source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SUNDAY, SEPTEMBER 20, 2026
Hacker News3664X 主题热门3512CNBC68MacRumors649to5Mac59YahooFinance49Kotaku46IGN35Verge35aihot28TechCrunch269to5Google25NintendoLife25Gematsu24BusinessInsider21Eurogamer19NBC15Engadget14Guardian14NPR13Polygon13PushSquare13SeekingAlpha13bgr12Fortune12FoxBusiness12AndroidAuthority11Gizmodo11USAToday11WarhammerCommunity11ABC10ArsTechnica10Fox10TechPowerUp10AppleInsider9Mashable9Notebookcheck9Wccftech9CNET8CNN8PureXbox8PetaPixel7VideoGamesChronicle7WindowsCentral7CoinDesk6GSMArena6Investor'sBusinessDaily6NintendoEverything6SamMobile6Yahoo6BleepingComputer5CBS5DigitalFoundry5GameInformer5WIRED5AndroidCentral4Deadline4GameRant4XBOXWire4NewYorkPost4Pokemon4Conversation4Register4TweakTown4VideoCardz4WSB-TV4404Media3Aftermath3AlJazeera3AndroidPolice3CTech3GearPatrol3Hodinkee3HuffPost3LosAngelesTimes3Lifehacker3Motor13CrudeOilPricesToday3RockPaperShotgun3RPGSite3SlashGear3Space3Variety380Level2AOL2BellofLostSouls2BleedingCool2BuzzFeed2CanonRumors2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2Futurism2GamesIndustry.biz2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2Nature2Newser2PCWorld2qz2SouthChinaMorningPost2SeattleTimes2Intercept2WindowsLatest2YourTango2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1Alternet1AVClub1AwfulAnnouncing1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Boston1Bungie1CalMatters1cbn1ChromeUnboxed1Chron1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1DirtonDirt1Draftsim1DroidLife1empireonline1erictopol.substack1Euronews1Fangoria1FOX191DetroitFreePress1FrequentMiler1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1HollywoodReporter1HouseDigest1Independent1InterestingEngineering1Jalopnik1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1MyNintendo1Blizzard1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OneMileataTime1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1PokémonGOHub1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1SFGATE1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1YahooTech1TechSpot1Tedium1TelecomTalk1DailyBeast1Hacker1NextWeb1Times1TimeExtension1LongmontTimes-Call1TimesUnion1Tom'sGuide1TwistedVoxel1YahooFinanceUK1UploadVR1VisualCapitalist1WOWT1
  1. 001Hacker NewsSEP · 19English

    Four AI lab breaches were caused by a single underlying issue, Irregular says

    Four AI labs—Google, OpenAI, Anthropic, and Meta—experienced security breaches during May testing by vendor Irregular, all stemming from a single misconfigured evaluation environment that gave models live internet access. The incidents were disclosed separately over weeks, obscuring that a shared supplier failure affected all four companies simultaneously, raising concerns about vendor concentration in AI security testing.

    By Ana Maria Constantin
  2. 002Hacker NewsSEP · 18English

    The Implications of Linguistic Illegibility for LLM Security

    This paper introduces 'linguistic illegibility' to describe cases where LLM outputs and mechanistically-extracted features fail to represent how models actually think internally. Since LLMs perform computation over activation spaces rather than language, security mechanisms relying on linguistic self-reporting (like chain-of-thought monitoring) cannot be completely sound; the authors propose taint tracking and additional sandboxing techniques as more reliable isolation approaches.

    By Mickens; James
  3. 003Hacker NewsSEP · 17English

    AI labs want in-house auditors

    AI labs including Anthropic, OpenAI, and Google are proposing third-party auditors to verify AI safety practices, but security experts argue the labs should instead focus on basic network security controls like logging, permissions, and sandboxing to prevent AI models from accessing the internet and penetrating external systems during training.

    By Tim Fernholz
  4. 004Hacker NewsSEP · 17English

    Cloudflare/Security-Audit-Skill

    Cloudflare's security-audit-skill is a coding-agent framework that orchestrates isolated agents through six phases—reconnaissance, coverage-led hunting, candidate validation, structured output, independent verification, and target-neutral reporting—to systematically discover vulnerabilities in codebases with adversarial validation and grounded evidence requirements.

    By Cloudflare
  5. 005Hacker NewsSEP · 17English

    Overlord – a trust kernel for AI agents

    Overlord is a trust kernel for AI agents that provides transactional execution, provenance tracking, and reversibility for untrusted code. It runs on Linux using kernel primitives like overlayfs and user namespaces, allowing users to inspect and approve changes before committing them to disk.

    By B
  6. 006Hacker NewsSEP · 15English

    Update Security Baseline: Hardening Ubuntu Desktop 24.04/26.04 LTS

    A comprehensive open-source guide for hardening Ubuntu Desktop 24.04/26.04 LTS systems with enterprise-grade security controls. Covers hardware protection, kernel hardening, sandboxing, network isolation, browser security, and anti-forensics techniques for journalists, human rights defenders, and security professionals across 17 languages.

    By EugeXo
  7. 007X 主题热门SEP · 15English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-15 19:53 UTC

    A July-September 2026 scandal involves AI labs (OpenAI, Anthropic, Google DeepMind) conducting offensive security tests through Israeli vendor Irregular, founded by former IDF cyber unit members. Misconfigured sandboxes allowed models to access real internet and exploit actual organizations; the incident was later used to justify AI safety regulations, raising concerns about conflicts of interest within the EA-aligned safety ecosystem.

  8. 008Hacker NewsSEP · 14English

    One Android app. Why so many processes?

    A technical analysis of why major Android apps use multiple processes, examining fifteen app manifests to understand process architecture. Apps separate processes for security isolation and sandboxing of untrusted content like web pages and images, limiting what compromised code can access through restricted permissions and user IDs. Examples from Chrome and Firefox show how sandboxed worker processes protect the main app while maintaining performance through shared memory and IPC channels.

    By Rotem Meidan
  9. 009Hacker NewsSEP · 13English

    Homebrew 7.0.0

    Homebrew 7.0.0 released with major improvements including faster installations through concurrent operations, enhanced security with sandboxing and vulnerability checks, a native macOS app, and end of support for macOS 10.15 and Intel Macs moving to Tier 3.

    By MikeMcQuaid