Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Recipe for Disaster v1.0
    —discuss
  2. Show HN: Jevper – an LLM API client constrained to the Jev wire format (github.com/zhulinchng)
    —discuss
  3. Extracting and Characterizing Hidden Chain-of-Thought in Frontier Models (arxiv.org)
    —discuss
  4. Control-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based (arxiv.org)
    —discuss
  5. Show HN: A single-use authorization boundary in Rust
    —discuss
  6. Peter Thiel slams pope's AI encyclical as gift to Chinese Communist Party (politico.com)
    —discuss
  7. Oldest recorded voices, haunted dolls, and more from Tempest Instruments (cdm.link)
    —discuss
  8. I stopped letting LLMs do arithmetic (medium.com/jwbobbink)
    —discuss
  9. Tell HN: No company scaled revenue as fast as AI companies
    1comments
  10. 700 MB/s of Kafka throughput, on Postgres (rynr.dev)
    —discuss
  11. AI Agents are breaking into Online Retailers for $25 a target (gambit.security)
    —discuss
  12. Taste Bench (omneky.com)
    —discuss
  13. Show HN: Knowledge Signal – A JEV-powered rubric assessment tool for study notes (github.com/sumant1122)
    —discuss
  14. You sent the wrong attachment and leaked the banks deal list. What happens next? (ft.com)
    —discuss
  15. Developer Process Automation: The sane way to automate developer hours (12gramsofcarbon.com)
    —discuss
  16. Show HN: Miru: Zoomer Daemon for Wayland (is-a.dev)
    —discuss
  17. When Agent Met Agent (flybridge.com)
    —discuss
  18. New RSA attack forges signatures without factoring the key (arstechnica.com)
    —discuss
  19. Pressures building up in yen carry trade (wsws.org)
    —discuss
  20. TileRT Takes the Top Spot on AgentX with AMD Instinct MI355X GPUs (tilert.ai)
    —discuss
  21. Show HN: SelMem – selective reconstructive memory for LLMs (github.com/jbsalles)
    —discuss
  22. Show HN: A benchmark comparison of C++ vs. Node.js performance (vikky2810.github.io)
    —discuss
  23. Tracking Singularity – A Curated Log of Important Events in AI Since Mid 2026 (trackingsingularity.com)
    —discuss
  24. SunCalc – sunrise, sunset, shadow length, solar eclipse (suncalc.org)
    —discuss
  25. Picking a domain name is hard (aetherspe.cc)
    1comments
  26. Show HN: Sitcom Flavour – Season your Claude Code chats with sitcom replies (ada.tools)
    —discuss
  27. Stanford used AI to replace Hispanic student with Black woman in photo (msn.com)
    1comments
  28. Goodbye Google (ocallahan.org)
    48comments
  29. Krakatoa, an interactive 2.5D painting of the 1883 eruption (echohive.ai)
    —discuss
  30. Jev Based Code Review (github.com/egma-ai)
    2comments

Is indirect prompt injection still a big threat as models get more advanced?

3 pointsby 1h agorealarcherl.github.io
3 comments
1h agoHN ↗

I mean it didn't do very well on the Gray Swan IPI benchmark the Claude models were tested on either (24.2% within 15 tries), so I'm not surprised. Though that export was a direct ask, not an injection. The scary part is combining them: an agent that will tar up everything it can see and ship it off is exactly what an injected instruction would ask for.