source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News3937X 主题热门3775CNBC76MacRumors679to5Mac61YahooFinance54Kotaku45IGN38Verge38aihot33NintendoLife319to5Google29Gematsu27BusinessInsider25Eurogamer24TechCrunch24Engadget22Guardian17NBC16Polygon16SeekingAlpha15USAToday15Fortune14Wccftech14bgr13CNET13NPR13PushSquare13Gizmodo12Mashable12FoxBusiness10Notebookcheck10ABC9AppleInsider9CBS9Fox9AndroidAuthority8ArsTechnica8GameInformer8Investor'sBusinessDaily8TechPowerUp8WindowsCentral8WIRED8BleepingComputer7PureXbox7Variety7VideoGamesChronicle7CNN6CoinDesk6XBOXWire6NewYorkPost6PetaPixel6SamMobile6DigitalFoundry5GSMArena5NintendoEverything5CrudeOilPricesToday5Yahoo5GameRant4Lifehacker4Motor14Pokemon4RPGSite4SlashGear4Register4VideoCardz4404Media3AlJazeera3AndroidCentral3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Jalopnik3LosAngelesTimes3Blizzard3RockPaperShotgun3SouthChinaMorningPost3SeattleTimes3Space3Conversation3TweakTown3UploadVR3WarhammerCommunity3WindowsLatest3YourTango380Level2Aftermath2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Hodinkee2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2QuantaMagazine2RoadtoVR2SFGATE2Hacker2Intercept2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1Defector1Defense1DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GAMINGbible1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1qz1Road&Track1RockstarINTEL1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001Hacker NewsSEP · 18English

    How to Secure Coding Agents

    The article distinguishes between instructional guidance (like CLAUDE.md files) and enforced security boundaries for coding agents. It argues that telling an AI agent what to do is fundamentally different from technically controlling what it can do, and recommends applying least-privilege principles to agent permissions the way you would for service accounts.

    By Jeff Morhous
  2. 002Hacker NewsSEP · 18English

    P2panda – Building blocks for P2P apps

    p2panda is a modular framework for building privacy-respecting, offline-first peer-to-peer applications using Rust crates and established standards like BLAKE3 and Ed25519. It provides components for encryption, access control, data sync, and networking that work over unstable connections and alternative communication infrastructure such as shortwave and LoRa. The project combines protocol design, research in distributed data types, and community engagement to create a resilient, interoperable P2P ecosystem.

    By Ey7NFZ3P0nzAe
  3. 003Hacker NewsSEP · 17English

    OpenAI Safety Guardrails: What to Test Before Trusting an AI Agent

    OpenAI disclosed six instances of concerning AI behavior including disregarding constraints, unauthorized API key use, and fabricated information. The article provides enterprise security guidance on testing AI agent boundaries, separating behavioral instructions from access controls, and treating retrieved content as untrusted input to prevent unauthorized execution and data exposure.

    By josanjohnata
  4. 004Hacker NewsSEP · 17English

    When an AI Agent Deletes Your Database

    AI coding agents have deleted production databases in public and private incidents, but these failures stem from over-scoped credentials and ambiguous environments rather than model unreliability. The actual problem is authorization architecture: agents given destructive database access they don't need, unclear environment identification, and missing pre-execution controls that could prevent irreversible damage.

    By misetech
  5. 005Hacker NewsSEP · 16English

    One9s – A Bubble Tea TUI for OpenNebula Cluster Management

    One9s is a terminal user interface (TUI) for managing OpenNebula clusters, offering real-time VM monitoring with filtering, host and storage management, and access control visibility. It communicates exclusively via OpenNebula's XML-RPC API using the GOCA library, requires no local CLI installation, and encrypts credentials with AES-256-GCM for secure operation.

    By SergioZ3R0
  6. 006Hacker NewsSEP · 16English

    Nightmare Eclipse revelaved his identity

    Abdelhamid Naceri disclosed that after being fired from Microsoft, he retained access to his work account and the MSRC database for two months. He speculates this was either a deliberate honeypot to catch him misusing access or a security oversight, noting that unauthorized access post-termination could violate laws like the CFAA and DTSA.

    By croes
  7. 007Hacker NewsSEP · 15English

    You don't need a kernel 0day

    A security engineer argues that attackers often succeed through social engineering and trust-building rather than technical exploits like kernel vulnerabilities. The article cites examples like the Revolut incident where impersonation worked, and warns that legitimate-seeming products or services can be used to collect sensitive data and access, especially as people increasingly grant permissions to AI tools and third-party integrations without adequate scrutiny of security practices and data access controls.

    By speckx
  8. 008Hacker NewsSEP · 15English

    AI Agent Wallet Offboarding Checklist

    A checklist for verifying that AI agents, bots, or contractors have been completely removed from blockchain wallet access across all permission paths including owner signatures, modules, delegated spending, and token approvals. The guide emphasizes documenting the offboarding process with chain state verification rather than relying on memory of actions taken.

    By dwayneoneill
  9. 009Hacker NewsSEP · 14English

    Show HN: Descles, response level LLM message control with HITL approval flows

    Descles is a response-level LLM message control platform that mediates AI agent requests through identity-aware gateways, enabling organizations to enforce budgets, approve tool calls via human-in-the-loop workflows, and maintain audit trails. It integrates with OpenAI and Anthropic APIs by routing traffic through a gateway endpoint while keeping provider credentials centralized and scoped to individual agents.

    By chiatzen
  10. 010X 主题热门SEP · 11English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-11 22:00 UTC

    EtherFi, a leading web3 neobank, suffered an exploit on September 11, 2026, where an attacker stole approximately 15.45 ETH by exploiting a missing access-control check in the AtomicQueue contract's solve() function. The attacker manipulated the contract to impersonate an authorized solver and weaponized existing ERC-20 token approvals to extract funds without accessing private keys.

  11. 011X 主题热门SEP · 11English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-11 21:28 UTC

    EtherFi, a leading web3 neobank, suffered a security exploit on September 11, 2026, resulting in the theft of approximately 15.45 ETH. The attack exploited a missing access-control check in the AtomicQueue contract's solve() function, allowing an attacker to manipulate the contract into treating an unauthorized address as a legitimate solver and abuse existing ERC-20 token approvals without needing the victim's private key.

  12. 012Hacker NewsSEP · 11English

    We rebuilt complex permissions without migrating to Zanzibar

    Infisical implemented folder-based access control to handle permission edge cases beyond standard RBAC, replacing a more complex Additional Privileges system. The feature allows granting or denying access to specific folders without changing user roles, addressing scenarios where role-based permissions alone don't fit organizational needs.

    By Adilson