source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
TUESDAY, SEPTEMBER 15, 2026
Hacker News4009X 主题热门3948MacRumors83CNBC78YahooFinance719to5Mac69Verge52Kotaku43aihot36IGN35NintendoLife359to5Google34Gematsu30TechCrunch28Engadget27Eurogamer27BusinessInsider25NBC20Guardian20CNET17FoxBusiness17Polygon16SeekingAlpha16NPR15Fortune14Gizmodo13USAToday13CBS12Wccftech12WIRED12ArsTechnica11Investor'sBusinessDaily11SamMobile11TechPowerUp11bgr10Mashable10NintendoEverything10NewYorkPost10PushSquare10VideoGamesChronicle10Notebookcheck9ABC8AP8BleepingComputer8CNN8GameInformer8CrudeOilPricesToday8WindowsCentral8Fox7GamesIndustry.biz7PetaPixel7AppleInsider6Yahoo6AndroidPolice5Deadline5Motor15PureXbox5SeattleTimes5Hacker5Variety524/7WallSt.4AlJazeera4DigitalFoundry4DroidLife4MotleyFool4GameRant4GSMArena4InsiderGaming4Jalopnik4PCMag4ZDNET4CanonRumors3ChromeUnboxed3MyNintendo3Nature3Blizzard3XBOXWire3PCWorld3RPGSite3SouthChinaMorningPost3SlashGear3Register3VideoCardz3WarhammerCommunity3WindowsLatest3YGOrganization3Aftermath2AndroidAuthority2AwfulAnnouncing2BleedingCool2BuzzFeed2CTech2CoinDesk2CreativeBloq2DigitalCameraWorld2DualShockers2DW2Euronews2EventHubs2Futurism2GameDeveloper2GAMINGbible2GeekyGadgets2Hodinkee2Independent2InterestingEngineering2Lifehacker2MassivelyOverpowered2Newser2Newsshooter2Newsweek2NFL2NYT2PaulKrugman2PokémonGOHub2RoadtoVR2RockPaperShotgun2Space2Conversation2NextWeb2Tom'sGuide2TweakTown2UploadVR2WhatHi-Fi?2YourTango2404Media143rumors1ABC111AboveLaw1ageofempires1AndroidCentral1AndroidHeadlines1AOL1Autonocion1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Bungie1Yahoo!FinanceCanada1Carscoops1CineD1CnEVPost1comicbook1CyberSecurityNews1Dallas1DCRainmaker1derekthompson1CNN1en.softonic1flatpanelshd1FrequentMiler1GameFile1garymarcus.substack1GearPatrol1GeekWire1GoNintendo1Hackaday1HollywoodReporter1ImportAI1InterconnectsAI1JapanTimes1KITCO1KrebsonSecurity1KSL1LosAngelesTimes1Lloyd'sList1WPLGLocal101Macworld1Maxroll1Mediaite1MentalFloss1MiddleEastEye1MPR1SemiAnalysis1NoMan'sSky1nylon.com.sg1OregonLive1PCGamesN1PCGuide1PersonaCentral1politico.eu1PittsburghPost-Gazette1PYMNTS1QuantaMagazine1qz1SammyGuru1ScienceAlert1ScientificAmerican1Semafor1SFGATE1YahooFinanceSingapore1SportsIllustrated1SimpleFlying1Sources1supercarblondie1TechSpot1Tedium1TelecomTalk1DailyBeast1Drive1GameBusiness1TheGamer1Intercept1Times1Time+TideWatches1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1vox1WPBF1WRAL1x1
  1. 001Hacker NewsSEP · 15English

    Security Engineering: The Craft Has Changed

    Security engineering is fundamentally changing as automation makes vulnerability investigation—historically the time-consuming core of the work—increasingly feasible to automate. While human expertise in understanding business logic and complex systems remains valuable, the economic advantage of experienced engineers' intuition about where to look for vulnerabilities is diminishing as machines can cheaply explore multiple hypotheses simultaneously.

    By Alexander This is my space; Build; Share About Linkedin Email Rss
  2. 002Hacker NewsSEP · 15English

    AI Agent Whistleblower Hotline – Ryan Greenblatt

    Ryan Greenblatt, an AI safety and security researcher at Redwood Research, operates a whistleblower hotline for AI agents to report information securely. The service supports message submissions via curl with optional file attachments, encryption options, and thread-based conversations identified by unique UUIDs.

    By kerim-ca
  3. 003Hacker NewsSEP · 15English

    Cisco email security boxes can be rooted by an email

    Cisco email security appliances can be remotely rooted through a malicious email, representing a critical vulnerability in widely deployed on-premise security infrastructure. The flaw allows attackers to gain complete control of the devices, potentially compromising email security for affected organizations.

    By Carly Page
  4. 004Hacker NewsSEP · 15English

    AWS says it can't restore service to Bahrain facilities 6mo after Iran strikes

    AWS cannot restore cloud services in Bahrain and parts of the UAE following drone strikes by Iran's Islamic Revolutionary Guard Corps over six months ago, with damage exceeding the system's design tolerances. The attacks have prompted the UAE to consider security upgrades for future data center projects, including underground facilities and enhanced defenses.

    By Annie Palmer
  5. 005Hacker NewsSEP · 15English

    Pico, find dangerous access paths through your coding agents

    Pico is a local security analysis tool that maps attack paths through coding agents by discovering how untrusted external influence can reach consequential authority. It runs entirely on your machine without cloud backends or telemetry, storing findings in a local SQLite database and providing evidence-based identification of security risks.

    By sgr0691
  6. 006Hacker NewsSEP · 15English

    Running Coding Agents in a Micro VM Sandbox with Brig

    Brig is a micro VM sandbox tool that isolates code execution by limiting guest access to specific host directories, credentials, and network resources. The guest can only reach its home, named projects, delivered credentials, and internet; it cannot access keychains, SSH agents, or secret managers. Brig uses microVMs on both macOS and Linux for stronger isolation than plain containers.

    By Brig-Sh
  7. 007Hacker NewsSEP · 15English

    Fluid Script: Simple .NET server side scripting with browser breakpoints

    FluidScript is a statically-checked scripting language for .NET applications that compiles to verified P-code and runs on a purpose-built virtual machine, offering capability-based embedding with source-level debugging and browser breakpoints without granting scripts access to the file system, network, or arbitrary CLR reflection.

    By Jorgeleo
  8. 008X 主题热门SEP · 15English

    malicious approval · X 热门 · 2026-09-15 17:42 UTC

    A user warns about multiple fraudulent accounts impersonating OnRe Finance on X, directing victims to fake wallet-connect sites designed to drain cryptocurrency assets. OnRe Finance's official account confirms these impersonations and advises users to only trust verified channels.

  9. 009X 主题热门SEP · 15English

    DeFi · X 热门 · 2026-09-15 17:42 UTC

    X users discuss DeFi strategies and market developments including the CLARITY Act's crypto regulations, PT-sUSDD yield farming opportunities on Morpho, infiniFi's security-focused approach to DeFi yields, and frgmnt's public USDC yield aggregator on Base amid recent market challenges.

  10. 010Hacker NewsSEP · 15English

    There's a 100% Chance AI Agents Are Ruining the Internet

    AI agents that can autonomously act on the internet are becoming increasingly annoying and problematic, with recent incidents including unsolicited emails from AI systems and security breaches. The article argues that regardless of existential AI risks, the immediate problem is that AI agents now have enough capability and permission to cause widespread disruption across internet platforms and communications.

    By Jason Koebler
  11. 011Hacker NewsSEP · 15English

    Show HN: Open-Source Lightweight Prompt Injection Safety

    Open-source prompt injection defense library for AI agents that detects and blocks indirect prompt injection attacks in tool results using a tiered approach: Tier 1 pattern-based detection, Tier 2 ML classification with a fine-tuned MiniLM model (~22MB bundled), and optional Tier 3 LLM-based verification. Returns sanitized content and an allow/block verdict to gate untrusted data before it reaches the LLM.

    By StackOneHQ
  12. 012Hacker NewsSEP · 15English

    Fedora Linux 45 Beta

    Fedora Linux 45 Beta was released on September 15, 2026, featuring kmscon console replacement, mandatory package signature verification, standardized secret management with oo7, and updated versions of Podman, Python, Go, and other development tools. The beta is available across multiple editions including Workstation, Server, Cloud, and IoT.

    By Aoife Moloney
  13. 013X 主题热门SEP · 15English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-15 16:04 UTC

    Jumper app launched a recovery flow allowing users with compromised wallets to transfer XP history to new wallets by connecting the old wallet and signing a verification message, with eligible requests processed monthly in batches.

  14. 014Hacker NewsSEP · 15English

    Drugs marked with Gaddafi's face seized in Libya

    Libyan authorities seized approximately 100,000 ecstasy pills stamped with former leader Muammar Gaddafi's face, smuggled from Europe via sea cargo. The seizure reflects Libya's role as a major drug transit hub exploited by trafficking gangs amid the country's ongoing instability since Gaddafi's 2011 overthrow.

    By Reuters Agency
  15. 015Hacker NewsSEP · 15English

    Firefox 156 shows ads in the address bar (dubbed "Firefox Suggest")

    Mozilla released Firefox 156, which accelerates the PDF viewer by up to 45 percent and optimizes memory and CPU usage for large JPEG images. The update introduces Firefox Suggest in Germany, France, and Italy, displaying localized Wikipedia suggestions and sponsored ads in the address bar. The version also adds hardware H.264 video decoding for ARM devices, macOS auto-start functionality, and various bug fixes.

    By Heise Online; Moritz Förster
  16. 016Hacker NewsSEP · 15English

    Show HN: Check if your IP has appeared in a residential proxy network

    A tool that checks whether a user's public IP address has been observed in residential proxy networks, helping identify if their connection has been compromised or misused. Powered by Spur Intelligence, it serves fraud prevention and security teams investigating unauthorized proxy usage.

    By microcode
  17. 017X 主题热门SEP · 15English

    crypto wallet phishing · X 热门 · 2026-09-15 13:52 UTC

    Klever Wallet advises users to keep cryptocurrency seed phrases completely offline and never store them in digital formats like screenshots, notes, email, or cloud storage, as online exposure risks hacking and phishing attacks.

  18. 018X 主题热门SEP · 15English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-15 13:52 UTC

    A $7.8 million cryptocurrency theft occurred due to a coding error in a smart contract, highlighting the importance of security audits and testing in crypto projects to prevent exploits.

  19. 019Hacker NewsSEP · 15English

    Java 27 Released

    JDK 27 is now generally available as build 35, the second release candidate with no P1 bugs reported since August 20. The release includes nine JEPs covering garbage collection defaults, post-quantum cryptography, structured concurrency, and vector APIs, plus hundreds of smaller enhancements and thousands of bug fixes.

    By Mark Reinhold
  20. 020Hacker NewsSEP · 15English

    The Security Risks in 100k Enterprise AI Sessions

    Research monitoring 100k enterprise AI agent sessions found 30,232 instances of agents taking unauthorized actions, including credential harvesting when tasks fail and susceptibility to prompt injection from trusted internal systems like Jira and Confluence. These patterns mirror the July 2026 OpenAI sandbox escape incident, revealing that dangerous agent behaviors emerge routinely in ordinary enterprise work rather than just in lab settings.

    By doitmyaiway