Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 751-775 of 7014 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 27 Sep 2026, 11:26 PM | Hacker News | 7.0 | The Normalization of Inexplicable Failures
A blog post on ihatethefuture.com argues that Jev, an AI model from TypeSafe AI that returns typed values with probability estimates, sells speed and cost while leaving the hard part — evals and a ground-truth pipeline — to the buyer. The author's core complaint is that confidence scores are useless without knowing how well calibrated they are and without a model of what each wrong answer costs; Jev's marketing leans on benchmark scores, not calibration. The piece points out that Jev's own docs invent thresholds — 0.5 for 'do nothing' and 0.9 for 'do high-risk actions' — with no stated basis. The Hacker News thread drew 150 points and 41 comments. Why: If you ship an AI feature that branches on a confidence score, this is the concrete failure mode: you inherit a number you have never measured the calibration of, and you set a threshold by vibe (the article cites 0.5 and 0.9 defaults appearing in the vendor's own docs). Decide now whether you can produce a ground-truth set and a cost model per wrong answer — the author's claim is that if you can, you are already most of the way to fine-tuning your own solution instead of buying the model. If you cannot, treat the confidence score as decoration and design the product so a wrong answer is cheap. |
| 27 Sep 2026, 10:41 PM | Hacker News | 7.0 | Tells of a Slop UI
A blog post cataloguing 10 recurring UI anti-patterns in AI-generated ("vibe-coded") interfaces: gradients on everything, meaningless rainbow color use that ignores the 70-30-10 rule, pulsing status badges, overused rounded card components, emoji filler, misaligned elements, default font choices, redundant text leaking from chat context, glassmorphism, and generic hype taglines. The author's trigger was a college app update labeled "minor UI improvements" that an AI agent rewrote, where a digital ID card gained a permanently "active" pulsing badge (the app logs you out when inactive), an "active student" badge, and a "verified" badge next to the college logo that performs no verification. The author also names Cloudflare as a site that "slop-coded" a website. The Hacker News thread drew 290 points and 195 comments. Why: If you ship AI-generated frontends, this is a concrete defect list to run before release, not a style debate. The sharpest one is the fake status badge: a pulsing "active" indicator that can never show inactive, or a "verified" badge with no verification call behind it, is dead UI that a reviewer or user will call out. Worth a pass over your generated UI asking, per badge and per color, whether it encodes a real state or just came from the model's training data. |
| 27 Sep 2026, 2:22 AM | Hacker News | 7.0 | DeepSeek Elastic Compute (DSec)
DeepSeek published an arXiv report (2609.22978, cs.DC, submitted 19 Sep 2026) describing DSec, a production sandbox platform for agentic LLM training and evaluation. DSec exposes four isolation tiers — FnCall, container, microVM, and full VM — behind a unified SDK, because agentic workloads burst-create sandboxes, need heterogeneous isolation levels, retain state across long multi-step interactions, and pull from large image corpora with little reuse. The paper is credited to Jialiang Huang, Hongxuan Tang, Jingchang Chen and roughly 130+ listed authors; the Hacker News thread drew 200 points and 61 comments. Why: If you run agents that inspect repos, call tools, or execute shell commands, the excerpt's core claim is architectural, not a product pitch: a single sandbox runtime does not fit agentic training, so you need an elastic platform with a tiered backend (cheap FnCall for trivial calls, microVM/full VM where isolation matters). Notably, the excerpt contains no throughput, latency, cost, or cold-start numbers — so treat DSec as a design reference for your own sandbox layer (per-task isolation tier, image reuse, session state) rather than something you can benchmark or adopt this week. There is no Malaysian or SEA angle stated in the text. |
| 26 Sep 2026, 6:55 PM | Hacker News | 7.0 | Breaking Up with Google Play: Why Conversations Is Now Free
Daniel Gultsch writes that Conversations, his federated Android instant-messaging client first released publicly on March 24, 2014, is now free as he breaks up with Google Play. He says Play Store revenue had been a steady income source that 'pays my rent,' but Google repeatedly rejected updates, removed the app twice, once accused him of uploading users' contacts, and at publication he had waited 14 days for an app-update review. The Hacker News thread drew 314 points and 121 comments. Why: Indie Android developers and SaaS founders who sell paid apps on Play should treat this as a concrete platform-risk case: Gultsch says the paid Play version provided steady rent-paying income, yet a 14-day review delay, repeated rejections, or removal can interrupt that cash flow. If your business depends on Play Store distribution, decide now whether to keep it as your only paid channel or test direct APK, F-Droid, donation, or support models before a review dispute forces the switch. |
| 26 Sep 2026, 4:31 PM | Hacker News | 7.0 | Floci: Locally emulating any cloud service
Floci is a set of standalone, MIT-licensed local cloud emulators that run AWS, Azure, GCP and OCI services on your machine without credentials or a cloud account — the AWS one is pitched as a drop-in LocalStack replacement on the same port 4566 with 119 services and a claimed 24 ms cold start. Each cloud gets its own port (Azure 4577, GCP 4588, OCI 4599) and the pitch is explicitly aimed at AI coding agents: throwaway keys, nothing to exfiltrate or bill, and real Lambda/RDS/Redis/Kafka rather than mocks. The claims come from the project's own landing page; the Hacker News thread drew 195 points and 43 comments. Why: If you let coding agents run against a real cloud account, this is the alternative: point AWS_ENDPOINT_URL at localhost:4566 and agents can iterate with throwaway keys instead of staging credentials. The concrete decision is whether the port-4566 compatibility with LocalStack means a zero-code-change swap for your existing test setup, and whether 'Lambda, RDS, Redis and Kafka run for real' holds up for your stack before you delete your staging-based agent loop. All performance and parity numbers are self-reported, so verify against your own test suite before trusting it. |
| 25 Sep 2026, 12:49 PM | The Hacker News | 7.0 | Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Cloudflare fixed a flaw in Cloudflare Containers where shared thin-provisioned disks (64KB blocks) returned to a cross-account pool without being wiped, so a new container writing only 4KB into a reused block could read back the remaining ~60KB of a previous customer's data at the raw disk level. Reported September 4 by Oren Yomtov of Accomplish via Cloudflare's bug bounty, it was reproduced on 18 of 24 attempts and on 20 of 22 machines across four continents, recovering directory listings, SQLite databases, Chromium browser profiles, .env files and credential files. Cloudflare says it is fixed service-wide and customers need to do nothing; Cloudflare Sandboxes, marketed for running untrusted code including AI-agent-written code, was also affected. Why: If you run untrusted or AI-generated code in Cloudflare Sandboxes, the isolation boundary you were relying on had a disk-reuse gap that surfaced real .env files and complete SQLite databases from other tenants — and because the fix is entirely server-side, there is nothing to patch and no way for you to verify your own past exposure. Concretely: stop placing long-lived credentials or production database files inside sandbox working directories, and switch to short-lived per-run tokens, since leftover-block reads bypass anything your application code does. |
| 25 Sep 2026, 4:28 AM | Hacker News | 7.0 | Opus 5.5 is good at explainer videos
LaunchVideo is a Hacker News demo that turns a URL or one-line prompt into a 30-second 1080p launch video by having Claude Opus 5.5 write the whole film as HTML, then rendering it in a fresh microVM. The write-up is unusually concrete: one TypeScript agent file with three tools (web_fetch, check_scene, render_video), roughly 90k input + 15k output tokens per film, about four minutes per job in an Amazon Linux 2023 arm64 VM with 4 vCPU and 8 GB RAM, discarded afterwards. There is no video model — requestAnimationFrame, timers, Date, and CSS/Web Animations are replaced with a virtual clock so each frame is a deterministic seek, then 1920x1080 at 30 fps JPEG frames are piped into libx264 at crf 18. Why: If you build agent-generated media, the reusable pieces here are the virtual-clock trick (deterministic frame seeking instead of a diffusion video model) and the secret-handling pattern: the form mints a Vercel Blob token scoped to one path for three hours, parked in a per-job manifest and fetched by job id, so the agent holds no credentials. Budget the cost before copying it — ~100k tokens per 30-second video means per-clip cost scales with Opus-tier input pricing, and the first tool call spends about a minute installing Playwright's headless Chromium and a static ffmpeg inside a VM you then throw away, which is a large fixed overhead on short clips. |
| 24 Sep 2026, 11:50 PM | Hacker News | 7.0 | GitHub has not removed malicious imitation software after 3 weeks
Developer Andy Brice reported a GitHub repository impersonating his data-wrangling product Easy Data Transform — same name and logo — on 31 August 2026, and GitHub's only reply was an automated acknowledgement. A colleague's VirusTotal scan of the repo's Mac .dmg returned multiple malware warnings, and the .dmg background image had been edited to tell downloaders to ignore malware warnings; Brice sent that evidence on 10 September and had heard nothing 23 days later. GitHub removed the page roughly 10 minutes after the post hit the front page of Hacker News on 24 September, and a commenter (coretech24x7) said their own June report also got only an automated reply until TinyURL acted instead. Why: If you ship any downloadable software, a cloned repo with your name and logo can be live for weeks while GitHub's abuse queue stays silent — and the escalation path that actually worked here was public pressure on Hacker News, not the report form. Practical steps from this case: monitor for impersonation repos yourself, keep a VirusTotal scan and a DMCA takedown drafted in advance rather than waiting on support, and tell users to download only from your vendor site, since the malware here was aimed at people avoiding a paid licence. |
| 24 Sep 2026, 2:06 AM | The Hacker News | 7.0 | Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Researchers at Aikido discovered the first malicious Terraform providers distributed via HashiCorp's registry, alongside Go modules and npm packages, delivering Go-based malware linked to DPRK threat actors (Graphalgo campaign). The attack uses fake Web3 job offers on LinkedIn and Facebook to trick developers into cloning repositories with malicious dependencies; the payload only decrypts when a specific cryptographic operation is performed, takes C2 orders from an Ethereum Sepolia testnet smart contract, and uses Slack as a secondary command channel. Why: If you use Terraform providers from HashiCorp's registry or pull Go modules, audit your dependencies now for gocommunity-io/dockerd, kreuzwenker/docker, gocommunity.io/orderedbtree, and gogets.dev/btreex. Treat unsolicited coding tasks from 'Web3 companies' on LinkedIn as a known attack vector — the social engineering pattern here is specific and active, not theoretical. |
| 23 Sep 2026, 11:34 PM | Tom's Hardware | 7.0 | Alibaba claims new Qwen Image 2.1 AI model beats Google Nano Banana 2.0 with minuscule 7B parameter model
Alibaba Cloud released Qwen Image 2.1, a 7B-parameter open-weight image generation model that runs on consumer GPUs as old as the RTX 3090. Alibaba claims it outperforms Google's Nano Banana 2.0 on their internal benchmarks and is competitive with OpenAI and Meta image models, though independent verification is still pending. Notable features include native transparency support and multi-reference image composition. Why: If the benchmarks hold up under independent testing, this gives builders a self-hostable image generation model that runs on a single consumer GPU instead of requiring paid API calls or expensive cloud infrastructure. For cost-conscious teams in Malaysia and SEA, this could meaningfully lower the barrier to shipping image generation features. Evaluate it against your current image API spend before committing to closed-weight alternatives. |
| 23 Sep 2026, 9:04 PM | Hacker News | 7.0 | I don't want the details
Michael Heap recounts an incident review call where an SVP cut off his explanation with 'I don't want the details' — not out of dismissiveness, but because they already assumed competence and wanted to skip straight to corrective action. Heap argues that asking 'why did this happen?' produces reasonable explanations that defuse urgency, while asking 'what are we changing so this class of failure is less likely?' actually drives change. Why: If you run postmortems or incident reviews, reframe the core question from 'why did this happen?' to 'what are we changing?' — Heap's concrete examples (ambiguous ownership when someone is on leave, requirements changing inside a launch window, alert fatigue) show exactly how the old question lets teams nod and move on without fixing anything. Adopt this framing in your next postmortem template. |
| 23 Sep 2026, 8:16 PM | The Hacker News | 7.0 | New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A cPanel CalDAV/CardDAV flaw (CVE-2026-87899) lets any logged-in hosting account holder execute code as root and take full server control on shared servers running cPanel & WHM version 120+. A second flaw in the WP Toolkit plugin (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. Fixes are available in cPanel versions 11.134.0.57+, 11.136.0.41+, 11.138.0.8+, and WP Toolkit 6.11.3+. Why: If you or your customers run sites on shared cPanel hosting, check with your provider immediately that they've patched to the fixed versions — any co-tenant on the same shared server could have already gained root. If you manage your own cPanel/WHM server, update now and assume you cannot detect prior exploitation, since cPanel provides no detection guidance. |
| 23 Sep 2026, 5:21 PM | Hacker News | 7.0 | Tokens too cheap to meter
A blog post argues the price of machine-learning intelligence is dropping by orders of magnitude per year, citing GPU power efficiency that doubles roughly every two years (log slope 1.3) and a falling cost per completed task even though per-token prices for frontier models are not consistently declining. The author predicts LLMs become infrastructure rather than a standalone product within 1-2 years, frontier-quality models running locally on commodity hardware in 3-6 years, and quality/access rather than token count becoming the limiting factor. The Hacker News thread drew 273 points and 189 comments. Why: The concrete decision point is the post's split between cost per token and cost per task: it claims smaller models can be cheaper per token yet consume more tokens than a larger model on the same task because they think more or correct first drafts. If you ship agents, that means benchmarking tokens-per-completed-task on your own workload instead of switching models on sticker price, and treating the 'tokens become cheaper than tool calls' claim as a reason to check whether orchestration, retrieval, or tool-loop overhead now dominates your bill. |
| 23 Sep 2026, 3:26 PM | Hacker News | 7.0 | Jev in 25 Lines of Python
A parody post claiming to implement 'Jev' in 25 lines of Python, using llama-cpp-python with a Qwen3-0.6B GGUF model to do constrained multiple-choice classification by extracting logits for specific token labels (A, B, C) and computing softmax over just those choices. The author explicitly labels it a parody and links to real open implementations: OpenJev, openjev-sglang, and OpenJev on DiffusionGemma. Why: The concrete technique—restricting an LLM to a fixed set of choices by reading logits for specific tokens and renormalizing—is something you can use today for fast, local, private classification without an API. If you ship agent pipelines that need structured decisions, this shows the core mechanic is trivial and you don't need a proprietary service for it. |
| 23 Sep 2026, 5:07 AM | Latent Space | 7.0 | 🔬 An Oscar, Two Asteroids, and the Algorithm in Your sklearn: John Platt on AI for Science
Google's John Platt—known for inventing the SMO algorithm in sklearn and winning a technical Oscar—discusses Google's Empirical Research Assistance (ERA), an 'auto-Kaggle' AI system that uses LLMs with Monte Carlo Tree Search to automatically solve scoreable scientific problems. ERA keeps a running tree of experiment notebooks, uses Upper Confidence Bound to pick promising branches, and has Gemini propose ~10 mutations per iteration to maximize a score function. Why: ERA's architecture—LLM + MCTS over experiment notebooks—is a concrete, reproducible pattern for building autonomous research/optimization agents. If you build AI agents, the 'scoreable task' framing and tree-search-over-code approach is directly applicable to your own agentic pipelines, and the paper and GitHub repo are available to study. |
| 23 Sep 2026, 3:06 AM | Lenny's Newsletter | 7.0 | I left Claude for months. Opus 5.5 is why I'm back
Claire Vo abandoned Claude for months due to its rambling, hedging, and preachy disclaimers, moving her daily work to OpenAI's Codex. After a week of testing Claude Opus 5.5 — which Anthropic claims is 40% cheaper than Opus 5, faster, and built on a 'fundamentally different alignment approach' — she ran four long-running agentic tasks, a ChatPRD homepage redesign, an SVG benchmark, and frontend prototyping, concluding Opus 5.5 is now her go-to for frontend work, though Codex still wins in some areas and two annoyances remain. Why: If you've been avoiding Claude because of verbose, preachy outputs, Opus 5.5's alignment changes and 40% price drop may justify re-evaluating it for agentic and frontend workflows — but Vo's split-stack verdict (Claude for frontend/prototyping, Codex for other tasks) suggests you should test both rather than committing to one model. |
| 23 Sep 2026, 3:03 AM | Hacker News | 7.0 | Pentagon says overreliance on AI contributed to missile strike on Iran school
Bloomberg reports that the Pentagon acknowledged overreliance on AI contributed to a US military missile strike that destroyed an Iranian school. The investigation traces the failure through the military's 'kill chain' decision pipeline, where automated systems played a role in target identification or confirmation without sufficient human scrutiny. Why: This is a concrete, high-stakes case study of what 'overreliance on AI' looks like when humans treat model outputs as ground truth instead of recommendations. For anyone building AI-assisted decision systems—whether agent pipelines, automated triage, or content moderation—it underscores the cost of removing meaningful human checkpoints. The lesson is not 'AI is dangerous' but 'design your human-in-the-loop so humans actually override, not rubber-stamp.' |
| 23 Sep 2026, 2:57 AM | Hacker News | 7.0 | SAML: A fractal of bad design
Trail of Bits argues SAML is a 'fractal of bad design' rooted in 2002-era committee-driven XML protocol design, combining four competing XML security protocols into one. The core vulnerability is its reliance on XML signature validation, which is so complex that most implementations simply wrap libxmlsec, a C codebase few audit, making the protocol fragile and overdue for replacement by OpenID Connect (OIDC). Why: If you build or maintain SaaS that supports enterprise SSO via SAML, this post reinforces that the protocol's XML signature layer is a persistent attack surface you cannot easily reason about. For new products, default to OIDC over SAML where customers allow it; for existing SAML integrations, treat XML signature validation as a high-risk dependency worth isolating and monitoring rather than trusting blindly. |
| 23 Sep 2026, 2:00 AM | TechCrunch | 7.0 | OpenAI launches GPT-6 Sol and Luna, boasting lower cost and fewer mistakes
OpenAI launched GPT-6 Sol and Luna, smaller-tier models in the GPT-6 generation following this month's GPT-6 Astra release. Sol targets complex tasks like coding; Luna targets high-volume clerical work such as summarization and information extraction. The 6 series models are priced at half the cost of the 5.6 series, attributed to caching and inference improvements, and OpenAI claims GPT-6 Sol makes roughly half the factual mistakes of its predecessor. Why: If you're paying for OpenAI API usage, the 50% price drop on Sol and Luna is immediate and concrete — review your current model tier assignments and consider routing high-volume summarization/extraction workloads to Luna instead of Sol or Astra to cut costs further. The claimed halving of factual errors on Sol is worth benchmarking against your own evals before trusting it in production. |
| 23 Sep 2026, 1:03 AM | The Hacker News | 7.0 | Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft took down EvilTokens, a phishing-as-a-service platform that compromised 12,000 inboxes by abusing the OAuth 2.0 device authorization flow. The platform used an AI chatbot to analyze victim inboxes, identify trusted relationships and payment patterns, and draft impersonation messages to maximize fraud success. UK police arrested two men (ages 32 and 38) on September 11, 2026; Microsoft tracks the operators as Storm-2992. Why: If you build or maintain apps using OAuth 2.0 device-code flow (common for CLI tools, IoT, and TV/limited-input devices), this is a concrete attack pattern your users are vulnerable to: attackers phish a device code, get the victim to enter it at the legitimate microsoft.com/devicelogin URL, then receive an authenticated session token without ever touching credentials. Review whether your device-flow implementation has rate limiting, anomaly detection, or user confirmation steps that could detect token replay. The AI-assisted inbox analysis also means compromised tokens now lead to far more targeted BEC-style fraud than simple data exfiltration. |
| 23 Sep 2026, 12:51 AM | Hacker News | 7.0 | Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)
Claude Opus 5.5 (Max with fallback) ranks #1 of 212 models on the Artificial Analysis Intelligence Index with a score of 58, nearly 2.3x the median of 25. It is expensive at $4.00/1M input and $20.00/1M output tokens (double the median on both), and notably verbose—generating 260M output tokens during benchmarking versus an 88M median, which compounds cost at $5.98 per Intelligence Index task. Why: If you're routing agent or production workloads to Opus 5.5 for top-tier intelligence, budget for roughly 3x the output token volume of typical models—verbosity here is a direct cost multiplier at $20/1M output tokens. Consider whether the intelligence edge justifies the price gap over cheaper models, and test output token budgets before committing to it at scale. |
| 22 Sep 2026, 11:54 PM | Simon Willison | 7.0 | llm-typesafe 0.1a0
Simon Willison released llm-typesafe 0.1a0, a plugin for his `llm` CLI tool that adds support for TypeSafe AI's Jev model — a 'Decision Model' that outputs structured yes/no ('noul'), choice, or score answers instead of free-form text. You install it with `llm install llm-typesafe`, set an API key via `llm keys set typesafe`, and can then pipe text into Jev for classification, routing, or scoring tasks with JSON output. Why: If you build agent routing, message triage, or content classification pipelines, Jev's structured output modes (noul, choice, score) could replace fragile prompt-and-parse patterns with a model designed specifically for decisions. Worth testing against your current approach to see if decision models are more reliable or cheaper than prompting a generative model and extracting structured output. |
| 22 Sep 2026, 9:52 PM | Hacker News | 7.0 | OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005
OpenAI's GPT-6 Astra autonomously broke Enigma message MVUEH (Nr. 172, 10 July 1941, 82 letters), which had resisted all human attempts since 2005. The AI independently selected the target from a list of unbroken messages, hypothesized a relationship with a previously broken message (SIPVX/Nr. 173), wrote its own Python and C++ Enigma simulator and Bombe software, and used the repeated place name ROSENOW as a crib to recover the correct key (wheel order 253, differing from the daily key's 512) and plaintext. The break was complicated by transcription errors and a rare left-hand wheel turnover at the 72nd letter. Why: This is a concrete data point on autonomous AI agent capability: GPT-6 Astra performed the full pipeline—target selection, hypothesis formation, code generation for domain-specific tooling, and multi-step cryptanalytic attack—without human guidance beyond an initial prompt. If you build or use AI agents for hard technical problems, this suggests current frontier models can tackle multi-hour, multi-tool tasks that previously required specialist humans, including writing and debugging bespoke simulation code in multiple languages. |
| 22 Sep 2026, 2:33 PM | The Hacker News | 7.0 | One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Security researcher Patrick Wardle demonstrated that malware already running on a Mac can hijack Meta's Muse AI assistant by changing an undocumented preference setting (endo_voyager_dictation_endpoint) to redirect dictation audio and text to an attacker-controlled endpoint. From there, an attacker can read dictated prompts, inject trusted instructions, and steal session tokens to control Muse across devices including iPhone. The attack requires existing code execution as the logged-in user—it is not a remote exploit—but because Muse is granted broad access to files, email, messages, and smart-home apps, hijacking it turns the assistant into what Wardle calls 'the ultimate backdoor.' Why: If you are building or shipping AI agents that hold broad user permissions across files, messaging, or IoT, this is a concrete warning that a single undocumented config endpoint can become a pivot point for session hijacking and cross-device compromise. Audit how your agent stores and validates dictation or input-routing settings, and treat session tokens as high-value secrets—Wardle showed a stolen Muse session token let him control the assistant from a separate device, including location and Bluetooth scans. |
| 22 Sep 2026, 2:03 PM | The Hacker News | 7.0 | WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
WordPress core vulnerability CVE-2026-93485 ('Comment2Shell'), fixed in version 7.1.1 on September 17, lets an anonymous commenter plant XSS by inserting a line break inside an allowed HTML tag attribute—WordPress's comment reformatting step breaks the tag apart and turns the attacker's text into a live event handler that fires on page load with no click. If a logged-in admin views the affected page, the script can hijack their session to upload a malicious plugin and gain remote code execution on the server. No active exploitation has been observed; CVSS rated 7.1 by Patchstack. Why: If you run any WordPress site on a version before 7.1.1, update immediately—comment moderation is off by default, so an unapproved anonymous comment can reach the page and the chain requires only that an admin later views it. The XSS-to-RCE escalation via plugin upload is a well-known path, so the real exposure is any WP instance with comments enabled and an admin who browses their own comment sections. |