this post was submitted on 27 Jun 2026
31 points (89.7% liked)

Programmer Humor

31994 readers
271 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 3 years ago
MODERATORS
 

Found this on Lobsters, thought it was an entertaining read. For more context, you might want to read the previous instalment, CVE-2024-YIKES (also linked early on in the post itself).

top 5 comments
sorted by: hot top controversial new old
[–] Lojcs@piefed.social 2 points 1 hour ago* (last edited 1 hour ago)

This was very entertaining until I realized it's untagged satire. Now I'm pissed

Edit: Nvm, it is tagged satire I just didn't read the low contrast text

[–] Dadifer@lemmy.world 3 points 4 hours ago

The future is so much stupider than we anticipated.

[–] LPThinker@lemmy.world 6 points 5 hours ago

Depressingly plausible scenario. Software needs to become a licensed engineering field with professional liability or something soon!

[–] RustyNova@lemmy.world 7 points 5 hours ago

I was about to share it, then I saw it's satire.

Urgh

[–] Jakylla@jlai.lu -1 points 7 hours ago

Summary

A malicious package passed seven independent AI-powered security gates, each of which failed to stop it for a different reason, none of which was “the code is safe.” The incident was resolved when the attacker’s autonomous agent read a file it shouldn’t have, which is also how the incident started.

Seven LLMs were arranged in series. Six assumed another had read the code; the seventh read it and apologised.

Key Learnings

A cross-functional Agentic Security Working Group has been chartered, replacing the cross-functional Security Working Group established after CVE-2024-YIKES, which never met. The new working group’s kickoff has been scheduled by an AI calendaring assistant into the same slot as the CVE-2024-YIKES retrospective. The calendaring assistant has marked both as Tentative.