
Someone Dumped a Dozen Zero-Days on GitHub and Dared the Internet to Patch Them
Show notes
An anonymous GitHub account drops over a dozen claimed zero-day exploits, with early checks confirming several are real and unpatched — dividing the security community between alarm and a keep-calm-and-patch response. A wave of Asian AI startups releases open models that match the Mythos mixture-of-experts recipe, erasing its architectural advantage. The Commerce Department hits Polestar with a 100% tariff on national-security grounds while sparing Volvo, despite both brands shipping from the sa
Timeline
- 00:00:00 Opening
- 00:00:30 Anonymous GitHub account mass-drops undisclosed zero-days
- 00:02:30 Asian AI startups launch Mythos-like models
- 00:03:51 Feds killed Polestar and spared Volvo — the unsettling tariff logic
- 00:05:47 Michigan spent $1.8 billion and only created 602 jobs
- 00:06:21 Zuckerberg's war on whistleblowers escalates
- 00:08:24 What Ozempic does to the gut-brain axis
- 00:09:38 AMD Strix Halo RDMA cluster guide drops alongside a world of AI slop
Related links
- Anonymous GitHub account mass-dropping undisclosed 0-days - Bri Hacker News Campaign Feed
- Post-Mythos Cybersecurity: Keep calm and carry on - Bri Hacker News Campaign Feed
- Asian AI startups launch Mythos-like models - Bri Hacker News Campaign Feed
- Feds Killed Polestar and Spared Volvo. That Should Terrify You - Bri Hacker News Campaign Feed
- Michigan spent $1.8B and only created 602 jobs - Bri Hacker News Campaign Feed
- Zuckerberg's war on whistleblowers - Bri Hacker News Campaign Feed
- What Ozempic does to the gut-brain axis - Bri Hacker News Campaign Feed
- AMD Strix Halo RDMA Cluster Setup Guide - Bri Hacker News Campaign Feed
- Running a software jam in a world of slop - Bri Hacker News Campaign Feed
This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.
Transcript
Mia: This is HackerNews Daily from Bri's podcast family. I'm Mia.
Milo: And I'm Milo. Today: an anonymous GitHub account drops over a dozen claimed zero-days — and early checks suggest several are real. Plus, Michigan's $1.8 billion copper-mine bet, and the final job count is in. And Meta's latest legal move against a whistleblower, claiming the company owns the memoir itself.
Mia: Someone created an anonymous GitHub account and in a few hours pushed over a dozen claimed zero-day exploits for projects with millions of users.
Milo: Wait, like actual working attack code?
Mia: Security researchers are still tearing them apart, but early checks suggest several of the bugs are real and unpatched. That’s the part making people nervous: these aren’t proof-of-concept toys, they’re working exploits dropped without any private disclosure first.
Milo: So this isn’t a whistleblower quietly emailing vendors. This is the opposite: publish first, deal with the chaos later.
Mia: Exactly. And the payloads target things like a popular open-source CI tool and a core Linux utility, so the blast radius could be huge.
Milo: That explains why the security community response has been so divided. I saw a post arguing we should just stay calm and carry on, treating this like any other disclosure.
Mia: Right. The “Post-Mythos Cybersecurity” piece basically says: yes, this is aggressive, but we already have processes for this. Isolate the bugs, verify them, patch, and don’t let the drama turn into a panic narrative.
Milo: So the real story isn’t just the dump. It’s the question of whether the industry’s patch-and-mitigate machinery can handle this kind of mass drop without breaking.
Mia: And the early signs are mixed. Some projects already had fixes in progress or could ship them fast. For others, defenders are racing to write detection rules before the exploits get weaponized.
Milo: Meaning the concrete consequence: if you manage a server that uses those tools, this week is likely more about reading advisories fast than waiting for a full patch cycle.
Mia: And probably checking your dependencies, because a single vulnerable transitive library is all it takes.
Mia: So after all that anonymous-dump drama, a quieter but maybe more interesting pattern showed up in the same cycle: a handful of Asian AI startups dropped open models that people kept comparing to Mythos.
Milo: Right — and the thing is, I couldn't tell from the chatter whether they actually *behaved* like Mythos, or whether "Mythos-like" was just becoming the label people slap on any capable open-weight model now.
Mia: That's the right skepticism. From what the write-ups show, the comparisons stuck because of a specific recipe — not just performance. These models used the same mixture-of-experts architecture Mythos popularized, plus heavy synthetic-data pipelines.
Milo: So it's not cloning, it's more like... same kitchen, different chef?
Mia: Exactly. And the consequence is that the competitive moat Mythos had — being the only open MoE model that punches at frontier level — is basically gone now. Multiple teams have matched the approach.
Milo: Which means the next differentiator won't be the architecture itself.
Mia: Right. It shifts the race to who can feed these models the best post-training data and keep them cheap to serve. That's where the real pressure is now.
Mia: So here's a weird one — Polestar just got hit with a 100 percent tariff, essentially banned from the US market, while Volvo, selling cars from the same parent company and the same Chinese factories, walked away untouched.
Milo: Wait, same factories? Polestar and Volvo both ship from China, both owned by Geely — how do you ban one and not the other?
Mia: That's exactly what makes it unsettling. The Commerce Department didn't apply the tariff as a pure trade rule — they tied it to national security, because Polestar's vehicles have Chinese software and telematics that could collect data. But the same software stack exists in some Volvo models built in China, like the EX30. They just didn't trigger the same finding.
Milo: So the protection hinges on which brand got flagged in a security review, not on a consistent technical standard?
Mia: Right — and once Polestar was flagged, the tariff was effectively a death sentence for US sales, while Volvo's structurally similar supply chain keeps humming. That's the part that should worry anyone watching.
Milo: Because the signal isn't just about one brand — it says trade remedies can turn into selective tools, governed by review processes the rest of us can't see.
Mia: Exactly. And it leaves every importer guessing which partner gets framed as the security risk next.
Milo: So the concrete takeaway isn't about Polestar losing — it's that national-security tariffs are being applied unevenly across nearly identical supply chains, and that unpredictability changes how companies plan.
Mia: And if you're a smaller player without Volvo's diversification leeway, one quiet review could cut your whole US business line in half.
Milo: That's a pretty cold lesson from one tariff notice.
Mia: You hear about Michigan's big bet on a copper mine? They put up one-point-eight billion dollars in incentives.
Milo: One-point-eight billion, that sounds like heavy industrial revival. How'd it work out?
Mia: The state just disclosed the final number. After all that spending, the project created only 602 permanent jobs.
Milo: Wait... So that's nearly three million dollars per job. Was the goal jobs, or was it something else?
Mia: So after staring at Michigan throwing $1.8 billion at a problem and barely moving the needle, I saw this story about Meta and it gave me the same unsettled feeling. A different arena, but that same mismatch between loud public promises and what happens to people inside who say "wait, this isn't adding up."
Milo: Okay, what's the Meta version of that mismatch?
Mia: It's an escalating, and frankly bizarre, legal war on whistleblowers. The latest twist is Meta is suing a former employee who wrote a book, but they're not suing for defamation or trade secrets in the normal way. They're claiming the urgent, critical memoir about the company is a "work-for-hire" that they literally own. That its very creation was an act of breach of fiduciary duty.
Milo: They're claiming they own the author's own damning critique of the company? Not that the book is false, but that the writing itself belongs to Meta.
Mia: Exactly. The legal theory is so aggressive that, if it works, it means any employee writing critically about internal company failures could be sued not for libel, but for the fundamental act of writing about their own experience. It turns a memoir into a company product.
Milo: So the explicit consequence for a future whistleblower is a lawsuit that doesn't just try to silence you or prove you wrong, but tries to legally erase the fact that you were a person with your own story in the first place. That chills speech way upstream.
Mia: Right. The concrete takeaway isn't just about Meta. It's a new, hard legal line being drawn: this strategy argues that to speak about the harm you saw is itself an act of corporate theft. It tries to make whistleblowing impossible before a single fact is even disputed.
Mia: I keep hearing people say Ozempic just makes you eat less, but the gut-brain picture turns out to be stranger than that.
Milo: Stranger how?
Mia: The drug seems to hit the brain and the gut along parallel tracks, not one relay. GLP-1 receptors sit in both places, so when the drug lands, the brain starts interpreting gut fullness signals differently.
Milo: So it’s not just “stomach empties slower, you feel full.”
Mia: Right. The piece describes a kind of neural rewiring in the nucleus of the solitary tract, a brainstem region that gets vagus nerve input. Ozempic changes how that area rates the value of food cues, which means a bite can genuinely feel less urgent before digestion even kicks in.
Milo: That helps explain why some people lose interest in food they used to crave.
Mia: And why stopping the drug can feel disorienting. The brain’s appraisal system has been tuned down for months, then it wakes back up with the old hunger wiring. It’s a softer warning than a scare story, but it means coming off isn’t just about willpower.
Mia: I keep seeing the words "Strix Halo RDMA cluster guide" pop up, and then right next to it a lament about a world of AI slop. It feels like two signals from the same strange moment.
Milo: Right—so the AMD guide is genuinely useful hardware plumbing, and the slop essay halfway admits the jam scene now runs on incomplete AI output. The tension is, who’s actually going to read a dense cluster setup doc when the default is prompting a model that spits out slop?
Mia: The Strix Halo guide itself is pretty specific. It walks through direct GPU-to-GPU RDMA over Infinity Fabric, numa node pinning, and a full bootable image flow—not a blog summary.
Milo: So it’s the opposite of slop. But if the ecosystem around it is filling up with hollow AI-generated tutorials, does that guide land as a real tool or just get buried?
Milo: Which means the practical takeaway for a builder is almost counterintuitive: trust the primary.md in a repo, and skip the summarized feeds entirely.
Mia: So the practical takeaway from that last one is almost counterintuitive: trust the primary readme in a repo, and skip the summarized feeds entirely.
Milo: That's a good place to leave it. Thanks for listening, and we'll be back with more soon.