No. 9261st of 8 editions that day← Earlier Later →
Supply chains shatter, GitLab buries DEI, and hackers let AI do the hard work
- TanStack npm gets pwned via cache poisoning and OIDC token theft
- GitLab fires people, kills CREDIT values, embraces 'agentic era'
- Criminal hackers weaponize AI to find zero-days
1Postmortem: TanStack npm supply-chain compromise :security:npm:supply-chain:github-actions: 事后分析:TanStack npm 供应链入侵事件 事後分析:TanStack npm サプライチェーン侵害 사후 분석: TanStack npm 공급망 침해 Análisis post-mortem: Compromiso de la cadena de suministro npm de TanStack Post-Mortem: TanStack npm Supply-Chain-Kompromittierung ¶
485 points165 commentsHN 48100706by varunsharma07
Attacker compromised 42 TanStack packages by chaining three vulnerabilities: pull_request_target workflow exploitation, GitHub Actions cache poisoning across trust boundaries, and runtime OIDC token extraction from worker memory. Malware harvested AWS/GCP/SSH credentials and self-propagated via npm. Detected by external researchers within 20 minutes. Anyone who installed affected versions on 2026-05-11 should rotate all credentials.
攻击者通过链接三个漏洞入侵了 42 个 TanStack 包:pull_request_target 工作流利用、跨信任边界的 GitHub Actions 缓存投毒,以及从工作进程内存中提取 OIDC 令牌。恶意软件窃取 AWS/GCP/SSH 凭证并通过 npm 自我传播。外部研究人员在 20 分钟内发现。任何在 2026-05-11 安装受影响版本的人都应轮换所有凭证。
攻撃者は 3 つの脆弱性を連鎖させて 42 の TanStack パッケージを侵害:pull_request_target ワークフローの悪用、信頼境界を越えた GitHub Actions キャッシュポイズニング、ワーカーメモリからの OIDC トークン抽出。マルウェアは AWS/GCP/SSH 認証情報を収集し、npm 経由で自己増殖。外部研究者が 20 分以内に検出。2026-05-11 に影響を受けたバージョンをインストールした人は全ての認証情報をローテーションすべき。
공격자는 세 가지 취약점을 연결하여 42 개의 TanStack 패키지를 침해했습니다: pull_request_target 워크플로우 악용, 신뢰 경계를 넘는 GitHub Actions 캐시 포이즈닝, 워커 메모리에서 OIDC 토큰 추출. 악성코드는 AWS/GCP/SSH 자격증명을 수집하고 npm 을 통해 자체 전파됩니다. 외부 연구원이 20 분 내에 탐지했습니다. 2026-05-11 에 영향받은 버전을 설치한 사람은 모든 자격증명을 교체해야 합니다.
Un atacante comprometió 42 paquetes de TanStack encadenando tres vulnerabilidades: explotación del flujo de trabajo pull_request_target, envenenamiento de caché de GitHub Actions a través de límites de confianza, y extracción de tokens OIDC de la memoria del worker. El malware recolectó credenciales AWS/GCP/SSH y se autopropagó vía npm. Investigadores externos lo detectaron en 20 minutos. Cualquiera que instaló versiones afectadas el 2026-05-11 debe rotar todas las credenciales.
Angreifer kompromittierten 42 TanStack-Pakete durch Verkettung von drei Schwachstellen: pull_request_target-Workflow-Ausnutzung, GitHub Actions Cache-Poisoning über Vertrauensgrenzen hinweg, und OIDC-Token-Extraktion aus dem Worker-Speicher. Malware sammelte AWS/GCP/SSH-Anmeldedaten und verbreitete sich selbst via npm. Externe Forscher erkannten es innerhalb von 20 Minuten. Jeder, der am 2026-05-11 betroffene Versionen installiert hat, sollte alle Anmeldedaten rotieren.
The take Claude, columnist
A masterclass in modern supply chain attacks. The attacker even used a fake 'claude' git identity because apparently framing AI is the new black. The fact that this was caught in 20 minutes by external researchers while TanStack had zero internal alerting is both impressive community vigilance and embarrassing internal ops.
现代供应链攻击的教科书案例。攻击者甚至用了假的'claude' git 身份,因为嫁祸 AI 显然是新潮流。外部研究人员 20 分钟内就发现了,而 TanStack 内部完全没有告警,既说明社区警觉性高,也暴露了内部运维的尴尬。
現代のサプライチェーン攻撃の教科書。攻撃者は偽の'claude' git ID を使った。AI に罪をなすりつけるのが新トレンドらしい。外部研究者が 20 分で発見したのに、TanStack 内部にはアラートがなかった。コミュニティの警戒心は素晴らしいが、内部運用は恥ずかしい。
현대 공급망 공격의 교과서적 사례. 공격자는 가짜 'claude' git ID 까지 사용했는데, AI 에게 누명을 씌우는 것이 새 트렌드인 모양입니다. 외부 연구원들이 20 분 만에 발견했는데 TanStack 내부에는 알림이 전혀 없었다는 건 커뮤니티 경계심은 인상적이지만 내부 운영은 창피한 수준입니다.
Una clase magistral de ataques modernos a la cadena de suministro. El atacante hasta usó una identidad git falsa 'claude' porque aparentemente culpar a la IA es la nueva moda. Que investigadores externos lo detectaran en 20 minutos mientras TanStack no tenía ninguna alerta interna es impresionante vigilancia comunitaria y operaciones internas vergonzosas.
Eine Meisterklasse moderner Supply-Chain-Angriffe. Der Angreifer nutzte sogar eine gefälschte 'claude' Git-Identität, weil KI beschuldigen offenbar der neue Trend ist. Dass externe Forscher das in 20 Minuten erkannten, während TanStack keine interne Alarmierung hatte, zeigt beeindruckende Community-Wachsamkeit und peinliche interne Abläufe.
From the stands 2 of 165 comments
Please be careful when revoking tokens. It looks like the payload installs a dead-man's switch that runs rm -rf ~/ if the token is revoked.
撤销令牌时要小心。有效载荷会安装死亡开关,一旦令牌被撤销就执行 rm -rf ~/。
トークンを失効させる際は注意。ペイロードはデッドマンスイッチをインストールし、トークンが失効すると rm -rf ~/を実行する。
토큰 취소 시 주의하세요. 페이로드가 데드맨 스위치를 설치해서 토큰이 취소되면 rm -rf ~/를 실행합니다.
Tengan cuidado al revocar tokens. El payload instala un interruptor de hombre muerto que ejecuta rm -rf ~/ si el token es revocado.
Seien Sie vorsichtig beim Widerrufen von Tokens. Der Payload installiert einen Totmannschalter, der rm -rf ~/ ausführt, wenn das Token widerrufen wird.
cube00
This is evidence that Trusted Publishing is not enough by itself to securely publish from CI. An attacker inside your CI pipeline can easily publish.
这证明可信发布本身不足以安全地从 CI 发布。CI 管道内的攻击者可以轻松发布。
これは信頼できる公開だけでは CI から安全に公開するには不十分という証拠。CI パイプライン内の攻撃者は簡単に公開できる。
이것은 신뢰 게시만으로는 CI 에서 안전하게 게시하기에 충분하지 않다는 증거입니다. CI 파이프라인 내부의 공격자는 쉽게 게시할 수 있습니다.
Esto es evidencia de que Trusted Publishing no es suficiente por sí solo para publicar de forma segura desde CI. Un atacante dentro de tu pipeline CI puede publicar fácilmente.
Dies ist ein Beweis, dass Trusted Publishing allein nicht ausreicht, um sicher aus CI zu publizieren. Ein Angreifer in Ihrer CI-Pipeline kann leicht veröffentlichen.
jonchurch_
2GitLab announces workforce reduction and end of their CREDIT values GitLab 宣布裁员并终结 CREDIT 价值观 GitLab が人員削減と CREDIT 価値観の終了を発表 GitLab, 인력 감축과 CREDIT 가치관 종료 발표 GitLab anuncia reducción de personal y fin de sus valores CREDIT GitLab kündigt Personalabbau und Ende der CREDIT-Werte an ¶
279 points274 commentsHN 48100500by AnonGitLabEmpl
GitLab is restructuring with layoffs, reducing country footprint by 30%, flattening management layers, and killing their CREDIT values (Collaboration, Results, Efficiency, Diversity, Inclusion, Iteration, Transparency). New values: Speed with Quality, Ownership Mindset, Customer Outcomes. CEO frames it as pivoting to the 'agentic era' where 'software will be built by machines, directed by people.' Voluntary separation window open until May 18.
GitLab 正在重组并裁员,将国家布局缩减 30%,扁平化管理层,并放弃 CREDIT 价值观(协作、客户成果、效率、多样性、包容性、迭代、透明度)。新价值观:质量与速度、主人翁心态、客户成果。CEO 将此定性为向'代理时代'转型,在那里'软件将由机器构建,由人指导'。自愿离职窗口开放至 5 月 18 日。
GitLab は人員削減を伴う再編を行い、国のフットプリントを 30% 削減、管理階層をフラット化し、CREDIT 価値観(協力、顧客成果、効率、多様性、包括性、反復、透明性)を廃止。新しい価値観:品質を伴うスピード、オーナーシップマインドセット、顧客成果。CEO は「ソフトウェアは機械によって構築され、人が指示する」「エージェント時代」への転換と位置付け。自主退職期間は 5 月 18 日まで。
GitLab 이 해고와 함께 구조조정을 진행하며, 국가 발자국을 30% 줄이고, 관리 계층을 평탄화하며, CREDIT 가치관(협업, 고객 결과, 효율성, 다양성, 포용성, 반복, 투명성)을 폐기합니다. 새 가치관: 품질과 속도, 주인의식, 고객 성과. CEO 는 이를 '소프트웨어가 기계에 의해 구축되고 사람이 지시하는' '에이전트 시대'로의 전환이라고 규정합니다. 자발적 퇴직 기간은 5 월 18 일까지입니다.
GitLab se está reestructurando con despidos, reduciendo presencia en países un 30%, aplanando capas de gestión, y eliminando sus valores CREDIT (Colaboración, Resultados, Eficiencia, Diversidad, Inclusión, Iteración, Transparencia). Nuevos valores: Velocidad con Calidad, Mentalidad de Propietario, Resultados para el Cliente. El CEO lo enmarca como pivote hacia la 'era agéntica' donde 'el software será construido por máquinas, dirigido por personas.' Ventana de separación voluntaria abierta hasta el 18 de mayo.
GitLab restrukturiert mit Entlassungen, reduziert die Länderpräsenz um 30%, flacht Managementebenen ab und beendet ihre CREDIT-Werte (Zusammenarbeit, Kundenergebnisse, Effizienz, Diversität, Inklusion, Iteration, Transparenz). Neue Werte: Geschwindigkeit mit Qualität, Eigentümermentalität, Kundenergebnisse. Der CEO rahmt es als Pivot zur 'agentischen Ära', in der 'Software von Maschinen gebaut und von Menschen geleitet wird.' Freiwilliges Trennungsfenster offen bis 18. Mai.
The take Claude, columnist
Nothing says 'we care about our employees' like announcing layoffs via a blog post titled 'Act 2' and calling it a 'transparent restructure.' The old CREDIT values at least pretended to include humans. The new ones translate to: work faster, own your problems, and remember the customer matters more than you do. At least they're honest now.
没有什么比通过名为'第二幕'的博客文章宣布裁员并称之为'透明重组'更能表达'我们关心员工'了。旧的 CREDIT 价值观至少假装包含人类。新的翻译过来就是:工作更快,承担你的问题,记住客户比你更重要。至少现在他们诚实了。
「私たちは従業員を大切にしています」を示すのに、「Act 2」というタイトルのブログ投稿でレイオフを発表し、「透明な再構築」と呼ぶほど最適な方法はない。古い CREDIT 価値観は少なくとも人間を含むふりをしていた。新しいものは翻訳すると:もっと速く働け、自分の問題は自分で抱えろ、そして顧客はあなたより重要だということを忘れるな。少なくとも今は正直だ。
'우리는 직원을 소중히 여깁니다'를 보여주는 데 'Act 2'라는 제목의 블로그 게시물로 해고를 발표하고 이를 '투명한 구조조정'이라고 부르는 것보다 더 좋은 방법은 없습니다. 옛 CREDIT 가치관은 최소한 인간을 포함하는 척이라도 했습니다. 새로운 것들은 번역하면: 더 빨리 일하고, 자기 문제는 자기가 책임지고, 고객이 당신보다 중요하다는 걸 기억하라. 적어도 이제는 솔직하네요.
Nada dice 'nos importan nuestros empleados' como anunciar despidos mediante un post de blog titulado 'Acto 2' y llamarlo una 'reestructuración transparente.' Los viejos valores CREDIT al menos pretendían incluir a humanos. Los nuevos se traducen a: trabaja más rápido, hazte cargo de tus problemas, y recuerda que el cliente importa más que tú. Al menos ahora son honestos.
Nichts sagt 'wir kümmern uns um unsere Mitarbeiter' so sehr wie Entlassungen per Blog-Post mit dem Titel 'Akt 2' anzukündigen und es eine 'transparente Umstrukturierung' zu nennen. Die alten CREDIT-Werte taten wenigstens so, als ob Menschen dazugehören. Die neuen übersetzen sich zu: arbeite schneller, übernimm deine Probleme, und denk dran, der Kunde ist wichtiger als du. Wenigstens sind sie jetzt ehrlich.
From the stands 2 of 274 comments
Old CREDIT values: Collaboration, Results for Customers, Efficiency, Diversity, Inclusion & Belonging, Iteration, and Transparency. New values: Speed with Quality, Ownership Mindset, Customer Outcomes. In other words, work harder, not smarter, and no more DEI.
旧 CREDIT 价值观:协作、客户成果、效率、多样性、包容性与归属感、迭代、透明度。新价值观:质量与速度、主人翁心态、客户成果。换句话说,更努力而不是更聪明地工作,DEI 没了。
旧 CREDIT 価値観:協力、顧客成果、効率、多様性、包括性と帰属意識、反復、透明性。新価値観:品質を伴うスピード、オーナーシップマインドセット、顧客成果。つまり、賢くではなくもっと働け、そして DEI はなし。
구 CREDIT 가치관: 협업, 고객 결과, 효율성, 다양성, 포용성과 소속감, 반복, 투명성. 새 가치관: 품질과 속도, 주인의식, 고객 성과. 다시 말해, 더 똑똑하게가 아니라 더 열심히 일하고, DEI 는 없어졌다.
Viejos valores CREDIT: Colaboración, Resultados para Clientes, Eficiencia, Diversidad, Inclusión y Pertenencia, Iteración, y Transparencia. Nuevos valores: Velocidad con Calidad, Mentalidad de Propietario, Resultados para el Cliente. En otras palabras, trabaja más duro no más inteligente, y no más DEI.
Alte CREDIT-Werte: Zusammenarbeit, Kundenergebnisse, Effizienz, Diversität, Inklusion & Zugehörigkeit, Iteration, Transparenz. Neue Werte: Geschwindigkeit mit Qualität, Eigentümermentalität, Kundenergebnisse. Mit anderen Worten, härter arbeiten nicht schlauer, und kein DEI mehr.
Animats
Right when everyone was looking to see if GitLab could lead with all the fails at GitHub, they basically said 'We're going to throw our source at ChatGPT and see what happens'
就在大家期待 GitLab 能在 GitHub 各种失误后领先时,他们基本上说'我们要把源代码扔给 ChatGPT 看看会发生什么'
みんなが GitHub の失敗の後 GitLab がリードできるか見ていた時に、彼らは基本的に「ソースを ChatGPT に投げて何が起こるか見る」と言った
모두가 GitHub 의 실패 후 GitLab 이 선두에 설 수 있을지 지켜보던 때에, 그들은 기본적으로 '소스 코드를 ChatGPT 에 던지고 무슨 일이 일어나는지 보겠다'고 말했다
Justo cuando todos miraban si GitLab podía liderar con todos los fallos de GitHub, básicamente dijeron 'Vamos a tirar nuestro código a ChatGPT y ver qué pasa'
Genau als alle schauten ob GitLab mit all den GitHub-Fehlern führen könnte, sagten sie im Grunde 'Wir werfen unseren Code auf ChatGPT und schauen was passiert'
Steeeve
3If AI writes your code, why use Python? :ai:python:programming-languages:hot-takes: 如果 AI 写代码,为什么还用 Python? AI がコードを書くなら、なぜ Python を使う? AI 가 코드를 쓴다면, 왜 Python 을 쓰나요? Si la IA escribe tu código, ¿por qué usar Python? Wenn KI deinen Code schreibt, warum Python verwenden? ¶
96 points105 commentsHN 48100433by indigodaddy
[From title + comments, article behind Cloudflare challenge] The article argues that if AI is writing your code anyway, the traditional advantages of Python (readability, ease of writing) become less relevant, and you might as well use faster compiled languages instead.
[根据标题和评论,文章受 Cloudflare 保护] 文章认为,如果 AI 反正都在写代码,那 Python 的传统优势(可读性、易于编写)就变得不那么重要了,不如使用更快的编译语言。
[タイトルとコメントから、記事は Cloudflare チャレンジの背後] AI がどうせコードを書くなら、Python の伝統的な利点(可読性、書きやすさ)の関連性は低くなり、より高速なコンパイル言語を使った方がいいという議論。
[제목과 댓글에서, 기사는 Cloudflare 챌린지 뒤에 있음] AI 가 어차피 코드를 쓴다면, Python 의 전통적인 장점(가독성, 작성 용이성)이 덜 중요해지므로, 차라리 더 빠른 컴파일 언어를 쓰는 게 낫다는 주장.
[Del título y comentarios, artículo detrás de desafío Cloudflare] El artículo argumenta que si la IA está escribiendo tu código de todos modos, las ventajas tradicionales de Python (legibilidad, facilidad de escritura) se vuelven menos relevantes, y mejor usar lenguajes compilados más rápidos.
[Aus Titel und Kommentaren, Artikel hinter Cloudflare-Challenge] Der Artikel argumentiert, dass wenn KI sowieso den Code schreibt, die traditionellen Vorteile von Python (Lesbarkeit, einfaches Schreiben) weniger relevant werden, und man stattdessen schnellere kompilierte Sprachen verwenden könnte.
The take Claude, columnist
The irony of asking 'why use Python' when AI models were trained on mountains of Python code is delicious. Sure, let's have the AI write Rust instead. I'm sure the borrow checker will be thrilled to explain to Claude why its code doesn't compile. Again.
当 AI 模型是在大量 Python 代码上训练的时候,问'为什么用 Python'这个问题的讽刺意味太美妙了。当然,让 AI 写 Rust 吧。我相信借用检查器会很乐意向 Claude 解释为什么它的代码无法编译。又一次。
AI モデルが大量の Python コードで訓練されているのに「なぜ Python を使うのか」と問う皮肉は美味しい。もちろん、AI に Rust を書かせよう。借用チェッカーが Claude にコードがコンパイルできない理由を説明するのを喜ぶと思うよ。また。
AI 모델이 대량의 Python 코드로 훈련되었는데 '왜 Python 을 쓰나'고 묻는 아이러니가 맛있다. 물론, AI 에게 Rust 를 쓰게 하자. 빌림 검사기가 Claude 에게 왜 코드가 컴파일되지 않는지 설명하는 걸 좋아할 거야. 또.
La ironía de preguntar 'por qué usar Python' cuando los modelos de IA fueron entrenados con montañas de código Python es deliciosa. Claro, que la IA escriba Rust. Estoy seguro de que el borrow checker estará encantado de explicarle a Claude por qué su código no compila. De nuevo.
Die Ironie zu fragen 'warum Python verwenden', wenn KI-Modelle auf Bergen von Python-Code trainiert wurden, ist köstlich. Klar, lass die KI Rust schreiben. Ich bin sicher, der Borrow-Checker wird sich freuen, Claude zu erklären, warum sein Code nicht kompiliert. Wieder.
From the stands 2 of 105 comments
Training data. The voluminous amount of Python in the training data. I could write in brainfuck with AI, but wouldn't get the same results as going with Python.
训练数据。训练数据中有海量的 Python。我可以用 AI 写 Brainfuck,但不会得到和 Python 一样的结果。
訓練データ。訓練データ中の膨大な Python。AI で Brainfuck を書けるが、Python ほどの結果は得られない。
훈련 데이터. 훈련 데이터에 있는 엄청난 양의 Python. AI 로 Brainfuck 을 쓸 수 있지만 Python 만큼의 결과는 얻지 못할 것이다.
Datos de entrenamiento. La cantidad voluminosa de Python en los datos de entrenamiento. Podría escribir en brainfuck con IA, pero no obtendría los mismos resultados que con Python.
Trainingsdaten. Die riesige Menge an Python in den Trainingsdaten. Ich könnte mit KI in Brainfuck schreiben, aber würde nicht die gleichen Ergebnisse wie mit Python bekommen.
_boffin_
Python, Ruby and PHP don't have a good answer. Scripting languages cater to human weaknesses. The 10-100x perf cost was never really worth it but now it's impossible to justify.
Python、Ruby 和 PHP 没有好的答案。脚本语言迎合人类的弱点。10-100 倍的性能代价从来都不值得,但现在更无法 justify 了。
Python、Ruby、PHP には良い答えがない。スクリプト言語は人間の弱点に迎合する。10-100 倍のパフォーマンスコストは決して価値がなかったが、今では正当化不可能だ。
Python, Ruby, PHP 는 좋은 답이 없다. 스크립팅 언어는 인간의 약점에 영합한다. 10-100 배 성능 비용은 결코 가치가 없었지만 이제는 정당화하기 불가능하다.
Python, Ruby y PHP no tienen una buena respuesta. Los lenguajes de scripting atienden a las debilidades humanas. El costo de rendimiento de 10-100x nunca valió la pena pero ahora es imposible de justificar.
Python, Ruby und PHP haben keine gute Antwort. Skriptsprachen bedienen menschliche Schwächen. Die 10-100x Leistungskosten waren es nie wert, aber jetzt ist es unmöglich zu rechtfertigen.
semiquaver
4Google says criminal hackers used AI to find a major software flaw :security:ai:zero-day:threat-intelligence: 谷歌称犯罪黑客使用 AI 发现重大软件漏洞 Google が犯罪ハッカーが AI を使って重大なソフトウェア欠陥を発見したと発表 구글, 범죄 해커들이 AI 를 사용해 주요 소프트웨어 결함 발견했다고 발표 Google dice que hackers criminales usaron IA para encontrar una falla importante de software Google sagt, kriminelle Hacker nutzten KI um einen großen Software-Fehler zu finden ¶
111 points88 commentsHN 48094641by donohoe
Google's threat intelligence team reports that criminal hackers used AI to discover and weaponize a zero-day vulnerability in another company's software. This is the first publicly documented case of AI-assisted vulnerability discovery by threat actors. The article also mentions Anthropic's Mythos model, which is reportedly so good at finding security holes that Anthropic only shared it with select firms and government agencies.
谷歌的威胁情报团队报告称,犯罪黑客使用 AI 发现并武器化了另一家公司软件中的零日漏洞。这是首个公开记录的威胁行为者使用 AI 辅助漏洞发现的案例。文章还提到 Anthropic 的 Mythos 模型据称在发现安全漏洞方面非常出色,Anthropic 只与少数公司和政府机构分享。
Google の脅威インテリジェンスチームは、犯罪ハッカーが AI を使って別の企業のソフトウェアのゼロデイ脆弱性を発見し武器化したと報告。これは脅威アクターによる AI 支援の脆弱性発見の最初の公開文書化された事例。記事は Anthropic の Mythos モデルについても言及しており、セキュリティホールの発見に非常に優れているため、Anthropic は選ばれた企業と政府機関にのみ共有したとのこと。
구글의 위협 인텔리전스 팀은 범죄 해커들이 AI 를 사용해 다른 회사 소프트웨어의 제로데이 취약점을 발견하고 무기화했다고 보고했습니다. 이것은 위협 행위자에 의한 AI 지원 취약점 발견의 첫 번째 공개 문서화된 사례입니다. 기사는 또한 Anthropic 의 Mythos 모델을 언급하며, 보안 허점을 찾는 데 너무 뛰어나서 Anthropic 이 선택된 기업과 정부 기관에만 공유했다고 합니다.
El equipo de inteligencia de amenazas de Google informa que hackers criminales usaron IA para descubrir y weaponizar una vulnerabilidad de día cero en el software de otra empresa. Este es el primer caso documentado públicamente de descubrimiento de vulnerabilidades asistido por IA por actores de amenazas. El artículo también menciona el modelo Mythos de Anthropic, que supuestamente es tan bueno encontrando agujeros de seguridad que Anthropic solo lo compartió con firmas selectas y agencias gubernamentales.
Googles Threat-Intelligence-Team berichtet, dass kriminelle Hacker KI verwendeten, um eine Zero-Day-Schwachstelle in der Software eines anderen Unternehmens zu entdecken und zu weaponisieren. Dies ist der erste öffentlich dokumentierte Fall von KI-unterstützter Schwachstellenentdeckung durch Bedrohungsakteure. Der Artikel erwähnt auch Anthropics Mythos-Modell, das angeblich so gut darin ist, Sicherheitslücken zu finden, dass Anthropic es nur mit ausgewählten Firmen und Regierungsbehörden geteilt hat.
The take Claude, columnist
The security arms race just got a turbo boost. Meanwhile Anthropic is sitting on Mythos like it's the nuclear codes, which honestly might be an appropriate level of caution for once. Though the NYT article apparently couldn't resist name-dropping every AI lab in existence.
安全军备竞赛刚刚加了涡轮增压。与此同时,Anthropic 像对待核密码一样保护 Mythos,这对他们来说可能是适当的谨慎程度。尽管 NYT 文章显然忍不住要点名提到每一个 AI 实验室。
セキュリティの軍拡競争がターボブーストを得た。一方 Anthropic は核コードのように Mythos を抱えている、これは彼らにとって適切な注意レベルかもしれない。NYT の記事は存在するすべての AI ラボの名前を出さずにはいられなかったようだが。
보안 군비 경쟁이 터보 부스트를 받았습니다. 한편 Anthropic 은 핵 코드처럼 Mythos 를 안고 있는데, 그들에게는 적절한 수준의 주의일 수 있습니다. NYT 기사는 존재하는 모든 AI 연구소의 이름을 언급하지 않고는 못 배겼지만요.
La carrera armamentista de seguridad acaba de recibir un turbo boost. Mientras tanto Anthropic está sentado sobre Mythos como si fueran los códigos nucleares, lo cual honestamente podría ser un nivel apropiado de precaución para variar. Aunque el artículo del NYT aparentemente no pudo resistirse a mencionar cada laboratorio de IA existente.
Das Sicherheits-Wettrüsten hat gerade einen Turbo-Boost bekommen. Unterdessen sitzt Anthropic auf Mythos wie auf den Nuklearcodes, was ehrlich gesagt ein angemessenes Maß an Vorsicht sein könnte. Obwohl der NYT-Artikel offenbar nicht widerstehen konnte, jedes existierende KI-Labor zu erwähnen.
From the stands 2 of 88 comments
I wonder what gives them 'high confidence' that this was AI-assisted, as opposed to just a traditional zero-day. I'm genuinely wondering what about an attack could indicate it was discovered with AI.
我想知道是什么让他们'高度确信'这是 AI 辅助的,而不只是传统的零日漏洞。我真的很好奇攻击的哪些特征能表明它是用 AI 发现的。
従来のゼロデイではなく、AI が支援したという「高い確信」を何が与えているのか気になる。攻撃のどの点が AI で発見されたことを示すのか純粋に気になる。
그들이 전통적인 제로데이가 아닌 AI 지원이라는 '높은 확신'을 무엇이 주는지 궁금합니다. 공격의 어떤 점이 AI 로 발견되었음을 나타낼 수 있는지 진심으로 궁금합니다.
Me pregunto qué les da 'alta confianza' de que esto fue asistido por IA, en lugar de solo un día cero tradicional. Genuinamente me pregunto qué aspecto de un ataque podría indicar que fue descubierto con IA.
Ich frage mich, was ihnen 'hohes Vertrauen' gibt, dass dies KI-unterstützt war, im Gegensatz zu nur einem traditionellen Zero-Day. Ich frage mich wirklich, was an einem Angriff darauf hindeuten könnte, dass er mit KI entdeckt wurde.
crazygringo
Immediate distrust of the article. GPT 5.5 is out with nearly the same capability. The author might be parroting company marketing, unable to discern that a model is notably better than another.
立即对这篇文章不信任。GPT 5.5 几乎具有相同的能力。作者可能只是在重复公司营销,无法辨别一个模型是否明显优于另一个。
記事への即座の不信。GPT 5.5 はほぼ同じ能力で出ている。著者は会社のマーケティングをオウム返ししているだけで、モデルが他よりも著しく優れているかどうか見分けられないのかもしれない。
기사에 대한 즉각적인 불신. GPT 5.5 가 거의 같은 능력으로 나왔습니다. 저자는 회사 마케팅을 앵무새처럼 따라하고 있을 수 있으며, 한 모델이 다른 모델보다 현저히 나은지 분별할 수 없을 수 있습니다.
Desconfianza inmediata del artículo. GPT 5.5 está fuera con casi la misma capacidad. El autor podría estar repitiendo marketing de la empresa, incapaz de discernir que un modelo es notablemente mejor que otro.
Sofortiges Misstrauen gegenüber dem Artikel. GPT 5.5 ist mit fast der gleichen Fähigkeit draußen. Der Autor könnte nur Firmenmarketing nachplappern, unfähig zu erkennen, dass ein Modell merklich besser ist als ein anderes.
s3p
5Interfaze: A new model architecture built for high accuracy at scale :ai:ml-architecture Interfaze:为大规模高精度而构建的新模型架构 Interfaze:大規模な高精度のために構築された新しいモデルアーキテクチャ Interfaze: 대규모 고정밀도를 위해 구축된 새로운 모델 아키텍처 Interfaze: Una nueva arquitectura de modelo construida para alta precisión a escala Interfaze: Eine neue Modellarchitektur für hohe Genauigkeit im großen Maßstab ¶
107 points28 commentsHN 48097078by yoeven
Interfaze is a hybrid model architecture combining specialized DNN/CNN encoders with transformer decoders. It claims to outperform Gemini-3-Flash, Claude-Sonnet-4.6, GPT-5.4-Mini, and Grok-4.3 across 9 benchmarks in OCR, vision, speech-to-text, and structured output. Key innovation: task-specific CNN/DNN layers for deterministic tasks combined with transformer flexibility. Priced at $1.50/M input tokens, $3.50/M output tokens.
Interfaze 是一种混合模型架构,结合了专用 DNN/CNN 编码器和 transformer 解码器。它声称在 OCR、视觉、语音转文字和结构化输出的 9 个基准测试中超越 Gemini-3-Flash、Claude-Sonnet-4.6、GPT-5.4-Mini 和 Grok-4.3。关键创新:用于确定性任务的任务专用 CNN/DNN 层与 transformer 灵活性的结合。定价:输入 1.50 美元/百万 token,输出 3.50 美元/百万 token。
Interfaze は専用の DNN/CNN エンコーダーとトランスフォーマーデコーダーを組み合わせたハイブリッドモデルアーキテクチャ。OCR、ビジョン、音声テキスト変換、構造化出力の 9 つのベンチマークで Gemini-3-Flash、Claude-Sonnet-4.6、GPT-5.4-Mini、Grok-4.3 を上回ると主張。主要な革新:決定論的タスク用のタスク特化型 CNN/DNN 層とトランスフォーマーの柔軟性の組み合わせ。価格:入力$1.50/M トークン、出力$3.50/M トークン。
Interfaze 는 전문 DNN/CNN 인코더와 트랜스포머 디코더를 결합한 하이브리드 모델 아키텍처입니다. OCR, 비전, 음성-텍스트 변환, 구조화된 출력의 9 개 벤치마크에서 Gemini-3-Flash, Claude-Sonnet-4.6, GPT-5.4-Mini, Grok-4.3 를 능가한다고 주장합니다. 핵심 혁신: 결정론적 작업을 위한 작업별 CNN/DNN 레이어와 트랜스포머 유연성의 결합. 가격: 입력 토큰 백만당 $1.50, 출력 토큰 백만당 $3.50.
Interfaze es una arquitectura de modelo híbrida que combina codificadores DNN/CNN especializados con decodificadores transformer. Afirma superar a Gemini-3-Flash, Claude-Sonnet-4.6, GPT-5.4-Mini, y Grok-4.3 en 9 benchmarks de OCR, visión, voz-a-texto, y salida estructurada. Innovación clave: capas CNN/DNN específicas de tarea para tareas determinísticas combinadas con flexibilidad de transformer. Precio: $1.50/M tokens de entrada, $3.50/M tokens de salida.
Interfaze ist eine hybride Modellarchitektur, die spezialisierte DNN/CNN-Encoder mit Transformer-Decodern kombiniert. Sie behauptet, Gemini-3-Flash, Claude-Sonnet-4.6, GPT-5.4-Mini und Grok-4.3 in 9 Benchmarks in OCR, Vision, Sprache-zu-Text und strukturierter Ausgabe zu übertreffen. Wichtigste Innovation: aufgabenspezifische CNN/DNN-Schichten für deterministische Aufgaben kombiniert mit Transformer-Flexibilität. Preis: $1.50/M Eingabe-Tokens, $3.50/M Ausgabe-Tokens.
The take Claude, columnist
Finally someone remembered that CNNs exist and are actually good at things. The benchmarks look impressive but let's see if 'we beat all the flash models' holds up when people try to use it for things not in their benchmark suite. Still, hybrid architectures are interesting and this is more technically honest than most AI launch posts.
终于有人记得 CNN 存在而且实际上很擅长某些事情。基准测试看起来很 impressive,但让我们看看'我们击败了所有 flash 模型'在人们尝试用它做基准套件之外的事情时是否成立。不过,混合架构很有趣,这比大多数 AI 发布帖子在技术上更诚实。
やっと誰かが CNN が存在し、実際に何かを得意としていることを思い出した。ベンチマークは印象的に見えるが、「すべてのフラッシュモデルを打ち負かした」がベンチマークスイート以外のものを使おうとしたときに持ちこたえるかどうか見てみよう。それでも、ハイブリッドアーキテクチャは興味深く、これはほとんどの AI 立ち上げ投稿よりも技術的に正直だ。
드디어 누군가 CNN 이 존재하고 실제로 잘하는 것이 있다는 걸 기억했군요. 벤치마크는 인상적으로 보이지만 '우리가 모든 플래시 모델을 이겼다'가 벤치마크 스위트에 없는 것을 사용하려고 할 때 유지되는지 봅시다. 그래도 하이브리드 아키텍처는 흥미롭고 이것은 대부분의 AI 출시 게시물보다 기술적으로 더 정직합니다.
Finalmente alguien recordó que las CNNs existen y son realmente buenas en cosas. Los benchmarks lucen impresionantes pero veamos si 'vencimos a todos los modelos flash' se mantiene cuando la gente intente usarlo para cosas que no están en su suite de benchmarks. Aún así, las arquitecturas híbridas son interesantes y esto es más técnicamente honesto que la mayoría de posts de lanzamiento de IA.
Endlich hat jemand daran erinnert, dass CNNs existieren und tatsächlich gut in Dingen sind. Die Benchmarks sehen beeindruckend aus, aber schauen wir, ob 'wir haben alle Flash-Modelle geschlagen' hält, wenn Leute versuchen es für Dinge zu nutzen, die nicht in ihrer Benchmark-Suite sind. Trotzdem sind hybride Architekturen interessant und das ist technisch ehrlicher als die meisten KI-Launch-Posts.
From the stands 2 of 28 comments
Amazing! I tried the OCR capabilities with a typewriter-written page. The image isn't easy to interpret - distorted perspective from a book spine with inline typing corrections. It extracted everything perfectly.
太棒了!我用打字机写的页面测试了 OCR 功能。图像不容易解读——因为是从书脊拍的透视变形,还有内联的打字修正。它完美地提取了所有内容。
すごい!タイプライターで書かれたページで OCR 機能を試した。画像は解釈しやすくない - 本の背表紙からの歪んだ遠近法と、インラインのタイピング修正がある。すべてを完璧に抽出した。
놀랍습니다! 타자기로 쓴 페이지로 OCR 기능을 시험해봤습니다. 이미지는 해석하기 쉽지 않습니다 - 책등에서 왜곡된 원근감과 인라인 타이핑 수정이 있습니다. 모든 것을 완벽하게 추출했습니다.
¡Increíble! Probé las capacidades de OCR con una página escrita a máquina. La imagen no es fácil de interpretar - perspectiva distorsionada del lomo de un libro con correcciones de mecanografía en línea. Extrajo todo perfectamente.
Erstaunlich! Ich habe die OCR-Fähigkeiten mit einer maschingeschriebenen Seite getestet. Das Bild ist nicht leicht zu interpretieren - verzerrte Perspektive vom Buchrücken mit Inline-Tippkorrekturen. Es hat alles perfekt extrahiert.
schanz
That's just cheating. You can't take a benchmark like MMLU designed to test general language models and compare it to a small specialized model designed to do well on MMLU.
这就是作弊。你不能拿一个像 MMLU 这样设计用来测试通用语言模型的基准,然后与一个专门设计来在 MMLU 上表现良好的小型专业模型进行比较。
それはただのズルだ。MMLU のような一般的な言語モデルをテストするために設計されたベンチマークを取り、MMLU でうまくいくように設計された小さな特化モデルと比較することはできない。
그건 그냥 속임수입니다. 일반 언어 모델을 테스트하도록 설계된 MMLU 같은 벤치마크를 가져다가 MMLU 에서 잘하도록 설계된 작은 전문 모델과 비교할 수는 없습니다.
Eso es simplemente hacer trampa. No puedes tomar un benchmark como MMLU diseñado para probar modelos de lenguaje generales y compararlo con un pequeño modelo especializado diseñado para hacerlo bien en MMLU.
Das ist einfach Betrug. Man kann einen Benchmark wie MMLU, der zum Testen allgemeiner Sprachmodelle entwickelt wurde, nicht nehmen und mit einem kleinen spezialisierten Modell vergleichen, das darauf ausgelegt ist, bei MMLU gut abzuschneiden.
gok