<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: bearsyankees</title><link>https://news.ycombinator.com/user?id=bearsyankees</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 01 May 2026 23:57:53 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=bearsyankees" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by bearsyankees in "Ask HN: Who is hiring? (May 2026)"]]></title><description><![CDATA[
<p>Strix (strix.ai, <a href="https://github.com/usestrix/strix" rel="nofollow">https://github.com/usestrix/strix</a>)| Founding Engineer | NYC/SF<p>We built the largest open-source AI pentesting framework — 25k GitHub stars, 80k active users, 15B LLM tokens processed daily, 1,800 pentests run per day. Two of us right now. You'd be the third.<p>Looking for a founding-engineer engineer who's done 0→1 before and wants to own the architecture of something already at scale. You'll touch everything — infra, product, research tooling. Python/TypeScript stack, AI-native workflows, real security problems.<p>Email hiring@usestrix.com — tell us something you've built and why it was hard.</p>
]]></description><pubDate>Fri, 01 May 2026 16:56:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47977083</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47977083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47977083</guid></item><item><title><![CDATA[Context.ai seemingly cause of Vercel breach]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/jaimeblascob/status/2045960143209152981">https://twitter.com/jaimeblascob/status/2045960143209152981</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47827611">https://news.ycombinator.com/item?id=47827611</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 19 Apr 2026 21:01:37 +0000</pubDate><link>https://twitter.com/jaimeblascob/status/2045960143209152981</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47827611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47827611</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead. Cal.com Just Learned the Wrong Lesson"]]></title><description><![CDATA[
<p><a href="https://x.com/steipete/status/2044423791405924562" rel="nofollow">https://x.com/steipete/status/2044423791405924562</a> very soon it seems...</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:26:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781387</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781387</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781387</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead"]]></title><description><![CDATA[
<p>I don't know if I fully agree with this -- how many people were actually self-hosting cal infra? I def could be wrong though</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:25:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781367</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781367</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781367</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead. Cal.com Just Learned the Wrong Lesson"]]></title><description><![CDATA[
<p>+1, at this point all companies need to be continuously testing their whole stack. The dumb scanners are now a thing of the past, the second your site goes live it will get slammed by the latest AI hackers</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:24:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781347</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781347</guid></item><item><title><![CDATA[New comment by bearsyankees in "Cal.com is going closed source"]]></title><description><![CDATA[
<p>Think this is a bad, bad move...<p><a href="https://news.ycombinator.com/item?id=47780712">https://news.ycombinator.com/item?id=47780712</a></p>
]]></description><pubDate>Wed, 15 Apr 2026 15:50:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780837</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47780837</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780837</guid></item><item><title><![CDATA[Open Source Isn't Dead]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/cal-com-is-closing-its-code-due-to-ai-threats">https://www.strix.ai/blog/cal-com-is-closing-its-code-due-to-ai-threats</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47780712">https://news.ycombinator.com/item?id=47780712</a></p>
<p>Points: 356</p>
<p># Comments: 186</p>
]]></description><pubDate>Wed, 15 Apr 2026 15:43:37 +0000</pubDate><link>https://www.strix.ai/blog/cal-com-is-closing-its-code-due-to-ai-threats</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47780712</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780712</guid></item><item><title><![CDATA[Show HN: Greptile for Security (open source)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/pentesting-every-pull-request">https://www.strix.ai/blog/pentesting-every-pull-request</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47771386">https://news.ycombinator.com/item?id=47771386</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 14 Apr 2026 20:54:36 +0000</pubDate><link>https://www.strix.ai/blog/pentesting-every-pull-request</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47771386</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47771386</guid></item><item><title><![CDATA[We love open source: finding a critical auth bypass in etcd (CVE-2026-33413)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass">https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47755711">https://news.ycombinator.com/item?id=47755711</a></p>
<p>Points: 4</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 13 Apr 2026 18:01:00 +0000</pubDate><link>https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47755711</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47755711</guid></item><item><title><![CDATA[What Now (and What's Next)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/your-first-visitors-arent-users-theyre-bots">https://www.strix.ai/blog/your-first-visitors-arent-users-theyre-bots</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47754754">https://news.ycombinator.com/item?id=47754754</a></p>
<p>Points: 11</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 13 Apr 2026 16:48:39 +0000</pubDate><link>https://www.strix.ai/blog/your-first-visitors-arent-users-theyre-bots</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47754754</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47754754</guid></item><item><title><![CDATA[Yale senior hacks United, gets 2.6M miles]]></title><description><![CDATA[
<p>Article URL: <a href="https://yaledailynews.com/articles/hacking-helpfully-yale-senior-co-founds-a-startup-and-wins-rewards">https://yaledailynews.com/articles/hacking-helpfully-yale-senior-co-founds-a-startup-and-wins-rewards</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47662379">https://news.ycombinator.com/item?id=47662379</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 06 Apr 2026 15:42:46 +0000</pubDate><link>https://yaledailynews.com/articles/hacking-helpfully-yale-senior-co-founds-a-startup-and-wins-rewards</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47662379</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47662379</guid></item><item><title><![CDATA[CVE-2026-33413 found in ETCD by open source AI agent (strix.ai), 8.8 CVSS]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.wiz.io/vulnerability-database/cve/cve-2026-33413">https://www.wiz.io/vulnerability-database/cve/cve-2026-33413</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47504424">https://news.ycombinator.com/item?id=47504424</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 24 Mar 2026 15:47:35 +0000</pubDate><link>https://www.wiz.io/vulnerability-database/cve/cve-2026-33413</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47504424</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47504424</guid></item><item><title><![CDATA[Caido partners with Strix for the best of both worlds in AI penstesting]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/partnering-with-caido">https://www.strix.ai/blog/partnering-with-caido</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47415431">https://news.ycombinator.com/item?id=47415431</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 17 Mar 2026 17:06:23 +0000</pubDate><link>https://www.strix.ai/blog/partnering-with-caido</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47415431</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47415431</guid></item><item><title><![CDATA[First Impressions on Open-Source Claude Security (Strix)]]></title><description><![CDATA[
<p>Article URL: <a href="https://theartificialq.github.io/2026/02/28/strix-first-impressions.html">https://theartificialq.github.io/2026/02/28/strix-first-impressions.html</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47234248">https://news.ycombinator.com/item?id=47234248</a></p>
<p>Points: 8</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 03 Mar 2026 15:54:47 +0000</pubDate><link>https://theartificialq.github.io/2026/02/28/strix-first-impressions.html</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47234248</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47234248</guid></item><item><title><![CDATA[Strix Is an Open-Source Claude Code Security]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/">https://www.strix.ai/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47125130">https://news.ycombinator.com/item?id=47125130</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 23 Feb 2026 17:05:54 +0000</pubDate><link>https://www.strix.ai/</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47125130</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47125130</guid></item><item><title><![CDATA[Finding a Cross-Tenant Vulnerability in GCP's Apigee]]></title><description><![CDATA[
<p>Article URL: <a href="https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/">https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46888423">https://news.ycombinator.com/item?id=46888423</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 04 Feb 2026 17:08:12 +0000</pubDate><link>https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=46888423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46888423</guid></item><item><title><![CDATA[Reverse Engineering US Airline's PNR System and Accessing All Reservations]]></title><description><![CDATA[
<p>Article URL: <a href="https://alexschapiro.com/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability">https://alexschapiro.com/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46328992">https://news.ycombinator.com/item?id=46328992</a></p>
<p>Points: 134</p>
<p># Comments: 63</p>
]]></description><pubDate>Fri, 19 Dec 2025 18:15:17 +0000</pubDate><link>https://alexschapiro.com/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=46328992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46328992</guid></item><item><title><![CDATA[Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files]]></title><description><![CDATA[
<p>Article URL: <a href="https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k">https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46137514">https://news.ycombinator.com/item?id=46137514</a></p>
<p>Points: 821</p>
<p># Comments: 288</p>
]]></description><pubDate>Wed, 03 Dec 2025 17:44:33 +0000</pubDate><link>https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=46137514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46137514</guid></item><item><title><![CDATA[Pwning OpenAI Atlas Through Exposed Browser Internals]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.hacktron.ai/blog/hacking-openai-atlas-browser">https://www.hacktron.ai/blog/hacking-openai-atlas-browser</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46124637">https://news.ycombinator.com/item?id=46124637</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 02 Dec 2025 18:31:57 +0000</pubDate><link>https://www.hacktron.ai/blog/hacking-openai-atlas-browser</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=46124637</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46124637</guid></item><item><title><![CDATA[Low PNR Entropy: I accessed all airline bookings via simple math]]></title><description><![CDATA[
<p>Article URL: <a href="https://alexschapiro.com/blog/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability">https://alexschapiro.com/blog/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46109876">https://news.ycombinator.com/item?id=46109876</a></p>
<p>Points: 4</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 01 Dec 2025 17:06:51 +0000</pubDate><link>https://alexschapiro.com/blog/security/vulnerability/2025/11/20/avelo-airline-reservation-api-vulnerability</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=46109876</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46109876</guid></item></channel></rss>