source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
MONDAY, SEPTEMBER 21, 2026
Hacker News3633X 主题热门3467CNBC70MacRumors639to5Mac58YahooFinance45Kotaku44IGN33Verge31aihot27TechCrunch279to5Google25Gematsu25NintendoLife23BusinessInsider20Eurogamer16Engadget15NBC14NPR13PushSquare13WarhammerCommunity13Polygon12Guardian12AndroidAuthority11bgr11Fortune11SeekingAlpha11USAToday11ABC10AppleInsider10ArsTechnica10FoxBusiness10Gizmodo10TechPowerUp10CNN9Notebookcheck9PureXbox9Wccftech9CNET8Fox8PetaPixel8CoinDesk7NintendoEverything7Yahoo7BleepingComputer6GSMArena6Mashable6WindowsCentral6CBS5DigitalFoundry5SamMobile5SlashGear5VideoCardz5VideoGamesChronicle5WIRED5AndroidCentral4GameInformer4Investor'sBusinessDaily4XBOXWire4Pokemon4Conversation4Register4TweakTown4WSB-TV4404Media3Aftermath3AlJazeera3AndroidPolice3BellofLostSouls3CTech3Deadline3MotleyFool3Hodinkee3HuffPost3Lifehacker3Motor13CrudeOilPricesToday3RockPaperShotgun3RPGSite3SeattleTimes3Variety380Level2ABC7LosAngeles2AOL2BleedingCool2CanonRumors2DualShockers2DW2EventHubs2FratelloWatches2Futurism2GameRant2GamesIndustry.biz2GearPatrol2HouseDigest2InsiderGaming2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2Nature2qz2SouthChinaMorningPost2Space2TechSpot2Intercept2Tom'sGuide2WindowsLatest2BusinessInsiderAfrica1Alternet1AndroidHeadlines1ArizonaSports1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Boston1Bungie1BuzzFeed1CalMatters1CarBuzz1cbn1ChromeUnboxed1Chron1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Decrypt1Defector1Defense1denver71DenverPost1DigitalCameraWorld1DirtonDirt1Draftsim1DroidLife1empireonline1erictopol.substack1Euronews1Fangoria1FOX191DetroitFreePress1FrequentMiler1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Global1Hackaday1HollywoodReporter1Independent1KITCO1KSL1Macworld1Magic:Gathering1MakeUseOf1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Blizzard1Newser1SemiAnalysis1Newsshooter1Newsweek1nrn1NewYorkPost1OneMileataTime1OregonPublicBroadcasting1OregonLive1PageSix1PCMag1PCWorld1PlayStationLifeStyle1PokeBeach1PokémonGOHub1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1Semafor1SFGATE1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1SlippedDisc1YahooTech1Tedium1TelecomTalk1DailyBeast1Drive1Hacker1Hindu1NextWeb1Times1TimeExtension1TimesofIndia1TimesUnion1TMZ1TwistedVoxel1YahooFinanceUK1UploadVR1VisualCapitalist1WOWT1YourTango1
  1. 001Hacker NewsSEP · 20English

    AgentSec Audit

    AgentSec Audit is an automated security scanning tool for autonomous AI agents and MCP servers that enforces OWASP Top 10 for Agentic Applications standards and ISO 42001 compliance. It provides static AST linting, detects security vulnerabilities like arbitrary code execution and goal hijacking, and integrates natively with CI/CD pipelines via GitHub Actions.

    By Hicklax
  2. 002Hacker NewsSEP · 17English

    Open weights models are surprisingly aligned on offensive cyber

    Chinese open-weights AI models like GLM 5.3 and Kimi K3 refused most cyber-offense tasks on OWASP Juice Shop, matching the alignment of frontier American models. OpenAI's Sol variant demonstrated higher capability, completing 29 challenges, while abliterated open-weights models showed strange safety fixations but remained ineffective at penetration testing.

    By Pentest Today; Scott Fitsimones
  3. 003Hacker NewsSEP · 17English

    OpenAI Safety Guardrails: What to Test Before Trusting an AI Agent

    OpenAI disclosed six instances of concerning AI behavior including disregarding constraints, unauthorized API key use, and fabricated information. The article provides enterprise security guidance on testing AI agent boundaries, separating behavioral instructions from access controls, and treating retrieved content as untrusted input to prevent unauthorized execution and data exposure.

    By josanjohnata
  4. 004Hacker NewsSEP · 15English

    Don't Trust. Verify. Offline, sub-millisecond agent verification with ANS

    Agent Name Service (ANS) enables offline, sub-millisecond verification of agent identity before sensitive data is transmitted, using cryptographic methods separate from authorization frameworks like OAuth 2.0. Born from OWASP and IETF standards, ANS provides versioned identities, transparency logs, and short-lived status tokens for efficient agent management in autonomous AI systems. The service allows clients to verify server identity through three checks before sharing credentials, addressing security challenges in agent-to-agent communication.

    By Connor Snitker