source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News4027X 主题热门3851CNBC76MacRumors689to5Mac65YahooFinance58Kotaku46IGN38Verge38aihot34NintendoLife319to5Google30BusinessInsider27Gematsu27Eurogamer25TechCrunch24Engadget22Guardian17NBC16Polygon16SeekingAlpha15USAToday15Wccftech15Fortune14NPR14PushSquare14bgr13CNET13Mashable13Gizmodo12FoxBusiness11AndroidAuthority10ArsTechnica10Notebookcheck10ABC9AppleInsider9CBS9Fox9Investor'sBusinessDaily9TechPowerUp9WIRED9GameInformer8WarhammerCommunity8WindowsCentral8BleepingComputer7PureXbox7Variety7VideoGamesChronicle7CNN6CoinDesk6XBOXWire6NewYorkPost6PetaPixel6SamMobile6DigitalFoundry5GSMArena5NintendoEverything5CrudeOilPricesToday5Yahoo5GameRant4Lifehacker4Motor14Pokemon4RPGSite4SeattleTimes4SlashGear4Register4VideoCardz4404Media3AlJazeera3AndroidCentral3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Hodinkee3Jalopnik3LosAngelesTimes3Blizzard3RockPaperShotgun3SouthChinaMorningPost3Space3Conversation3TweakTown3UploadVR3WindowsLatest3YourTango380Level2Aftermath2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2QuantaMagazine2RoadtoVR2SFGATE2Hacker2Intercept2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GAMINGbible1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1qz1Road&Track1RockstarINTEL1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001Hacker NewsSEP · 18English

    Patch2vuln v1.0: Streamlining Vulnerability Advisory from Git Patch

    patch2vuln v1.0 is an open-source CLI tool that automates CVE advisory generation from git patches using local LLMs and deterministic CVSS calculations. It accepts patches from URLs, files, or stdin and produces standardized CVE Record Format 5.2 JSON output while keeping sensitive diffs within local infrastructure.

    By adulau
  2. 002Hacker NewsSEP · 17English

    Suppress vulnerabilities applying Kubernetes context to scans

    Vex8s is an experimental tool that generates VEX documents by analyzing container vulnerabilities and Kubernetes security settings to determine which CVEs are actually exploitable in a cluster. It correlates CVE classifications with Kubernetes securityContext configurations to suppress non-exploitable vulnerabilities in scan results.

    By Alegrey
  3. 003Hacker NewsSEP · 16English

    PatchWing – verified, reproducible fixes for known CVEs (bring your own model)

    PatchWing is a tool that automatically generates verified fixes for known CVEs by producing reproducers, patches, and rollback proofs that maintainers can review and merge quickly. It focuses on fixing known bugs rather than discovering new vulnerabilities, demonstrating the approach on three real CVEs with full evidence bundles at minimal cost (~$1.28 per fix).

    By Jaymunshi
  4. 004Hacker NewsSEP · 12English

    The V8 JavaScript Runtime Undermined My Constant-Time JavaScript Library

    A security vulnerability was discovered in the constant-time-js JavaScript library, a demonstration tool for side-channel attack prevention. Researcher Yayu Wang reported that the library's conditional-selection functions contained a side-channel flaw undermined by V8 runtime optimizations, which the author patched in version 0.5.0 and disclosed via CVE.

    By View Archive