Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    87comments
  2. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    166comments
  3. Saving another 100TB of RAM(cloudflare.com ↗)
    29comments
  4. Cloudflare Quick Tunnels(cloudflare.com ↗)
    214comments
  5. Xcode 27.1 Beta Release Notes(developer.apple.com ↗)
    54comments
  6. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    10comments
  7. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    41comments
  8. How to Write with an LLM(sockpuppet.org ↗)
    235comments
  9. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    70comments
  10. Cyclomatic Complexity in C#(ndepend.com ↗)
    3comments
  11. OpenJev(openjev.com ↗)
    234comments
  12. The Implications of Linguistic Illegibility for LLM Security(arxiv.org ↗)
    14comments
  13. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    29comments
  14. Two parallel neural ectoderm progenitors contribute to the developing brain(newscientist.com ↗)
    49comments
  15. A search-and-inference database from scratch in pure Zig(antfly.io ↗)
    14comments
  16. From Geometry to Algebra and Back Again: 4000 Years of Papers (2023) [video](youtube.com ↗)
    discuss
  17. C++26: Trivial infinite loops are no longer undefined behaviour(sandordargo.com ↗)
    160comments
  18. How SpaceX streamlined the Raptor engine(construction-physics.com ↗)
    19comments
  19. Size-Specialized Memory Allocation(go.dev ↗)
    discuss
  20. Minimal Phone 2(minimalcompany.com ↗)
    138comments
  21. I vibed a proof of Conway's conjecture(overreacted.io ↗)
    172comments
  22. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    88comments
  23. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    12comments
  24. Korea raises data breach fines to 10% of revenue(koreajoongangdaily.com ↗)
    59comments
  25. US Military had close call after using AI for hallucinated intelligence report(cnn.com ↗)
    262comments
  26. Border agents can search cellphones without a warrant or reasonable suspicion(lawandcrime.com ↗)
    121comments
  27. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss
  28. Show HN: Ax-check.com – Can agents use your product?(ax-check.com ↗)
    25comments
  29. Mathematicians Build Long-Awaited Graph Sandwich(quantamagazine.org ↗)
    15comments
  30. Show HN: Scry, programmable internet search w/ congestion pricing(scry.io ↗)
    16comments

HEIF Heist: image parser RCE exploit

9 pointsby 8h agoheif-heist.com
5 comments
6h agoHN ↗

The one thing you'd expect on a website like this: how the exploit works, is missing.

The entire thing feels like marketing.

6h agoHN ↗

I mean, they kind of do? I assume they're hesitant to write a how-to on how to tailor the exploit image:

These are not out-of-the-box exploits. Exploitation requires fingerprinting the target version and tailoring the payload image(s). Some of our RCE attempts landed only after thousands of image uploads. That said, an AI agentic approach with a frontier model like GPT-5.6 Sol cut exploit development time down to roughly 1 to 3 days from initial probe to remote RCE. A motivated attacker can convert a vulnerable upload endpoint into RCE or an info leak.

6h agoHN ↗

I was under the impression the underlying issue has been patched. If it hasn't, this page and their initial blog post seem irresponsible. If it has indeed been patched why not provide a detailed write up?

5h agoHN ↗

Is this the new way to go viral ? Registering a domain and vibecode the content

4h agoHN ↗

Perhaps this is the exploit chain (they mention libheif at the start of their exploit chain)

  https://www.hacktron.ai/blog/hacking-openai

and HN discussion

  https://news.ycombinator.com/item?id=49749656