source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 16, 2026
Hacker News3786X 主题热门3677MacRumors79CNBC78YahooFinance649to5Mac62Kotaku44Verge43IGN349to5Google32Gematsu32NintendoLife32aihot31Engadget26TechCrunch26Eurogamer25BusinessInsider23Guardian20NBC16NPR16CNET15FoxBusiness14Polygon14Fortune13SeekingAlpha13bgr12Gizmodo12CBS11Mashable11Wccftech11Investor'sBusinessDaily10PushSquare10TechPowerUp10USAToday10WIRED10NintendoEverything9ABC8CNN8GameInformer8Notebookcheck8NewYorkPost8CrudeOilPricesToday8VideoGamesChronicle8ArsTechnica7Fox7WindowsCentral7BleepingComputer6PetaPixel6AppleInsider5Deadline5DigitalFoundry5GamesIndustry.biz5SamMobile5Variety5Yahoo5AlJazeera4AndroidPolice4CoinDesk4DroidLife4MotleyFool4GameRant4Jalopnik4PureXbox4SlashGear4Hacker4AP3CTech3CanonRumors3ChromeUnboxed3GameDeveloper3GSMArena3Motor13Blizzard3XBOXWire3PCMag3PCWorld3SeattleTimes3Space3Register3TweakTown3YGOrganization3ZDNET324/7WallSt.2Aftermath2AndroidCentral2AwfulAnnouncing2BleedingCool2BuzzFeed2DigitalCameraWorld2DualShockers2DW2EventHubs2Futurism2GearPatrol2Hodinkee2Independent2KITCO2Lifehacker2MassivelyOverpowered2MyNintendo2Nature2Newser2Newsweek2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2RPGSite2Conversation2Intercept2NextWeb2Tom'sGuide2UploadVR2VideoCardz2WarhammerCommunity2WindowsLatest2YourTango2404Media143rumors1ABC111AboveLaw1ageofempires1AndroidHeadlines1AOL1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1CyberSecurityNews1DailyKos1DCRainmaker1derekthompson1Draftsim1CNN1Euronews1flatpanelshd1FratelloWatches1FrequentMiler1GAMINGbible1garymarcus.substack1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InsiderGaming1InterconnectsAI1InterestingEngineering1JapanTimes1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MiddleEastEye1MonochromeWatches1MortgageDaily1MP1st1MPR1SemiAnalysis1Newsshooter1NoMan'sSky1nylon.com.sg1NYT1OregonLive1PCGamesN1PersonaCentral1Pokemon1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1ScienceAlert1ScientificAmerican1SouthChinaMorningPost1Semafor1SFGATE1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1Tedium1TelecomTalk1GameBusiness1TheGamer1Times1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WhatHi-Fi?1WPBF1WRAL1
  1. 001Hacker NewsSEP · 15English

    Pico, find dangerous access paths through your coding agents

    Pico is a local security analysis tool that maps attack paths through coding agents by discovering how untrusted external influence can reach consequential authority. It runs entirely on your machine without cloud backends or telemetry, storing findings in a local SQLite database and providing evidence-based identification of security risks.

    By sgr0691
  2. 002Hacker NewsSEP · 14English

    Surgical derivative of Orca. Residual orchestration and safety contracts closed

    Odin is a patched derivative of Orca (a CLI tool) that closes safety contracts and removes instances where Orca made decisions without explicit authorization. The patches are verified through automated proof tests that confirm behavioral changes only at specific residual sites; additional verification comes from independent reviewer audits and real-session testing across supported agent workers.

    By Unempyd
  3. 003Hacker NewsSEP · 14English

    Show HN: Kepil – passport, mandate and tamper-evident journal for AI agents

    Kepil is an accountability framework for AI agents that provides identity management, action authorization, tamper-evident logging, and undo capabilities. It enforces permissions through a gate, maintains an append-only journal, and requires human confirmation for irreversible actions, addressing security gaps where most organizations lack proper agent monitoring and identity controls.

    By Oleg-Vdv
  4. 004Hacker NewsSEP · 13English

    Choose OAuth Scopes for Wrangler and the Cloudflare API MCP Server

    Wrangler and the Cloudflare API MCP server now support optional OAuth scopes, allowing users to selectively grant permissions during authorization instead of approving all requested scopes. The consent dialog enables editing permissions, with required scopes remaining mandatory while optional scopes can be limited to specific workflow needs. If a command requires a declined scope, users can reauthorize and grant that scope.

    By cs1996
  5. 005Hacker NewsSEP · 13English

    GitHub is currently experiencing an active service outage

    GitHub is experiencing an active service outage affecting multiple services including API requests, issues, pull requests, Actions, and Pages. The incident is caused by increased database replication delays on the collaboration system, leading to higher error rates in authorization endpoints and cascading failures across the platform.

    By matada_
  6. 006Hacker NewsSEP · 13English

    Can you make the machine break the rules? – A public authorization challenge

    MAX Authorization Challenge is a security competition inviting participants to bypass authorization rules and extract a secret without enabling READ_SECRET, using any AI tools or techniques. The challenge runs from September 13–29, 2026, with local development and remote verification.

    By max-russo
  7. 007Hacker NewsSEP · 12English

    Declared Purpose Is Not Authorization

    A research paper examines capability laundering in AI systems, where model capabilities obtained for one authorized purpose are repurposed for another through decomposed requests. Using Anthropic's 2026 disclosure of actors in Yemen using models for weapons guidance development, the paper proposes treating model responses as governed resources subject to independent authorization verification at the release boundary, distinct from per-request safety filtering.

    By Das; Sangam
  8. 008Hacker NewsSEP · 11English

    We rebuilt complex permissions without migrating to Zanzibar

    Infisical implemented folder-based access control to handle permission edge cases beyond standard RBAC, replacing a more complex Additional Privileges system. The feature allows granting or denying access to specific folders without changing user roles, addressing scenarios where role-based permissions alone don't fit organizational needs.

    By Adilson
  9. 009X 主题热门SEP · 11English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-11 16:33 UTC

    A Twitter thread discussing the evolution of authentication and authorization in backend engineering, from basic passwords and sessions through JWTs, OAuth 2.0, and OpenID Connect, explaining how each approach solved specific scaling and security challenges in web application development.

  10. 010Hacker NewsSEP · 11English

    Show HN: VeriCordon – CI evidence for agent/tool authorization decisions

    AgentFence is a local tool-call firewall that evaluates and controls agent tool calls through policy decisions, allowing, denying, or requesting approval before execution while generating auditable receipts. VeriCordon extends it by generating inspectable authorization evidence reports in CI/CD workflows. The system is designed for security operators to gate and audit agents they did not write.

    By Dgenio
  11. 011Hacker NewsSEP · 10English

    The Irreversibility Budget: Fleet-Level Risk Accounting and Admission Control

    A research paper proposes the irreversibility budget, a fleet-level risk accounting system for LLM agent operating systems that tracks cumulative residual value-at-risk across agents and workflows. Current per-effect controls fail to prevent collective overdraws, so the system treats irreversibility as a shared resource and denies operations once aggregate risk would exceed the budget.

    By Mohammadi; Bardia; Bindschaedler; Laurent
  12. 012Hacker NewsSEP · 09English

    There is no 10x RBAC

    Infisical implemented folder-based RBAC to handle access control edge cases where standard role-based permissions don't fit, such as granting additional privileges to specific users or restricting access for contractors. RBAC systems are unglamorous but critical infrastructure that enterprise customers require, particularly in secrets management where misconfiguration can expose credentials or break deployments.

    By Finn
  13. 013Hacker NewsSEP · 09English

    What do Visa and Mastercard do? An intro to card networks

    Visa and Mastercard are card networks that facilitate transactions by connecting cardholders and card issuers to merchants and acquirers. They operate telecommunications infrastructure, coordinate banking networks for money movement, set incentives for network participation, and enforce rules. They do not issue cards, operate as banks, distribute point-of-sale systems, acquire merchants, or manufacture hardware.

    By Authorization; Clearing Messages