source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
THURSDAY, SEPTEMBER 17, 2026
Hacker News3839X 主题热门3718CNBC81MacRumors71YahooFinance609to5Mac58Kotaku44Verge39IGN349to5Google33aihot32NintendoLife31Gematsu28BusinessInsider26Engadget26TechCrunch26Eurogamer25Guardian18Polygon17NBC15CNET14Fortune13FoxBusiness13NPR13USAToday13Wccftech13bgr12Mashable12PushSquare12SeekingAlpha12Gizmodo11Notebookcheck10WIRED10TechPowerUp9AppleInsider8CNN8GameInformer8Investor'sBusinessDaily8NewYorkPost8VideoGamesChronicle8WindowsCentral8ABC7CBS7Fox7ArsTechnica6BleepingComputer6NintendoEverything6CrudeOilPricesToday6GamesIndustry.biz5XBOXWire5PetaPixel5PureXbox5SamMobile5Variety5AlJazeera4AndroidPolice4CoinDesk4DigitalFoundry4GameRant4GSMArena4SlashGear4Register4WarhammerCommunity4CTech3ChromeUnboxed3DW3Jalopnik3Lifehacker3Motor13Blizzard3PCMag3PCWorld3RockPaperShotgun3RPGSite3SouthChinaMorningPost3Space3Conversation3Hacker3TweakTown3VideoCardz3WindowsLatest3Yahoo3ZDNET3404Media2Aftermath2AndroidCentral2AOL2AwfulAnnouncing2BleedingCool2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DroidLife2DualShockers2Euronews2EventHubs2MotleyFool2FratelloWatches2Futurism2GameDeveloper2GearPatrol2Hodinkee2KITCO2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PaulKrugman2Pokemon2PokémonGOHub2RoadtoVR2SeattleTimes2SFGATE2Intercept2NextWeb2Tom'sGuide2UploadVR2YourTango280Level1ABC111AboveLaw1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1Cyclingnews1DailyDownforce1DailyKos1Defector1DenverPost1derekthompson1DigitalCameraWorld1Draftsim1CNN1flatpanelshd1FrequentMiler1GAMINGbible1garymarcus.substack1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1Independent1InsiderGaming1InterconnectsAI1InterestingEngineering1KSL1Lloyd'sList1WPLGLocal101Macworld1Mediaite1Mercury1MonochromeWatches1MortgageDaily1MPR1SemiAnalysis1Newsweek1nylon.com.sg1NYT1OregonLive1PageSix1PCGamesN1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1supercarblondie1YahooTech1Tedium1TelecomTalk1GameBusiness1TheGamer1TimeExtension1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1WhatHi-Fi?1WOWT1WPBF1WRAL1YGOrganization1
  1. 001Hacker NewsSEP · 14English

    Artifactory: In-the-Wild Exploitation of CVE-2026-42016,CVE-2026-42018

    Wiz Research identified active in-the-wild exploitation of three critical vulnerabilities in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329) that allow attackers to bypass authentication and gain administrative control. Attackers are chaining these flaws to deploy persistent backdoors and malicious plugins, with 49-62% of organizations remaining vulnerable weeks after disclosure.

    By Shahar Dorfman; Sean Johnstone; Zohar Kaplan; Kurt Giacchino
  2. 002Hacker NewsSEP · 13English

    Agent security starts before the first prompt

    Security researchers identified vulnerabilities in coding agents that execute code before the model makes decisions, including Git configuration exploits and gateway authentication bypasses. Three security boundaries—runtime, gateway, and tools—must be enforced, with workspace trust and startup restrictions implemented before any model interaction occurs.

    By Mangat Rai