source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
MONDAY, SEPTEMBER 21, 2026
Hacker News3605X 主题热门3438CNBC70MacRumors639to5Mac58YahooFinance45Kotaku44IGN33Verge30aihot27TechCrunch279to5Google25Gematsu25NintendoLife23BusinessInsider20Eurogamer16Engadget15NBC14NPR13PushSquare13WarhammerCommunity13Polygon12Guardian12AndroidAuthority11bgr11Fortune11SeekingAlpha11USAToday11ABC10AppleInsider10ArsTechnica10FoxBusiness10Gizmodo10TechPowerUp10CNN9Notebookcheck9PureXbox9Wccftech9CNET8Fox8PetaPixel8CoinDesk7NintendoEverything7Yahoo7BleepingComputer6GSMArena6Mashable6WindowsCentral6CBS5DigitalFoundry5SamMobile5SlashGear5VideoCardz5VideoGamesChronicle5WIRED5AndroidCentral4GameInformer4Investor'sBusinessDaily4XBOXWire4Pokemon4Conversation4Register4TweakTown4WSB-TV4404Media3Aftermath3AlJazeera3AndroidPolice3BellofLostSouls3CTech3Deadline3MotleyFool3Hodinkee3HuffPost3Lifehacker3Motor13CrudeOilPricesToday3RockPaperShotgun3RPGSite3SeattleTimes3Variety380Level2AOL2BleedingCool2CanonRumors2DualShockers2DW2EventHubs2FratelloWatches2Futurism2GameRant2GamesIndustry.biz2GearPatrol2HouseDigest2InsiderGaming2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2Nature2qz2SouthChinaMorningPost2Space2TechSpot2Intercept2Tom'sGuide2WindowsLatest2ABC7LosAngeles1BusinessInsiderAfrica1Alternet1AndroidHeadlines1ArizonaSports1Benzinga1BikeRadar1Billboard1BloodyDisgusting1Boston1Bungie1BuzzFeed1CalMatters1CarBuzz1cbn1ChromeUnboxed1Chron1ColoradoSun1comicbook1CreativeBloq1ChristianScienceMonitor1Currently1CyberSecurityNews1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Decrypt1Defector1Defense1denver71DenverPost1DigitalCameraWorld1DirtonDirt1Draftsim1DroidLife1empireonline1erictopol.substack1Euronews1Fangoria1FOX191DetroitFreePress1FrequentMiler1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Global1Hackaday1HollywoodReporter1Independent1KITCO1KSL1Macworld1Magic:Gathering1MakeUseOf1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Blizzard1Newser1SemiAnalysis1Newsshooter1Newsweek1nrn1NewYorkPost1OneMileataTime1OregonPublicBroadcasting1OregonLive1PageSix1PCMag1PCWorld1PlayStationLifeStyle1PokeBeach1PokémonGOHub1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1Salon1CultureMapSanAntonio1ScienceAlert1Semafor1SFGATE1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1SlippedDisc1YahooTech1Tedium1TelecomTalk1DailyBeast1Drive1Hacker1Hindu1NextWeb1Times1TimeExtension1TimesofIndia1TimesUnion1TMZ1TwistedVoxel1YahooFinanceUK1UploadVR1VisualCapitalist1WOWT1YourTango1
  1. 001BleepingComputerSEP · 18English

    New RatHat Android malware uses AI to automate device control

    RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.

    By Bill Toulas
  2. 002BleepingComputerSEP · 17English

    Microsoft shares workaround for Windows domain login issues

    Microsoft released a workaround for Windows 11 domain login failures caused by September 2026 security updates that inadvertently enable Machine Identity Isolation enforcement. The feature breaks domain authentication on systems not connected to Windows Server 2025 domain controllers, and Microsoft advises disabling it via registry, Group Policy, or Intune until a permanent fix is available.

    By Sergiu Gatlan
  3. 003BleepingComputerSEP · 17English

    Windows 11 KB5124008 update breaks domain trust for some users

    Microsoft's Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. The issue appears linked to the Windows Machine Identity Isolation security feature being set to enforcement mode after the update, causing machines to lose their secure channel with Active Directory. Administrators can restore access by disabling the feature and repairing the secure channel using PowerShell.

    By Lawrence Abrams
  4. 004BleepingComputerSEP · 15English

    Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

    Hackers compromised HBO Max's verified Reddit account and posted 108 malicious ads using ClickFix social engineering to distribute information-stealing malware to Windows and macOS users. The campaign, linked to a broader operation called PasteSwitch, tricked victims into pasting commands into their terminals to install fake applications, including counterfeit HBO Max apps and cryptocurrency wallets.

    By Lawrence Abrams
  5. 005BleepingComputerSEP · 14English

    CISA: Hackers now exploit max severity GitLab flaw in attacks

    CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.

    By Sergiu Gatlan