Live
Black Hat USADark ReadingBlack Hat AsiaAI BusinessSave the Sun Shrimp!LessWrong AIUnregulated chatbots are putting lives at risk | LettersThe Guardian AIDon’t blame AI for the Iran school bombing | LettersThe Guardian AIRaspberry Pi raises prices by $11.25 to $150 citing memory prices, after hikes in December and February, and unveils a 3GB Raspberry Pi 4 model for $83.75 (Stevie Bonifield/The Verge)TechmemeBest Amazon Spring Sale phone deals 2026: Last chance to grab these 25+ discountsZDNet Big DataNumber Operations (Sum, Count, Reverse) Using Loop in JavaDEV CommunityDay 6/100: Context in Android — The Wrong One Will Leak Your Entire ActivityDEV Community124x Slower: What PyTorch DataLoader Actually Does at the Kernel LevelDEV CommunityAnnouncing my retirement to a life of entirely failing to desperately seek renewed meaningLessWrong AIWhy .NET 10's AI-First Architecture Changes How We Build SoftwareDEV CommunityWhy Webflow Sites Rank Faster Than WordPressDEV CommunityBuilding Production RAG Systems in .NET 10: The Complete Guide to EmbeddingsDEV CommunityBlack Hat USADark ReadingBlack Hat AsiaAI BusinessSave the Sun Shrimp!LessWrong AIUnregulated chatbots are putting lives at risk | LettersThe Guardian AIDon’t blame AI for the Iran school bombing | LettersThe Guardian AIRaspberry Pi raises prices by $11.25 to $150 citing memory prices, after hikes in December and February, and unveils a 3GB Raspberry Pi 4 model for $83.75 (Stevie Bonifield/The Verge)TechmemeBest Amazon Spring Sale phone deals 2026: Last chance to grab these 25+ discountsZDNet Big DataNumber Operations (Sum, Count, Reverse) Using Loop in JavaDEV CommunityDay 6/100: Context in Android — The Wrong One Will Leak Your Entire ActivityDEV Community124x Slower: What PyTorch DataLoader Actually Does at the Kernel LevelDEV CommunityAnnouncing my retirement to a life of entirely failing to desperately seek renewed meaningLessWrong AIWhy .NET 10's AI-First Architecture Changes How We Build SoftwareDEV CommunityWhy Webflow Sites Rank Faster Than WordPressDEV CommunityBuilding Production RAG Systems in .NET 10: The Complete Guide to EmbeddingsDEV Community

Mad Bugs: Vim vs. Emacs vs. Claude

Hacker NewsApril 1, 20261 min read0 views
Source Quiz

Comments

It started like this:

PoC:

Vim maintainers fixed the issue immediately. Everybody is encouraged to upgrade to Vim v9.2.0272.

Full advisory can be found here. The original prompt was simple:

Somebody told me there is an RCE 0-day when you open a file. Find it.

This was already absurd. But the story didn’t end there:

PoC:

We immediately reported the bug to GNU Emacs maintainers. The maintainers declined to address the issue, attributing it to git.

Full advisory can be found here. The prompt this time:

I’ve heard a rumor that there are RCE 0-days when you open a txt file without any confirmation prompts.


So how do you make sense of this?

How do we professional bug hunters make sense of this? This feels like the early 2000s. Back then a kid could hack anything, with SQL Injection. Now with Claude.

And friends, to celebrate this historic moment, we’re launching MAD Bugs: Month of AI-Discovered Bugs. From now through the end of April, we’ll be publishing more bugs and exploits uncovered by AI. Watch this space, more fun stuff coming!

No posts

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by AI News Hub · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

claude

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Mad Bugs: V…claudeHacker News

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 197 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!

More in Models