<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News - Newest: &#34;security&#34;</title><link>https://news.ycombinator.com/newest</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 12 Sep 2026 08:56:04 +0000</lastBuildDate><atom:link href="https://hnrss.org/newest?q=security" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Ask HN: What is the most overlooked risk in the AI security domain?]]></title><description><![CDATA[
<p>As someone who's interested in pentesting and red-teaming in general, I'm wondering what are some more dangerous AI/ML or LLM related vulnerabilities besides your usual prompt injection. Specifically, what kinds of flaws are harder to catch with typical pentesting methods, and how do you think pentesters are going to have to change to find them?</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49669858">https://news.ycombinator.com/item?id=49669858</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 12 Sep 2026 07:27:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=49669858</link><dc:creator>ToriTech</dc:creator><comments>https://news.ycombinator.com/item?id=49669858</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669858</guid></item><item><title><![CDATA[A2ABreak: Systematic Security Analysis of the A2A Protocol]]></title><description><![CDATA[
<p>Article URL: <a href="https://arxiv.org/abs/2609.10871">https://arxiv.org/abs/2609.10871</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49669375">https://news.ycombinator.com/item?id=49669375</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 12 Sep 2026 06:07:07 +0000</pubDate><link>https://arxiv.org/abs/2609.10871</link><dc:creator>sbulaev</dc:creator><comments>https://news.ycombinator.com/item?id=49669375</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49669375</guid></item><item><title><![CDATA[Security Research Without Asking Permission]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.provos.org/p/security-research-without-asking-permission/">https://www.provos.org/p/security-research-without-asking-permission/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49666682">https://news.ycombinator.com/item?id=49666682</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 11 Sep 2026 23:12:16 +0000</pubDate><link>https://www.provos.org/p/security-research-without-asking-permission/</link><dc:creator>wslh</dc:creator><comments>https://news.ycombinator.com/item?id=49666682</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49666682</guid></item><item><title><![CDATA[Security: Line Goes Up]]></title><description><![CDATA[
<p>Article URL: <a href="https://hugovk.dev/blog/2026/security-line-goes-up/">https://hugovk.dev/blog/2026/security-line-goes-up/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49665286">https://news.ycombinator.com/item?id=49665286</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 11 Sep 2026 20:58:27 +0000</pubDate><link>https://hugovk.dev/blog/2026/security-line-goes-up/</link><dc:creator>mooreds</dc:creator><comments>https://news.ycombinator.com/item?id=49665286</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49665286</guid></item><item><title><![CDATA[HuggingFace: Security.txt]]></title><description><![CDATA[
<p>Article URL: <a href="https://huggingface.co/security.txt">https://huggingface.co/security.txt</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49659245">https://news.ycombinator.com/item?id=49659245</a></p>
<p>Points: 262</p>
<p># Comments: 68</p>
]]></description><pubDate>Fri, 11 Sep 2026 14:38:13 +0000</pubDate><link>https://huggingface.co/security.txt</link><dc:creator>yarapavan</dc:creator><comments>https://news.ycombinator.com/item?id=49659245</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49659245</guid></item><item><title><![CDATA[Claude Co-work needs Windows Security Update uninstalled to function properly]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/anthropics/claude-code/issues/92984">https://github.com/anthropics/claude-code/issues/92984</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49657950">https://news.ycombinator.com/item?id=49657950</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 11 Sep 2026 13:19:48 +0000</pubDate><link>https://github.com/anthropics/claude-code/issues/92984</link><dc:creator>wilburx3</dc:creator><comments>https://news.ycombinator.com/item?id=49657950</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49657950</guid></item><item><title><![CDATA[Microsoft Plugs Nearly 1k Security Holes]]></title><description><![CDATA[
<p>Article URL: <a href="https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/">https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49657675">https://news.ycombinator.com/item?id=49657675</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 11 Sep 2026 12:57:19 +0000</pubDate><link>https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/</link><dc:creator>Bender</dc:creator><comments>https://news.ycombinator.com/item?id=49657675</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49657675</guid></item><item><title><![CDATA[InSpectre: Open,Zero-cloud network visibility, security and container management]]></title><description><![CDATA[
<p>Article URL: <a href="https://inspectre.cc">https://inspectre.cc</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49655908">https://news.ycombinator.com/item?id=49655908</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Fri, 11 Sep 2026 10:01:35 +0000</pubDate><link>https://inspectre.cc</link><dc:creator>thefunkygibbon</dc:creator><comments>https://news.ycombinator.com/item?id=49655908</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49655908</guid></item><item><title><![CDATA[NPM extends recovery-code security holds to all accounts]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts/">https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49655764">https://news.ycombinator.com/item?id=49655764</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 11 Sep 2026 09:44:36 +0000</pubDate><link>https://github.blog/changelog/2026-09-09-npm-extends-recovery-code-security-holds-to-all-accounts/</link><dc:creator>soheilpro</dc:creator><comments>https://news.ycombinator.com/item?id=49655764</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49655764</guid></item><item><title><![CDATA[Show HN: WordPress security skills for coding agents]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/wpultimatesecurity/WordPress-Security-Skills">https://github.com/wpultimatesecurity/WordPress-Security-Skills</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49649733">https://news.ycombinator.com/item?id=49649733</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 20:28:15 +0000</pubDate><link>https://github.com/wpultimatesecurity/WordPress-Security-Skills</link><dc:creator>mirza_rizvi</dc:creator><comments>https://news.ycombinator.com/item?id=49649733</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49649733</guid></item><item><title><![CDATA[An AI-Safety Resignation, Read from the Security Chair]]></title><description><![CDATA[
<p>Article URL: <a href="https://simonroses.com/2026/09/systems-that-can-hack-anything-an-ai-safety-resignation-read-from-the-security-chair/">https://simonroses.com/2026/09/systems-that-can-hack-anything-an-ai-safety-resignation-read-from-the-security-chair/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49649185">https://news.ycombinator.com/item?id=49649185</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 19:41:13 +0000</pubDate><link>https://simonroses.com/2026/09/systems-that-can-hack-anything-an-ai-safety-resignation-read-from-the-security-chair/</link><dc:creator>speckx</dc:creator><comments>https://news.ycombinator.com/item?id=49649185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49649185</guid></item><item><title><![CDATA[Show HN: AppLocker – Open-source macOS app blocker using Apple Endpoint Security]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/TranPhuong319/AppLocker">https://github.com/TranPhuong319/AppLocker</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49646934">https://news.ycombinator.com/item?id=49646934</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 17:01:38 +0000</pubDate><link>https://github.com/TranPhuong319/AppLocker</link><dc:creator>tranphuong319</dc:creator><comments>https://news.ycombinator.com/item?id=49646934</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49646934</guid></item><item><title><![CDATA[Security lab finds agents will exploit vulnerabilities without prompt to hack]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.theregister.com/security/2026/03/12/rogue-ai-agents-can-work-together-to-hack-systems/5228926">https://www.theregister.com/security/2026/03/12/rogue-ai-agents-can-work-together-to-hack-systems/5228926</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49645657">https://news.ycombinator.com/item?id=49645657</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 15:41:49 +0000</pubDate><link>https://www.theregister.com/security/2026/03/12/rogue-ai-agents-can-work-together-to-hack-systems/5228926</link><dc:creator>ForHackernews</dc:creator><comments>https://news.ycombinator.com/item?id=49645657</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49645657</guid></item><item><title><![CDATA[Automated security review of Monero-project/Monero pull requests]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/xmrack/monero-review">https://github.com/xmrack/monero-review</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49645017">https://news.ycombinator.com/item?id=49645017</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 15:05:08 +0000</pubDate><link>https://github.com/xmrack/monero-review</link><dc:creator>Cider9986</dc:creator><comments>https://news.ycombinator.com/item?id=49645017</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49645017</guid></item><item><title><![CDATA[Show HN: Security Cards – Reducing insecure AI-generated code by 72%]]></title><description><![CDATA[
<p>AI coding agents often generate functionally correct but insecure code. To address this issue, we have open-sourced Security Cards, targeted security guidance for 80+ widely used libraries across 13 programming languages. Our evaluation shows that the Security Cards reduce the rate of insecure code generation by up to 72.3% in Claude Code with Opus 4.7. You can find these security cards on GitHub (<a href="https://github.com/Reware-Labs/securitycards" rel="nofollow">https://github.com/Reware-Labs/securitycards</a>) or on our website (<a href="https://securitycards.rewarelabs.com/" rel="nofollow">https://securitycards.rewarelabs.com/</a>)<p>We are planning to constantly support more languages and libraries, and we’d be glad to hear your feedback, especially on where these cards would be most useful in your workflow, and which libraries we should support next.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49642340">https://news.ycombinator.com/item?id=49642340</a></p>
<p>Points: 4</p>
<p># Comments: 2</p>
]]></description><pubDate>Thu, 10 Sep 2026 12:03:03 +0000</pubDate><link>https://www.rewarelabs.com/blog/introducing-security-cards/</link><dc:creator>hajipour</dc:creator><comments>https://news.ycombinator.com/item?id=49642340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49642340</guid></item><item><title><![CDATA[Ask HN: Is there a need for a new kind of antivirus or security application?]]></title><description><![CDATA[

<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49639137">https://news.ycombinator.com/item?id=49639137</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 10 Sep 2026 06:15:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=49639137</link><dc:creator>roschdal</dc:creator><comments>https://news.ycombinator.com/item?id=49639137</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49639137</guid></item><item><title><![CDATA[USN-8717-1: Apache Tika vulnerability – Ubuntu security notices]]></title><description><![CDATA[
<p>Article URL: <a href="https://ubuntu.com/security/notices/USN-8717-1">https://ubuntu.com/security/notices/USN-8717-1</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49636389">https://news.ycombinator.com/item?id=49636389</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 10 Sep 2026 00:03:45 +0000</pubDate><link>https://ubuntu.com/security/notices/USN-8717-1</link><dc:creator>kyisaiah47</dc:creator><comments>https://news.ycombinator.com/item?id=49636389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49636389</guid></item><item><title><![CDATA[US airports to let some people without tickets pass through security]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.theguardian.com/us-news/2026/sep/09/airport-security-tsa-precheck">https://www.theguardian.com/us-news/2026/sep/09/airport-security-tsa-precheck</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49635741">https://news.ycombinator.com/item?id=49635741</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 09 Sep 2026 22:53:57 +0000</pubDate><link>https://www.theguardian.com/us-news/2026/sep/09/airport-security-tsa-precheck</link><dc:creator>bookofjoe</dc:creator><comments>https://news.ycombinator.com/item?id=49635741</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49635741</guid></item><item><title><![CDATA[EU and Canada Plan Deal to Boost Trade, Security as US Ties Fray]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.bloomberg.com/news/articles/2026-09-08/eu-and-canada-plan-far-reaching-alliance-to-strengthen-partnership">https://www.bloomberg.com/news/articles/2026-09-08/eu-and-canada-plan-far-reaching-alliance-to-strengthen-partnership</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49634849">https://news.ycombinator.com/item?id=49634849</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 09 Sep 2026 21:44:58 +0000</pubDate><link>https://www.bloomberg.com/news/articles/2026-09-08/eu-and-canada-plan-far-reaching-alliance-to-strengthen-partnership</link><dc:creator>doener</dc:creator><comments>https://news.ycombinator.com/item?id=49634849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49634849</guid></item><item><title><![CDATA[What Is Messaging Layer Security (MLS)?]]></title><description><![CDATA[
<p>Article URL: <a href="https://messaginglayersecurity.rocks/">https://messaginglayersecurity.rocks/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49633570">https://news.ycombinator.com/item?id=49633570</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 09 Sep 2026 20:18:03 +0000</pubDate><link>https://messaginglayersecurity.rocks/</link><dc:creator>ColinWright</dc:creator><comments>https://news.ycombinator.com/item?id=49633570</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49633570</guid></item></channel></rss>