source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 25, 2026
Hacker News3587X 主题热门3526CNBC67YahooFinance62aihot55Verge529to5Mac48IGN46MacRumors40Kotaku37TechCrunch27Engadget25AndroidAuthority239to5Google22NintendoLife20ArsTechnica17Eurogamer17Guardian17Wccftech15BusinessInsider14Investor'sBusinessDaily14USAToday14FoxBusiness13PushSquare13WarhammerCommunity13Polygon12TechPowerUp12Fortune11Gizmodo10Mashable10SeekingAlpha10CBS9CNET9Gematsu9NBC9NPR9VideoGamesChronicle9CNN8MotleyFool8GSMArena8NintendoEverything8Notebookcheck8PureXbox8VideoCardz8ABC7bgr7BleepingComputer7AppleInsider6CoinDesk6Fox6NewYorkPost6WIRED6Yahoo6AlJazeera5DroidLife5HollywoodReporter5InsiderGaming5PlayStationLifeStyle5TechSpot5Tom'sGuide5Aftermath4AndroidCentral4Deadline4GamesIndustry.biz4PetaPixel4SamMobile4SlashGear4Conversation4Hacker4UploadVR4Variety4WindowsCentral4404Media3AndroidPolice3BellofLostSouls3EventHubs3GameInformer3GearPatrol3Hackaday3HuffPost3Lifehacker3Motor13PCMag3PokeBeach3RockPaperShotgun3RPGSite3SouthChinaMorningPost3WhatHi-Fi?3WSB-TV36abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2Currently2DaringFireball2DCRainmaker2Futurism2GAMINGbible2HouseDigest2Jalopnik2MyNintendo2Nature2XBOXWire2Pokemon2qz2Road&Track2RoadtoVR2SeattleTimes2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown224/7WallSt.180Level1ageofempires1Alternet1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CalMatters1CarBuzz1cbn1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1ChristianScienceMonitor1DailyKos1DarkHorizons1Decrypt1Defense1denver71Designboom1DigitalCameraWorld1DigitalFoundry1DirtonDirt1Draftsim1DSOGaming1Electrek1empireonline1GameGPU1erictopol.substack1Fangoria1ForexFactory1franchisetimes1DetroitFreePress1GameRant1GameWorldObserver1GamingOnLinux1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1Hodinkee1HoustonChronicle1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1LosAngelesTimes1MacObserver1MakeUseOf1Mashed1MLive1MorningBrew1MortgageDaily1Motorsport1MP1st1NBC5Chicago1BloombergLaw1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1nrn1NYT1CrudeOilPricesToday1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1QuantaMagazine1Realtor1RockstarINTEL1Salon1SeattleRed1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SoraNews241SpaceNews1statnews1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Times1TimesofIndia1TimesUnion1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1YourTango1
  1. 001BleepingComputerSEP · 24English

    New RemControl Android banking malware targets users in Europe and Canada

    RemControl, a new Android banking malware-as-a-service platform, targets users in Europe and Canada through malvertising campaigns impersonating the TVTap IPTV app. The malware uses over 30 phishing overlays to steal banking credentials and can perform remote actions including screenshot capture and keystroke logging. It evades detection by blocking Google Play Protect and uses Telegram channels to dynamically rotate its command-and-control infrastructure.

    By Bill Toulas
  2. 002BleepingComputerSEP · 24English

    Placeholder domain used in dev docs now serves ClickFix attacks

    The placeholder domain third-party.com, widely used in developer documentation as an example hostname, is now serving ClickFix attacks that impersonate Cloudflare verification pages to trick Windows users into executing malicious PowerShell commands. Unlike IANA-reserved documentation domains, third-party.com is a normally registered domain whose owner can control its content, creating a security vulnerability for developers who copy example code literally.

    By Lawrence Abrams
  3. 003BleepingComputerSEP · 22English

    Microsoft reminds admins to migrate Entra ID users to passkeys

    Microsoft is retiring SMS and voice as first-factor authentication methods for Entra ID starting February 2027, requiring administrators to migrate users to phishing-resistant alternatives like passkeys, FIDO2 security keys, or QR code authentication. The company has already ended SMS sign-in for free tenants and is rolling out passkeys as the default authentication method. Organizations must complete migration before the deadline to avoid sign-in disruptions.

    By Sergiu Gatlan
  4. 004BleepingComputerSEP · 20English

    North Korean WaterPlum hackers infected 30,000 devices worldwide

    North Korean hacking group WaterPlum compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, stealing over $10.7 million in cryptocurrency. The group, linked to the 'Contagious Interview' campaign, targets job seekers through fake interviews and malicious software packages. A joint advisory from Japanese, US, Australian, and German authorities connects WaterPlum to North Korea's weapons programs and fraudulent IT worker operations.

    By Bill Toulas
  5. 005BleepingComputerSEP · 18English

    New RatHat Android malware uses AI to automate device control

    RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.

    By Bill Toulas