Hacker Newsnew | past | comments | ask | show | jobs | submit | nizbit's commentslogin

I’m not a part of “We”


The honest headline is “Unhardened QEMU on an unpatched host with user-mode networking won’t contain a capable agent”.


Russia doesn’t think so.


Yes with an extra helping of emdashes!


Making calls across a trust boundary, what could go wrong?


It's Claude code talking to another Claude code. They're both already leaking your data to Anthropic in the first place.


Pretty much nothing with minimum viable guardrails (restricted shell into Container into MicroVM into VM + Firewall) which any dev knows how to setup, the fact that most don't is mostly about lazyness/recklessness.

Ready for the downvotes.


Smells like MCSE of the early oughts. Fun times.


Collision counts are absurd. CVE-2026-43739 has roughly twenty credited researchers; CVE-2026-43816 has nearly as many. And ai attribution getting credit.


One CVE even lists the same person twice!

CVE-2026-64691: Ruslan Dautov, Ruslan Dautov


> One CVE even lists the same person twice!

Not necessarily. Could be two persons sharing that name. See https://revstat.ine.pt/index.php/REVSTAT/article/view/382


How did you unearth such a remarkable find of 2 different faculty individuals named "Philipp Otto" collaborating on the same paper :) ?


One of them lists an anonymous person!

CVE-2026-43744: Mathis Mansière, an anonymous researcher


It reads as if "an anonymous researcher" is describing Mathis Mansière, which is quite humorous.


This reminds me of my favorite segment of the TV show Curb Your Enthusiasm: https://youtu.be/JqrJ4wGid4Y


Spell checker fixed a typo, it was originally "an Anonymous researcher" /s


Genius, that made my day!


It's Ted Danson.


Nah you pay a guy and you get your inspection sticker. This has always been the way.


Gods work, thank you!


Thanks DoD! While you’re at it let’s keep SCCM around for another 50 years! Woooo!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: