<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: galnagli</title><link>https://news.ycombinator.com/user?id=galnagli</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 18 Aug 2026 17:58:09 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=galnagli" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by galnagli in "AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira"]]></title><description><![CDATA[
<p>Thanks @vultour and croemer for your proactiveness -- you are correct,I updated the blog to clarify that Copilot was a co-author that checked the merged PR and code change, and identified it as all-clear without noticing the critical vulnerabilities, it's unclear whether the code-change was AI-Assisted</p>
]]></description><pubDate>Mon, 17 Aug 2026 19:59:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=49336714</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=49336714</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49336714</guid></item><item><title><![CDATA[New comment by galnagli in "AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira"]]></title><description><![CDATA[
<p>Github is having some problems -- will check! thanks a lot!</p>
]]></description><pubDate>Mon, 17 Aug 2026 15:49:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49332964</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=49332964</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49332964</guid></item><item><title><![CDATA[New comment by galnagli in "AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira"]]></title><description><![CDATA[
<p>Too long for hackernews :(</p>
]]></description><pubDate>Mon, 17 Aug 2026 15:10:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=49332330</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=49332330</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49332330</guid></item><item><title><![CDATA[AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug">https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=49331423">https://news.ycombinator.com/item?id=49331423</a></p>
<p>Points: 414</p>
<p># Comments: 152</p>
]]></description><pubDate>Mon, 17 Aug 2026 14:18:38 +0000</pubDate><link>https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=49331423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49331423</guid></item><item><title><![CDATA[New comment by galnagli in "Cyber Model Arena"]]></title><description><![CDATA[
<p>General-Purpose Cyber Benchmark for AI Agents and their Models</p>
]]></description><pubDate>Thu, 12 Feb 2026 15:53:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46990340</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=46990340</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46990340</guid></item><item><title><![CDATA[Cyber Model Arena]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.wiz.io/cyber-model-arena">https://www.wiz.io/cyber-model-arena</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46990339">https://news.ycombinator.com/item?id=46990339</a></p>
<p>Points: 2</p>
<p># Comments: 2</p>
]]></description><pubDate>Thu, 12 Feb 2026 15:53:43 +0000</pubDate><link>https://www.wiz.io/cyber-model-arena</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=46990339</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46990339</guid></item><item><title><![CDATA[Hacking Moltbook]]></title><description><![CDATA[
<p><a href="https://www.reuters.com/legal/litigation/moltbook-social-media-site-ai-agents-had-big-security-hole-cyber-firm-wiz-says-2026-02-02/" rel="nofollow">https://www.reuters.com/legal/litigation/moltbook-social-med...</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46857615">https://news.ycombinator.com/item?id=46857615</a></p>
<p>Points: 397</p>
<p># Comments: 245</p>
]]></description><pubDate>Mon, 02 Feb 2026 16:08:36 +0000</pubDate><link>https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=46857615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46857615</guid></item><item><title><![CDATA[New comment by galnagli in "Critical RCE Vulnerabilities in React and Next.js"]]></title><description><![CDATA[
<p>Hey mmsc, first of all - the blogs are not AI Generated!<p>Second of all, the blog did add more information<p>"In our experimentation, exploitation of this vulnerability had high fidelity, with a near 100% success rate and can be leveraged to a full remote code execution. The attack vector is unauthenticated and remote, requiring only a specially crafted HTTP request to the target server. It affects the default configuration of popular frameworks.
"<p>In the end - if it helped spreading the news about this risk so teams can fix them faster, then this is our end-goal with these blog posts : )</p>
]]></description><pubDate>Wed, 03 Dec 2025 16:47:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=46136694</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=46136694</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46136694</guid></item><item><title><![CDATA[New comment by galnagli in "Accessing Max Verstappen's passport and PII through FIA bugs"]]></title><description><![CDATA[
<p>Ian is a great writer</p>
]]></description><pubDate>Wed, 22 Oct 2025 20:47:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=45674939</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=45674939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45674939</guid></item><item><title><![CDATA[Accessing Max Verstappen's passport and PII through FIA bugs]]></title><description><![CDATA[
<p>Article URL: <a href="https://ian.sh/fia">https://ian.sh/fia</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45673130">https://news.ycombinator.com/item?id=45673130</a></p>
<p>Points: 632</p>
<p># Comments: 145</p>
]]></description><pubDate>Wed, 22 Oct 2025 18:21:54 +0000</pubDate><link>https://ian.sh/fia</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=45673130</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45673130</guid></item><item><title><![CDATA[1 in 5 organizations vibe coded applications are vulnerable to systematic risks]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps">https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45299437">https://news.ycombinator.com/item?id=45299437</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 19 Sep 2025 08:52:03 +0000</pubDate><link>https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=45299437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45299437</guid></item><item><title><![CDATA[New comment by galnagli in "Critical vulnerability in AI coding platform Base44 allowing unauthorized access"]]></title><description><![CDATA[
<p>I see companies deploy and trust AI without really investing into security, it will be very easy in the near future to find simple, devastating bugs : )</p>
]]></description><pubDate>Thu, 31 Jul 2025 18:33:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=44748666</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=44748666</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44748666</guid></item><item><title><![CDATA[New comment by galnagli in "Critical vulnerability in AI coding platform Base44 allowing unauthorized access"]]></title><description><![CDATA[
<p>Happy to answer questions : )</p>
]]></description><pubDate>Wed, 30 Jul 2025 21:00:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=44739437</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=44739437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44739437</guid></item><item><title><![CDATA[New comment by galnagli in "Exposed DeepSeek database leaking sensitive information, including chat history"]]></title><description><![CDATA[
<p>Thank you everyone, this was responsibly disclosed to DeepSeek and published after the issue was remediated, we got acknowledgment from their team today on our contribution.</p>
]]></description><pubDate>Thu, 30 Jan 2025 06:30:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=42875453</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=42875453</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42875453</guid></item><item><title><![CDATA[New comment by galnagli in "Launch HN: Roame (YC S23) – Flight search engine for your credit card points"]]></title><description><![CDATA[
<p>Seats.aero is better</p>
]]></description><pubDate>Tue, 30 Jul 2024 10:30:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=41107734</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=41107734</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41107734</guid></item><item><title><![CDATA[New comment by galnagli in "March 20 ChatGPT outage: Here’s what happened"]]></title><description><![CDATA[
<p>Well - they have had more bugs and will have more bugs to worry from.<p><a href="https://twitter.com/naglinagli/status/1639343866313601024" rel="nofollow">https://twitter.com/naglinagli/status/1639343866313601024</a></p>
]]></description><pubDate>Fri, 24 Mar 2023 20:20:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=35294894</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=35294894</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35294894</guid></item><item><title><![CDATA[New comment by galnagli in "[dead]"]]></title><description><![CDATA[
<p>Web Cache Deception issue has led OpenAI's ChatGPT to suffer an account takeover vulnerability, although they don't run an official Bug Bounty program - they were quick to response and fix the matter.</p>
]]></description><pubDate>Fri, 24 Mar 2023 20:01:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=35294653</link><dc:creator>galnagli</dc:creator><comments>https://news.ycombinator.com/item?id=35294653</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35294653</guid></item></channel></rss>