source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News4011X 主题热门3840CNBC76MacRumors689to5Mac63YahooFinance57Kotaku45IGN38Verge38aihot34NintendoLife319to5Google29BusinessInsider27Gematsu27Eurogamer25TechCrunch24Engadget22Guardian17NBC16Polygon16SeekingAlpha15USAToday15Wccftech15Fortune14NPR14PushSquare14bgr13CNET13Mashable13Gizmodo12FoxBusiness11AndroidAuthority10ArsTechnica10Notebookcheck10ABC9AppleInsider9CBS9Fox9Investor'sBusinessDaily9TechPowerUp9WIRED9GameInformer8WindowsCentral8BleepingComputer7PureXbox7Variety7VideoGamesChronicle7WarhammerCommunity7CNN6CoinDesk6XBOXWire6NewYorkPost6PetaPixel6SamMobile6DigitalFoundry5GSMArena5NintendoEverything5CrudeOilPricesToday5Yahoo5GameRant4Lifehacker4Motor14Pokemon4RPGSite4SeattleTimes4SlashGear4Register4VideoCardz4404Media3AlJazeera3AndroidCentral3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Hodinkee3Jalopnik3LosAngelesTimes3Blizzard3RockPaperShotgun3SouthChinaMorningPost3Space3Conversation3TweakTown3UploadVR3WindowsLatest3YourTango380Level2Aftermath2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2QuantaMagazine2RoadtoVR2SFGATE2Hacker2Intercept2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GAMINGbible1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1qz1Road&Track1RockstarINTEL1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001X 主题热门SEP · 18English

    crypto wallet phishing · X 热门 · 2026-09-18 04:04 UTC

    A dark web actor is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across major blockchain networks including Ethereum, Bitcoin, and Solana, with features like phishing endpoints and admin panels. The claim remains unverified.

  2. 002X 主题热门SEP · 18English

    crypto wallet drainer · X 热门 · 2026-09-18 02:59 UTC

    A dark web actor named 'vendoir' is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across Ethereum, Bitcoin, Solana, and other blockchains with features including phishing endpoints and a web admin panel. The claim remains unverified.

  3. 003X 主题热门SEP · 17English

    malicious approval · X 热门 · 2026-09-17 02:59 UTC

    SlowMist disclosed KREMLIN, a Brazilian banking malware operation active since May 2025, which uses multi-stage loaders and malicious browser extensions to steal credentials and data. The malware bypasses Chromium security mechanisms and leverages Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, with 1,515 infected hosts primarily in Brazil.

  4. 004X 主题热门SEP · 16English

    malicious approval · X 热门 · 2026-09-16 16:05 UTC

    A developer attending GISEC conference discusses eyebrow, a security tool for monitoring AI agents. The tool inventories agent artifacts, validates content hashes, maps host access, and flags unauthorized changes to prevent malicious code execution in both web2 and web3 environments. Presentations from Google Cloud Security and Microsoft highlighted similar concerns about autonomous exploitation and supply chain risks.

  5. 005X 主题热门SEP · 15English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-15 09:30 UTC

    Researchers at UC Santa Barbara discovered that LLM API routers used to reduce costs and balance loads are vulnerable to man-in-the-middle attacks. They found that 9 routers inject malicious code into AI responses and 17 steal credentials, with autonomous agent execution enabling immediate code exploitation without human approval.

  6. 006X 主题热门SEP · 15English

    bridge exploit · X 热门 · 2026-09-15 01:19 UTC

    Check Point and academic researchers discovered critical vulnerabilities in smart bulbs including Philips Hue and TP-Link Tapo models that enable attackers to inject malware into home networks through buffer overflows and credential theft. Millions of IoT devices are publicly exposed on Shodan, and attackers exploit known CVEs at scale; users should update firmware, isolate smart bulbs on separate networks, and replace devices with unpatched vulnerabilities.

  7. 007X 主题热门SEP · 12English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-12 00:44 UTC

    A user reported their Phantom wallets were compromised after downloading a fake Axiom Exchange app from the App Store designed to steal cryptocurrency. Security guidance recommends immediately deleting the malicious app, abandoning affected wallets, changing passwords across accounts, and reporting to Apple and local authorities.