frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

GPT-6 Sol and Luna

https://openai.com/index/introducing-gpt-6-sol-and-luna/
832•OfficialTurkey•3h ago•440 comments

Claude Opus 5.5

https://www.anthropic.com/claude-opus-5-5
907•km144•4h ago•673 comments

'We hacked the FBI:' Hackers say they have data on all FBI employees

https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
126•spenvo•3h ago•74 comments

OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005

https://www.cryptocellar.org/bgac/the-mvueh-break.html
491•sohkamyung•7h ago•341 comments

SAML: A Fractal of Bad Design

https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/
84•aray07•2h ago•32 comments

Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)

https://artificialanalysis.ai/models/claude-opus-5-5
173•theanonymousone•4h ago•51 comments

WordPress: Unauthenticated path traversal leading to conditional RCE

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
114•vntok•4h ago•59 comments

What California is learning from solar panels built over irrigation canals

https://www.kqed.org/science/2002033/heres-what-california-is-learning-from-solar-panels-built-ov...
35•Jtsummers•18h ago•23 comments

Native apps written in TypeScript and CSS

https://github.com/geastack/examples
38•arbayi•1h ago•7 comments

Unreal Agent

https://unreallabs.ai/blog/unreal-agent/
66•trollied•2h ago•42 comments

No Sloptober

https://no-sloptober.com/
9•jeremiahlee•8m ago•0 comments

Markdown in /src

https://htmx.org/essays/markdown-in-src/
48•perrygeo•22h ago•15 comments

OpenAI is well positioned to fast-follow Jev

https://arcturus-labs.com/blog/2026/09/21/will-openai-eat-jevs-lunch/
225•JohnBerryman•6h ago•168 comments

An update on how we confirm your age group on Discord

https://discord.com/blog/safer-for-teens-same-discord-for-adults
54•meetpateltech•3h ago•9 comments

Show HN: Training a model to identify AI web content from structure alone

https://arxiv.org/abs/2609.15369
21•jochenmadler•8h ago•5 comments

Did OpenAI solve the wrong Navier-Stokes problem?

https://www.scientificamerican.com/article/did-openai-solve-the-wrong-navier-stokes-problem/
48•tomjakubowski•20h ago•19 comments

Rabbit Hole: Minimum L-seams

https://www.fractalkitty.com/rabbit-hole-minimum-l-seams/
19•evakhoury•5d ago•5 comments

MUNI Heritage Weekend in San Francisco

https://daniel.lawrence.lu/blog/2026-09-20-muni-heritage-weekend/
131•plun9•1d ago•32 comments

How did AMD Ryzen get 50% faster in two years?

https://lemire.me/blog/2026/09/18/how-did-amd-ryzen-get-50-faster-in-two-years/
128•ibobev•4d ago•27 comments

Show HN: JevBench, a reproducible benchmark for typed decision models

https://benchmarkheaven.com/jev-models
28•florianstandhar•8h ago•1 comments

A Faster Shortest Path Algorithm

https://www.vals.ai/blogs/faster-shortest-path-algorithm
25•leumon•1h ago•5 comments

16-bit Intel 8088 chip (c. 1985)

https://allpoetry.com/16-bit-Intel-8088-chip
90•rbanffy•5h ago•12 comments

The UV index is not the warm sensation of sunlight on bare skin

https://blog.asciitweezers.com/the-uv-index-is-not-the-warm-sensation-of-sunlight-on-bare-skin/
3•evakhoury•7m ago•0 comments

George Lucas Returns to Earth, Bearing Gifts

https://commonedge.org/george-lucas-returns-to-earth-bearing-gifts/
46•surprisetalk•1d ago•22 comments

The JavaScript Midlife Crisis

https://maroun-baydoun.com/blog/javascript-midlife-crisis/
14•maroun-baydoun•1h ago•5 comments

Launch HN: Coverage Cat (YC S22) – Umbrella insurance via your personal agent

https://www.coveragecat.com/
28•botacode•3h ago•19 comments

Apple has added persistent 'ads' to iOS, and it's driving users crazy

https://www.techradar.com/phones/iphone/i-wish-apple-would-just-stop-that-crap-apple-has-added-pe...
517•MC995•6h ago•392 comments

There's a high chance of devices being sold with GrapheneOS preinstalled in 2027

https://grapheneos.social/@GrapheneOS/117299954135808210
201•Cider9986•4h ago•92 comments

Overreliance on AI contributed to missile strike on Iran school – Pentagon

https://www.bloomberg.com/graphics/2026-iran-school-attack/
235•devonnull•2h ago•124 comments

People hooked on vapes try a new way to quit: cigarettes

https://www.bloomberg.com/news/articles/2026-09-18/to-quit-vaping-some-are-starting-to-smoke
52•alephnerd•19h ago•48 comments
Open in hackernews

'We hacked the FBI:' Hackers say they have data on all FBI employees

https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
126•spenvo•3h ago
https://archive.ph/96YBP

Comments

dgellow•3h ago
Im sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this
ben_w•48m ago
If the claim is true, I'd expect them to have used either those models or Grok or similar.

Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.

smalltorch•3h ago
Thats a major attack on the US.

If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?

lenerdenator•41m ago
Is it, though?

If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.

smalltorch•26m ago
Uh yeah, it dangerous. Public data brokerage doesn't identify FBI agents in a master roster?

Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.

Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.

Joel_Mckay•40m ago
In general, most governments have standard operational policies that mitigate such issues (ISO 15408.) =3
dvh•34m ago
ISO and ICC start with the same letter, just saying...
Joel_Mckay•31m ago
The International Cricket Council does have very strict rules. lol =3
kelseyfrog•2h ago
So they're getting access to a year's worth of free credit reporting for the inconvenience?
tencentshill•2h ago
Well that's a big one.

Perhaps firing expertise and hiring incompetents wasn't a good idea.

nateb2022•1h ago
There's incompetence in every major company including Oracle. PeopleSoft isn't known for being the most modern or secure thing out there. Less reliance on 3rd party software like this will be a good thing going forward.
lenerdenator•48m ago
That's assuming that the result of this will be to switch away from PeopleSoft.
nateb2022•44m ago
I think enterprise software in this vein used to have a quasi-monopoly due to the sheer work required to build software of its size (not enough engineers exist in the government to do so), and the difficulty for competitors to enter regulated markets and so pretty much 1-2 options to choose from.

AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.

sarchertech•34m ago
Enterprise software is complicated mostly because of number of customers it can support.

Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”

There are so many counter examples.

htrp•1h ago
TLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)
ok123456•51m ago
PeopleSoft 0-day.

Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.

lenerdenator•46m ago
It doesn't do nothing. It does make things somewhat harder to attack.

There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.

0xbadcafebee•42m ago
The attackers exfil'd 3TB of data, which obviously included PII, from AWS servers. They should've had DLP, active monitoring, countermeasures, using a security vendor (you can set this up for AWS services using CloudTrail, CloudWatch Logs, etc). You're supposed to have that for sensitive government or military work, and it should have (at least) caught that much traffic going to a rando external IP, blocked and flagged.

If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).

jimbob45•36m ago
iAMkenough•1h ago
In the same week the head of the FBI went on national TV to claim credit for increasing the bureau's use of AI by 605%, whatever that's supposed to mean.

https://www.tomshardware.com/tech-industry/artificial-intell...

giancarlostoro•49m ago
It means when the FBI builds a case against you make sure your lawyer hires a competent forensic expert. I've seen and heard "expert" testimonies in some court cases that make me angry. There's people using tools that digitally "enhance" small images, and that gets presented as evidence in court. It bewilders me how adding pixels to an image is evidence.
applfanboysbgon•1h ago
Wow, that is bold. I wonder if they'll get away with it because incompetent leadership has decimated the US's capabilities? This certainly doesn't bode well for the US's odds against its nation-state rivals.
TZubiri•1h ago
Is their name a reference to pokemon? Or to the meme that the FBI/CIA glows through the screen?
clint•46m ago
They've been on an streak for over 6 years now, check out their wikipedia page.
bitwize•44m ago
You're thinking of "glowie", "shiny" is def a Pokémon thing.
mech422•26m ago
also an mmo thing - hunting for collectibles in game
yepyoukno•16m ago
“Glowie” is a white supremacist slur for “Jew” or “fed” (they think the Feds are “a bunch of Jews”.)

They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)

It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.

phainopepla2•3m ago
I think you have the etymology wrong, although there was (schizophrenic) racism involved in the coining of the term. The "glow" part doesn't come from the fact that they're white (or not dark), it comes from Terry Davis saying that "CIA n*'s glow in the dark" (i.e. are obviously spotted and can't hide their identities).
giancarlostoro•52m ago
...and this is how the FBI makes you a higher priority target, and you wind up caught.
clint•50m ago
US keeps arresting and charging people from this group for well over 6 years now, and this happens in 2026. They don't sound very scared.
woko•2m ago
The group is not afraid, but the individuals who got charged probably stopped all black-hat activity: there was an individual in his early twenties who "was sentenced to three years in prison and ordered to return $5 million", which is life-changing to say the least.
Simulacra•50m ago
Again?
reactordev•36m ago
There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…
mikeyinternews•24m ago
this is the way
mjhagen•10m ago
So say we all
gchamonlive•12m ago
I think it's one of the first two special episodes right at the beginning of the series, and it's the sole reason why the fleet could sustain evading the cylons
ishouldstayaway•5m ago
It's not just a scene; it's the whole premise of the setting. It's why the Galactica survived and the newer ships did not. It's why the new Vipers got wiped out and they had to pull the old ones out of mothballs.

In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.

28304283409234•2m ago
"What do you hear, Starbuck?"
corvad•35m ago
Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.
john_strinlai•34m ago
they have been on an absolute roll for quite awhile now.
corvad•32m ago
Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.
ctkhn•17m ago
I wonder if that was really a 0-day or an intentional backdoor?
paimapi•4m ago
it's Oracle, 99% chance it's a 0-day lol
levocardia•28m ago
So, what are the odds this was done with an open-weight LLM?
KronisLV•28m ago
That feels like publicly announcing that you want to be in a lot of trouble.
jgalt212•25m ago
If I use Claude or OpenAI swarm to commit crimes, and the vendor knows I'm up to no good, what's their liability? Do they plan to invoke the phone company defense?
phendrenad2•22m ago
Imagine the FBI's relief when the hackers only got a list of their employees, not the UFO files.
jacobgold•20m ago
At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

China hacked 22.1 million records of US government employees:

https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

Taek•13m ago
Google seems capable
tdhz77•10m ago
Mythos can do much worse
titzer•4m ago
And the city wonders why I don't want to put my credit card info in their crappy parking app and would instead prefer to put a quarter into the meter for 30 mins.
lotsofpulp•32s ago
What info can be gleaned from that? Surely the mere fact that you have a credit card means your name and billing address are floating around.
simur•1m ago
Yeah, about the medical information. Recently in Poland there was a hack on the medical system called MrDr that is used by commercial medical facilities. Estimated 21M people could've been affected. So it is already happening and the scariest thing is, we don't have control on where our data is stored on. Even the EU GDPR didn't make it easy to control what data lands where.
steveBK123•20m ago
Claiming they got all employee & spouse data.

Wondering about pets..

Ancapistani•16m ago
Meh - I'll believe it when I see the actual data.

Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.

bearjaws•16m ago
America is at war and losing comically.

Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.

The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".

Almost like its run by a bunch of 80 year olds...

whynotmaybe•11m ago
> data totalled between two and three terabytes.

That's lot of data for a list of employees.

AraneaDev•1m ago
I was gonna say. What else did they get, whole dossiers with photos etc?
Apocryphon•9m ago
Remember how the original Mission Impossible movie (1996) was about the bad guys getting the NOC list? This feels somehow even worse than that.
S-E-P•2m ago
Hasn't that db been pwned previously?
0cf8612b2e1e•27m ago
Considering how bad most enterprise software is, I assumed the only real relevance was if the sales team ponied up some lavish perks to the right VP who only has to sign checks and never actually interact with the software.
Zigurd•27m ago
Not even the FBI has hostage negotiators good enough to get you out of an Oracle contract.
quickthrowman•14m ago
I imagine Oracle lawyers to be identical to the Cylons pointing guns at President Gaius Baltar and forcing him to sign death warrants on New Caprica.

https://youtu.be/2_nUztwPiEY

mc32•1h ago
Do you think this is a consequence of the seemingly quarterly RIFs at Oracle? Is it that offshoring wasn’t such a good idea?
lenerdenator•50m ago
The irony, of course, is that this will likely have a negative impact upon Oracle's reputation, which will have a negative impact upon its value, which will then be resolved with more RIFs.

It's okay. Larry got another island.

jmclnx•14m ago
I doubt it, look at all other breaches over the years.

If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.

Betelbuddy•52m ago
Lets hope the Epstein files see the light of day, thanks to AI...
rayiner•50m ago
Doesn’t seem new. Do you remember the 2015 OPM hack? https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag.... My data got leaked in that.
freejazz•19m ago
Probably just one of the new recruits clicking on a link while viewing beastiality
consumer451•14m ago
Was that the one where due to political grand-standing, we had a government shutdown that led to furloughing the contractors who worked on security, so no one was watching the dashboard? Or was that a different one?
baggachipz•37m ago
I always assumed DOGE + Ka$h would create an impenetrable fortress of strength; a beacon on the hill of brilliance and security.
classified•11m ago
If you use Trump Coins to reflect the Evil Eye away from you, nothing bad can happen to you.
I’m skeptical that multiple terabytes of data were exfiltrated quietly. I’m struggling to see this as anything other than a bluff.
iAMkenough•28m ago
I'm less skeptical after seeing it happen to IDScan and terrabytes of government-issued IDs being exfiltrated quietly.

Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.

ChosenEnd•1m ago
Mythos can hack 200 million government employees