source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 16, 2026
Hacker News3645X 主题热门3529MacRumors78CNBC72YahooFinance649to5Mac59Kotaku44Verge43IGN339to5Google32aihot31Gematsu31NintendoLife30TechCrunch25Engadget24Eurogamer24BusinessInsider23Guardian20CNET15NBC15NPR15FoxBusiness14Fortune13Polygon13SeekingAlpha13bgr12Gizmodo12CBS11Wccftech11Investor'sBusinessDaily10Mashable10TechPowerUp10USAToday10WIRED10PushSquare9CNN8NintendoEverything8Notebookcheck8NewYorkPost8CrudeOilPricesToday8VideoGamesChronicle8ABC7ArsTechnica7Fox7GameInformer7WindowsCentral7BleepingComputer6AppleInsider5Deadline5GamesIndustry.biz5PetaPixel5Variety5Yahoo5AndroidPolice4DigitalFoundry4DroidLife4MotleyFool4GameRant4Jalopnik4PureXbox4SamMobile4SlashGear4Hacker4AlJazeera3AP3CanonRumors3ChromeUnboxed3CoinDesk3GameDeveloper3GSMArena3Motor13Blizzard3XBOXWire3PCMag3PCWorld3SeattleTimes3Register3TweakTown3YGOrganization3ZDNET324/7WallSt.2Aftermath2AndroidCentral2AwfulAnnouncing2BleedingCool2BuzzFeed2CTech2DualShockers2DW2EventHubs2Futurism2Hodinkee2Independent2Lifehacker2MassivelyOverpowered2MyNintendo2Nature2Newser2Newsweek2PaulKrugman2PokémonGOHub2RoadtoVR2RPGSite2Space2Conversation2NextWeb2Tom'sGuide2UploadVR2VideoCardz2WarhammerCommunity2WindowsLatest2YourTango2404Media143rumors1ABC111AboveLaw1ageofempires1AndroidHeadlines1AOL1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1CyberSecurityNews1DailyKos1DCRainmaker1derekthompson1DigitalCameraWorld1Draftsim1CNN1Euronews1flatpanelshd1FrequentMiler1GAMINGbible1garymarcus.substack1GearPatrol1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InsiderGaming1InterconnectsAI1InterestingEngineering1JapanTimes1KITCO1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MiddleEastEye1MonochromeWatches1MPR1SemiAnalysis1Newsshooter1NoMan'sSky1nylon.com.sg1NYT1OregonLive1PCGamesN1PersonaCentral1Pokemon1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1RockPaperShotgun1SammyGuru1ScienceAlert1ScientificAmerican1SouthChinaMorningPost1Semafor1SFGATE1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1Tedium1TelecomTalk1GameBusiness1TheGamer1Intercept1Times1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WhatHi-Fi?1WPBF1WRAL1
  1. 001Hacker NewsSEP · 12English

    Finding Zero-Days with Any Model

    A researcher demonstrates that zero-day vulnerability discovery is not exclusive to frontier AI models like Anthropic's Mythos, but can be achieved through orchestration frameworks like IronCurtain using commercial models (Opus, Sonnet) and open-weight models (GLM 5.1). The author replicated Anthropic's discovery of a 27-year-old OpenBSD TCP SACK vulnerability and autonomously found new zero-days, though at significant token costs ($30–$150 per investigation).

    By wslh
  2. 002HackadaySEP · 12English

    This Week In Security: It’s Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs

    Microsoft's August 2026 Patch Tuesday delivers nearly 1,000 security fixes, including two actively exploited zero-day privilege escalation vulnerabilities and a critical remote code execution bug in Windows DNS. LG smart TVs extensively collect user data for ad targeting, tracking viewing habits, device fingerprints, and network information even when disabled, while containing numerous security vulnerabilities that could expose home networks.

    By Mike Kershaw
  3. 003Hacker NewsSEP · 11English

    Microsoft Plugs Nearly 1k Security Holes

    Microsoft released 974 security patches in September, its largest single batch ever, with 113 critical flaws including two actively exploited zero-days. AI-assisted vulnerability discovery is accelerating patch volumes across major software vendors, but security experts warn organizations struggle to test and deploy fixes at this scale.

    By Bender
  4. 004HackerSEP · 10English

    Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

    Four espionage-linked threat groups deployed an undisclosed exploit kit called BlueMoon within a week, chaining vulnerabilities in Windows and Chrome to achieve code execution and privilege escalation. APT31 first used BlueMoon on August 28, 2026, targeting NGOs and trading firms via phishing, with other China-aligned actors following days later. The kit exploits patched Chromium flaws and a Windows buffer overflow to inject malware and steal credentials.

    By The Hacker News
  5. 005HackerSEP · 09English

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google patched 230 security vulnerabilities in Chrome, including CVE-2026-87491, an out-of-bounds write in V8 that enables arbitrary code execution within the sandbox and has been actively exploited in the wild. Researcher Jihyeon Jeong discovered the flaw and received a $2,500 bug bounty; Google has not disclosed attack details but confirmed exploits exist in the wild.

    By The Hacker News
  6. 006HackerSEP · 09English

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft released a record 974 security patches addressing vulnerabilities across Windows, Office, SQL, and Developer Tools, including two actively exploited zero-day flaws in Windows. The update brings the total resolved vulnerabilities to 999 when including non-Microsoft CVEs, with over 110 assigned critical severity ratings.

    By The Hacker News
  7. 007Hacker NewsSEP · 09English

    Google warns of new Chrome zero-day bug exploited in attacks

    Google patched 230 vulnerabilities including CVE-2026-87491, a seventh actively exploited Chrome zero-day in 2025. The high-severity flaw in the V8 engine allows remote attackers to execute arbitrary code via crafted HTML. Updates are rolling out across Windows, Mac, and Linux.

    By Sergiu Gatlan
  8. 008BleepingComputerSEP · 09English

    Google warns of new Chrome zero-day bug exploited in attacks

    Google patched 230 vulnerabilities including CVE-2026-87491, a seventh actively exploited Chrome zero-day this year stemming from an out-of-bounds write in the V8 engine. The high-severity flaw allows remote attackers to execute arbitrary code via crafted HTML pages. Updates rolled out to Windows, Mac, and Linux systems and should reach most users within days or weeks.

    By Sergiu Gatlan
  9. 009RegisterSEP · 09English

    Microsoft breaks Patch Tuesday record with 974-CVE deluge

    Microsoft released 974 CVE patches in its latest Patch Tuesday, setting a new record. The deluge of security updates highlights ongoing vulnerabilities across Microsoft's product portfolio, including critical issues in on-premises SharePoint under active zero-day attack.

    By Jessica Lyons
  10. 010KrebsonSecuritySEP · 09English

    Microsoft Plugs Nearly 1,000 Security Holes

    Microsoft released updates for 974 security vulnerabilities, its largest single patch batch ever, with 113 rated critical and two active zero-day exploits. AI-assisted discovery is accelerating vulnerability detection across major software companies, but organizations struggle to test and deploy patches at the increasing pace.