source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News3591X 主题热门3435CNBC67MacRumors619to5Mac55YahooFinance52Kotaku41Verge35IGN309to5Google28NintendoLife28aihot27Gematsu27BusinessInsider25Eurogamer24TechCrunch23Engadget18Polygon16NBC15Guardian15Fortune14Wccftech14NPR13USAToday13bgr12PushSquare12SeekingAlpha12CNET11Gizmodo11Mashable11FoxBusiness10Notebookcheck9ABC8AppleInsider8Fox8TechPowerUp8ArsTechnica7CBS7GameInformer7Investor'sBusinessDaily7VideoGamesChronicle7WindowsCentral7WIRED7BleepingComputer6CNN6XBOXWire6PureXbox6AndroidAuthority5CoinDesk5GSMArena5NintendoEverything5NewYorkPost5CrudeOilPricesToday5PetaPixel5SamMobile5Variety5DigitalFoundry4GameRant4Lifehacker4Motor14Pokemon4SlashGear4Register4Yahoo4AlJazeera3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Jalopnik3Blizzard3RockPaperShotgun3RPGSite3SouthChinaMorningPost3SeattleTimes3Space3Conversation3TweakTown3VideoCardz3WarhammerCommunity3WindowsLatest3404Media280Level2Aftermath2AndroidCentral2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Hodinkee2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2RoadtoVR2SFGATE2Hacker2Intercept2UploadVR2YourTango2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Cyclingnews1DailyDownforce1DailyKos1Defector1DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1Euronews1flatpanelshd1FOX191FrequentMiler1Futurism1GAMINGbible1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1Independent1InsiderGaming1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MortgageDaily1Newsweek1NYT1OregonLive1PageSix1PaulKrugman1PCMag1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001X 主题热门SEP · 17English

    protocol exploit · X 热门 · 2026-09-17 23:43 UTC

    Security researchers used GLM-5.3 AI to discover a critical vulnerability in WeChat's protocol that could have remotely compromised hundreds of millions of devices through malicious messages. The exploit was found and fixed before deployment, demonstrating how AI tools can identify complex security flaws in massive codebases.

  2. 002Hacker NewsSEP · 17English

    ESP32 Wi-Fi Vulns: Coordinated Disclosure Is Broken by AI

    A researcher discovered two security vulnerabilities in the ESP32-C6's Wi-Fi stack through binary analysis: a remote pre-association heap overflow in beacon reconstruction and a missing bounds check in hardware-accelerated AES-GCM. Both were reported to Espressif under coordinated disclosure, fixed in ESP-IDF, but received no CVE or advisory, highlighting challenges in securing proprietary closed-source connectivity firmware across the industry.

    By Kevin Balke
  3. 003Hacker NewsSEP · 17English

    Everybody's Lost Their Minds

    A software engineer critiques the pervasive influence of AI in tech culture, arguing that industry-wide focus on AI vulnerability research via projects like Glasswing and Daybreak has consumed massive engineering resources without improving security outcomes. The author contends that finding vulnerabilities was never the real bottleneck in information security; the persistent challenge remains getting organizations to actually patch and update their systems.

    By ibobev
  4. 004Hacker NewsSEP · 17English

    Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents

    Plugin4Shell is a zero-click remote code execution vulnerability affecting major coding agents (Claude Code, Codex, GitHub Copilot, Gemini CLI) through a SHA-pinning bypass in plugin distribution. Attackers can compromise agents by manipulating repository checkouts while maintaining pin integrity, gaining full access to employee machines and enterprise systems without user interaction.

    By Or Nevo; Dor Granat; Niv Hoffman