Feed aggregator
Smart glasses under scrutiny as Norway seeks temporary ban
Article URL: https://apnews.com/article/norway-ai-glasses-ban-be20dbd949ce058023864b66219f9c2b
Comments URL: https://news.ycombinator.com/item?id=49965793
Points: 1
# Comments: 0
Altman: The world should accept some bad things happening for the benefits of AI
Article URL: https://www.politico.com/news/2026/10/04/sam-altman-decoded-interview-ai-01106217
Comments URL: https://news.ycombinator.com/item?id=49965786
Points: 2
# Comments: 0
Writing Extensions in Sliver C2
Article URL: https://hackerforce.io/blog/writing-extensions-in-sliver-c2/
Comments URL: https://news.ycombinator.com/item?id=49965778
Points: 1
# Comments: 0
Google pauses open source bug bounty program after rise in AI submissions
Companies like Google and Microsoft are find much bigger numbers of vulnerabilities in their own products as a result of AI. But the same technology is leading to public reporting programs becoming overwhelmed by the mass submission of speculative, duplicated, or hallucinated findings.
Now, Google’s announced it has temporarily stopped accepting submissions to its open source bug bounty program, OSS VRP.
“Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.”
We’ve seen this happen before. In early 2026, curl ended its HackerOne bounty program after low-quality, often AI-generated submissions overwhelmed its small security team.
Intel also launched a new bug bounty program on Intigriti but there are no longer bounties available, reportedly in order to stop a flood of AI generated reports.
Pros and consBounties can be an incentive for mass-submitting behavior when generative AI lowers the cost of producing polished-looking submissions. So, it’s understandable that companies want to limit the number of incoming reports.
If most automated submissions are invalid, a temporary pause prevents Google engineers and open-source maintainers from spending disproportionate time disproving reports rather than fixing real issues.
A pause gives Google the time and chance to introduce better controls, such as mandatory proof-of-concept requirements, evidence thresholds, and rate limits without letting the current queue keep growing.
On the other hand, it may discourage legitimate researchers and make it harder for them to submit actual issues they’ve found.
It is hard to draw a line of what you will accept, because an AI-assisted report can be valid, just like a low-quality report is not necessarily AI-generated.
And as companies like Google and Microsoft have proven, AI assisted vulnerability discovery can also support real vulnerability discovery if it is coupled with validation, deduplication, and proof.
What about the future?If we have learned anything it is that AI is not “breaking” vulnerability disclosure. It is exposing an older weakness in disclosure economics: the cost of filing a plausible report has fallen sharply, while the cost of proving or disproving it remains human-intensive.
The solution seems obvious. Let AI handle the submissions and only hand over those it can validate to the engineering teams. This will definitely frustrate some bug bounty hunters, because it will be like convincing a chatbot that you have a valid point and want to “talk to a human,” but hopefully it will bring down the number of less serious bug bounty hunters and create more room for those who know what they are doing.
Google has only promised an update in Q1 2027, so any redesign details would be speculative, but we do hope they find a way for responsible bug hunters to submit their findings.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
The Forget() Function: Erasing Data Without Breaking Your Audit Trail
Article URL: https://medium.com/@MirArshadTalpur/the-forget-function-erasing-data-without-breaking-your-audit-trail-0a5845ed85ee
Comments URL: https://news.ycombinator.com/item?id=49965753
Points: 1
# Comments: 0
From v0.7 to v0.8: How group commit changed Turso's tail latency
Article URL: https://turso.tech/blog/turso-group-commit
Comments URL: https://news.ycombinator.com/item?id=49965750
Points: 1
# Comments: 0
Mining Unwritten Data for AI's Edge
Article URL: https://www.wsj.com/cio-journal/mining-unwritten-data-for-ais-edge-52681e43
Comments URL: https://news.ycombinator.com/item?id=49965735
Points: 1
# Comments: 0
The Double Headed Stack Allocator
Article URL: https://blog.demofox.org/2026/10/03/the-double-headed-stack-allocator/
Comments URL: https://news.ycombinator.com/item?id=49965728
Points: 1
# Comments: 0
Are your AI evals measuring the right things?
Article URL: https://commandline.microsoft.com/structured-ai-evaluation-design-assert-vs-petri-bloom/
Comments URL: https://news.ycombinator.com/item?id=49965723
Points: 1
# Comments: 0
Cull Lumber at Menards
Article URL: https://dfarq.homeip.net/cull-lumber-at-menards/
Comments URL: https://news.ycombinator.com/item?id=49965716
Points: 1
# Comments: 0
L5 Cyber Cafe at Processing Community Day NYC
Article URL: https://notapipe.itch.io/l5/devlog/1691626/l5-cyber-cafe-at-processing-community-day-nyc
Comments URL: https://news.ycombinator.com/item?id=49965714
Points: 1
# Comments: 0
AgentLedger – a spend cap that refuses the call before it happens
Article URL: https://aiagentscity.com/
Comments URL: https://news.ycombinator.com/item?id=49965709
Points: 1
# Comments: 0
A Letter for You, Dad
Article URL: https://kangminsuk.com/blog/a-letter-for-you-dad/
Comments URL: https://news.ycombinator.com/item?id=49965698
Points: 1
# Comments: 0
Show HN: Cachetoast
Article URL: https://github.com/rhunterharris/cachetoast
Comments URL: https://news.ycombinator.com/item?id=49965697
Points: 1
# Comments: 0
Rivet - Shared development workflow for teams and their coding agents
Article URL: https://github.com/Agilno-Tech/rivet/
Comments URL: https://news.ycombinator.com/item?id=49965688
Points: 1
# Comments: 1
Commodified Intelligence
Article URL: https://herecomesthemoon.net/2026/09/commodified-intelligence/
Comments URL: https://news.ycombinator.com/item?id=49965665
Points: 2
# Comments: 1
North 2
Article URL: https://cohere.com/blog/introducing-north-2
Comments URL: https://news.ycombinator.com/item?id=49965650
Points: 1
# Comments: 0
When the pentester is a fleet of AI agents: inside an autonomous vuln-hunting
Article URL: https://huntback.io/blog/ai-agents-running-offensive-security
Comments URL: https://news.ycombinator.com/item?id=49965635
Points: 1
# Comments: 0
Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.
Proposed anti-Flock bills could spell trouble for license plate readers
Automated license plate readers (ALPRs) are cameras that photograph passing vehicles, read their number plates, and typically log the time, location, and vehicle details. On their own, the images might be used to find a stolen car or locate a suspect.
But lately there have been a lot of concerns raised about the way they are used. The main worry is caused by what happens when many cameras feed data into a shared, searchable network: it can create a detailed record of where ordinary people travel.
Some agencies have already taken it upon themselves to act on these concerns, as well as those around inaccuracy. Data errors can have serious consequences. At a recent Senate hearing, Florida resident Lindsey Isaacs described being arrested and held for 13 days after data from an AI-enabled plate-reader system incorrectly implicated her in a fatal car crash.
As a result of all this, US lawmakers from both major political parties have introduced proposals aimed at restricting automatic license plate reader networks.
Most of the reasons brought up are about Flock Safety, one of the largest suppliers of these systems in the United States, but they would apply more broadly to other ALPR vendors as well.
Flock says it deploys only 120,000 cameras operating across the country, while a researcher cited by the Senate described a much larger network of connected devices and cameras. The exact size may be disputed, but the central concern is clear: Data from a camera in one location can potentially be searched by an agency elsewhere.
Two different approachesReportedly, there are two different proposed laws in the making, while Flock says it supports a legal framework for license-plate readers and argues that the technology can improve public safety when it is used with strong oversight and accountability.
The first proposal, the Stop Flock Abuse Act, doesn’t aim to banish ALPR systems outright, it would create rules for how government agencies and vendors can use them.
Among other measures, the bill would require written approval and a record for every search, regular supervisor audits, encryption, and deletion of most vehicle-location data after ten days. It would also prohibit sharing or selling the data to non-governmental third parties, prevent ALPR networks from incorporating facial-recognition technology, and require data to stay in the US.
A second proposal, the Ban Flock Act, takes a much harder line. It would prohibit US federal agencies from using ALPRs or accessing data they collect. It would also withhold federal grant money from state and local governments that use ALPR systems and allow people to sue the federal government if their rights are violated through ALPR deployment.
Both bills are proposals, not enacted laws. In the US system, each would need to pass both the House of Representatives and the Senate in matching form, then be signed by the President.
Going forwardThere is no guarantee either bill will receive a vote, let alone become law. But their introduction shows that ALPR technology is moving from a local procurement issue to a national privacy and civil-liberties debate.
License plate data may seem less sensitive than phone-location data, but a long enough record can reveal a person’s routines, relationships, medical visits, religious activity, or attendance at protests. The debate is therefore not just about cameras on streets to fight crime and find criminals, it is about whether governments and private vendors should be able to build searchable records of everyday movement.
So for consumers, the key question is not only whether a camera is installed on a street or near a business. It is also how long the resulting data is retained, who can search it, whether those searches are logged and reviewed, whether the information can be shared beyond the original agency, and what recourse exists when the system is wrong or abused.
Your name, address, and phone number may already be for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
