The blog post is the better link: https://invariantlabs.ai/blog/mcp-github-vulnerability
Yes. And to actually read the thread
https://xcancel.com/lbeurerkellner/status/192699149173542951...
(This was originally posted to https://news.ycombinator.com/item?id=44100082 but we've since merged the threads.)