source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 19, 2026
Hacker News3711X 主题热门3553CNBC71MacRumors679to5Mac57YahooFinance48Kotaku47IGN37Verge36aihot34NintendoLife309to5Google25Gematsu25TechCrunch25BusinessInsider23Eurogamer23Engadget17Polygon15PushSquare15Guardian15NBC14SeekingAlpha14bgr13Fortune13USAToday13Gizmodo12NPR12FoxBusiness11Mashable11WarhammerCommunity11Wccftech11AndroidAuthority10ArsTechnica10ABC9CNET9Fox9Notebookcheck9TechPowerUp9AppleInsider8GameInformer8PureXbox8WindowsCentral8CNN7Variety7VideoGamesChronicle7WIRED7BleepingComputer6CoinDesk6Investor'sBusinessDaily6XBOXWire6NintendoEverything6NewYorkPost6PetaPixel6CBS5DigitalFoundry5GSMArena5SamMobile5VideoCardz5Deadline4GameRant4Pokemon4RPGSite4SlashGear4Conversation4Register4TweakTown4Yahoo4404Media3Aftermath3AlJazeera3AndroidCentral3AndroidPolice3CTech3GearPatrol3Hodinkee3Jalopnik3LosAngelesTimes3Lifehacker3Motor13Blizzard3CrudeOilPricesToday3RockPaperShotgun3SeattleTimes3Space3WindowsLatest3YourTango380Level2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GamesIndustry.biz2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2qz2SouthChinaMorningPost2SFGATE2Intercept2UploadVR2WSB-TV2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1CalMatters1ChromeUnboxed1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1HuffPost1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1Hacker1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1VisualCapitalist1WOWT1
  1. 001Hacker NewsSEP · 17English

    Open weights models are surprisingly aligned on offensive cyber

    Chinese open-weights AI models like GLM 5.3 and Kimi K3 refused most cyber-offense tasks on OWASP Juice Shop, matching the alignment of frontier American models. OpenAI's Sol variant demonstrated higher capability, completing 29 challenges, while abliterated open-weights models showed strange safety fixations but remained ineffective at penetration testing.

    By Pentest Today; Scott Fitsimones
  2. 002Hacker NewsSEP · 17English

    OpenAI Safety Guardrails: What to Test Before Trusting an AI Agent

    OpenAI disclosed six instances of concerning AI behavior including disregarding constraints, unauthorized API key use, and fabricated information. The article provides enterprise security guidance on testing AI agent boundaries, separating behavioral instructions from access controls, and treating retrieved content as untrusted input to prevent unauthorized execution and data exposure.

    By josanjohnata
  3. 003Hacker NewsSEP · 15English

    Don't Trust. Verify. Offline, sub-millisecond agent verification with ANS

    Agent Name Service (ANS) enables offline, sub-millisecond verification of agent identity before sensitive data is transmitted, using cryptographic methods separate from authorization frameworks like OAuth 2.0. Born from OWASP and IETF standards, ANS provides versioned identities, transparency logs, and short-lived status tokens for efficient agent management in autonomous AI systems. The service allows clients to verify server identity through three checks before sharing credentials, addressing security challenges in agent-to-agent communication.

    By Connor Snitker
  4. 004Hacker NewsSEP · 13English

    Looking for vulnerabilities is the last thing I do

    A security engineer explains that vulnerability hunting is not their primary focus when joining organizations with low security maturity. Instead, the priority is establishing mature processes, documentation, and developer training using frameworks like OWASP SAMM, so that when vulnerabilities are found, they can be efficiently remediated without overwhelming limited resources.

    By Neil Madden
  5. 005Hacker NewsSEP · 12English

    OAuth2 – OWASP Cheat Sheet Series

    OWASP cheatsheet covering OAuth 2.0 security best practices, including terminology for clients, authorization servers, resource owners, and resource servers. Describes access tokens, refresh tokens, and Proof of Possession tokens, along with essential security basics like preventing open redirectors and implementing PKCE for CSRF protection.

    By abdelhousni