source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 25, 2026
X 主题热门3860Hacker News3807CNBC71YahooFinance65aihot60Verge569to5Mac52IGN48MacRumors47Kotaku39Engadget31TechCrunch289to5Google26NintendoLife24AndroidAuthority23ArsTechnica18Eurogamer18Guardian18BusinessInsider15Investor'sBusinessDaily15PushSquare15Wccftech15USAToday14WarhammerCommunity14FoxBusiness13TechPowerUp13Polygon12Fortune11Gizmodo11CNET10Gematsu10Mashable10NBC10NPR10SeekingAlpha10CBS9CNN9NintendoEverything9VideoCardz9VideoGamesChronicle9BleepingComputer8MotleyFool8GSMArena8Notebookcheck8PureXbox8ABC7bgr7Fox7AndroidPolice6AppleInsider6CoinDesk6NewYorkPost6WIRED6Yahoo6AlJazeera5AndroidCentral5DroidLife5GamesIndustry.biz5HollywoodReporter5InsiderGaming5PetaPixel5PlayStationLifeStyle5PokeBeach5TechSpot5Tom'sGuide5Aftermath4Deadline4Lifehacker4SamMobile4SlashGear4Conversation4Hacker4UploadVR4Variety4WindowsCentral4404Media3BellofLostSouls3EventHubs3GameInformer3GearPatrol3Hackaday3HuffPost3Motor13PCMag3RockPaperShotgun3RPGSite3SouthChinaMorningPost3WhatHi-Fi?3WSB-TV36abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2Currently2DaringFireball2DCRainmaker2Electrek2Futurism2GAMINGbible2HouseDigest2Jalopnik2MyNintendo2Nature2XBOXWire2Pokemon2qz2Road&Track2RoadtoVR2SeattleTimes2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown224/7WallSt.180Level1ageofempires1Alternet1Apple1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CalMatters1CarBuzz1cbn1CineD1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1ChristianScienceMonitor1DailyKos1DarkHorizons1Decrypt1Defense1denver71Designboom1DigitalCameraWorld1DigitalFoundry1DirtonDirt1Draftsim1DSOGaming1empireonline1GameGPU1erictopol.substack1Fangoria1ForexFactory1franchisetimes1DetroitFreePress1GameRant1GameWorldObserver1GamingOnLinux1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1Hodinkee1HoustonChronicle1iLovetheUpperWestSide1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1LosAngelesTimes1MacObserver1MakeUseOf1Mashed1MLive1MorningBrew1MortgageDaily1Motorsport1MP1st1NBC5Chicago1BloombergLaw1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1nrn1NYT1CrudeOilPricesToday1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1Psyche1QuantaMagazine1Realtor1RockstarINTEL1Salon1SeattleRed1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SlowBoring1SoraNews241SpaceNews1statnews1YahooTech1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Register1Times1TimesofIndia1TimesUnion1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1YourTango1
  1. 001HackerSEP · 24English

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    Threat actors are actively exploiting WordPress CVE-2026-87902, a critical remote code execution vulnerability, within hours of its public disclosure. The attacks target servers meeting specific preconditions and use local PHP files like pearcmd.php to execute malicious code, with over 68 exploitation attempts recorded from multiple countries since September 22, 2026.

    By The Hacker News
  2. 002HackerSEP · 24English

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    WordPress patched a critical vulnerability (CVE-2026-87902, CVSS 9.2) affecting versions 4.7.0 through 7.1.1 that allows unauthenticated attackers to load external PHP files, potentially enabling code execution on some servers. The fix shipped September 22 across all supported branches, and site owners are urged to update immediately as no workaround exists.

    By The Hacker News
  3. 003BleepingComputerSEP · 24English

    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability allowing unauthenticated remote code execution through path traversal. After initial reconnaissance probes following the patch release on September 22, malicious activity increased tenfold as attackers progressed to writing executable files to disk. WordPress 7.1.2 addresses the flaw across all supported versions.

    By Bill Toulas
  4. 004Hacker NewsSEP · 24English

    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability that allows unauthenticated remote code execution through path traversal. Malicious activity increased tenfold within days of the patch release, with attackers now writing executable files to disk. WordPress addressed the flaw in version 7.1.2 and backported fixes to all supported versions.

    By Bill Toulas