Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bearsyankees
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
We got admin access to Baseten's production GitHub
(strix.ai)
321 points
by
bearsyankees
1d ago
|
184 comments
2.
▲
We wanted to use Baseten for inference, we got admin access to their GitHub
(strix.ai)
9 points
by
bearsyankees
6d ago
|
0 comments
3.
▲
by
bearsyankees
23d ago
If this is the case then IMO all the more reason to publicize it -- my SSN shouldn't be exposed just because I applied for a lease [ and we shouldn't just brush that off as something that is a given ]
4.
▲
by
bearsyankees
23d ago
Also, as far as I know, no residents were ever alerted that their data was exposed so this also is a bit of a public disclosure angle
5.
▲
by
bearsyankees
23d ago
Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a c
6.
▲
by
bearsyankees
23d ago
Thanks!! Just trying to protect other's (and in this case, my own) data :)
7.
▲
by
bearsyankees
23d ago
yep
8.
▲
A Blackstone real estate company exposed SSN digits, DOBs, addresses and more
(alexschapiro.com)
123 points
by
bearsyankees
23d ago
|
56 comments
9.
▲
by
bearsyankees
2mo ago
yeah you mean because OAI is only whitebox? or expand on that a bit, haven't played around a ton w the oss codex sec
10.
▲
by
bearsyankees
2mo ago
would love it to see it h2h against https://github.com/usestrix/strix (45k stars)
11.
▲
by
bearsyankees
2mo ago
granola's disclosure: https://docs.granola.ai/help-center/policies/security-contri...
12.
▲
Finding a 1 click account takeover (and webcam access) in Granola
(strix.ai)
6 points
by
bearsyankees
2mo ago
|
1 comments
13.
▲
by
bearsyankees
2mo ago
https://www.strix.ai/blog/granola -> technical writeup
14.
▲
Granola Discloses a 1 Click Session Takeover of Its Notes App
(docs.granola.ai)
3 points
by
bearsyankees
2mo ago
|
1 comments
15.
▲
One Click Account Takeover in Granola AI Notetaker
(strix.ai)
7 points
by
bearsyankees
2mo ago
|
0 comments
16.
▲
CVE-2026-59208: Cross-Issuer Account Takeover in n8n
(strix.ai)
20 points
by
bearsyankees
2mo ago
|
10 comments
17.
▲
by
bearsyankees
5mo ago
oh apologies, thanks for the reminder
18.
▲
by
bearsyankees
5mo ago
appreciate the feedback!!
19.
▲
by
bearsyankees
5mo ago
https://x.com/strix_ai/status/2051361018450948511
20.
▲
by
bearsyankees
5mo ago
fixed now
21.
▲
by
bearsyankees
5mo ago
apologies, just a vc firm
22.
▲
Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
(strix.ai)
221 points
by
bearsyankees
5mo ago
|
101 comments
23.
▲
by
bearsyankees
5mo ago
Strix (strix.ai, https://github.com/usestrix/strix )| Founding Engineer | NYC/SF We built the largest open-source AI pentesting framework — 25k GitHub stars, 80k active users, 15B LLM tokens processed daily, 1,800
24.
▲
Context.ai seemingly cause of Vercel breach
(twitter.com)
3 points
by
bearsyankees
5mo ago
|
0 comments
25.
▲
by
bearsyankees
5mo ago
https://x.com/steipete/status/2044423791405924562 very soon it seems...
26.
▲
by
bearsyankees
5mo ago
I don't know if I fully agree with this -- how many people were actually self-hosting cal infra? I def could be wrong though
27.
▲
by
bearsyankees
5mo ago
+1, at this point all companies need to be continuously testing their whole stack. The dumb scanners are now a thing of the past, the second your site goes live it will get slammed by the latest AI hackers
28.
▲
by
bearsyankees
5mo ago
Think this is a bad, bad move... https://news.ycombinator.com/item?id=47780712
29.
▲
Open Source Isn't Dead
(strix.ai)
356 points
by
bearsyankees
5mo ago
|
186 comments
30.
▲
Show HN: Greptile for Security (open source)
(strix.ai)
2 points
by
bearsyankees
5mo ago
|
0 comments
More ›