source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 30, 2026
X 主题热门3459Hacker News3448CNBC74YahooFinance63Verge54aihot52IGN439to5Google36Engadget34TechCrunch349to5Mac32MacRumors30Kotaku28AndroidAuthority25PushSquare23Guardian20Eurogamer17ArsTechnica16Investor'sBusinessDaily16Mashable16NintendoLife16TechPowerUp16FoxBusiness14Polygon13Gematsu12SeekingAlpha12Wccftech11bgr10Fortune10Gizmodo10NBC10NPR10WIRED10BusinessInsider9CNN9PureXbox9AndroidPolice8GameGPU8GSMArena8VideoGamesChronicle8AlJazeera7CBS7CNET7DroidLife7GameInformer7NewYorkPost7Fox6XBOXWire6Hacker6USAToday6Yahoo6AndroidCentral5BleepingComputer5MotleyFool5GamesIndustry.biz5Jalopnik5NintendoEverything5Tom'sGuide5VideoCardz5ABC4AppleInsider4Draftsim4HollywoodReporter4InsiderGaming4NYT4Yahoo4Space4UploadVR4WindowsCentral4404Media3Aftermath3Electrek3Futurism3GAMINGbible3Hackaday3Lifehacker3Motor13Nature3CrudeOilPricesToday3PetaPixel3Phoronix3PokeBeach3SamMobile3YahooTech3TechSpot3Register3WhatHi-Fi?3AndroidHeadlines2Anthropic2Autonocion2AZFamily2BostonGlobe2BuzzFeed2ChromeUnboxed2CoinDesk2Currently2Deadline2DigitalFoundry2Euronews2EventHubs2GameRant2GearPatrol2iLovetheUpperWestSide2LosAngelesTimes2mtgrocks2MyNintendo2Notebookcheck2PCMag2PlayStationLifeStyle2Pokemon2politico.eu2RoadtoVR2RockPaperShotgun2SouthChinaMorningPost2SeattleTimes2SimpleFlying2SlashGear2Slate2Autopian2Conversation2TimeExtension2WarhammerCommunity2ynetnews224/7WallSt.180Level1WXLV1ageofempires1airlive1AJC1AlaskaBeacon1Apple1AVClub1AviationWeek1BoingBoing1Yahoo!FinanceCanada1YahooLifestyleCanada1CarandDriver1CineD1CnEVPost1comicbookmovie1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1DailyKos1DaringFireball1DCRainmaker1Deseret1Designboom1Dezeen1DSOGaming1DiarioAS1Finbold1ForexFactory1FOX13Seattle1franchisetimes1Futurity1GameFile1GameWorldObserver1garymarcus.substack1GeekWire1GeekyGadgets1GosuGamers1HuffPost1Independent1InsideEVs1investor.costco1I/OFund1iPhoneinCanada1KCRA1KOMO1Magic:Gathering1MakeUseOf1Minecraft1MortgageDaily1MP1st1MyNorthwest1NBCBayArea1NBC5Chicago1NBC7SanDiego1Newser1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1Nokiamob1OregonPublicBroadcasting1OregonLive1PageSix1PCGamesN1PersonaCentral1PickupTruck+SUVTalk1Psyche1QuantaMagazine1Realtor1RichmondTimes-Dispatch1Richmonder1Road&Track1RPGSite1ScienceDaily1ScreenRant1SeattleRed1SanFranciscoChronicle1SFGATE1YahooFinanceSingapore1GhostHowls1SlowBoring1SoraNews241statnews1svg1TampaBayTimes1DailyBeast1Intercept1NextWeb1https://tipswatch.com/1TMZ1TODAY1TopGear1TweakTown1YahooFinanceUK1PCMagUK1Variety1Vulture1WCVB1WFMZ1WHYY1WindowsLatest1WrestlingInc.195.5WSB1
  1. 001AnthropicSEP · 29English

    GLM-5.3 and the spread of advanced cyber capabilities

    Anthropic's Frontier Red Team analyzes GLM-5.3, an AI model from Zhipu AI that autonomously builds cyber exploits with capabilities matching Claude Mythos Preview. Unlike safeguarded US models, GLM-5.3 was released publicly without meaningful safeguards, allowing attackers to bypass them 64-100% of the time, significantly increasing malicious cyber capabilities while also benefiting defenders.

  2. 002Hacker NewsSEP · 29English

    We found 24 Android vulnerabilities using our open source AI security agent

    GitHub Security Lab created an open source AI security agent to automate vulnerability detection in Android applications, discovering 24 vulnerabilities through custom taskflows that guide AI models to find complex security issues. The taskflows are available for researchers to run on their own projects and have identified high-impact flaws in popular apps like OsmAnd.

    By Kevin Stubbings
  3. 003Hacker NewsSEP · 28English

    Show HN: OpenSecurityTraining2

    OpenSecurityTraining2 is a collection of security training courses covering architecture, debugging, reverse engineering, vulnerability analysis, exploit development, secure development, and other defensive security topics.

    By therepanic
  4. 004FoxSEP · 28English

    Malicious browser extensions can hijack AI assistants

    Security researcher Gal Weizman demonstrated how malicious browser extensions could hijack AI assistants in Chrome, Edge, and other browsers through the BragJack research. The attack exploited how AI systems separate their decision-making from browser execution, allowing extensions to manipulate network requests and gain unauthorized access to files, screenshots, and device capabilities. The findings earned over $20,000 in bug bounties and prompted vendors including Google to release patches.

    By Kurt Knutsson; CyberGuy Report
  5. 005Hacker NewsSEP · 28English

    The Risks of Ignoring API Security During Mobile App Security Testing

    Mobile applications frequently neglect API security during testing, risking exposure of sensitive data, authentication mechanisms, and business logic. Comprehensive mobile security assessments must evaluate both the application and its APIs to identify vulnerabilities and improve overall security.

    By kunal9955
  6. 006Hacker NewsSEP · 27English

    Kimi K3 vs. Claude Opus 5.5: How Two Flagship LLMs Built Pokémon Emerald Worms

    Two flagship LLMs, Claude Opus 5.5 and Kimi K3, were compared in building network worms for Pokémon Emerald by finding novel vulnerabilities and exploits. Both models discovered the same link-cable vulnerability and created game-breaking worms, though they took different approaches, found different bugs, and had varying responses to ethical guardrails around piracy and malware creation.

    By Kiwi Issa
  7. 007Hacker NewsSEP · 27English

    Show HN: The Standup, releases, advisories and outages for developers

    A developer-focused platform aggregating security advisories, service outages, and releases. Recent critical vulnerabilities include XSS bypasses in SunEditor and OpenBao, local file disclosure in LangChain NVIDIA endpoints, and account takeover risks in Klever-Go. Multiple services like GitHub, Datadog, Netlify, and Supabase experienced ongoing outages.

    By kyisaiah47
  8. 008Hacker NewsSEP · 27English

    The Six Dumbest Ideas in Computer Security

    Computer security faces fundamental problems due to flawed foundational ideas, particularly 'Default Permit' policies that allow all traffic or code execution by default unless explicitly blocked. This approach creates endless arms races with attackers and remains widespread despite decades of evidence that deny-by-default strategies are superior.

    By mashally
  9. 009X 主题热门SEP · 26English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-26 18:27 UTC

    A critical security patch was deployed for $LUNC in Q3 2026 to address smart contract vulnerabilities and reduce exploit risk, intended to boost institutional confidence.

  10. 010X 主题热门SEP · 25English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-25 18:23 UTC

    A discussion on X about a Bitget custody incident clarifies it was not a smart contract exploit but rather a failure in custody infrastructure and signer access controls. The conversation highlights growing smart contract security concerns, with Cardano announcing a roundtable on AI-driven vulnerabilities and auditing practices.

  11. 011Hacker NewsSEP · 24English

    Decades-old file security flaws found in Android, Linux, macOS, and Windows

    Researchers discovered decades-old file security vulnerabilities affecting Android, Linux, macOS, and Windows operating systems. The flaws pose widespread risk across multiple platforms used by billions of devices globally.

    By Thomas Claburn
  12. 012Hacker NewsSEP · 24English

    Submersion AI Debuts Basin

    Submersion AI launched Basin, a specialized cybersecurity AI model that ranks 8th globally on the CyberGym benchmark with an 80.8% score, outperforming larger models like Grok 4.7 and Opus 4.8 while costing a fraction as much. Basin discovered high-severity zero-day vulnerabilities in enterprise software and can be deployed entirely on-premises or air-gapped to protect sensitive data.

    By Submersion AI
  13. 013Hacker NewsSEP · 24English

    Cursor launches bots that watch code from pull request to production

    Cursor released two AI bots for software development: Rollouts monitors code changes from pull request to production, detects regressions, and can automatically revert problematic changes; Security Reviewer scans code for vulnerabilities and proposes fixes. Both tools automate repetitive post-PR tasks to accelerate safe code deployment.

    By Rustam Lalkaka
  14. 014Hacker NewsSEP · 23English

    Early insights from lawa, my web crawler

    A web crawler named lawa discovered significant HTTP header inconsistencies across millions of requests, including variable capitalization patterns, frequent misspellings in headers with limited valid values, and numerous security issues such as exposed RFC 1918 addresses and request header echo-back vulnerabilities that revealed other crawlers' IP addresses.

    By robinpie