source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 16, 2026
Hacker News3926X 主题热门3802CNBC84MacRumors80YahooFinance679to5Mac63Kotaku47Verge46IGN369to5Google34aihot34NintendoLife34Gematsu32Eurogamer28TechCrunch27Engadget26BusinessInsider25Guardian20NBC16NPR16CNET15Polygon15FoxBusiness14Fortune13SeekingAlpha13bgr12Gizmodo12PushSquare12USAToday12Wccftech12CBS11Mashable11TechPowerUp11WIRED11Investor'sBusinessDaily10GameInformer9NintendoEverything9ABC8ArsTechnica8CNN8Fox8Notebookcheck8NewYorkPost8CrudeOilPricesToday8VideoGamesChronicle8WindowsCentral7AppleInsider6BleepingComputer6PetaPixel6SamMobile6Deadline5DigitalFoundry5GamesIndustry.biz5Variety5Yahoo5AlJazeera4AndroidPolice4CoinDesk4DroidLife4MotleyFool4GameRant4GSMArena4Jalopnik4PureXbox4SlashGear4Hacker4AP3BuzzFeed3CTech3CanonRumors3ChromeUnboxed3DW3GameDeveloper3Lifehacker3Motor13Blizzard3XBOXWire3PCMag3PCWorld3SeattleTimes3Space3Register3TweakTown3VideoCardz3YGOrganization3ZDNET324/7WallSt.2404Media2Aftermath2AndroidCentral2AOL2AwfulAnnouncing2BleedingCool2DigitalCameraWorld2DualShockers2Euronews2EventHubs2FratelloWatches2Futurism2GearPatrol2Hodinkee2Independent2KITCO2MassivelyOverpowered2MyNintendo2Nature2Newser2Newsweek2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2RPGSite2Conversation2Intercept2NextWeb2Tom'sGuide2UploadVR2WarhammerCommunity2WindowsLatest2YourTango243rumors1ABC111AboveLaw1ageofempires1AndroidHeadlines1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1CyberSecurityNews1DailyKos1DCRainmaker1Defector1DenverPost1derekthompson1Draftsim1CNN1flatpanelshd1FrequentMiler1GAMINGbible1garymarcus.substack1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InsiderGaming1InterconnectsAI1InterestingEngineering1JapanTimes1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MiddleEastEye1MonochromeWatches1MortgageDaily1MP1st1MPR1SemiAnalysis1Newsshooter1NoMan'sSky1nylon.com.sg1NYT1OregonLive1PCGamesN1PersonaCentral1Pokemon1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1ScienceAlert1ScientificAmerican1SouthChinaMorningPost1Semafor1SFGATE1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1Tedium1TelecomTalk1GameBusiness1TheGamer1Times1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WhatHi-Fi?1WPBF1WRAL1
  1. 001Hacker NewsSEP · 16English

    What is LLMjacking, and why should IT pros care?

    LLMjacking is a cybersecurity threat where attackers use stolen cloud credentials to gain unauthorized access to victims' paid AI model services and computing resources. The tactic has evolved from simple freeloading to building offensive attack tools, with threat actors now leveraging compromised LLMs for malicious purposes rather than just personal use. IT professionals should implement defenses like short-lived credentials, least-privilege access, usage monitoring, and strong authentication practices.

    By Billy Hurley
  2. 002Hacker NewsSEP · 16English

    Show HN: LaunchPad-Lite – Open-Source Next.js 15 with Better Auth and Drizzle

    LaunchPad-Lite is a free, open-source Next.js 15 starter template featuring authentication via Better Auth, Drizzle ORM with PostgreSQL, and a pre-built dashboard with dark mode support. Built by BZDevelopments and MIT licensed, it provides a foundation for full-stack applications with no additional dependencies or costs.

    By BZDevelopments
  3. 003Hacker NewsSEP · 16English

    Residential proxies as the next front in the AI wars

    AI providers face obstacles accessing fresh internet data as publishers monetize access and domains block scraper bots. Authentication requirements emerge as a solution, but raise privacy concerns similar to UK age-verification laws. Residential proxies—IP addresses from ordinary broadband users—offer a workaround to bypass VPN detection and access restrictions.

    By Martin Anderson
  4. 004Hacker NewsSEP · 16English

    Signal registration without a phone number now available in Android beta

    Signal has launched Signal Login, an optional registration method allowing users to create accounts without phone numbers, first on Android then iOS. The feature requires a one-time $2.99 payment to prevent spam, uses zero-knowledge proofs for privacy, and remains optional alongside traditional phone-number-based registration.

    By AboutSignal
  5. 0059to5MacSEP · 16English

    Apple explains how the iPhone 18 Pro’s new Reference Image camera mode works

    Apple introduced Reference Image, a new camera mode on iPhone 18 Pro designed to verify photograph authenticity through a chain-of-custody system that begins at sensor initialization during manufacturing. The system uses cryptographic signing, Private Cloud Compute processing, and quantum-resistant encryption to create verifiable digital negatives while preserving photographer anonymity and protecting against manipulation throughout the editing chain.

    By Marcus Mendes
  6. 006Hacker NewsSEP · 16English

    Noise-Coded Illumination for Forensic and Photometric Video Analysis

    Researchers propose embedding subtle noise-like illumination patterns into video scenes to create temporal watermarks that help detect manipulated footage. This approach creates an information asymmetry favoring verification, making it difficult for adversaries to create convincing fake videos even when aware of the technique, with applications for protecting high-stakes public events and interviews.

    By Michael; Peter F; Hao; Zekun; Belongie; Serge; Davis; Abe
  7. 007MacRumorsSEP · 16English

    Apple Details How Reference Image Proves a Photo is Real

    Apple introduced Apple Reference Image on iPhone 18 Pro models to cryptographically verify that photos were taken with an iPhone and haven't been edited or AI-generated. The feature boots the camera sensor into a specialized mode that signs pixel data immediately after capture, creating a secure digital negative protected from software tampering and verified through Private Cloud Compute.

    By Juli Clover
  8. 008Hacker NewsSEP · 16English

    Breaking macOS Screen Time for fun and profit

    A security researcher details methods for bypassing macOS Screen Time protections, explaining how the 4-digit PIN system flows through UI, controller, XPC, and CoreData layers. The analysis reveals that Apple stores PINs as plain text in an SQLite database and documents the lockout escalation mechanism and Mach services involved in the verification process.

    By Kieran Klukas
  9. 009Hacker NewsSEP · 15English

    What made global e-commerce possible (it wasn't encryption)

    Global e-commerce emerged not from encryption but from existing liability structures and pragmatic solutions like cookies and credit card tokenization. Physical credentials—premises, cards, IDs—were abandoned online, and identity verification was replaced by fraud modeling based on behavior and history rather than actual verification.

    By zerolayers
  10. 010Hacker NewsSEP · 15English

    You don't need a kernel 0day

    A security engineer argues that attackers often succeed through social engineering and trust-building rather than technical exploits like kernel vulnerabilities. The article cites examples like the Revolut incident where impersonation worked, and warns that legitimate-seeming products or services can be used to collect sensitive data and access, especially as people increasingly grant permissions to AI tools and third-party integrations without adequate scrutiny of security practices and data access controls.

    By speckx
  11. 011Hacker NewsSEP · 15English

    Show HN: Open-source passive NFC tag that signs with ECDSA, verified on-chain

    toluTag is an open-source passive NFC tag using NXP SE05x secure elements to sign ECDSA messages verifiable on Ethereum, enabling physical objects to authenticate on-chain without requiring central servers or extractable private keys.

    By Mwbpnftechnology
  12. 012Hacker NewsSEP · 15English

    .NET MVC Recommended Resources

    Resource compilation for ASP.NET MVC developers covering getting started guides, Azure cloud deployment, and security best practices including authentication, OAuth integration, and CSRF prevention.

    By Brysonbw
  13. 013Hacker NewsSEP · 14English

    Gateway HTTP for Telegram

    Flux is an HTTP gateway that connects Telegram accounts via MTProto and exposes them through a REST API, real-time SSE streams, and signed webhooks. Built on NestJS, Prisma, PostgreSQL, and Redis, it manages multiple Telegram instances with a Vue 3 dashboard, supporting message operations, media handling, and durable event delivery with HMAC-signed webhook payloads.

    By PedroL
  14. 014Hacker NewsSEP · 14English

    Sign in as Y Combinator

    TrustedRouter offers a sign-in integration for apps to verify Y Combinator company affiliation through OAuth and verified email domains. Users authenticate with company context including company name, domain, and founding year, with the system checking email verification and funding organization match before granting company-specific benefits.

    By ljlolel
  15. 015Hacker NewsSEP · 14English

    Hacking AI customer service agents

    Security researcher Inti De Ceukelaire demonstrated vulnerabilities in AI customer service agents at DEF CON 34, revealing techniques to bypass authentication, exfiltrate data, and execute unauthorized actions through prompt injection, email spoofing, and knowledge base exploitation—findings that generated over $50,000 in bug bounties.

    By Ayoub; Inti De Ceukelaire
  16. 016BleepingComputerSEP · 14English

    CISA: Hackers now exploit max severity GitLab flaw in attacks

    CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.

    By Sergiu Gatlan
  17. 017Hacker NewsSEP · 14English

    Recursive Self-Improvement (RSI)

    Content appears to be a browser session management interface with messages about account activity across tabs. No substantive news or content to analyze.

    By Theseus-Labs-Rsi
  18. 018Hacker NewsSEP · 14English

    Detecting and Weaponizing NetScaler

    CVE-2026-19490 is a critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway affecting SAML handling. An unauthenticated request exploits the vulnerability to execute post-login code, with impact ranging from crash to root access depending on configuration. Patches are available in versions 13.1-63.21 and 14.1-73.32 or later.

    By Jon Williams; Threat Enablement; Analysis Team
  19. 019X 主题热门SEP · 14English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-14 04:01 UTC

    A cybersecurity interview preparation post containing 15 sample questions and answers covering fundamental concepts like the CIA Triad, threat vs. vulnerability vs. risk, authentication vs. authorization, incident response, encryption types, and security tools.

  20. 020Hacker NewsSEP · 14English

    Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping

    Chess.com exposed 7.3 million user records through data scraping rather than a direct breach. The leaked file contains usernames, emails, names, countries, chess ratings, and internal Google Ad Manager audience tags, but no passwords or payment data. Evidence suggests the data was collected over nine days using the platform's find-friends feature, similar to a 2023 incident but at roughly nine times the scale.

    By Pierluigi Paganini