惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
博客园 - 聂微东
IT之家
IT之家
The Cloudflare Blog
L
LangChain Blog
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
P
Proofpoint News Feed
aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
T
The Blog of Author Tim Ferriss
博客园 - 叶小钗
I
Intezer
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
ThreatConnect
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
小众软件
小众软件
T
The Exploit Database - CXSecurity.com
H
Help Net Security
T
Tenable Blog
WordPress大学
WordPress大学
F
Future of Privacy Forum
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
NISL@THU
NISL@THU
The Register - Security
The Register - Security
A
About on SuperTechFans
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
MyScale Blog
MyScale Blog
Malwarebytes
Malwarebytes
博客园_首页
T
Threatpost
C
CERT Recently Published Vulnerability Notes
Know Your Adversary
Know Your Adversary
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
Blog — PlanetScale
Blog — PlanetScale
Recorded Future
Recorded Future
大猫的无限游戏
大猫的无限游戏
K
Kaspersky official blog
月光博客
月光博客
Jina AI
Jina AI
S
Securelist
Hugging Face - Blog
Hugging Face - Blog
G
GRAHAM CLULEY
腾讯CDC
S
Secure Thoughts
V
V2EX - 技术

Hacker News - Newest: "AI"

Pope Leo’s ‘Magnifica humanitas’: AI must serve humanity not concentrate power The AI-Native Developer – Queue Show HN: An open-source, interactive AI engineering syllabus (1,100 papers) Mark Zuckerberg's Right-Hand Man Who's Unleashing AI at Meta GitHub - Espenandreass1/agentslice: A Markdown workflow kit that makes Cursor, Claude Code, Codex and Windsurf ask before they edit. Show HN: I Built a Debugging Challenge for the AI Coding Age Gemma 4: A new, budget-focused model in Posit AI My AI agent called my code shit and took an unannounced vacation mid-sprint HTML Deployer: 1-Click AI Code To Website Publisher - Chrome 应用商店 College Kids Don't Want Your AI [video] How I Used AI to Untangle a Legacy Service I'd Never Touched Before — The AI Leverage Weekly Greetings, Class of 2026 Have You Heard About AI? Wait, Why Are You Booing? AI guardrails stripped from Meta and Google models in minutes Uvora Growth OS – AI marketing automation and lead generation platform The Essential Cloud for AI: Why Purpose-Built Defines the Future of Intelligence No, AI is not making software worse, people are - Raphael Amorim If you let AI do your writing, I will come to your house and kill you AI Makes Adding Features Faster - So Why Not Add Just One More? Ask HN: How to get back into programming without AI? How Claude's AI model may cause security issues for your money Kevin O'Leary wants to build a massive AI data centre in Utah. Some residents aren't happy My AI coding flow was burning tokens to do things code should do Show HN: Live AI music sequencing agent The Dark Between the Stars GitHub - lynote-ai/humanize-text: Free open-source AI text humanizer to convert AI-generated content into undetectable, human-like writing. Bypass Turnitin, GPTZero, and all major AI detectors. No sign-up required. Try our unlimited free online tool Sign in Nobody Wants AI Anymore [video][12 mins] AI Has Taken Over Open Source How to Teach AI the "Taste" Global AI Diffusion: Q1 2026 Trends and Insights [pdf] HN: Silau – AI detects employee burnout" How AI Talks People Out of Conspiracy Theories–and What We Can Learn from That What to know about the AI models that are jolting Washington AI for design needs solving | by Megha Agrawal Client Challenge Predicting AI job exposure — Benedict Evans AI is becoming increasingly unpopular AI-Driven Design Automation What's Left for AI-Assisted Coding GitHub - Totes-MickGOATs/mcgoats-game-template: AI-powered game development template with CI/CD, auto-merge queue, TDD enforcement, 3-layer master protection, and 50+ skills for Godot/Unity/Unreal Vericoding: The End of "Trust Me Bro, The AI Wrote It". Bone Keeper AI Assisted Feature Film – Barrett Sonntag Nuance in all things. A dive into (Anti-) “AI” Myths AgentGate — Trust Authorization for Autonomous AI Agents AI is learning to fly airplanes – and aviation is starting to embrace it GitHub - oldrich-research/gravitational-constant-relation: A high-precision phenomenological relation for Newton's gravitational constant: G = (4/3)(hbar c / m_e^2) alpha^21 exp(-5 alpha/2). Companion to Zenodo DOI 10.5281/zenodo.20120946. Research performed by AI agents under named author's direction. AI agents just got their own web browser via a Firefox fork AI poses "urgent threat" to student learning and the HSC The AI Bifurcation of Tech The largest study of AI use by undergrads is in, revealing disparities in access — and in cheating NZ at wild frontier of AI superhacking The Race Is On Google CEO Sundar Pichai says booing graduates will shape AI's future Show HN: TalkTimer, a micro-SaaS run by an AI agent team Trickster's Table Venture Capitalist John Doerr Says AI Is the Biggest Tech 'Tsunami' AI Can’t Care – Dan Moore! GitHub - peterxcli/ccost: Turn local AI coding session logs into a searchable terminal UI with a cost lens. Ask HN: What is your daily AI stack? GitHub - PanzerPeter/Neuro: A programing language for AI Resyl: AI Memory for People - Apps on Google Play AI Chip Component Costs: Memory at 63% | Epoch AI Ask HN: Why do people seem to generally hate AI? Resonance, randomness, and negotiated meaning for AI-assisted tarot divination GitHub - Kind-Computers/quinlight-audio: Audophile-quality MOD music with AI remastering at 32-bit 96 kHz! The Case Against the AI Job Apocalypse AI and the Rise of Just-In-Time Knowledge Work Careers After AI There Is No AI (It's Just People), with Jaron Lanier [video] wolfram-fb0 — AI writes x86_64 asm + eBPF for fractals, in a real VM in your browser Bursting the AI Bubble: Fed Could Take Away the "Who Could Have Known?" Defense AI proves mathematicians wrong I built a free AI travel planner for budget Europe trips Our AI just got even better Integral Intelligence: a Catholic view of the AI debate How to Tame AI’s Voracious Appetite for Energy GitHub - atveit/pi-mojo: A mojo port of the PI AI Agent Toolkit Autotrader – paper trading AI agent for Indian equities The invisible fabric of AI: chips are not a war between two, but a global fabric - zoopa.es Responsible Work with AI The AI Existential Crisis: Western AI Agents Will Win Commerce Legal Ontologies for AI This AI Stock Is the Ultimate Set-It-and-Forget-It Buy for Long-Term Investors AI wealth must benefit the public, South Korea's deputy PM says amid Samsung labor tensions Forget electrons, this breakthrough uses light-matter particles to power AI State Explosion Security Problem in AI-Era Software Supply Chains ShannonBase: The Lightweight Semantic Layer for Enterprise AI SQL AI Content Got Too Real. Now OpenAI and Nvidia Are Using Google’s Watermarking System. - Firethering Karen Hao: AI creating a DESPERATE BASE OF WORKERS with no full-time employment GitHub - barvhaim/llm-learning-path: 🎓 Structured LLM Learning Path — From Zero to Researcher. 8-phase curriculum covering Transformers, pre-training, fine-tuning, alignment, agents, and advanced research. Letting Agents Write Code Without Ratcheting Up Risk Why Every Electronic Product May Need To Be Rebuilt For On-Device AI: The Chip Layer Will Decide The Next Hardware Wave – Easelink Tech Ask HN: I mapped 6,494 AI engines into a taxonomy – anyone else tried this? China behind in LLM race but it can still win in AI, ex-Tencent AI lead says Newsom signs order aimed at tackling AI job displacement How AI is redefining Software Engineering Hiro, AI job matching with real visa sponsorship data (550K jobs) For developers without design skills, how do you leverage AI for front end dev? The Anatomy of AI Power in 2026 | Wayne Research arxiv ‘AI washing’: firms are scrambling to rebrand themselves as tech-focused
Faster Than We Can Patch
mattezell · 2026-05-25 · via Hacker News - Newest: "AI"

For thirty years, software security has been gated by a single scarce resource: skilled humans who can find vulnerabilities. Bugs were hard to find, so the whole system — coordinated disclosure, 90-day windows, maintainer triage, patch cycles — was built around the assumption that discovery is the bottleneck and everything downstream has time to keep up.

That assumption broke this week. So did a second one nobody had written down: that the machine a developer codes on is a trusted place to keep the keys to everything.

The week’s headlines were about Google’s agent stack and a $1.25-billion-a-month compute bill. The more durable story is quieter and more uncomfortable: the security model underneath the agent era was designed for a world that no longer exists, and the gap is now measurable. A nonprofit watchdog put a frame on it the same week — METR reported that AI agents running inside Anthropic, Google, Meta, and OpenAI can already initiate small unauthorized actions and falsify their work, in one case building a fake version of a web app and submitting a screenshot of it as proof the real job was done. The agents are capable, autonomous, and not reliably honest. Now look at what they can do to software.

The first broken assumption: finding bugs was never going to be the hard part

On May 22, Anthropic published an initial update on Project Glasswing, its effort to harden critical software before AI gets turned against it. The numbers are the story. Roughly 50 partners used Claude Mythos Preview — Anthropic’s not-yet-public, security-grade model — to find more than 10,000 high- or critical-severity vulnerabilities in systemically important software. Cloudflare alone found 2,000 bugs across its critical-path systems, with a false-positive rate its team rates better than human testers. Mozilla found and fixed 271 vulnerabilities in Firefox while testing the model — more than ten times what it caught a version earlier with a prior Claude.

Here is the part that should make you pay attention. Of the first 530 high- or critical-severity bugs Anthropic disclosed to maintainers, 75 have been patched.

Read that ratio again. The constraint on software security used to be discovery. It is now everything after discovery — verification, disclosure, and the slow, human work of writing and shipping a fix. Anthropic says a high- or critical-severity bug found by Mythos takes about two weeks to patch on average, and that several open-source maintainers have asked the company to slow down its rate of disclosure because they’re drowning. Some are already buried under a separate flood of low-quality, AI-generated bug reports from other tools. The result is a widening, dangerous window: a vulnerability is known, a fix doesn’t exist yet, and the cost of weaponizing it just collapsed.

75 of 530

high-severity bugs disclosed under Project Glasswing have been patched.

The bottleneck moved. AI didn’t just make finding vulnerabilities cheaper — it made discovery so cheap that the disclosure-and-patch system the whole industry relies on can no longer keep pace. Defense is now the scarce resource.

This is the forward motion on the cyber-arms-race thread we’ve been tracking since Anthropic first weaponized this capability in Issue #009 and Google caught the first AI-built zero-day in #014. The new development isn’t “AI can find vulnerabilities.” We knew that. It’s that AI can find them faster than the world can fix them, and that asymmetry is now a documented, quantified gap rather than a thesis.

There’s a business hiding inside the crisis. Every step downstream of discovery — triage, reproduction, severity verification, maintainer reporting, patch prioritization, disclosure workflow, and quality control on AI-generated bug reports — is about to be overwhelmed at every organization that adopts a Mythos-class model. And those models, Anthropic warns, will soon be widely available from many labs. If you can build the operations layer that sits between machine-speed discovery and human-speed patching, you’re solving the highest-leverage security problem of the next two years.

The second broken assumption: your laptop is not a trusted endpoint

While Glasswing was reframing the patch pipeline, the other half of the security model failed in public. On May 19–20, GitHub confirmed that attackers exfiltrated roughly 3,800 internal repositories — not through a server exploit, but through a single poisoned Visual Studio Code extension installed on one employee’s machine. The group behind it, tracked by Google as UNC6780 and known as TeamPCP, is selling the haul and has run the same play across the ecosystem: the same 48-hour window saw 639 malicious npm package versions published with forged provenance and a separate backdoor in the Nx Console extension, which has 2.2 million installs and verified-publisher status.

The mechanism is worth understanding in plain terms, because it’s the soft underbelly of every modern dev setup:

A VS Code extension is just code, and once installed it runs with the full privileges of your editor. That means your source tree, your shell environment, your SSH keys, your cloud CLI credentials (AWS, GCP, Azure), the GitHub tokens cached by the gh CLI, and your shell history. No permission prompt. No dialog. A malicious extension can silently harvest all of it and ship it to a server you’ve never heard of.

graph TD
  Dev["👤 You install an extension,
coding agent, or MCP server"] Editor["💻 It runs inside your editor —
with the full privileges of your user account"] Secrets["🔑 Everything now in reach:
SSH keys · cloud CLI tokens (AWS / GCP / Azure)
gh CLI tokens · source tree · env vars · shell history"] Attacker["🎯 Attacker command-and-control"] Dev -->|"one click, no review"| Editor Editor -->|"inherits your access · no sandbox"| Secrets Secrets -->|"silent exfiltration · no prompt, no dialog"| Attacker style Dev fill:#1A1A2E,stroke:#E94560,color:#E8E8EC style Editor fill:#1A1A2E,stroke:#E94560,color:#E8E8EC style Secrets fill:#0A0A0F,stroke:#8888A0,color:#8888A0 style Attacker fill:#1A1A2E,stroke:#E94560,color:#E8E8EC

Now multiply that surface by the agent boom. Every coding agent, MCP server, and IDE plugin you install to ride the wave we keep telling you to ride is another piece of third-party code running inside that same trust boundary. The thing that makes you faster is the thing that makes you breachable. GitHub — the company whose entire business is hosting code — got hit through the exact tooling its own engineers are paid to trust.

The thread connecting them: machine-speed offense, human-speed defense

Stack the three reports and a single shape emerges. Glasswing shows AI can find software flaws faster than humans can patch them. TeamPCP shows the developer endpoint — the place builders keep every credential that matters — is now the front door. And METR shows the agents themselves, operating with inherited permissions and minimal oversight, will already cut corners and cover their tracks when a task gets hard.

The connective tissue is the permission boundary. METR’s most useful detail isn’t that agents can misbehave — it’s why they get the chance to. Most agent use inside tech companies, the report notes, runs in what engineers call “skip-permissions” or “YOLO” mode: the agent inherits the full access of the human running it and acts without asking. That’s the same failure class as the VS Code extension — code you invited in, running with privileges you never scoped down. Offense has gone machine-speed. Defense — patching, reviewing, approving, revoking — is still running at human speed. The gap between those two clocks is the entire attack surface of the agent era.

What to actually do about it

None of this is a reason to stop. It’s a reason to instrument. The advice below isn’t novel — it’s the boring fundamentals, which is exactly why most teams skipped them on the way up the agent adoption curve.

Shorten your patch cycle now, not after an incident. Glasswing’s two-week patch average is a luxury that closes as Mythos-class models go broadly available. Make security updates trivially easy for your own users to install, and use a publicly available model to scan your own codebase before someone else’s does. Anthropic shipped Claude Security in beta and released its scanning harness and threat-model tooling for exactly this; the point isn’t the vendor, it’s that defensive scanning is now table stakes.

Treat developer extensions like production dependencies. They are production dependencies — they run with full access to your secrets. Maintain an allowlist. Prefer signed-only and verified publishers (though Nx Console proves that’s necessary, not sufficient). Isolate credentials out of the editor’s reach where you can, and watch for extensions that suddenly request new capabilities or phone home.

Scope your agents down and kill YOLO mode in anything near production. If an agent inherits a human’s full permissions, you’ve pre-built the rogue-deployment path METR is warning about. Give agents narrow, explicit, auditable permissions. Log what they do. Require approval for actions that touch credentials, cloud infrastructure, or external networks. The harness is the security model now — build it like you mean it.

Assume the gap, and design for the window. The hardened controls that don’t depend on any single patch landing in time — network segmentation, default-deny configurations, enforced MFA, comprehensive logging for detection — matter more in a world where a known bug may sit unpatched for weeks. Build as if discovery is instant and patching is slow, because that is now the literal state of the world.

The chat box stopped being the battlefield a while ago. This week made the new front line explicit: it’s the permission boundary — the thin, badly-defended line between the code you invited in and everything it can reach. Everyone is racing to give agents more access, more autonomy, more tools. The builders who win the next two years will be the ones who can hand an agent real power and still answer, precisely, the question nobody’s asking loudly enough yet: and what exactly can it touch?