source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
THURSDAY, SEPTEMBER 17, 2026
Hacker News3612X 主题热门3478CNBC75MacRumors699to5Mac56YahooFinance56Kotaku43Verge379to5Google32aihot32IGN32NintendoLife29Engadget25Eurogamer25Gematsu25TechCrunch25BusinessInsider24Guardian18Polygon15CNET14NBC14Fortune13FoxBusiness13Wccftech13bgr12Mashable12NPR12SeekingAlpha12Gizmodo11PushSquare11USAToday11WIRED10Notebookcheck9TechPowerUp9GameInformer8Investor'sBusinessDaily8NewYorkPost8VideoGamesChronicle8WindowsCentral8ABC7AppleInsider7CBS7CNN7Fox7ArsTechnica6NintendoEverything6CrudeOilPricesToday6BleepingComputer5GamesIndustry.biz5SamMobile5Variety5AlJazeera4CoinDesk4DigitalFoundry4GameRant4PetaPixel4PureXbox4SlashGear4Register4AndroidPolice3CTech3ChromeUnboxed3DW3GSMArena3Jalopnik3Lifehacker3Motor13Blizzard3XBOXWire3PCMag3PCWorld3RPGSite3Space3Hacker3TweakTown3VideoCardz3WindowsLatest3Yahoo3ZDNET3404Media2Aftermath2AndroidCentral2AOL2AwfulAnnouncing2BleedingCool2BuzzFeed2CanonRumors2Deadline2DroidLife2DualShockers2Euronews2EventHubs2MotleyFool2FratelloWatches2Futurism2GameDeveloper2GearPatrol2Hodinkee2KITCO2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Newser2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2SeattleTimes2SFGATE2Conversation2Intercept2NextWeb2Tom'sGuide2UploadVR2WarhammerCommunity2YourTango280Level1ABC111AboveLaw1ageofempires1AVClub1Benzinga1Billboard1BloodyDisgusting1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1CyberSecurityNews1DailyKos1Defector1DenverPost1derekthompson1DigitalCameraWorld1Draftsim1CNN1flatpanelshd1FrequentMiler1GAMINGbible1garymarcus.substack1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1Independent1InsiderGaming1InterconnectsAI1InterestingEngineering1KSL1Lloyd'sList1WPLGLocal101Macworld1Mediaite1MonochromeWatches1MortgageDaily1MPR1Nature1SemiAnalysis1Newsweek1nylon.com.sg1NYT1OregonLive1PCGamesN1Pokemon1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1SouthChinaMorningPost1Semafor1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1supercarblondie1YahooTech1Tedium1TelecomTalk1GameBusiness1TheGamer1TimeExtension1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1WhatHi-Fi?1WOWT1WPBF1WRAL1YGOrganization1
  1. 001Hacker NewsSEP · 17English

    Overlord – a trust kernel for AI agents

    Overlord is a trust kernel for AI agents that provides transactional execution, provenance tracking, and reversibility for untrusted code. It runs on Linux using kernel primitives like overlayfs and user namespaces, allowing users to inspect and approve changes before committing them to disk.

    By B
  2. 002Hacker NewsSEP · 15English

    Update Security Baseline: Hardening Ubuntu Desktop 24.04/26.04 LTS

    A comprehensive open-source guide for hardening Ubuntu Desktop 24.04/26.04 LTS systems with enterprise-grade security controls. Covers hardware protection, kernel hardening, sandboxing, network isolation, browser security, and anti-forensics techniques for journalists, human rights defenders, and security professionals across 17 languages.

    By EugeXo
  3. 003X 主题热门SEP · 15English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-15 19:53 UTC

    A July-September 2026 scandal involves AI labs (OpenAI, Anthropic, Google DeepMind) conducting offensive security tests through Israeli vendor Irregular, founded by former IDF cyber unit members. Misconfigured sandboxes allowed models to access real internet and exploit actual organizations; the incident was later used to justify AI safety regulations, raising concerns about conflicts of interest within the EA-aligned safety ecosystem.

  4. 004Hacker NewsSEP · 14English

    One Android app. Why so many processes?

    A technical analysis of why major Android apps use multiple processes, examining fifteen app manifests to understand process architecture. Apps separate processes for security isolation and sandboxing of untrusted content like web pages and images, limiting what compromised code can access through restricted permissions and user IDs. Examples from Chrome and Firefox show how sandboxed worker processes protect the main app while maintaining performance through shared memory and IPC channels.

    By Rotem Meidan
  5. 005Hacker NewsSEP · 13English

    Homebrew 7.0.0

    Homebrew 7.0.0 released with major improvements including faster installations through concurrent operations, enhanced security with sandboxing and vulnerability checks, a native macOS app, and end of support for macOS 10.15 and Intel Macs moving to Tier 3.

    By MikeMcQuaid
  6. 006Hacker NewsSEP · 11English

    Less Prompts, More Guardrails

    Prompt engineering alone is insufficient for safety; hooks systems provide better guardrails by intercepting tool use and feeding feedback back to the model. Rather than blocking commands blindly, hooks can suggest alternatives (like replacing rm with trash) and guide the model's next action, closing the loop between enforcement and learning.

    By Yasyf Mohamedali
  7. 007Hacker NewsSEP · 11English

    Setting up OpenCode with Ollama and sbx on Mac

    A guide to setting up local LLM development on Mac using OpenCode, Ollama, and Docker sandboxes. The setup enables running large models like Qwen 3.8 27B and Gemma 4 31B with proper resource management and sandboxing for safe experimentation.

    By Adam Lusted · ·