Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    427comments
  2. Claude Opus 5.5(anthropic.com)
    648comments
  3. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    339comments
  4. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    45comments
  5. SAML: A Fractal of Bad Design(trailofbits.com)
    22comments
  6. Obscura: The first VPN that can't log your activity(obscura.com)
    38comments
  7. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    49comments
  8. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    54comments
  9. Unreal Agent(unreallabs.ai)
    38comments
  10. What California is learning from solar panels built over irrigation canals(kqed.org)
    8comments
  11. Native apps written in TypeScript and CSS(github.com/geastack)
    6comments
  12. Explaining to business people why building software is still hard(manager.dev)
    34comments
  13. Did OpenAI solve the wrong Navier-Stokes problem?(scientificamerican.com)
    8comments
  14. An update on how we confirm your age group on Discord(discord.com)
    6comments
  15. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    166comments
  16. MUNI Heritage Weekend in San Francisco(lawrence.lu)
    30comments
  17. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    4comments
  18. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    1comments
  19. Markdown in /src(htmx.org)
    12comments
  20. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    19comments
  21. Overreliance on AI contributed to missile strike on Iran school – Pentagon(bloomberg.com)
    114comments
  22. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    12comments
  23. Launch HN: Coverage Cat (YC S22) – Umbrella insurance via your personal agent(coveragecat.com)
    19comments
  24. George Lucas Returns to Earth, Bearing Gifts(commonedge.org)
    15comments
  25. The JavaScript Midlife Crisis(maroun-baydoun.com)
    4comments
  26. A Faster Shortest Path Algorithm(vals.ai)
    4comments
  27. There's a high chance of devices being sold with GrapheneOS preinstalled in 2027(grapheneos.social)
    86comments
  28. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    385comments
  29. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    40comments
  30. Writing Rust code that's fast by asking agents to make the code faster(minimaxir.com)
    46comments

'We hacked the FBI:' Hackers say they have data on all FBI employees

79 pointsby 3h ago404media.co
42 comments
2h agoHN ↗

Im sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this

25m agoHN ↗

If the claim is true, I'd expect them to have used either those models or Grok or similar.

Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.

2h agoHN ↗

Thats a major attack on the US.

If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?

18m agoHN ↗

Is it, though?

If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.

3m agoHN ↗

Uh yeah, it dangerous. Public data brokerage doesn't identify FBI agents in a master roster?

Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.

Hopefully there was some forsight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.

17m agoHN ↗

In general, most governments have standard operational policies that mitigate such issues (ISO 15408.) =3

11m agoHN ↗

ISO and ICC start with the same letter, just saying...

7m agoHN ↗

The International Cricket Council does have very strict rules. lol =3

1h agoHN ↗

So they're getting access to a year's worth of free credit reporting for the inconvenience?

1h agoHN ↗

Well that's a big one.

Perhaps firing expertise and hiring incompetents wasn't a good idea.

52m agoHN ↗

There's incompetence in every major company including Oracle. PeopleSoft isn't known for being the most modern or secure thing out there. Less reliance on 3rd party software like this will be a good thing going forward.

25m agoHN ↗

That's assuming that the result of this will be to switch away from PeopleSoft.

21m agoHN ↗

I think enterprise software in this vein used to have a quasi-monopoly due to the sheer work required to build software of its size (not enough engineers exist in the government to do so), and the difficulty for competitors to enter regulated markets and so pretty much 1-2 options to choose from.

AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.

11m agoHN ↗

Enterprise software is complicated mostly because of number of customers it can support.

Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”

There are so many counter examples.

4m agoHN ↗

Considering how bad most enterprise software is, I assumed the only real relevance was if the sales team ponied up some lavish perks to the right VP who only has to sign checks and never actually interact with the software.

4m agoHN ↗

Not even the FBI has hostage negotiators good enough to get you out of an Oracle contract.

41m agoHN ↗

Do you think this is a consequence of the seemingly quarterly RIFs at Oracle? Is it that offshoring wasn’t such a good idea?

27m agoHN ↗

The irony, of course, is that this will likely have a negative impact upon Oracle's reputation, which will have a negative impact upon its value, which will then be resolved with more RIFs.

It's okay. Larry got another island.

29m agoHN ↗

Lets hope the Epstein files see the light of day, thanks to AI...

14m agoHN ↗

I always assumed DOGE + Ka$h would create an impenetrable fortress of strength; a beacon on the hill of brilliance and security.

1h agoHN ↗

TLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)

28m agoHN ↗

PeopleSoft 0-day.

Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.

23m agoHN ↗

It doesn't do nothing. It does make things somewhat harder to attack.

There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.

19m agoHN ↗

The attackers exfil'd 3TB of data, which obviously included PII, from AWS servers. They should've had DLP, active monitoring, countermeasures, using a security vendor (you can set this up for AWS services using CloudTrail, CloudWatch Logs, etc). You're supposed to have that for sensitive government or military work, and it should have (at least) caught that much traffic going to a rando external IP, blocked and flagged.

If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).

13m agoHN ↗

I’m skeptical that multiple terabytes of data were exfiltrated quietly. I’m struggling to see this as anything other than a bluff.

5m agoHN ↗

I'm less skeptical after seeing it happen to IDScan and terrabytes of government-issued IDs being exfiltrated quietly.

Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.

26m agoHN ↗

It means when the FBI builds a case against you make sure your lawyer hires a competent forensic expert. I've seen and heard "expert" testimonies in some court cases that make me angry. There's people using tools that digitally "enhance" small images, and that gets presented as evidence in court. It bewilders me how adding pixels to an image is evidence.

47m agoHN ↗

Wow, that is bold. I wonder if they'll get away with it because incompetent leadership has decimated the US's capabilities? This certainly doesn't bode well for the US's odds against its nation-state rivals.

41m agoHN ↗

Is their name a reference to pokemon? Or to the meme that the FBI/CIA glows through the screen?

22m agoHN ↗

They've been on an streak for over 6 years now, check out their wikipedia page.

21m agoHN ↗

You're thinking of "glowie", "shiny" is def a Pokémon thing.

29m agoHN ↗

...and this is how the FBI makes you a higher priority target, and you wind up caught.

27m agoHN ↗

US keeps arresting and charging people from this group for well over 6 years now, and this happens in 2026. They don't sound very scared.

13m agoHN ↗

There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…

12m agoHN ↗

Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.

11m agoHN ↗

they have been on an absolute roll for quite awhile now.

9m agoHN ↗

Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.

5m agoHN ↗

So, what are the odds this was done with an open-weight LLM?

5m agoHN ↗

That feels like publicly announcing that you want to be in a lot of trouble.