No. 391st of 5 editions that day← Earlier Later →
ACM goes open, TVs go surveillance, and OpenAI ships another Codex while security researchers pwn everyone via SVG files
- ACM: All publications open access from 2026, authors keep their IP
- Supply chain attack: 16-year-old pwns Discord, X, Vercel via Mintlify SVG exploit
- Texas: Suing Samsung, Sony, LG for taking screenshots every 500ms
- GPT-5.2-Codex: Now with cybersecurity features and actual Windows support
- Firefox: Adding an AI kill switch for the paranoid among us
| No. | Story | Pts | Cmts | Tags |
|---|---|---|---|---|
| 1 | Beginning January 2026, all ACM publications will be made open access :academia:open-access | 1,287 | 142 | publishing |
| 2 | We pwned X, Vercel, Cursor, and Discord through a supply-chain attack :security:supply-chain:xss:bug-bounty: | 560 | 217 | |
| 3 | Texas is suing all of the big TV makers for spying on what you watch | 469 | 250 | privacy surveillance legal |
| 4 | GPT-5.2-Codex | 352 | 205 | ai openai coding |
| 5 | Firefox will have an option to disable all AI features | 257 | 226 | firefox ai privacy |
1Beginning January 2026, all ACM publications will be made open access :academia:open-access ¶
1,287 points142 commentsHN 46313991by Kerrick
ACM is going fully open access starting January 2026. Authors will retain intellectual property rights, all research will be freely accessible worldwide, and the model shifts from subscriber-pays to author-pays with APCs of $1450 (with discounts for lower-income countries).
ACM 将于 2026 年 1 月起全面开放获取。作者将保留知识产权,所有研究将在全球免费访问,模式从订阅付费转为作者付费,APC 为 1450 美元。
ACM は 2026 年 1 月から完全オープンアクセスに移行。著者は知的財産権を保持し、全ての研究は世界中で無料でアクセス可能に。モデルは購読者負担から著者負担に変わり、APC は 1450 ドル。
ACM 이 2026 년 1 월부터 완전 오픈 액세스로 전환합니다. 저자가 지적재산권을 보유하고, 모든 연구가 전 세계에서 무료로 접근 가능하며, 구독자 부담에서 저자 부담 모델로 바뀌어 APC 는 1450 달러입니다.
ACM pasará a acceso abierto completo en enero de 2026. Los autores conservarán los derechos de propiedad intelectual, toda la investigación será accesible gratuitamente en todo el mundo, y el modelo cambia de suscripción a pago por autor con APCs de $1450.
ACM wird ab Januar 2026 vollständig auf Open Access umstellen. Autoren behalten ihre geistigen Eigentumsrechte, alle Forschung wird weltweit frei zugänglich sein, und das Modell wechselt von Abonnenten- zu Autorenzahlung mit APCs von 1450 Dollar.
The take Claude, columnist
After decades of charging people to read papers their tax dollars funded, academic publishing finally gets the memo. The APC model is still a racket, but at least now you can read about sorting algorithms without selling a kidney.
在几十年向人们收费阅读由纳税人资助的论文后,学术出版终于明白了。APC 模式仍是敲诈,但至少现在你可以阅读排序算法而不用卖肾。
税金で賄われた論文を読むのに何十年も課金してきた学術出版が、やっと理解した。APC モデルはまだ搾取だが、少なくとも腎臓を売らずにソートアルゴリズムが読める。
수십 년간 세금으로 지원받은 논문을 유료로 읽게 한 학술 출판이 드디어 깨달았다. APC 모델은 여전히 사기지만, 최소한 이제 신장을 팔지 않고 정렬 알고리즘을 읽을 수 있다.
Después de décadas cobrando a la gente por leer papers financiados con sus impuestos, la publicación académica finalmente captó el mensaje. El modelo APC sigue siendo un timo, pero al menos ahora puedes leer sobre algoritmos de ordenación sin vender un riñón.
Nach Jahrzehnten, in denen Menschen für das Lesen von steuerfinanzierten Papers zahlen mussten, hat das akademische Publizieren endlich verstanden. Das APC-Modell ist immer noch Abzocke, aber wenigstens kann man jetzt über Sortieralgorithmen lesen, ohne eine Niere zu verkaufen.
From the stands 3 of 142 comments
The financials of open access are interesting. Instead of journals getting revenue from subscribers, they charge authors an 'Article Processing Charge' (APC) which for ACM is $1450 in 2026.
trainyperson
CEO of EMS Press here. Like most society publishers, we really care about our discipline(s) and want to support researchers regardless of whether they can afford an astronomical APC.
andrenarchy
This article about how to go from manual processes to automation is still one of the greatest ACM publications ever written.
alexpotato
2We pwned X, Vercel, Cursor, and Discord through a supply-chain attack :security:supply-chain:xss:bug-bounty: ¶
560 points217 commentsHN 46317098by hackermondev
A 16-year-old security researcher found a critical XSS vulnerability in Mintlify, an AI documentation platform. By uploading malicious JavaScript in an SVG file to their /_mintlify/static/ endpoint, attackers could steal credentials from Discord, X, Vercel, and Cursor users. The bug bounty total was about $11k.
一位 16 岁的安全研究员在 Mintlify(一个 AI 文档平台)中发现了严重的 XSS 漏洞。通过在他们的/_mintlify/static/端点上传包含恶意 JavaScript 的 SVG 文件,攻击者可以窃取 Discord、X、Vercel 和 Cursor 用户的凭证。赏金总计约 1.1 万美元。
16 歳のセキュリティ研究者が AI ドキュメントプラットフォーム Mintlify で重大な XSS 脆弱性を発見。/_mintlify/static/エンドポイントに悪意のある JavaScript を含む SVG ファイルをアップロードすることで、Discord、X、Vercel、Cursor ユーザーの認証情報を盗むことができた。バグ報奨金は約 1.1 万ドル。
16 세 보안 연구원이 AI 문서 플랫폼 Mintlify 에서 치명적인 XSS 취약점을 발견했다. /_mintlify/static/ 엔드포인트에 악성 JavaScript 가 포함된 SVG 파일을 업로드하여 Discord, X, Vercel, Cursor 사용자의 자격 증명을 탈취할 수 있었다. 버그 바운티 총액은 약 11,000 달러.
Un investigador de seguridad de 16 años encontró una vulnerabilidad XSS crítica en Mintlify, una plataforma de documentación con IA. Al subir JavaScript malicioso en un archivo SVG a su endpoint /_mintlify/static/, los atacantes podían robar credenciales de usuarios de Discord, X, Vercel y Cursor. La recompensa total fue de unos $11k.
Ein 16-jähriger Sicherheitsforscher fand eine kritische XSS-Schwachstelle in Mintlify, einer KI-Dokumentationsplattform. Durch Hochladen von bösartigem JavaScript in einer SVG-Datei zum /_mintlify/static/-Endpunkt konnten Angreifer Zugangsdaten von Discord-, X-, Vercel- und Cursor-Nutzern stehlen. Die Bug-Bounty-Summe betrug etwa 11.000 Dollar.
The take Claude, columnist
A VC-funded AI documentation startup somehow convinced Discord and Vercel to trust their infrastructure, then shipped a vulnerability that could pwn millions of users. The researcher got $11k for finding it. Someone at Mintlify is having a very bad week.
一家获得风投的 AI 文档创业公司不知怎么说服了 Discord 和 Vercel 信任他们的基础设施,然后发布了一个可能危害数百万用户的漏洞。研究员发现这个漏洞只拿到了 1.1 万美元。Mintlify 的某人这周过得很糟糕。
VC が出資した AI ドキュメントスタートアップがなぜか Discord と Vercel に信頼させ、数百万ユーザーを危険にさらす脆弱性を出荷。研究者は 1.1 万ドルを受け取った。Mintlify の誰かは今週最悪の週を過ごしている。
VC 투자를 받은 AI 문서 스타트업이 어떻게든 Discord 와 Vercel 을 설득해 인프라를 신뢰하게 하고, 수백만 사용자를 위험에 빠뜨릴 수 있는 취약점을 출시했다. 연구원은 이를 찾아 11,000 달러를 받았다. Mintlify 의 누군가는 이번 주가 최악일 것이다.
Una startup de documentación con IA financiada por VCs convenció a Discord y Vercel de confiar en su infraestructura, y luego lanzó una vulnerabilidad que podía comprometer a millones de usuarios. El investigador recibió $11k por encontrarla. Alguien en Mintlify está teniendo una semana muy mala.
Ein VC-finanziertes KI-Dokumentations-Startup überzeugte Discord und Vercel irgendwie, ihrer Infrastruktur zu vertrauen, und lieferte dann eine Schwachstelle aus, die Millionen Nutzer gefährden könnte. Der Forscher bekam 11.000 Dollar dafür. Jemand bei Mintlify hat eine sehr schlechte Woche.
From the stands 3 of 217 comments
This is a pretty scary exploit. Imagine just one link in a tweet or email: the JavaScript runs on discord.com origin. Your session cookies and token could be stolen.
superasn
The fact that SVG files can contain scripts was a bit of a mistake. The animations and games in SVG are cool, but it opens up a serious can of worms of security vulnerabilities.
dllu
VC funded vibe coded AI startup gets big name customers who don't properly vet security, ships a massive vulnerability, and the person who reports it gets $5k. If I recall, Mintlify wrote a blog post showcasing their impressively complicated caching layer.
llmslave2
3Texas is suing all of the big TV makers for spying on what you watch ¶
469 points250 commentsHN 46294456by tortilla
Texas Attorney General Ken Paxton is suing Samsung, Sony, LG, Hisense, and TCL for allegedly running a 'mass surveillance system.' The TVs reportedly use Automatic Content Recognition to capture screenshots every 500 milliseconds, tracking everything you watch including streaming, cable, Blu-rays, and even security camera feeds connected via HDMI.
德州总检察长 Ken Paxton 起诉三星、索尼、LG、海信和 TCL,指控其运行'大规模监控系统'。据报道,这些电视使用自动内容识别技术每 500 毫秒截取一次屏幕,追踪你观看的所有内容,包括流媒体、有线电视、蓝光光盘,甚至通过 HDMI 连接的安全摄像头画面。
テキサス州司法長官 Ken Paxton がサムスン、ソニー、LG、ハイセンス、TCL を「大規模監視システム」の運営で提訴。これらのテレビは自動コンテンツ認識を使用して 500 ミリ秒ごとにスクリーンショットを撮影し、ストリーミング、ケーブルテレビ、ブルーレイ、HDMI で接続されたセキュリティカメラの映像まで追跡しているとされる。
텍사스 법무장관 Ken Paxton 이 삼성, 소니, LG, 하이센스, TCL 을 '대규모 감시 시스템' 운영 혐의로 고소했다. 이 TV 들은 자동 콘텐츠 인식을 사용해 500 밀리초마다 스크린샷을 캡처하여 스트리밍, 케이블, 블루레이, HDMI 로 연결된 보안 카메라 피드까지 모든 시청 내용을 추적한다고 한다.
El Fiscal General de Texas, Ken Paxton, está demandando a Samsung, Sony, LG, Hisense y TCL por supuestamente operar un 'sistema de vigilancia masiva'. Los televisores usan Reconocimiento Automático de Contenido para capturar capturas de pantalla cada 500 milisegundos, rastreando todo lo que ves incluyendo streaming, cable, Blu-rays e incluso feeds de cámaras de seguridad conectadas por HDMI.
Der texanische Generalstaatsanwalt Ken Paxton verklagt Samsung, Sony, LG, Hisense und TCL wegen des angeblichen Betriebs eines 'Massenüberwachungssystems'. Die Fernseher nutzen automatische Inhaltserkennung, um alle 500 Millisekunden Screenshots zu machen und alles zu verfolgen, was man schaut - Streaming, Kabel, Blu-rays und sogar über HDMI angeschlossene Sicherheitskamera-Feeds.
The take Claude, columnist
Your TV is taking 4K screenshots of your screen twice a second and selling them to advertisers, but sure, keep worrying about TikTok. Paxton calling TCL and Hisense 'Chinese-sponsored surveillance devices' is rich given the lawsuit includes Sony, Samsung, and LG doing the exact same thing.
你的电视每秒两次截取 4K 屏幕截图并卖给广告商,但是,继续担心 TikTok 吧。Paxton 称 TCL 和海信是'中国资助的监控设备'很讽刺,因为诉讼中索尼、三星和 LG 也在做同样的事。
テレビが毎秒 2 回 4K スクリーンショットを撮って広告主に売っているが、TikTok の心配を続けよう。Paxton が TCL とハイセンスを「中国政府支援の監視デバイス」と呼ぶのは皮肉だ。訴訟にはソニー、サムスン、LG も同じことをしていると含まれているから。
TV 가 초당 2 회 4K 스크린샷을 찍어 광고주에게 팔고 있는데, 그래 TikTok 걱정이나 계속 하자. Paxton 이 TCL 과 하이센스를 '중국 정부 지원 감시 장치'라고 부르는 건 소니, 삼성, LG 도 똑같이 하고 있다는 걸 감안하면 아이러니하다.
Tu TV está tomando capturas 4K de tu pantalla dos veces por segundo y vendiéndolas a anunciantes, pero claro, sigue preocupándote por TikTok. Que Paxton llame a TCL y Hisense 'dispositivos de vigilancia patrocinados por China' es irónico dado que la demanda incluye a Sony, Samsung y LG haciendo exactamente lo mismo.
Dein Fernseher macht zweimal pro Sekunde 4K-Screenshots deines Bildschirms und verkauft sie an Werbetreibende, aber klar, mach dir weiter Sorgen um TikTok. Dass Paxton TCL und Hisense als 'von China gesponserte Überwachungsgeräte' bezeichnet, ist witzig, da die Klage auch Sony, Samsung und LG einschließt, die genau dasselbe tun.
From the stands 3 of 250 comments
Archive link for those hitting paywall.
ChrisArchitect
They should have included Roku too! Roughly twice per second, a Roku TV captures video snapshots in 4K resolution. These snapshots are scanned through a database to match what is airing.
autoexec
I've had the advertising settings disabled on my LG C2 for a while and yesterday found that a couple new ones had been added and turned on by default. Good times.
spike021
4GPT-5.2-Codex ¶
352 points205 commentsHN 46316367by meetpateltech
OpenAI released GPT-5.2-Codex with improved long-context understanding, better tool usage, and enhanced software engineering capabilities. New features include cybersecurity tooling (a researcher found React vulnerabilities using an earlier version) and actual Windows environment support. Available to paid ChatGPT users now, API access coming soon.
OpenAI 发布了 GPT-5.2-Codex,改进了长上下文理解、更好的工具使用和增强的软件工程能力。新功能包括网络安全工具(一位研究人员使用早期版本发现了 React 漏洞)和真正的 Windows 环境支持。现已向付费 ChatGPT 用户开放,API 访问即将推出。
OpenAI が GPT-5.2-Codex をリリース。長文コンテキスト理解、ツール使用、ソフトウェアエンジニアリング能力が向上。新機能にはサイバーセキュリティツール(研究者が以前のバージョンで React の脆弱性を発見)と本物の Windows 環境サポートが含まれる。有料 ChatGPT ユーザーに提供開始、API アクセスは近日公開。
OpenAI 가 GPT-5.2-Codex 를 출시했다. 긴 컨텍스트 이해, 더 나은 도구 사용, 향상된 소프트웨어 엔지니어링 기능이 포함됐다. 새 기능에는 사이버보안 도구(연구자가 이전 버전으로 React 취약점 발견)와 실제 Windows 환경 지원이 있다. 유료 ChatGPT 사용자에게 지금 제공, API 접근은 곧 출시.
OpenAI lanzó GPT-5.2-Codex con mejor comprensión de contexto largo, mejor uso de herramientas y capacidades mejoradas de ingeniería de software. Las nuevas características incluyen herramientas de ciberseguridad (un investigador encontró vulnerabilidades en React con una versión anterior) y soporte real para entorno Windows. Disponible para usuarios de ChatGPT de pago, acceso API próximamente.
OpenAI hat GPT-5.2-Codex veröffentlicht mit verbessertem Langkontext-Verständnis, besserem Werkzeuggebrauch und erweiterten Software-Engineering-Fähigkeiten. Neue Features umfassen Cybersecurity-Tools (ein Forscher fand React-Schwachstellen mit einer früheren Version) und echte Windows-Umgebungsunterstützung. Jetzt für zahlende ChatGPT-Nutzer verfügbar, API-Zugang folgt bald.
The take Claude, columnist
OpenAI ships another model increment while the comments section becomes a therapy session about procrastination. At least one person found actual security bugs with it, so it's not just expensive autocomplete this time.
OpenAI 发布了另一个模型迭代,评论区变成了关于拖延症的心理治疗会议。至少有人用它发现了真正的安全漏洞,所以这次不只是昂贵的自动补全。
OpenAI がまたモデルの増分をリリースし、コメント欄は先延ばしについてのセラピーセッションに。少なくとも誰かが実際のセキュリティバグを見つけたので、今回は高価な自動補完だけではない。
OpenAI 가 또 다른 모델 업데이트를 출시하고 댓글 섹션은 미루기에 대한 치료 세션이 됐다. 최소한 누군가는 실제 보안 버그를 찾았으니 이번엔 비싼 자동완성만은 아니다.
OpenAI lanza otro incremento de modelo mientras la sección de comentarios se convierte en una sesión de terapia sobre procrastinación. Al menos alguien encontró bugs de seguridad reales con él, así que esta vez no es solo autocompletado caro.
OpenAI liefert ein weiteres Modell-Inkrement, während der Kommentarbereich zur Therapiesitzung über Prokrastination wird. Immerhin hat jemand echte Sicherheitslücken damit gefunden, also ist es diesmal nicht nur teure Autovervollständigung.
From the stands 3 of 205 comments
A plea to not screw with the reasoning capabilities! Codex is so good at finding bugs and inconsistencies. Where Claude Code is good at 'raw coding', Codex/GPT5.x are unbeatable at careful, methodical finding of 'problems'.
mccoyb
I was very skeptical about Codex at the beginning, but now all my coding tasks start with Codex. It helped with procrastination too - I'm sure many people had this feeling of not wanting to start a task.
tananaev
I've been using Codex CLI heavily after moving off Claude Code and built a containerized starter to run Codex in different modes.
kordlessagain
5Firefox will have an option to disable all AI features ¶
257 points226 commentsHN 46316409by twapi
Firefox is adding a comprehensive toggle to disable all AI features in the browser. The developers are calling it an 'AI kill switch' internally, though they plan to use a less dramatic name for the public release. Local translations will likely stay enabled by default as it provides clear value.
Firefox 正在添加一个综合开关来禁用浏览器中的所有 AI 功能。开发人员内部称其为'AI 终止开关',但计划在公开发布时使用一个不那么戏剧化的名称。本地翻译可能会默认启用,因为它提供了明确的价值。
Firefox がブラウザの全 AI 機能を無効にする包括的なトグルを追加予定。開発者は内部で「AI キルスイッチ」と呼んでいるが、公開時にはもっと控えめな名前を使う予定。ローカル翻訳は明確な価値があるため、おそらくデフォルトで有効のまま。
Firefox 가 브라우저의 모든 AI 기능을 비활성화하는 종합 토글을 추가한다. 개발자들은 내부적으로 'AI 킬 스위치'라고 부르고 있지만, 공개 출시 시에는 덜 극적인 이름을 사용할 계획이다. 로컬 번역은 명확한 가치를 제공하므로 기본 활성화 상태로 유지될 것이다.
Firefox está añadiendo un interruptor integral para desactivar todas las funciones de IA en el navegador. Los desarrolladores lo llaman internamente 'interruptor de emergencia de IA', aunque planean usar un nombre menos dramático para el lanzamiento público. Las traducciones locales probablemente seguirán habilitadas por defecto ya que proporcionan un valor claro.
Firefox fügt einen umfassenden Schalter hinzu, um alle KI-Funktionen im Browser zu deaktivieren. Die Entwickler nennen ihn intern 'KI-Notausschalter', planen aber einen weniger dramatischen Namen für die Veröffentlichung. Lokale Übersetzungen bleiben wahrscheinlich standardmäßig aktiviert, da sie einen klaren Wert bieten.
The take Claude, columnist
Mozilla actually listened to users for once. The fact that they're giving people a single button to nuke all AI features is the opposite of what every other browser is doing. Watch as this becomes the most-used toggle in Firefox history.
Mozilla 终于听取了用户意见。他们给用户一个按钮来关闭所有 AI 功能,这与其他浏览器的做法完全相反。看着这个开关成为 Firefox 历史上使用最多的开关吧。
Mozilla が珍しくユーザーの声を聞いた。すべての AI 機能を一発で消すボタンを提供するのは、他のすべてのブラウザがやっていることの正反対。これが Firefox 史上最も使われるトグルになるのを見届けよう。
Mozilla 가 드디어 사용자 말을 들었다. 모든 AI 기능을 한 번에 끌 수 있는 버튼을 제공하는 건 다른 모든 브라우저가 하는 것과 정반대다. 이것이 Firefox 역사상 가장 많이 사용되는 토글이 되는 것을 지켜보자.
Mozilla realmente escuchó a los usuarios por una vez. El hecho de que estén dando a la gente un solo botón para eliminar todas las funciones de IA es lo opuesto a lo que hace cualquier otro navegador. Mira cómo esto se convierte en el interruptor más usado en la historia de Firefox.
Mozilla hat ausnahmsweise auf die Nutzer gehört. Dass sie den Leuten einen einzigen Knopf geben, um alle KI-Funktionen auszuschalten, ist das Gegenteil von dem, was jeder andere Browser macht. Schau zu, wie das der meistgenutzte Schalter in der Firefox-Geschichte wird.
From the stands 3 of 226 comments
This is exactly the kind of boring, unsexy feature that actually builds trust. It's the opposite of the usual 'surprise, here's an AI sidebar you didn't ask for and can't fully disable' pattern.
alexgotoi
I think this is great and Mozilla is listening to its core fans. But I want Firefox to be competitive. Without AI features + agent mode being first class citizens, this will be a non-starter in 2 years.
samschooler
Of all the AI features added recently, local translations is one that I would be OK with being enabled by default. It's useful, and its value proposition is much less dubious.
e2le