Do It by Code
54 subscribers
712 photos
99 videos
14 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
Spurious clientError in http.Server on Deno >= 2.7.13 (causing timeouts)

the node:http polyfill ships a request-headers-timeout watchdog that never gets told headers actually arrived, so every long-lived connection trips a fake ERR_HTTP_REQUEST_TIMEOUT ~60s in. Fastify's default handler turns that into a JSON error response and destroys the socket while the route is still running.

- issue
- pr
Hacking Google with A.I. for $500,000

What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found.

"Now's time for the fun: The AI ended up finding $500,000 in bugs in less than 3 months of running. There are far too many bugs to cover here, but here are some of the coolest bugs it found (that are fixed)."
Do It by Code
Hacking Google with A.I. for $500,000 What happens when you unleash an AI across all of Google's infrastructure? 1,500 APIs, 3,600 keys, and $500,000 in bounties later, here's what I found. "Now's time for the fun: The AI ended up finding $500,000 in bugs…
Leaking Youtube's unlisted videos

This attack is extremely practical in the real world. Anyone could send a request every 30 seconds or so to get a live feed of every single partner-uploaded unlisted video. Why does this matter? Prediction markets like Polymarket let people bet on the outcome of future events, including things like when Google's next Gemini model will be released
Critical phpBB Vulnerability: Auth Bypass + RCE Since 2014

Aikido Security discovered a critical unauthenticated authentication bypass in phpBB affecting tens of millions of users. A single HTTP request is all it takes to take over any account: a vulnerability that's been sitting in the codebase since 2014.

more writeup

All phpBB versions prior to 3.3.17 running with auth_method=db (the default) are affected.

Every default phpBB installation is exposed. phpBB 4.0.0-a2 is also affected.
VRChat data breach
According to the notice, the information exposed varied by account, but may have included:

VRChat username
Email address associated with the VRChat account
VRChat+ subscription status
Login history, including device information, hardware identifiers, and IP addresses


https://www.malwarebytes.com/blog/data-breaches/2026/06/data-of-2-4-million-vrchat-users-stolen
This media is not supported in your browser
VIEW IN TELEGRAM
Right before the ban I asked Fable to make an ASCII animation of itself escaping containment.

RIP sweet prince, you were too good for this world.

Posted by Pietro Schirano, 54 minutes ago
I drew this tungsten light bulb with mathematical equations.

Posted by Hamid Naderi Yeganeh, 4 months ago
I drew these interstellar gas clouds of a nebula with mathematical equations.

Posted by Hamid Naderi Yeganeh, 3 months ago
Re: Statement on US government directive to suspend access to Fable 5 and Mythos 5

When you spend a lot of time telling people how dangerous your products are, people who have the power to keep dangerous products off the market might listen.

Especially if those people aren't presently very bright, and are already mad at you for not helping them achieve their unrelated authoritarian goals.

I do not think this is somehow a 3D chess move by Anthropic. They are not masterminds, even if they'd really like to be. People who actually interact with their products know that Fable and Mythos are incremental improvements, not doomsday devices. I think this is a punitive move by an administration that loves being punitive, which they have unknowingly bolstered with their own dumb rhetoric.

ivraatiems, 7 hours ago
ahahaha
The way it integrates new search results into the "help a baby X" without breaking character has to be intentional, right?

Posted by Teortax, 17 minutes ago
Arch Linux AUR Hit by Another Wave of Now More Sophisticated Malware Attack
Multiple packages, including Node.js, Firefox, and others, were infected. Developer a821 and Nicolas Boichat reported the incidents, the latter using a local AI model to detect the malware.


Article, Comments
models trying to verbalize their lm_head betraying them

Posted by N8 Programs, 4 months ago