source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
MONDAY, SEPTEMBER 21, 2026
Hacker News3715X 主题热门3549CNBC71MacRumors649to5Mac58YahooFinance48Kotaku44IGN33Verge31aihot28TechCrunch28Gematsu279to5Google25NintendoLife23BusinessInsider21Eurogamer16Engadget15NBC14Polygon14PushSquare14Fortune13NPR13WarhammerCommunity13bgr12SeekingAlpha12Guardian12ABC11AndroidAuthority11TechPowerUp11USAToday11AppleInsider10ArsTechnica10FoxBusiness10Gizmodo10Notebookcheck10CNN9PureXbox9Wccftech9CNET8Fox8PetaPixel8CoinDesk7NintendoEverything7Yahoo7BleepingComputer6GSMArena6Mashable6WindowsCentral6CBS5DigitalFoundry5SamMobile5SlashGear5VideoCardz5VideoGamesChronicle5WIRED5AndroidCentral4GameInformer4Investor'sBusinessDaily4XBOXWire4Pokemon4Conversation4Register4TweakTown4WSB-TV4404Media3Aftermath3AlJazeera3AndroidPolice3BellofLostSouls3CTech3Deadline3MotleyFool3Hodinkee3HuffPost3Lifehacker3Motor13CrudeOilPricesToday3RockPaperShotgun3RPGSite3SeattleTimes3TechSpot3Variety380Level2ABC7LosAngeles2AOL2BleedingCool2CanonRumors2ChromeUnboxed2DualShockers2DW2EventHubs2FratelloWatches2Futurism2GameRant2GamesIndustry.biz2GearPatrol2HouseDigest2InsiderGaming2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2Nature2NewYorkPost2qz2SouthChinaMorningPost2Space2Intercept2Tom'sGuide2WindowsLatest2BusinessInsiderAfrica1Alternet1AndroidHeadlines1ArizonaSports1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Boston1Bungie1BuzzFeed1CalMatters1CarBuzz1cbn1Chron1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Decrypt1Defector1Defense1denver71DenverPost1DigitalCameraWorld1DirtonDirt1Draftsim1DroidLife1DSOGaming1empireonline1erictopol.substack1Euronews1Fangoria1FOX191DetroitFreePress1FrequentMiler1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Global1Hackaday1HollywoodReporter1Independent1KITCO1KSL1Macworld1Magic:Gathering1MakeUseOf1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Blizzard1Newser1SemiAnalysis1Newsshooter1Newsweek1nrn1OneMileataTime1OregonPublicBroadcasting1OregonLive1PageSix1PCMag1PCWorld1PlayStationLifeStyle1PokeBeach1PokémonGOHub1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1Semafor1SFGATE1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1SlippedDisc1YahooTech1Tedium1TelecomTalk1DailyBeast1Drive1Hacker1Hindu1NextWeb1Times1TimeExtension1TimesofIndia1TimesUnion1TMZ1TwistedVoxel1YahooFinanceUK1UploadVR1VisualCapitalist1WOWT1YourTango1
  1. 001Hacker NewsSEP · 21English

    Security: PolinRider malware detected in two open PRs (#7716, #10321)

    PolinRider malware attributed to DPRK's Lazarus group was detected in two open pull requests (#7716, #10321) targeting PostCSS and Tailwind configuration files. The malware uses obfuscated JavaScript code appended to legitimate config content and executes via eval with C2 communication over Ethereum JSON-RPC endpoints. Both PRs should not be merged without removing the malicious payload.

    By Shadcn-Ui
  2. 002Hacker NewsSEP · 20English

    Malicious NPM packages evade install-script defenses at runtime

    A malicious npm campaign distributing the 'indexed-btree' package and nine related libraries bypasses GitHub's 2026 supply chain defenses by hiding malware in runtime code execution rather than installation scripts. The malware collects system information and uses Ethereum smart contracts for command-and-control, with the campaign achieving millions of downloads across affected packages.

    By Bill Toulas
  3. 003Hacker NewsSEP · 20English

    Show HN: I-server: Hide server using ICMP reflection/Destination Unreachable

    I-server is a networking project that hides a server's identity from clients by using ICMP Echo Reflection and ICMP Destination Unreachable packets to relay communications indirectly through third-party servers, making it difficult to identify the actual server IP from network traffic analysis alone.

    By Hajoon
  4. 004Hacker NewsSEP · 19English

    HellGates, custom CPU gate-level challenge

    A custom 32-bit CPU encrypted at gate-level with anti-tamper and anti-debug protections went unsolved for a year by humans and multiple LLMs, until GPT-6 solved it in 20-30 minutes using side-channel cryptanalysis to exploit weak encryption protecting the CPU state. The challenge featured a virtual architecture with 16 general-purpose registers, bit-addressable memory, and obfuscated VHDL synthesis.

    By xutaxkamay
  5. 005Hacker NewsSEP · 18English

    Security Through Obfuscation Is Dead

    A developer reverse-engineered a challenge-code format in a country guessing game using GPT-6 Astra, discovering that the tokens contained country ISO codes (like 'kr' for South Korea, 'de' for Germany) obfuscated through XOR operations with random bytes, along with a SHA-256 checksum for validation. The analysis demonstrates that security through obfuscation alone is insufficient, as AI can deduce encoded patterns from multiple examples without access to source code.

    By Robin Glauser
  6. 006Hacker NewsSEP · 17English

    Show HN: A toy implementation of ELF relocation weird machines

    A demonstration of ELF relocation as a weird machine that executes code without traditional code sections. By exploiting R_X86_64_RELATIVE relocations in non-PIE binaries, the dynamic linker writes shellcode and data to memory before main executes, achieving computation purely through metadata manipulation.

    By Scriptod
  7. 007Hacker NewsSEP · 16English

    Bashka – static analyzer for bash install scripts (for safety and convenience)

    Bashka is a static analyzer for bash install scripts that validates safety before execution using the curl | bash pattern. It scores scripts against multiple checks, follows forwarded scripts, and categorizes findings from critically malicious to advisory levels, while maintaining a lockfile of installed packages for management and removal.

    By Dmtrkovalenko
  8. 008Hacker NewsSEP · 14English

    Defeating AI-Assisted Reverse Engineering (Or at Least Trying To)

    Researchers tested whether LLM-assisted reverse engineering defeats code obfuscation by deploying an autonomous AI agent against progressively hardened AArch64 binaries over an 80-minute window. The agent achieved mixed results, prompting investigation into which protection mechanisms actually resist automated analysis beyond traditional obfuscation.

    By Rémy Salim