<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: bearsyankees</title><link>https://news.ycombinator.com/user?id=bearsyankees</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 29 Jul 2026 06:19:15 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=bearsyankees" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by bearsyankees in "OpenAI just open-sourced Codex Security"]]></title><description><![CDATA[
<p>yeah you mean because OAI is only whitebox? or expand on that a bit, haven't played around a ton w the oss codex sec</p>
]]></description><pubDate>Tue, 28 Jul 2026 21:33:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=49090217</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49090217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49090217</guid></item><item><title><![CDATA[New comment by bearsyankees in "OpenAI just open-sourced Codex Security"]]></title><description><![CDATA[
<p>would love it to see it h2h against <a href="https://github.com/usestrix/strix" rel="nofollow">https://github.com/usestrix/strix</a> (45k stars)</p>
]]></description><pubDate>Tue, 28 Jul 2026 21:23:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=49090091</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49090091</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49090091</guid></item><item><title><![CDATA[New comment by bearsyankees in "We found a 1 click account takeover (and webcam access) in Granola"]]></title><description><![CDATA[
<p>granola's disclosure: <a href="https://docs.granola.ai/help-center/policies/security-contributions/desktop-app-navigation-vulnerability" rel="nofollow">https://docs.granola.ai/help-center/policies/security-contri...</a></p>
]]></description><pubDate>Tue, 28 Jul 2026 19:56:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49089073</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49089073</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49089073</guid></item><item><title><![CDATA[Finding a 1 click account takeover (and webcam access) in Granola]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/granola">https://www.strix.ai/blog/granola</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49089047">https://news.ycombinator.com/item?id=49089047</a></p>
<p>Points: 6</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 28 Jul 2026 19:54:57 +0000</pubDate><link>https://www.strix.ai/blog/granola</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49089047</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49089047</guid></item><item><title><![CDATA[New comment by bearsyankees in "Granola Discloses a 1 Click Session Takeover of Its Notes App"]]></title><description><![CDATA[
<p><a href="https://www.strix.ai/blog/granola" rel="nofollow">https://www.strix.ai/blog/granola</a> -> technical writeup</p>
]]></description><pubDate>Wed, 22 Jul 2026 14:44:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49007653</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49007653</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49007653</guid></item><item><title><![CDATA[Granola Discloses a 1 Click Session Takeover of Its Notes App]]></title><description><![CDATA[
<p>Article URL: <a href="https://docs.granola.ai/help-center/policies/security-contributions/desktop-app-navigation-vulnerability">https://docs.granola.ai/help-center/policies/security-contributions/desktop-app-navigation-vulnerability</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49007641">https://news.ycombinator.com/item?id=49007641</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 22 Jul 2026 14:44:22 +0000</pubDate><link>https://docs.granola.ai/help-center/policies/security-contributions/desktop-app-navigation-vulnerability</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=49007641</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49007641</guid></item><item><title><![CDATA[One Click Account Takeover in Granola AI Notetaker]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/granola">https://www.strix.ai/blog/granola</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48993371">https://news.ycombinator.com/item?id=48993371</a></p>
<p>Points: 7</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 21 Jul 2026 15:14:16 +0000</pubDate><link>https://www.strix.ai/blog/granola</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48993371</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48993371</guid></item><item><title><![CDATA[CVE-2026-59208: Cross-Issuer Account Takeover in n8n]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/n8n-cross-issuer-account-takeover">https://www.strix.ai/blog/n8n-cross-issuer-account-takeover</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48921422">https://news.ycombinator.com/item?id=48921422</a></p>
<p>Points: 20</p>
<p># Comments: 10</p>
]]></description><pubDate>Wed, 15 Jul 2026 14:30:07 +0000</pubDate><link>https://www.strix.ai/blog/n8n-cross-issuer-account-takeover</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48921422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48921422</guid></item><item><title><![CDATA[New comment by bearsyankees in "Securing a DoD Contractor: Finding a Multi-Tenant Authorization Vulnerability"]]></title><description><![CDATA[
<p>oh apologies, thanks for the reminder</p>
]]></description><pubDate>Mon, 04 May 2026 19:10:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=48013493</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48013493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48013493</guid></item><item><title><![CDATA[New comment by bearsyankees in "U.S. military data left exposed at an a16z startup for 150 days"]]></title><description><![CDATA[
<p>appreciate the feedback!!</p>
]]></description><pubDate>Mon, 04 May 2026 18:31:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=48012872</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48012872</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48012872</guid></item><item><title><![CDATA[New comment by bearsyankees in "U.S. military data left exposed at an a16z startup for 150 days"]]></title><description><![CDATA[
<p><a href="https://x.com/strix_ai/status/2051361018450948511" rel="nofollow">https://x.com/strix_ai/status/2051361018450948511</a></p>
]]></description><pubDate>Mon, 04 May 2026 18:30:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=48012851</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48012851</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48012851</guid></item><item><title><![CDATA[New comment by bearsyankees in "Securing a DoD contractor: Finding a multi-tenant authorization vulnerability"]]></title><description><![CDATA[
<p>fixed now</p>
]]></description><pubDate>Mon, 04 May 2026 18:28:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48012830</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48012830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48012830</guid></item><item><title><![CDATA[New comment by bearsyankees in "Securing a DoD contractor: Finding a multi-tenant authorization vulnerability"]]></title><description><![CDATA[
<p>apologies, just a vc firm</p>
]]></description><pubDate>Mon, 04 May 2026 18:26:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=48012785</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48012785</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48012785</guid></item><item><title><![CDATA[Securing a DoD contractor: Finding a multi-tenant authorization vulnerability]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup">https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48012162">https://news.ycombinator.com/item?id=48012162</a></p>
<p>Points: 221</p>
<p># Comments: 101</p>
]]></description><pubDate>Mon, 04 May 2026 17:46:32 +0000</pubDate><link>https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=48012162</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48012162</guid></item><item><title><![CDATA[New comment by bearsyankees in "Ask HN: Who is hiring? (May 2026)"]]></title><description><![CDATA[
<p>Strix (strix.ai, <a href="https://github.com/usestrix/strix" rel="nofollow">https://github.com/usestrix/strix</a>)| Founding Engineer | NYC/SF<p>We built the largest open-source AI pentesting framework — 25k GitHub stars, 80k active users, 15B LLM tokens processed daily, 1,800 pentests run per day. Two of us right now. You'd be the third.<p>Looking for a founding-engineer engineer who's done 0→1 before and wants to own the architecture of something already at scale. You'll touch everything — infra, product, research tooling. Python/TypeScript stack, AI-native workflows, real security problems.<p>Email hiring@usestrix.com — tell us something you've built and why it was hard.</p>
]]></description><pubDate>Fri, 01 May 2026 16:56:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=47977083</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47977083</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47977083</guid></item><item><title><![CDATA[Context.ai seemingly cause of Vercel breach]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/jaimeblascob/status/2045960143209152981">https://twitter.com/jaimeblascob/status/2045960143209152981</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47827611">https://news.ycombinator.com/item?id=47827611</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 19 Apr 2026 21:01:37 +0000</pubDate><link>https://twitter.com/jaimeblascob/status/2045960143209152981</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47827611</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47827611</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead. Cal.com Just Learned the Wrong Lesson"]]></title><description><![CDATA[
<p><a href="https://x.com/steipete/status/2044423791405924562" rel="nofollow">https://x.com/steipete/status/2044423791405924562</a> very soon it seems...</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:26:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781387</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781387</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781387</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead"]]></title><description><![CDATA[
<p>I don't know if I fully agree with this -- how many people were actually self-hosting cal infra? I def could be wrong though</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:25:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781367</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781367</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781367</guid></item><item><title><![CDATA[New comment by bearsyankees in "Open Source Isn't Dead. Cal.com Just Learned the Wrong Lesson"]]></title><description><![CDATA[
<p>+1, at this point all companies need to be continuously testing their whole stack. The dumb scanners are now a thing of the past, the second your site goes live it will get slammed by the latest AI hackers</p>
]]></description><pubDate>Wed, 15 Apr 2026 16:24:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=47781347</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47781347</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47781347</guid></item><item><title><![CDATA[New comment by bearsyankees in "Cal.com is going closed source"]]></title><description><![CDATA[
<p>Think this is a bad, bad move...<p><a href="https://news.ycombinator.com/item?id=47780712">https://news.ycombinator.com/item?id=47780712</a></p>
]]></description><pubDate>Wed, 15 Apr 2026 15:50:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47780837</link><dc:creator>bearsyankees</dc:creator><comments>https://news.ycombinator.com/item?id=47780837</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47780837</guid></item></channel></rss>