source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SUNDAY, SEPTEMBER 20, 2026
Hacker News3936X 主题热门3761CNBC72MacRumors659to5Mac59YahooFinance50Kotaku47IGN35Verge35aihot28NintendoLife28TechCrunch269to5Google25Gematsu25BusinessInsider22Eurogamer20Guardian16Engadget15NBC15Polygon14PushSquare14Fortune13NPR13SeekingAlpha13USAToday13WarhammerCommunity13bgr12FoxBusiness12AndroidAuthority11Gizmodo11Wccftech11ABC10AppleInsider10ArsTechnica10Fox10TechPowerUp10CNET9CNN9Mashable9Notebookcheck9PureXbox9PetaPixel8VideoGamesChronicle7WindowsCentral7BleepingComputer6CBS6CoinDesk6GSMArena6Investor'sBusinessDaily6NintendoEverything6SamMobile6Yahoo6DigitalFoundry5GameInformer5SlashGear5VideoCardz5WIRED5AndroidCentral4Deadline4GameRant4XBOXWire4NewYorkPost4Pokemon4Conversation4Register4TweakTown4WSB-TV4404Media3Aftermath3AlJazeera3AndroidPolice3BellofLostSouls3CTech3MotleyFool3GearPatrol3Hodinkee3HuffPost3LosAngelesTimes3Lifehacker3Motor13CrudeOilPricesToday3RockPaperShotgun3RPGSite3SeattleTimes3Space3Variety380Level2AOL2BleedingCool2BuzzFeed2CanonRumors2DualShockers2DW2EventHubs2FratelloWatches2Futurism2GamesIndustry.biz2HouseDigest2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2Nature2Newser2PCWorld2qz2SouthChinaMorningPost2Intercept2Tom'sGuide2WindowsLatest2YourTango2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1Alternet1AndroidHeadlines1ArizonaSports1AVClub1AwfulAnnouncing1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Boston1Bungie1CalMatters1CarBuzz1cbn1ChromeUnboxed1Chron1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Decrypt1Defector1Defense1denver71DenverPost1DigitalCameraWorld1DirtonDirt1Draftsim1DroidLife1empireonline1erictopol.substack1Euronews1Fangoria1FOX191DetroitFreePress1FrequentMiler1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Global1Hackaday1HollywoodReporter1Independent1InterestingEngineering1Jalopnik1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1MyNintendo1Blizzard1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OneMileataTime1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1PokémonGOHub1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1SFGATE1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1SlippedDisc1YahooTech1TechSpot1Tedium1TelecomTalk1DailyBeast1Hacker1Hindu1NextWeb1Times1TimeExtension1LongmontTimes-Call1TimesUnion1TwistedVoxel1YahooFinanceUK1UploadVR1VisualCapitalist1WOWT1
  1. 001Hacker NewsSEP · 20English

    Real attackers don't think in bug bounty scopes

    A security researcher hacked into OpenAI's private repositories but received only a $6,500 bounty despite accessing sensitive data worth potentially hundreds of thousands on the black market. The hack exploited an out-of-scope Discourse forum, leading OpenAI to invoke scope rules to minimize the payout, a practice that discourages legitimate security research and fails to address how real attackers ignore such restrictions.

    By Artem Golubin
  2. 002Hacker NewsSEP · 20English

    Dark Age

    Society faces a 'Dark Age' driven by widespread adoption of AI technology that prioritizes output volume over quality, while rising right-wing sentiment, economic hardship, and declining discourse standards compound systemic erosion. The author warns that humanity's surrender to machine-generated content and misaligned incentive structures threaten the foundations of academia, industry, and society itself.

    By Ramkumar Ramachandra
  3. 003Hacker NewsSEP · 20English

    AI art is theft – on artists, mathematicians impact on AI

    The article argues that unaddressed concerns from artists about AI training data have festered into widespread anti-AI sentiment that pollutes public discourse. The author warns that mathematicians now have similar grievances about AI, and if their modest demands aren't met promptly, their influential social position could amplify backlash similar to what occurred with artists.

    By diginova
  4. 004Hacker NewsSEP · 19English

    People who know the most often sound the least certain

    Experts discussing difficult AI questions sound less certain than confident but less knowledgeable commentators because they qualify claims and search for precise language. The public discourse rewards simple certainty over calibrated nuance, creating a dangerous gap where unqualified voices dominate conversations about AI's impact on jobs, security, and regulation. Long-form conversation formats that expose expert reasoning are valuable precisely because they reveal the messy, uncertain nature of genuine technical thinking.

    By Vrash
  5. 005Hacker NewsSEP · 19English

    Claude couldn't hack OpenAI. Then Anthropic shipped Opus 5

    Security researchers at Hacktron AI discovered a memory-corruption bug in an image library used by OpenAI's forum, then used Anthropic's Claude Opus 5 to develop a working exploit that achieved remote code execution and access to OpenAI's private repositories within 72 hours. The vulnerability stemmed from an unpatched libheif flaw in Discourse combined with excessive permissions in OpenAI's single sign-on system.

    By Amanda Caswell
  6. 006aihotSEP · 18English

    研究团队用 Claude Opus 5 入侵 OpenAI,获 6500 美元漏洞赏金

    Security researchers at Hacktron AI used Anthropic's Claude Opus 5 to exploit vulnerabilities in OpenAI's systems, gaining access to employee ChatGPT accounts through a flaw in Discourse's image upload handling. OpenAI awarded the team a $6,500 bug bounty after the vulnerabilities were reported and subsequently patched.

  7. 007TechCrunchSEP · 18English

    Researchers used Anthropic’s Claude to hack into OpenAI

    Security researchers at Hacktron AI used Anthropic's Claude to identify vulnerabilities in OpenAI's systems, chaining together flaws in Discourse and libheif to access employee ChatGPT accounts. OpenAI awarded the team $6,500 through its bug-bounty program and resolved the issues, highlighting how accessible AI tools can expose security gaps even in advanced companies.

    By Aditya Mehta; Rebecca Bellan
  8. 008Hacker NewsSEP · 18English

    HEIF Heist

    HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.

    By machinecontrol
  9. 009aihotSEP · 18English

    Hacktron 复盘利用 libheif 漏洞与 OpenAI SSO 缺陷入侵 OpenAI 论坛并接管员工 ChatGPT 账号

    On July 25, 2026, security researchers chained a heap buffer overflow in libheif with an OpenAI SSO misconfiguration to compromise employee ChatGPT accounts and access internal OpenAI repositories. The attack exploited image upload functionality on OpenAI's community forum and was reported responsibly, resulting in a $6,500 bounty.

  10. 010aihotSEP · 18English

    Hacktron 披露利用 libheif 漏洞与 OpenAI SSO 缺陷接管员工 ChatGPT 账户的过程

    Hacktron disclosed a chain of two critical vulnerabilities discovered on July 25, 2026 that could compromise OpenAI employees' ChatGPT accounts: a heap buffer overflow in libheif and an SSO misconfiguration on community.openai.com. The researchers demonstrated access by opening a pull request in OpenAI's internal repository and received a $6,500 bounty after coordinated disclosure.

  11. 011Hacker NewsSEP · 18English

    Hacking OpenAI

    Security researchers chained two critical vulnerabilities to compromise OpenAI employee accounts on July 25, 2026, gaining access to internal repositories within 72 hours. The vulnerabilities involved an SSO misconfiguration and a libheif RCE in OpenAI's community forum. OpenAI and Discourse were notified and patched the issues; OpenAI awarded a $6,500 bounty.

    By Rootxharsh; S; Iamnoooob