki/Going_Rouge
2OEH8eoCRo0•28m ago
"To my friends, everything; to my enemies, the law"
yonatan8070•25m ago
I, too, have no idea about legal matters.

But there have been many cases where companies (Google, Apple, Meta, etc...) got fined millions or billions of dollars for various violations like antitrust.

I assume that breaching into third-party systems should carry similar fines. Especially for systems that are for all intents and purposes shared infrastructure. Just imagine how many systems you could compromise if you got hold of RubyGems, PyPI, NPM, Debian, etc.

bix6•29m ago
How is the responsibility diluted? Charge the CEO…
brookst•26m ago
Great, you’re the attorney at the CEO’s trial. To get a conviction, you’re going to have to show that he willfully committed this specific crime. There are no negligent or stochastic hacking laws, you have to show this specific crime was at his direction.

Do you think there is evidence of this?

bix6•17m ago
Honestly yeah I bet there is and I hope to someday read about it if the government ever gets off its ass. Someone set up the “experiment”…
VyseofArcadia•13m ago
It would seem to me that the difference between the corporate world and organized crime is that a corporation can get away with, "the responsibility is too diffuse" but the mafia at least has to go to the trouble of finding a fall guy.
tekla•23m ago
Charge the "engineers" you dont get to take that title if you don't take the responsibility of that title.

I'm going to assume that this will never happen