source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 19, 2026
Hacker News3733X 主题热门3574CNBC71MacRumors689to5Mac57YahooFinance48Kotaku47IGN37Verge36aihot34NintendoLife30TechCrunch269to5Google25Gematsu25BusinessInsider23Eurogamer23Engadget17Polygon15PushSquare15Guardian15NBC14SeekingAlpha14bgr13Fortune13USAToday13FoxBusiness12Gizmodo12NPR12AndroidAuthority11Mashable11WarhammerCommunity11Wccftech11ArsTechnica10ABC9CNET9Fox9Notebookcheck9TechPowerUp9AppleInsider8GameInformer8PureXbox8WindowsCentral8CNN7Variety7VideoGamesChronicle7WIRED7BleepingComputer6CoinDesk6Investor'sBusinessDaily6XBOXWire6NintendoEverything6NewYorkPost6PetaPixel6CBS5DigitalFoundry5GSMArena5SamMobile5VideoCardz5Deadline4GameRant4Pokemon4RPGSite4SlashGear4Conversation4Register4TweakTown4Yahoo4404Media3Aftermath3AlJazeera3AndroidCentral3AndroidPolice3CTech3GearPatrol3Hodinkee3Jalopnik3LosAngelesTimes3Lifehacker3Motor13Blizzard3CrudeOilPricesToday3RockPaperShotgun3SeattleTimes3Space3WindowsLatest3YourTango380Level2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GamesIndustry.biz2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2qz2SouthChinaMorningPost2SFGATE2Intercept2UploadVR2WSB-TV2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1CalMatters1ChromeUnboxed1Chron1CineD1ColoradoSun1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1HuffPost1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1Hacker1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1VisualCapitalist1WOWT1
  1. 001Hacker NewsSEP · 18English

    HEIF Heist

    HEIF Heist is a class of remote attack exploiting vulnerabilities in native C/C++ image decoders like libheif and libde265 to achieve memory corruption, data exfiltration, or remote code execution. The vulnerability affects applications processing untrusted HEIF, HEIC, or AVIF images across web frameworks, cloud services, and communication platforms. Mitigation requires updating to patched versions and implementing defense-in-depth strategies like sandboxing image processing.

    By machinecontrol
  2. 002ArsTechnicaSEP · 18English

    Researchers used Claude to hack OpenAI

    Researchers from Hacktron AI used Anthropic's security tools to breach an OpenAI employee's ChatGPT account, gaining access to private software information as part of a paid bug bounty program. The incident underscores growing security vulnerabilities at leading AI companies amid concerns about powerful models being exploited by malicious actors and foreign adversaries.

    By Financial Times
  3. 003aihotSEP · 18English

    Hacktron 披露利用 libheif 漏洞与 OpenAI SSO 缺陷接管员工 ChatGPT 账户的过程

    Hacktron disclosed a chain of two critical vulnerabilities discovered on July 25, 2026 that could compromise OpenAI employees' ChatGPT accounts: a heap buffer overflow in libheif and an SSO misconfiguration on community.openai.com. The researchers demonstrated access by opening a pull request in OpenAI's internal repository and received a $6,500 bounty after coordinated disclosure.

  4. 004Hacker NewsSEP · 18English

    HEIF Heist- Hacking OpenAI, Slack, Meta, GitHub and Many Others

    HEIF Heist is a class of remote vulnerabilities in HEIF, HEIC, and AVIF image decoders (libheif, libde265) that affect services including OpenAI, Slack, Meta, and GitHub. By uploading crafted images, attackers can trigger memory corruption, data exposure, or remote code execution below the application layer. The Hacktron research team discovered the vulnerability affects numerous platforms and recommends updating to patched versions and implementing defense-in-depth strategies.

    By rochansinha