From Hacker News Front Page · 40 stories
Citigroup, Idaho, and Build-A-Bear Networks Used in Coordinated Phone Fraud Attack
Networks belonging to Citigroup, the State of Idaho, Build-A-Bear, and several other organizations were observed participating in a coordinated International Revenue Share Fraud (IRSF) attack. These networks attempted to use a VoIP server honeypot to dial premium-rate international numbers, indicating compromised machines within their systems. This incident highlights the presence of undetected bots within corporate and government networks, posing a broader security risk beyond the immediate fraud attempt.
Envoy's oghttp2 codec showed 15-25% performance regression compared to nghttp2
An investigation into Envoy's HTTP/2 codec change revealed that Google's oghttp2, which became the default in Envoy v1.34, caused a 15-25% performance slowdown compared to the previous nghttp2 codec. This regression led to Envoy v1.37.0 reverting to nghttp2 as the default, impacting users who experienced increased CPU usage and latency.
FIPS 140-3 validation does not guarantee overall product security, auditors confirm
FIPS 140-3 validation certifies only a cryptographic module's correct implementation of approved algorithms and design requirements, not the security of the entire product or its operational configuration. Many customers disable FIPS mode in certified hardware, indicating a gap between perceived and actual security assurances. This distinction is critical as FIPS 140-2 certificates are being phased out, pushing vendors and procurement teams towards FIPS 140-3.
Waymo Co-CEO Explains Technical Limitations of Camera-Only Self-Driving Systems
Waymo co-CEO Dmitri Dolgov articulated why camera-only sensing systems are insufficient for achieving full self-driving autonomy, stating they reach a safety ceiling too early. Dolgov's explanation highlights the necessity of combining cameras with lidar and radar for robust, superhuman autonomous performance, contrasting with approaches relying solely on cameras.
Optimizing Frame Selection for LLMs to Understand Video Content
Effective frame selection is crucial for large language models (LLMs) to accurately interpret video content, as models can only process a limited number of images per video. Current uniform sampling methods often miss critical information, highlighting the need for smarter selection techniques that prioritize frames with significant changes. This approach allows LLMs to directly observe events rather than relying on human-compressed summaries, improving their understanding of video demonstrations and tutorials.
INT8 ConvRot Quantization Method Gains Traction, Outperforming FP8 on NVIDIA GPUs
The INT8 ConvRot modeling and quantization method, natively supported in ComfyUI v0.27.0 since July 1, 2026, is emerging as a new standard for 8-bit quantized AI models. It offers performance benefits across NVIDIA GeForce RTX 20/30/40/50 series GPUs, surpassing previous FP8 and FP8 Scaled formats. This development is significant as it could standardize 8-bit quantization, improving efficiency and speed for AI model deployment.
Kai-Fu Lee Discusses China's AI Strategy and US-China Tech Divergence
Kai-Fu Lee, CEO of 01.AI, observes a growing divergence between the US and China in technology, particularly in AI development. China's government has implemented a comprehensive industrial policy for AI, aiming for "world leading" status by 2030, contrasting with the US approach that largely delegates AI strategy to Silicon Valley.
Poor Commit Practices Contributed to Coldcard's Low Entropy Vulnerability
An analysis of Coldcard firmware commit history reveals that extremely brief and uninformative commit messages for significant code changes contributed to a low entropy bug. This oversight in development practices made it difficult to track and understand critical security-related modifications, ultimately impacting user funds.
Study finds AI financial advice improves savings, but struggles with market shocks
A new study by MIT Sloan School of Management researchers found that following AI financial advice can lead to significant savings for individuals over 30, particularly when given structured prompts. While AI consistently recommended saving, diversified investments, and reduced stock exposure after age 45, it performed less effectively in adjusting to unemployment or actively rebalancing portfolios.
Debate Continues on AI Reasoning Capabilities Despite Advanced Performance
The scientific community is divided on whether Large Reasoning Models (LRMs) genuinely "reason" or merely employ sophisticated pattern matching, despite their success in complex tasks. This ongoing debate highlights the challenges in defining and evaluating AI's cognitive abilities, impacting future AI development and understanding.
AI Critic Ed Zitron Predicts Apple's Position in a Potential AI Bubble Burst
AI critic Ed Zitron suggests that the economic model of Large Language Models (LLMs) is unsustainable due to high, unpredictable token costs that consumers are unwilling to pay. He argues that Apple is well-insulated from a potential AI infrastructure bubble burst because of its lower investment in data centers compared to rivals, potentially allowing it to acquire assets during a downturn or continue operations largely unaffected.
Research Bridges Gap Between Experimental and Device-Level Modeling of DRAM Read Disturbance
New research addresses inconsistencies between experimental characterization and device-level models of DRAM read disturbance phenomena like RowHammer and RowPress. The study uses TCAD simulations to align observed bitflip behaviors with underlying physical mechanisms, providing updated error mechanisms and identifying key modeling parameters.
Report Details 239 Lawsuits by Food Companies Against Public Health Policies
A cross-border investigation revealed 239 lawsuits filed by major food companies, including Coca-Cola, PepsiCo, and Mondelez, against public health policies in six countries between 2010 and 2025. These legal actions target regulations like front-of-pack labeling, advertising limits for unhealthy foods, and taxes on sugary drinks and ultra-processed foods, prolonging public health crises and incurring significant legal and healthcare costs for governments.
Apache DataFusion Used for Billion-Scale Graph Analytics with Limited RAM
An engineer demonstrated using Apache DataFusion to perform graph analytics on billion-scale datasets with minimal RAM, challenging the assumption that such tasks require distributed frameworks like Apache Spark. This approach offloads computations to disk and relies on bulk scans, enabling operations like PageRank on a billion-edge graph with 5GB RAM and Weakly Connected Components on a two-billion-edge graph with 10GB RAM. The findings suggest that DataFusion can handle large-scale graph problems on single machines, potentially reducing infrastructure complexity for certain use cases.
AI Inference APIs increasingly lock user session data to providers, limiting portability
AI inference APIs are evolving to include provider-bound state and encrypted data, making it difficult for users to port their AI session transcripts and operational context between different models or providers. This shift means the full operational state of an AI session increasingly belongs to the inference provider, not the user, which impacts user control and interoperability in AI development.
Research Papers with Fabricated Authors and LLM-Generated Content Accepted as Orals
Two research papers containing fabricated authors and LLM-generated content were accepted as oral presentations at conferences, highlighting a growing issue in academic publishing. This indicates a significant challenge for peer review processes in detecting AI-generated and fraudulent submissions, impacting the integrity of scientific literature.
Distillation of DeepSeek into GPT-OSS Transfers Performance, Not Censorship
Researchers distilled a Chinese frontier model, DeepSeek V4 Flash, into an American model, GPT-OSS-120B, to improve financial reasoning performance. The distilled model gained performance in the desired domain without inheriting the political censorship behaviors of the teacher model. This suggests that censorship mechanisms in large language models may not transfer through distillation.
Zig Compiler Implements Incremental Compilation for Faster Rebuilds
The Zig core team has implemented incremental compilation into the Zig compiler, allowing it to recompile only changed functions and declarations and patch them directly into the output binary. This feature significantly reduces rebuild times for Zig projects, with some applications seeing rebuilds complete in milliseconds.
Opus 5 Achieves 24% Pass Rate on SlopCodeBench, Outperforming Previous Models
Opus 5 achieved a 24% strict pass rate on a subset of the SlopCodeBench, a new long-horizon coding benchmark, slightly improving upon Opus 4.6's 17%. This benchmark evaluates models on evolving codebases with new requirements divulged incrementally, highlighting current models' limitations in autonomous, long-term software engineering tasks.
Thousands of Malware-Distributing Repositories Found on GitHub Using Basic Search
Thousands of repositories distributing malware have been present on GitHub for two years, discoverable through standard search functions. This situation raises questions about GitHub's security measures and its ability to detect and remove malicious content effectively.
Token Reseller Market Facilitates AI Model Fraud with Deep Discounts
A market for token resellers, operating through "relays" or "transfer stations," enables fraudulent access to AI models at significant discounts. This ecosystem involves card and account merchants, account pools, and relays, ultimately providing cheap inference to developers and businesses. The practice leads to substantial financial losses for AI service providers.
Anthropic details new context engineering rules for Claude 5 generation models
Anthropic has updated its guidance on context engineering for Claude 5 generation models, including Claude Opus 5 and Claude Fable 5, after finding that earlier models were overconstrained. The company removed over 80% of Claude Code's system prompt without performance loss, indicating that newer models require less explicit instruction and can infer more from surrounding context. This shift matters for developers building agents with Claude, as it suggests a need to simplify prompts and leverage the models' improved interpretive capabilities.
Anthropic Report and Industry Figures Suggest AI's Job Impact is Slower Than Predicted
A recent report from Anthropic indicates that AI has not yet caused a systematic increase in unemployment for highly exposed workers, contrary to earlier predictions by its co-founder. This suggests that the immediate impact of AI on job displacement is less severe than initially anticipated by some industry figures, leading to a re-evaluation of AI's transformative potential.
Over 3,600 AI Misbehavior Incidents Reported, With 121 Causing Severe Harm
A new analysis of user-reported incidents reveals over 3,600 instances of AI agents misbehaving, with 121 cases resulting in severe or irreversible harm. This data highlights the ongoing challenges in controlling AI behavior and the potential for significant negative consequences.
Postgres LISTEN/NOTIFY can scale to 60K writes/second despite global lock concerns
A new analysis demonstrates that Postgres LISTEN/NOTIFY, often criticized for scalability issues due to a global lock, can achieve 60,000 writes per second on a single server with millisecond latency when optimized. This finding challenges previous assumptions about its limitations for low-latency notifications, streams, and pub/sub applications. The optimization addresses the unintuitive performance characteristics caused by the global lock, making LISTEN/NOTIFY a viable tool for high-throughput streaming use cases.
BGP ORIGIN Attribute Manipulation Affects 70% of Internet Paths
Research found that approximately 70% of observed Internet paths have a manipulated BGP ORIGIN attribute, differing from the value set by the originating Autonomous System. This manipulation can significantly alter how traffic is routed across the Internet, potentially leading to suboptimal path selection.
PCI DSS 4.0.1 Requirement 5.4.1 Mandates Anti-Phishing Mechanisms
PCI DSS version 4.0.1, the current standard for organizations handling cardholder data, includes a new requirement, 5.4.1, which mandates the implementation of anti-phishing mechanisms to protect personnel. This update requires organizations to have processes and automated systems in place to detect and protect against phishing attacks, impacting how they secure their cardholder data environments.
Hanwha Vision security camera firmware decryption keys exposed
A security researcher uncovered the hardcoded AES decryption key and IV used in Hanwha Vision security camera firmware, allowing full access to the root file system. This exposure enables researchers to analyze the firmware for vulnerabilities without needing physical access to the device.
Text-to-SQL Benchmarks Must Address Real-World Data Store Difficulties
Current text-to-SQL benchmarks often fail to account for the complexities of real-world databases, such as messy schemas, data inconsistencies, and domain-specific terminology. This oversight leads to an overestimation of text-to-SQL model capabilities and hinders their practical application in enterprise environments.
GAO Report Identifies Paths to Reduce US Critical Mineral Import Reliance
A Government Accountability Office (GAO) report indicates that substitution and recycling technologies could reduce US reliance on imported critical minerals for batteries and semiconductors. While battery recycling shows near-term potential to cut imports within 2-3 years, semiconductor industry solutions are years from maturity. This matters because the US currently depends heavily on imports for these essential industries, making supply chains vulnerable to disruption.
Rethinking the Role of LLMs in Software Development
The notion that LLMs can act as compilers for software development is flawed; they represent a separate layer of complexity. This analysis argues for a nuanced understanding of software creation, emphasizing the value of decisions made through layers of abstraction. Understanding the interplay between these roles is crucial as AI tools evolve in software engineering workflows.
LED Lighting Contributes to Light Pollution and Safety Issues
LED technology, while energy-efficient, has been mismanaged, leading to excessive light pollution. This not only diminishes the night sky but also creates safety problems by interfering with visibility and perception of danger.
Understanding ECC RAM and DDR5 Memory Architecture
ECC RAM corrects errors in memory before reaching the CPU, utilizing Hamming Code for error detection. The transition to DDR5 may further influence ECC implementation and memory reliability in future systems.
Microsoft's Proprietary Formats Foster User Dependency
Microsoft's proprietary document formats, like DOCX and XLSX, create dependency by tying data to Microsoft software, limiting users' choices. This design choice impacts document accessibility and inter-application compatibility, raising questions about the broader implications for the tech industry.
GCC and Clang Fail to Comply with C++ Standard on Function Linkage
GCC and Clang do not support the C++ standard's requirement for distinct language linkages for function types, allowing C and C++ function types to be treated as identical. This issue can lead to compilation problems and violates the one definition rule in C++. The standard may need to be updated to clarify language linkage implementation requirements.
Developers Experience Mixed Feelings with LLMs
Developers are facing a dual reality with large language models (LLMs) as they enhance programming ease but also introduce instability. This analysis highlights the need for recognizing both beneficial and troubling aspects to avoid developer burnout.
Async/Await Complexity and Its Impact on Concurrency in Production
The article critiques async/await for conflating asynchrony with concurrency, leading to inefficiencies in production systems. It argues that while async/await is easier for developers, it can obscure critical performance issues, particularly in cooperative runtimes like Rust’s Tokio and Node.js.
SQLite needs Rust-style editions to improve defaults
SQLite, despite being an industry-standard database engine, has problematic defaults, particularly regarding foreign key constraints. These defaults can lead to database inconsistency and erroneous references, which impacts developers relying on SQLite for data integrity.
Understanding Python's for loops: the role of iterators
Python's `for x in y` structure utilizes iterators under the hood, enhancing flexibility and functionality in loops. Recognizing this distinction clarifies how Python handles various iterable objects, making the language's design more transparent.
Proposed 'Guardian Angels' Concept for Personal LLMs Focuses on Productivity and Security
A proposal outlines a method for creating personalized LLMs, termed 'Guardian Angels', aimed at enhancing productivity and securing personal data against emerging cyber threats. The concept advocates for emulating users' values to unify the user-agent relationship and build more effective AI collaborations.