Feed aggregator

CISA Warns of Exploited Gitea Vulnerability

Security Week - 41 min 27 sec ago

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Ask HN: Why are Claude models so verbose?

Hacker News - 44 min 16 sec ago

Hello! First time poster, longtime reader. I’m a professional software engineer at a startup with about 50 engineers. My primary languages are Ruby (Rails), TypeScript (React), and Go.

Of my colleagues, I’m one of the ones who tries to keep up with new AI models on every release. When there’s a new frontier or open-weight model, I’ll give it an honest try for a few days as my main driver and report back to my colleagues.

I’m a Cursor user at work and in my side projects. My go-to models are GPT-5.6 Sol on high/xhigh for planning, GPT-5.6 Sol on low/Grok 4.6 on medium for implementation, and the occasional Claude Fable 5 for complex, harder-to-understand and implement tasks. Many of my colleagues are exclusively Claude users and use Claude Code.

I’m not the first one to observe this but I feel like any time I use Fable, Opus, or Sonnet, they are extremely verbose. They make a ton of extra code comments, they ignore instructions, and they invent solutions for things solved by language built-ins or preinstalled libraries like Active Support and es-toolkit. I don’t see this happening with any other model at the same rate.

My question are: Why do we think the Claude models do this at a seemingly higher rate? And have people found any effective means to curb this behavior?

Comments URL: https://news.ycombinator.com/item?id=49444272

Points: 1

# Comments: 0

Categories: Hacker News

Xiaomi's Xring Series suggests more OEM's switching to in-house SoCs

Hacker News - 44 min 17 sec ago

Go to Google and Search for "Xiaomi Xring Nasengetu Tech" for the article.

Comments URL: https://news.ycombinator.com/item?id=49444271

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: LLM-powered webapp to build LLM-powered webapps

Hacker News - 49 min 18 sec ago

Hey all,

The goal is to earn on token margins for LLM calls when you build an AI-powered webapp. I proxy OpenAI and Anthropic calls so that when you deploy a site to a subdomain, your users token usage will be tracked. I charge 2x the token cost to the end user, where the webapp creator gets 80% of the profit and I get 20%. The idea is to ramp your revenue from simple AI apps directly with your popularity and real usage

I've built this over the last 3 years. The system behind it is kind of crazy: I use Abstract Syntax Trees and have the LLM write AST transformation code to implement code changes to files. I haven't benchmarked it in a while, but last time I did, it cost more in tokens but produced more targeted code changes (as compared to other agent harnesses). I wrote a blog post about this idea when I first built it: https://codeplusequalsai.com/static/blog/prompting_llms_to_m...

Your development project is run inside a docker container, and you can publish it to make it public and get users, and hopefully earn revenue. The real big goal is to make it easier to build small LLM webapps and not worry about revenue model: as users grow (and token costs grow), so does your revenue, proportionally.

Do please tell me what you think about the idea and my implementation!

Comments URL: https://news.ycombinator.com/item?id=49444234

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Propose and Dual-Control for DNS Changes

Hacker News - 52 min 30 sec ago

Hey, Hacker News. I just want to pick your brain for a feature we're working on.

I don't know whether you have seen this as a pain point, but when I work in a company, a lot of times I try to launch something and need to change a DNS record.

It's always a source of friction in the organization. I have to email someone or give a link to a co-worker. They have to figure out how to do it, but also whether I have a business justification for doing it.

So, when we built this platform, we're trying to come up with a feature that makes it easier. Someone can send you a proposal for DNS record updates. Our system will take the instructions, whether they come from a website, copy and paste, email, or Slack. Anything put in here becomes a proposal for a DNS change, and then someone can approve it.

In addition, we believe that for sensitive DNS record changes, it is good to treat them like a bank transfer.

So we are building a new feature for dual control, two-person control, or multi-person control of the approval flow, as well as an audit history of who proposed what, who approved something, the date and time, and what changes were made.

In addition, we also want to get feedback. I have observed the design slop of the AI that I use, ChatGPT.

There are multiple problems. This is the one-shot outcome, and then we massively simplified it to this. Basically, the summary is that it keeps using very bold and solid colors that are very attention-grabbing. The AI also tends to print out a lot of text that is noisy to the user.

AI doesn't really understand the structure of the system or the relationship between which components contain which conversations.

For example, this requirement for person approval probably fits best in the system where you approve or reject something, right? It is also very verbose. So it took us a little bit of iteration to improve the design.

I'm not a designer. I would love to get feedback about the design and whether the observation of AI slop is the same. Have you experienced the same thing?

There are other kinds of AI slop. That's it. Thank you.

(AI Disclosure: ChatGPT 5.6 Luna was used for grammar fix and spell check)

Comments URL: https://news.ycombinator.com/item?id=49444218

Points: 1

# Comments: 0

Categories: Hacker News

Tell HN: HN Was Down

Hacker News - 54 min 25 sec ago

Comments URL: https://news.ycombinator.com/item?id=49444203

Points: 2

# Comments: 0

Categories: Hacker News

Handwritten Blog

Hacker News - 56 min ago

Article URL: https://handwritten.danieljanus.pl/

Comments URL: https://news.ycombinator.com/item?id=49444191

Points: 3

# Comments: 1

Categories: Hacker News

"A" for "Average"

Hacker News - 57 min 4 sec ago
Categories: Hacker News

Pages