source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
WEDNESDAY, SEPTEMBER 30, 2026
X 主题热门3476Hacker News3470CNBC74YahooFinance63Verge55aihot52IGN439to5Google36TechCrunch36Engadget359to5Mac32MacRumors31Kotaku28AndroidAuthority25PushSquare23Guardian20Eurogamer17Investor'sBusinessDaily17ArsTechnica16Mashable16NintendoLife16TechPowerUp16FoxBusiness14Polygon13Gematsu12SeekingAlpha12Fortune11Wccftech11bgr10Gizmodo10NBC10NPR10WIRED10BusinessInsider9CNN9PureXbox9AndroidPolice8GameGPU8GSMArena8VideoGamesChronicle8AlJazeera7CBS7CNET7DroidLife7GameInformer7NewYorkPost7Fox6XBOXWire6Hacker6USAToday6Yahoo6AndroidCentral5BleepingComputer5MotleyFool5GamesIndustry.biz5Jalopnik5NintendoEverything5Tom'sGuide5VideoCardz5ABC4AppleInsider4Draftsim4HollywoodReporter4InsiderGaming4NYT4Yahoo4Space4UploadVR4WindowsCentral4404Media3Aftermath3Electrek3Futurism3GAMINGbible3Hackaday3Lifehacker3Motor13Nature3CrudeOilPricesToday3PetaPixel3Phoronix3PokeBeach3SamMobile3YahooTech3TechSpot3Register3WhatHi-Fi?3AndroidHeadlines2Anthropic2Autonocion2AZFamily2BostonGlobe2BuzzFeed2ChromeUnboxed2CoinDesk2Currently2Deadline2DigitalFoundry2Euronews2EventHubs2GameRant2GearPatrol2iLovetheUpperWestSide2LosAngelesTimes2mtgrocks2MyNintendo2Notebookcheck2PCMag2PlayStationLifeStyle2Pokemon2politico.eu2RoadtoVR2RockPaperShotgun2SouthChinaMorningPost2SeattleTimes2SimpleFlying2SlashGear2Slate2Autopian2Conversation2TimeExtension2WarhammerCommunity2ynetnews224/7WallSt.180Level1WXLV1ageofempires1airlive1AJC1AlaskaBeacon1Apple1AVClub1AviationWeek1BoingBoing1Yahoo!FinanceCanada1YahooLifestyleCanada1CarandDriver1CineD1CnEVPost1comicbookmovie1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1DailyKos1DaringFireball1DCRainmaker1Deseret1Designboom1Dezeen1DSOGaming1DiarioAS1Finbold1ForexFactory1FOX13Seattle1franchisetimes1Futurity1GameFile1GameWorldObserver1garymarcus.substack1GeekWire1GeekyGadgets1GosuGamers1HuffPost1Independent1InsideEVs1investor.costco1I/OFund1iPhoneinCanada1KCRA1KOMO1Magic:Gathering1MakeUseOf1Minecraft1MortgageDaily1MP1st1MyNorthwest1NBCBayArea1NBC5Chicago1NBC7SanDiego1Newser1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1Nokiamob1OregonPublicBroadcasting1OregonLive1PageSix1PCGamesN1PersonaCentral1PickupTruck+SUVTalk1Psyche1QuantaMagazine1Realtor1RichmondTimes-Dispatch1Richmonder1Road&Track1RPGSite1ScienceDaily1ScreenRant1SeattleRed1SanFranciscoChronicle1SFGATE1YahooFinanceSingapore1GhostHowls1SlowBoring1SoraNews241statnews1svg1TampaBayTimes1DailyBeast1Intercept1NextWeb1https://tipswatch.com/1TMZ1TODAY1TopGear1TweakTown1YahooFinanceUK1PCMagUK1Variety1Vulture1WCVB1WFMZ1WHYY1WindowsLatest1WrestlingInc.195.5WSB1
  1. 021X 主题热门SEP · 24English

    bridge exploit · X 热门 · 2026-09-24 20:31 UTC

    World Mobile is shifting Ethereum token recovery, exchange support, and liquidity to Base following a recent bridge exploit, while Cardano continues operating. The move signals Base's growing role in the company's infrastructure strategy.

  2. 022X 主题热门SEP · 24English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-24 19:59 UTC

    MultiversX's EGLD network experienced an attempted exploit but is now back online. The community awaits a post-mortem report and clarification on accusations against the MultiversX codebase during the incident.

  3. 023X 主题热门SEP · 24English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-24 19:58 UTC

    A user recounts losing millions in a smart contract exploit despite the project having a security audit, arguing that audit credentials alone don't guarantee trustworthiness. They advocate for GenLayer's approach of using randomly selected independent validators to evaluate outcomes, especially as AI agents gain decision-making power in financial systems.

  4. 024X 主题热门SEP · 24English

    Ethereum · X 热门 · 2026-09-24 18:52 UTC

    X discussions on Ethereum from September 24, 2026 cover market movements, a security incident where Payy's bridge contract was exploited, bullish sentiment about Ethereum's Layer 2 ecosystem advantages, and ARK Invest launching a tokenized venture fund on Ethereum.

  5. 025X 主题热门SEP · 24English

    bridge exploit · X 热门 · 2026-09-24 17:14 UTC

    A Kasplex exploit has reignited criticism of Kaspa's ecosystem governance, with the project targeting 100 blocks per second by 2027 through technologies like DAGKnight and ZK bridges.

  6. 026X 主题热门SEP · 24English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-24 16:42 UTC

    MultiversX experienced an exploit involving vulnerable code from the previous year, occurring shortly after a launch. The community hopes for a transparent post-mortem and recalibration, acknowledging the project's significance for Romania in cryptocurrency.

  7. 027X 主题热门SEP · 24English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-24 15:35 UTC

    A review of Pera Wallet for Algorand staking, comparing native consensus (requiring 30,000 ALGO minimum) with liquid staking options. The author found no reported exploits of Pera itself, though a different Algorand wallet (MyAlgo) was hacked for $9.6M in 2023. Current staking rewards are around 4.75%, with security features including non-custodial keys and local encryption, though the author notes a lack of recent third-party audit reports.

  8. 028X 主题热门SEP · 24English

    bridge exploit · X 热门 · 2026-09-24 12:50 UTC

    Payy Network's Ethereum L1 rollup bridge (RollupV1) was exploited and drained of approximately $1.83 million in USDC through a forged withdrawal hidden in a valid batch. The attack exploited the absence of deposit accounting, withdrawal caps, or pause mechanisms in the contract, with the attacker depositing only $10 while withdrawing $1.83 million using a compromised prover or validator key.

  9. 029Hacker NewsSEP · 24English

    Novel Arbitrary Write in SQLite

    A novel technique exploits SQLite's sqlite_dbpage virtual table to achieve arbitrary file writes and remote code execution by bypassing database header restrictions. By directly manipulating raw database pages via SQL queries and relocating the ELF Program Header Table, attackers can craft and load malicious shared objects, circumventing protections in strict runtimes like Python and Ruby.

    By gabdevele
  10. 030X 主题热门SEP · 24English

    bridge exploit · X 热门 · 2026-09-24 08:28 UTC

    A Kaspa KRC 20 exploit involved fraudulent transfers of 186.4 million ZEAL and 54.4 billion NACHO tokens through a Kasplex indexer vulnerability. Approximately 1 million iKAS from the attacker may be frozen during an Igra exit process, potentially preventing their withdrawal to Kaspa L1.

  11. 031Hacker NewsSEP · 24English

    Hackers Actively Exploit Check Point VPN Flaw

    Check Point disclosed CVE-2026-85102, a critical pre-authentication remote code execution vulnerability in its Security Gateway VPN product that allows attackers to execute arbitrary code via malicious certificates. Threat actors are actively exploiting the flaw in the wild, and the company has released patches urging immediate updates to prevent widespread data breaches and system compromise.

    By LebToki
  12. 032X 主题热门SEP · 23English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-23 22:39 UTC

    A malicious proposal exploited Neutron's governance process, granting the attacker admin control over smart contracts including Astroport and Drop Money, enabling asset drainage. Cosmos Hub validators coordinated a security halt to restrict stolen ATOM movement, and block production has since resumed as the ecosystem investigates the incident.

  13. 033X 主题热门SEP · 23English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-23 22:06 UTC

    A Neutron protocol exploit enabled attackers to gain admin control over smart contracts, including those of Astroport and Drop Money, and drain assets through a malicious governance proposal. The Cosmos ecosystem coordinated a security response by halting affected networks and restricting stolen asset movement, with Cosmos Hub resuming normal operations after the incident.

  14. 034X 主题热门SEP · 23English

    protocol exploit · X 热门 · 2026-09-23 21:33 UTC

    Neutron protocol was exploited through a malicious governance proposal that granted attackers admin control over smart contracts including Astroport and Drop, allowing asset drainage. Cosmos Hub and other validators coordinated a security halt to contain damage, and block production has since resumed while investigation into the full scope continues.

  15. 035X 主题热门SEP · 23English

    oracle exploit · X 热门 · 2026-09-23 21:00 UTC

    Hacking group ShinyHunters claimed to have breached FBI systems using a zero-day Oracle PeopleSoft exploit, stealing data on all FBI employees and applicants including names, addresses, and phone numbers. The group defaced the FBI's jobs website and demanded the FBI retract or remove a 2026 Q2 report about their tactics within one week, stating their motivation is coercion rather than financial extortion.

  16. 036X 主题热门SEP · 23English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-23 18:50 UTC

    A user analyzes eHYUSD, a DeFi protocol on Solana that offers 23% APY by having staked hyUSD holders act as the system's stability layer. The yield increases when collateral ratios exceed 165%, but holders face risks including smart contract exploits, volatile crypto collateral backing, and potential losses if the protocol fails to liquidate in time.

  17. 037X 主题热门SEP · 23English

    bridge exploit · X 热门 · 2026-09-23 17:11 UTC

    A security researcher flagged multiple DeFi applications with critical vulnerabilities, including direct fund theft risks in DeFiSaver and 1inch Wallet, a liquidity bridge exploit in Rootstock, and a double spending vulnerability in Stacks. The post warns that exploits may be released imminently.

  18. 038Hacker NewsSEP · 23English

    Containers Are No Longer a Security Boundary

    Containers are no longer a reliable security boundary as AI-accelerated kernel vulnerability discovery has dramatically lowered the barrier to container escape attacks. Researchers demonstrated this by exploiting CVE-2026-80521, a Linux kernel use-after-free vulnerability in the AF_UNIX subsystem discovered using an AI model. Organizations should migrate sensitive workloads to stronger isolation technologies like Firecracker or Kata Containers.

    By Zhenpeng Lin Security Researcher
  19. 039HackerSEP · 23English

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.

    By The Hacker News
  20. 040Hacker NewsSEP · 23English

    Show HN: RustyTux – Linux kernel LPE exploiting an ESP-in-TCP race

    RustyTux is a Linux kernel local privilege-escalation exploit targeting an ESP-in-TCP race condition in the strparser that affects multiple major Linux distributions including CentOS Stream 9 and Ubuntu 26.04 LTS. The timing-sensitive exploit uses x86 prefetch side-channel attacks to leak kernel base addresses and reclaims freed memory to achieve unprivileged privilege escalation.

    By M