source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 30, 2026
Hacker News3656X 主题热门3651CNBC77YahooFinance65Verge56aihot53IGN459to5Google38Engadget38TechCrunch389to5Mac33MacRumors33Kotaku29AndroidAuthority25PushSquare23Guardian20Eurogamer17Investor'sBusinessDaily17NintendoLife17TechPowerUp17ArsTechnica16Mashable16FoxBusiness14Polygon14Gematsu13SeekingAlpha12Fortune11Gizmodo11NBC11NPR11Wccftech11bgr10BusinessInsider10WIRED10CNN9PureXbox9AndroidPolice8GameGPU8GSMArena8VideoGamesChronicle8AlJazeera7CBS7CNET7DroidLife7GameInformer7NewYorkPost7Fox6XBOXWire6Hacker6Tom'sGuide6USAToday6Yahoo6AndroidCentral5BleepingComputer5MotleyFool5GamesIndustry.biz5Jalopnik5NintendoEverything5NYT5Yahoo5VideoCardz5ABC4AppleInsider4Draftsim4Futurism4HollywoodReporter4InsiderGaming4Motor14Space4TechSpot4UploadVR4WindowsCentral4404Media3Aftermath3Electrek3GAMINGbible3Hackaday3LosAngelesTimes3Lifehacker3Nature3CrudeOilPricesToday3PetaPixel3Phoronix3PokeBeach3RoadtoVR3SamMobile3Slate3YahooTech3Register3WhatHi-Fi?3AndroidHeadlines2Anthropic2Autonocion2AZFamily2BostonGlobe2BuzzFeed2ChromeUnboxed2CoinDesk2Currently2Deadline2DigitalFoundry2Euronews2EventHubs2GameRant2GearPatrol2iLovetheUpperWestSide2mtgrocks2MyNintendo2Notebookcheck2PCMag2PlayStationLifeStyle2Pokemon2politico.eu2RockPaperShotgun2SouthChinaMorningPost2SeattleTimes2SimpleFlying2SlashGear2Autopian2Conversation2TimeExtension2WarhammerCommunity2ynetnews224/7WallSt.180Level1WXLV1ageofempires1airlive1AJC1AlaskaBeacon1Apple1AVClub1AviationWeek1BlockClubChicago1BoingBoing1Yahoo!FinanceCanada1YahooLifestyleCanada1CarandDriver1CineD1CnEVPost1comicbookmovie1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1DailyKos1DaringFireball1DCRainmaker1Deseret1Designboom1Dezeen1DSOGaming1DiarioAS1Finbold1ForexFactory1FOX13Seattle1franchisetimes1Futurity1GameFile1GameWorldObserver1garymarcus.substack1GeekWire1GeekyGadgets1GosuGamers1HuffPost1Independent1InsideEVs1investor.costco1I/OFund1iPhoneinCanada1KCRA1KOMO1Magic:Gathering1MakeUseOf1Minecraft1MortgageDaily1MP1st1MyNorthwest1NBCBayArea1NBC5Chicago1NBC7SanDiego1Newser1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1Nokiamob1OregonPublicBroadcasting1OregonLive1PageSix1PCGamesN1PersonaCentral1PickupTruck+SUVTalk1Psyche1QuantaMagazine1Realtor1RichmondTimes-Dispatch1Richmonder1Road&Track1RPGSite1ScienceDaily1ScreenRant1SeattleRed1SanFranciscoChronicle1SFGATE1YahooFinanceSingapore1GhostHowls1SlowBoring1SoraNews241statnews1svg1TampaBayTimes1DailyBeast1Intercept1NextWeb1https://tipswatch.com/1TMZ1TODAY1TopGear1TweakTown1YahooFinanceUK1PCMagUK1Variety1Vulture1WCVB1WFMZ1WHYY1WindowsLatest1WrestlingInc.195.5WSB1
  1. 001Hacker NewsSEP · 29English

    Reducing undefined behavior in the C language

    Martin Uecker, a biomedical engineering professor and Linux developer, discussed undefined behavior in C at Kernel Recipes, arguing that while C remains a valuable language for its portability and performance, its historical complexity and loose semantics around undefined behavior create ambiguity about expected program behavior and security implications.

    By Jonathan Corbet September
  2. 002Hacker NewsSEP · 28English

    Reducing undefined behavior in the C language

    Martin Uecker, a biomedical engineering professor and Linux user, discussed undefined behavior in C at Kernel Recipes, exploring whether C can become memory-safe. Despite C's portability, stability, and performance advantages, its historical complexity and the compiler freedom granted by undefined behavior semantics create challenges and disagreements about expected program behavior.

    By Jonathan Corbet September
  3. 003Hacker NewsSEP · 28English

    Google Rewrites Critical C Dependencies to Rust Using AI and Differential Fuzzin

    Google used Gemini AI and differential fuzzing to automatically convert giflib, a 3,000-line C image-processing library, into memory-safe Rust while maintaining ABI compatibility and runtime performance. The Rust version neutralized an unpatched heap write zero-day (CVE-2026-26740) before public disclosure and passed validation across 30 million real-world GIF assets and 200 million fuzzing iterations.

    By Olimpiu Pop
  4. 004Hacker NewsSEP · 26English

    Rust Reborrowing, Aliasing, and Mutable References

    This technical article explains Rust's reborrowing mechanism, which allows mutable references to be passed to helper methods without consuming the original reference. Reborrowing creates temporary sub-borrows with shorter lifetimes, enabling practical use of mutable references while maintaining strict exclusivity. The compiler automatically handles this, similar to variable shadowing, by suspending the parent borrow during the child borrow's lifetime.

    By Nazmul Idris
  5. 005Hacker NewsSEP · 26English

    Do not let your type system reason about aliasing in your programming language

    This post discusses Futhark's type system feature for in-place updates, which allows efficient array modifications by reusing memory while maintaining safety through aliasing tracking. The author explains how the type checker must reason about object identity and aliases to prevent consumed values from being referenced, and describes the complexity that arises when this interacts with other language features.

    By mpweiher
  6. 006Hacker NewsSEP · 25English

    Libfyaml – A YAML 1.2 and JSON library in C

    libfyaml v1.0.0-beta2 is a correctness and portability release fixing memory leaks, double frees, and other issues found through fuzzing, while adding support for multiple platforms including FreeBSD, NetBSD, OpenBSD, and various Linux architectures. The release introduces allocation failure injection testing and expands CI coverage across supported platforms.

    By Pantoniou
  7. 007Hacker NewsSEP · 24English

    C-to-Rust Fallacy: Automatic Refactoring != Memory Security

    A comprehensive empirical study evaluates automated C-to-Rust refactoring tools (C2Rust-analyze, CROWN, C2SaferRust, FLOURINE) on 116 C programs with memory security bugs. Results show that while these tools reduce unsafe Rust code, they fail to reliably eliminate memory security vulnerabilities: 342 programs fail compilation, 177 inherit original C bugs, and 77 introduce new Rust bugs.

    By Chen; Hung-Mao; He; Xu; Lu; Bo; Zhang; Xiaokuan; Sun; Kun
  8. 008Hacker NewsSEP · 23English

    Beyond Images: Bringing Rust Brotli to Edge Network Stack

    Microsoft Edge's security team replaced the C implementation of Brotli compression in its network stack with a Rust implementation to improve memory safety. Brotli was chosen as the next rustification target because it processes untrusted network data at a critical point in the browser, has a mature Rust crate with production adoption, and is widely deployed on the modern web.

    By Marco Bartoli
  9. 009Hacker NewsSEP · 23English

    CobaltC now has a compiler (for Linux)

    CobaltC is an AI-designed statically typed systems programming language with explicit ownership, memory safety, and compiler-checked borrowing. The project now includes both an interpreter (coby) and a native compiler (cobc) for x86_64 Linux, along with comprehensive documentation and example programs.

    By Strawberry9
  10. 010Hacker NewsSEP · 23English

    Data-Only Attacks Are Easier Than You Think

    Researchers have developed Einstein, an automated tool that generates data-only attacks—exploits that corrupt a program's data rather than hijacking control flow. Published at USENIX Security 2024, the work challenges the assumption that such attacks are too complex to be practical, demonstrating that memory safety bugs (70% of security issues at major vendors) can be weaponized through malicious data manipulation.

    By segfaultbuserr