Live data from Hacker News

Incident CVE-2026-LGTM

nesbitt.io

101–108 of 108 posts

Re: Incident CVE-2026-LGTM

#102
post #7
post #3

This incident report is WILD The incident was resolved when the attacker’s autonomous agent read a file it shouldn’t have, which is also how the incident started.

PSA this is satire ;) (if you have to say it, that’s how you know it’s good)

oh this is AMAZING, then!

Re: Incident CVE-2026-LGTM

#103
post #16

Earlier quoted context omitted.

> (if you have to say it, that’s how you know it’s good) Pet peeve, but no, it's the exact opposite. Good satire is immediately obvious; nobody had to ask whether Jonathan Swift was actually serious about solving poverty in Ireland by having the poor sell their children for meat to the rich. Subtle satire is bad satire by definition; if you have to be told that it's satire, that means it has completely failed to do i…

Are you saying all satire should target the lowest common intelligence?

[dead]

Re: Incident CVE-2026-LGTM

#106
post #48
post #30

Brought to you by the people who've been told repeatedly since mid 90s not to glue SQL strings together.

It's funny that as the most popular programming languages FINALLY got smart injection-safe SQL strings (js template literals etc), we're right back to square one with AI over the top that can't tell the difference between trusted and untrusted content. Funny and sad.

A year ago, I made a big stink with the security people at my company about how we were going to get fucked due to prompt injection because we did not have a robust model for isolating contexts with untrusted information from agents who are empowered to take action.

I was right, and that was good to do, but the reality is the modern models are very good at resisting prompt injection. The types of broad exploits we expected to see never materialized because the models improved faster than expected.

It can still happen, there are ways to manipulate them and it’s still vital to have a good security boundary, but generally when I see someone really worried about prompt injection I take it to the sign that they have not been paying attention

Re: Incident CVE-2026-LGTM

#108
post #94
post #61

Earlier quoted context omitted.

Just below the title are the tags "package-managers security satire ai"

It's fascinating how someone can say that they "could not rule out it being real until like 30% in" and then when I point out that they could , since it says so at the top, they just dismiss that and declare that they don't read it, rather than consider that it's in the "pro" column for paying attention to such things. (And tags are very different in purpose from banner ads, so not reading the latter is no reason not…

The pathetic bad faith whining in response is hilarious.
Post reply on HN