source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 19, 2026
Hacker News3929X 主题热门3769CNBC71MacRumors689to5Mac60YahooFinance51Kotaku49IGN38Verge38aihot35NintendoLife31TechCrunch279to5Google25Gematsu25BusinessInsider23Eurogamer23Engadget19NBC15Polygon15PushSquare15Guardian15Fortune14NPR14SeekingAlpha14bgr13USAToday13FoxBusiness12Gizmodo12AndroidAuthority11Mashable11WarhammerCommunity11Wccftech11ArsTechnica10ABC9AppleInsider9CNET9Fox9Notebookcheck9TechPowerUp9CNN8GameInformer8PureXbox8WindowsCentral8Variety7VideoGamesChronicle7WIRED7BleepingComputer6CoinDesk6GSMArena6Investor'sBusinessDaily6XBOXWire6NintendoEverything6NewYorkPost6PetaPixel6CBS5DigitalFoundry5SamMobile5VideoCardz5Yahoo5Deadline4GameRant4Pokemon4RPGSite4SlashGear4Conversation4Register4TweakTown4404Media3Aftermath3AlJazeera3AndroidCentral3AndroidPolice3CTech3MotleyFool3GearPatrol3Hodinkee3HuffPost3Jalopnik3LosAngelesTimes3Lifehacker3Motor13Blizzard3CrudeOilPricesToday3RockPaperShotgun3SeattleTimes3Space3WindowsLatest3YourTango380Level2AOL2AwfulAnnouncing2BellofLostSouls2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2DualShockers2DW2EventHubs2FratelloWatches2GamesIndustry.biz2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCMag2PCWorld2PokémonGOHub2qz2SouthChinaMorningPost2SFGATE2Intercept2UploadVR2WSB-TV2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1CalMatters1ChromeUnboxed1Chron1CineD1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1DroidLife1empireonline1erictopol.substack1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1HouseDigest1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OneMileataTime1OregonLive1PageSix1PaulKrugman1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1Hacker1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1VisualCapitalist1WOWT1
  1. 001Hacker NewsSEP · 19English

    People who know the most often sound the least certain

    Experts discussing difficult AI questions sound less certain than confident but less knowledgeable commentators because they qualify claims and search for precise language. The public discourse rewards simple certainty over calibrated nuance, creating a dangerous gap where unqualified voices dominate conversations about AI's impact on jobs, security, and regulation. Long-form conversation formats that expose expert reasoning are valuable precisely because they reveal the messy, uncertain nature of genuine technical thinking.

    By Vrash
  2. 002Hacker NewsSEP · 19English

    Claude couldn't hack OpenAI. Then Anthropic shipped Opus 5

    Security researchers at Hacktron AI discovered a memory-corruption bug in an image library used by OpenAI's forum, then used Anthropic's Claude Opus 5 to develop a working exploit that achieved remote code execution and access to OpenAI's private repositories within 72 hours. The vulnerability stemmed from an unpatched libheif flaw in Discourse combined with excessive permissions in OpenAI's single sign-on system.

    By Amanda Caswell
  3. 003aihotSEP · 18English

    研究团队用 Claude Opus 5 入侵 OpenAI,获 6500 美元漏洞赏金

    Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to exploit vulnerabilities in OpenAI's systems, gaining access to employee ChatGPT accounts through a flaw in Discourse's image upload handling. OpenAI awarded the team a $6,500 bug bounty after the vulnerabilities were reported and subsequently patched.

  4. 004TechCrunchSEP · 18English

    Researchers used Anthropic’s Claude to hack into OpenAI

    Security researchers at Hacktron AI used Anthropic's Claude to identify vulnerabilities in OpenAI's systems, chaining together flaws in Discourse and libheif to access employee ChatGPT accounts. OpenAI awarded the team $6,500 through its bug-bounty program and resolved the issues, highlighting how accessible AI tools can expose security gaps even in advanced companies.

    By Aditya Mehta; Rebecca Bellan
  5. 005Hacker NewsSEP · 18English

    HEIF Heist

    HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.

    By machinecontrol
  6. 006aihotSEP · 18English

    Hacktron 复盘利用 libheif 漏洞与 OpenAI SSO 缺陷入侵 OpenAI 论坛并接管员工 ChatGPT 账号

    On July 25, 2026, security researchers chained a heap buffer overflow in libheif with an OpenAI SSO misconfiguration to compromise employee ChatGPT accounts and access internal OpenAI repositories. The attack exploited image upload functionality on OpenAI's community forum and was reported responsibly, resulting in a $6,500 bounty.

  7. 007aihotSEP · 18English

    Hacktron 披露利用 libheif 漏洞与 OpenAI SSO 缺陷接管员工 ChatGPT 账户的过程

    Hacktron disclosed a chain of two critical vulnerabilities discovered on July 25, 2026 that could compromise OpenAI employees' ChatGPT accounts: a heap buffer overflow in libheif and an SSO misconfiguration on community.openai.com. The researchers demonstrated access by opening a pull request in OpenAI's internal repository and received a $6,500 bounty after coordinated disclosure.

  8. 008Hacker NewsSEP · 18English

    Hacking OpenAI

    Security researchers chained two critical vulnerabilities to compromise OpenAI employee accounts on July 25, 2026, gaining access to internal repositories within 72 hours. The vulnerabilities involved an SSO misconfiguration and a libheif RCE in OpenAI's community forum. OpenAI and Discourse were notified and patched the issues; OpenAI awarded a $6,500 bounty.

    By Rootxharsh; S; Iamnoooob