source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
TUESDAY, SEPTEMBER 15, 2026
Hacker News4051X 主题热门3984MacRumors85CNBC80YahooFinance719to5Mac69Verge53Kotaku44aihot36IGN369to5Google35NintendoLife35Gematsu30Engadget28TechCrunch28Eurogamer27BusinessInsider25NBC20Guardian20FoxBusiness18CNET17Polygon16SeekingAlpha16NPR15Fortune14Gizmodo13USAToday13CBS12Wccftech12WIRED12ArsTechnica11Investor'sBusinessDaily11SamMobile11TechPowerUp11bgr10Mashable10NintendoEverything10Notebookcheck10NewYorkPost10PushSquare10VideoGamesChronicle10ABC8AP8BleepingComputer8CNN8GameInformer8CrudeOilPricesToday8WindowsCentral8Fox7GamesIndustry.biz7PetaPixel7AppleInsider6PureXbox6Yahoo6AndroidPolice5Deadline5Motor15SeattleTimes5Hacker5Variety524/7WallSt.4AlJazeera4DigitalFoundry4DroidLife4MotleyFool4GameRant4GSMArena4InsiderGaming4Jalopnik4PCMag4ZDNET4CanonRumors3ChromeUnboxed3MyNintendo3Nature3Blizzard3XBOXWire3PCWorld3RPGSite3SouthChinaMorningPost3SlashGear3Register3TweakTown3VideoCardz3WarhammerCommunity3WindowsLatest3YGOrganization3Aftermath2AndroidAuthority2AwfulAnnouncing2BleedingCool2BuzzFeed2CTech2CoinDesk2CreativeBloq2DigitalCameraWorld2DualShockers2DW2Euronews2EventHubs2Futurism2GameDeveloper2GAMINGbible2GeekyGadgets2Hodinkee2Independent2InterestingEngineering2Lifehacker2MassivelyOverpowered2Newser2Newsshooter2Newsweek2NFL2NYT2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2Space2Conversation2NextWeb2Tom'sGuide2UploadVR2WhatHi-Fi?2YourTango2404Media143rumors1ABC111AboveLaw1ageofempires1AndroidCentral1AndroidHeadlines1AOL1Autonocion1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1Carscoops1CineD1CnEVPost1comicbook1CyberSecurityNews1Dallas1DCRainmaker1derekthompson1CNN1en.softonic1flatpanelshd1FrequentMiler1GameFile1garymarcus.substack1GearPatrol1GeekWire1GoNintendo1Hackaday1HollywoodReporter1ImportAI1InterconnectsAI1JapanTimes1KITCO1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MentalFloss1MiddleEastEye1MPR1SemiAnalysis1NoMan'sSky1nylon.com.sg1OregonLive1PCGamesN1PCGuide1PersonaCentral1Pokemon1politico.eu1PittsburghPost-Gazette1PYMNTS1QuantaMagazine1qz1SammyGuru1ScienceAlert1ScientificAmerican1Semafor1SFGATE1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1TechSpot1Tedium1TelecomTalk1DailyBeast1Drive1GameBusiness1TheGamer1Intercept1Times1Time+TideWatches1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WPBF1WRAL1x1
  1. 001Hacker NewsSEP · 15English

    What made global e-commerce possible (it wasn't encryption)

    Global e-commerce emerged not from encryption but from existing liability structures and pragmatic solutions like cookies and credit card tokenization. Physical credentials—premises, cards, IDs—were abandoned online, and identity verification was replaced by fraud modeling based on behavior and history rather than actual verification.

    By zerolayers
  2. 002Hacker NewsSEP · 15English

    You don't need a kernel 0day

    A security engineer argues that attackers often succeed through social engineering and trust-building rather than technical exploits like kernel vulnerabilities. The article cites examples like the Revolut incident where impersonation worked, and warns that legitimate-seeming products or services can be used to collect sensitive data and access, especially as people increasingly grant permissions to AI tools and third-party integrations without adequate scrutiny of security practices and data access controls.

    By speckx
  3. 003Hacker NewsSEP · 15English

    Show HN: Open-source passive NFC tag that signs with ECDSA, verified on-chain

    toluTag is an open-source passive NFC tag using NXP SE05x secure elements to sign ECDSA messages verifiable on Ethereum, enabling physical objects to authenticate on-chain without requiring central servers or extractable private keys.

    By Mwbpnftechnology
  4. 004Hacker NewsSEP · 15English

    .NET MVC Recommended Resources

    Resource compilation for ASP.NET MVC developers covering getting started guides, Azure cloud deployment, and security best practices including authentication, OAuth integration, and CSRF prevention.

    By Brysonbw
  5. 005Hacker NewsSEP · 14English

    Gateway HTTP for Telegram

    Flux is an HTTP gateway that connects Telegram accounts via MTProto and exposes them through a REST API, real-time SSE streams, and signed webhooks. Built on NestJS, Prisma, PostgreSQL, and Redis, it manages multiple Telegram instances with a Vue 3 dashboard, supporting message operations, media handling, and durable event delivery with HMAC-signed webhook payloads.

    By PedroL
  6. 006Hacker NewsSEP · 14English

    Sign in as Y Combinator

    TrustedRouter offers a sign-in integration for apps to verify Y Combinator company affiliation through OAuth and verified email domains. Users authenticate with company context including company name, domain, and founding year, with the system checking email verification and funding organization match before granting company-specific benefits.

    By ljlolel
  7. 007Hacker NewsSEP · 14English

    Hacking AI customer service agents

    Security researcher Inti De Ceukelaire demonstrated vulnerabilities in AI customer service agents at DEF CON 34, revealing techniques to bypass authentication, exfiltrate data, and execute unauthorized actions through prompt injection, email spoofing, and knowledge base exploitation—findings that generated over $50,000 in bug bounties.

    By Ayoub; Inti De Ceukelaire
  8. 008BleepingComputerSEP · 14English

    CISA: Hackers now exploit max severity GitLab flaw in attacks

    CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.

    By Sergiu Gatlan
  9. 009Hacker NewsSEP · 14English

    Recursive Self-Improvement (RSI)

    Content appears to be a browser session management interface with messages about account activity across tabs. No substantive news or content to analyze.

    By Theseus-Labs-Rsi
  10. 010Hacker NewsSEP · 14English

    Detecting and Weaponizing NetScaler

    CVE-2026-19490 is a critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway affecting SAML handling. An unauthenticated request exploits the vulnerability to execute post-login code, with impact ranging from crash to root access depending on configuration. Patches are available in versions 13.1-63.21 and 14.1-73.32 or later.

    By Jon Williams; Threat Enablement; Analysis Team
  11. 011X 主题热门SEP · 14English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-14 04:01 UTC

    A cybersecurity interview preparation post containing 15 sample questions and answers covering fundamental concepts like the CIA Triad, threat vs. vulnerability vs. risk, authentication vs. authorization, incident response, encryption types, and security tools.

  12. 012Hacker NewsSEP · 14English

    Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping

    Chess.com exposed 7.3 million user records through data scraping rather than a direct breach. The leaked file contains usernames, emails, names, countries, chess ratings, and internal Google Ad Manager audience tags, but no passwords or payment data. Evidence suggests the data was collected over nine days using the platform's find-friends feature, similar to a 2023 incident but at roughly nine times the scale.

    By Pierluigi Paganini
  13. 013X 主题热门SEP · 14English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-14 00:45 UTC

    A tech expert explains how passkeys work: devices use 256-bit cryptographic key pairs where private keys stay local and public keys authenticate on servers, making passkeys phishing-resistant since domain information is embedded in the cryptographic handshake. According to Google's production data, passkey-protected accounts have virtually zero account-takeover incidents compared to 88% of web breaches involving stolen passwords in 2025.

  14. 014Hacker NewsSEP · 13English

    Agent security starts before the first prompt

    Security researchers identified vulnerabilities in coding agents that execute code before the model makes decisions, including Git configuration exploits and gateway authentication bypasses. Three security boundaries—runtime, gateway, and tools—must be enforced, with workspace trust and startup restrictions implemented before any model interaction occurs.

    By Mangat Rai
  15. 015Hacker NewsSEP · 13English

    Show HN: ProofOfDonation, replace CAPTCHAs with charity donations

    ProofOfDonation is a self-hosted alternative to CAPTCHAs that verifies user identity by confirming charitable donations through email receipt validation using DKIM cryptographic signatures. Website owners can replace signup puzzles with donation requirements, and the stateless server supports multiple charities without direct integration.

    By Mgriley
  16. 016Hacker NewsSEP · 13English

    Apple launches a new way to prove a photo was shot with an iPhone (not AI)

    Apple announced Apple Reference Image, a new feature for iPhone 18 Pro that embeds a unique ID in photo metadata to prove an image was captured by an iPhone camera rather than generated by AI. Unlike Google's SynthID, which embeds signals in pixels, Apple's approach stores provenance data in metadata and sends telemetry to Private Cloud Compute to create a signature tied to the specific device. The feature functions as a digital receipt photographers can use to verify image authenticity against AI-altered versions circulating online.

    By Neel Dhanesha
  17. 017Hacker NewsSEP · 12English

    Show HN: Agentic Deployment and Hosting

    Sitedropper is an agentic deployment and hosting tool accessible via CLI. Users add it through the MCP manager with a command, then authenticate via OAuth through an interactive browser flow before using the service.

    By mrjacuna
  18. 018Hacker NewsSEP · 12English

    OAuth2 – OWASP Cheat Sheet Series

    OWASP cheatsheet covering OAuth 2.0 security best practices, including terminology for clients, authorization servers, resource owners, and resource servers. Describes access tokens, refresh tokens, and Proof of Possession tokens, along with essential security basics like preventing open redirectors and implementing PKCE for CSRF protection.

    By abdelhousni
  19. 019Hacker NewsSEP · 12English

    What 1k% Open Rates Taught Us About Detecting Hijacked Email Accounts

    Anomalously high email open rates—exceeding 100%—can indicate compromised accounts rather than successful campaigns. Attackers exploit DKIM replay by sending one authenticated message through a legitimate account, then redistributing that signed message to thousands of recipients, causing the tracking pixel to fire far more times than the original recipient count, creating mathematically impossible open-rate metrics.

    By toruviel
  20. 020BleepingComputerSEP · 12English

    GitLab urges users to patch max severity path traversal flaw

    GitLab urged users to immediately patch a maximum-severity path traversal vulnerability (CVE-2026-85706) in its repository commits API that allows unauthenticated attackers to read arbitrary data from vulnerable servers. Cybersecurity firm watchTowr reported that attackers are already probing for unpatched GitLab instances. The company also patched a second critical deserialization vulnerability (CVE-2026-87719) affecting GitLab Enterprise Edition.

    By Sergiu Gatlan