Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
galnagli
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
galnagli
1mo ago
Thanks @vultour and croemer for your proactiveness -- you are correct,I updated the blog to clarify that Copilot was a co-author that checked the merged PR and code change, and identified it as all-clear without noticing the critical vulner
2.
▲
by
galnagli
1mo ago
Github is having some problems -- will check! thanks a lot!
3.
▲
by
galnagli
1mo ago
Too long for hackernews :(
4.
▲
AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
(wiz.io)
424 points
by
galnagli
1mo ago
|
157 comments
5.
▲
Cyber Model Arena
(wiz.io)
2 points
by
galnagli
7mo ago
|
2 comments
6.
▲
by
galnagli
7mo ago
General-Purpose Cyber Benchmark for AI Agents and their Models
7.
▲
Hacking Moltbook
(wiz.io)
397 points
by
galnagli
8mo ago
|
245 comments
8.
▲
by
galnagli
10mo ago
Hey mmsc, first of all - the blogs are not AI Generated! Second of all, the blog did add more information "In our experimentation, exploitation of this vulnerability had high fidelity, with a near 100% success rate and can be leveraged
9.
▲
by
galnagli
11mo ago
Ian is a great writer
10.
▲
Accessing Max Verstappen's passport and PII through FIA bugs
(ian.sh)
632 points
by
galnagli
11mo ago
|
145 comments
11.
▲
1 in 5 organizations vibe coded applications are vulnerable to systematic risks
(wiz.io)
2 points
by
galnagli
1y ago
|
0 comments
12.
▲
by
galnagli
1y ago
I see companies deploy and trust AI without really investing into security, it will be very easy in the near future to find simple, devastating bugs : )
13.
▲
by
galnagli
1y ago
Happy to answer questions : )
14.
▲
by
galnagli
2y ago
Thank you everyone, this was responsibly disclosed to DeepSeek and published after the issue was remediated, we got acknowledgment from their team today on our contribution.
15.
▲
by
galnagli
2y ago
Seats.aero is better
16.
▲
by
galnagli
3y ago
Well - they have had more bugs and will have more bugs to worry from. https://twitter.com/naglinagli/status/1639343866313601024
17.
▲
by
galnagli
3y ago
Web Cache Deception issue has led OpenAI's ChatGPT to suffer an account takeover vulnerability, although they don't run an official Bug Bounty program - they were quick to response and fix the matter.