source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News3824X 主题热门3664CNBC71MacRumors669to5Mac59YahooFinance54Kotaku42Verge36IGN34NintendoLife31aihot309to5Google29Gematsu27BusinessInsider25Eurogamer24TechCrunch23Engadget18Guardian17Polygon16NBC15SeekingAlpha15USAToday15Fortune14Wccftech14NPR13PushSquare13bgr12CNET12Mashable12Gizmodo11FoxBusiness10AppleInsider9CBS9Fox9Notebookcheck9ABC8GameInformer8Investor'sBusinessDaily8TechPowerUp8WindowsCentral8WIRED8ArsTechnica7PureXbox7VideoGamesChronicle7AndroidAuthority6BleepingComputer6CNN6CoinDesk6XBOXWire6NewYorkPost6PetaPixel6Variety6GSMArena5NintendoEverything5CrudeOilPricesToday5SamMobile5Yahoo5DigitalFoundry4GameRant4Lifehacker4Motor14Pokemon4RPGSite4SlashGear4Register4VideoCardz4404Media3AlJazeera3AndroidCentral3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Jalopnik3LosAngelesTimes3Blizzard3RockPaperShotgun3SouthChinaMorningPost3SeattleTimes3Space3Conversation3TweakTown3WarhammerCommunity3WindowsLatest380Level2Aftermath2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Hodinkee2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2RoadtoVR2SFGATE2Hacker2Intercept2UploadVR2YourTango2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1Defector1Defense1DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GAMINGbible1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Newsshooter1Newsweek1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1QuantaMagazine1qz1Road&Track1RockstarINTEL1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001CyberSecurityNewsSEP · 17English

    CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory

    CISA and five international cybersecurity agencies published technical guidance documenting 17 techniques hackers use to compromise Microsoft Active Directory environments, exploiting identity configurations, legacy protocols, and certificate services to escalate privileges and establish persistence in enterprise networks.

    By Guru Baran
  2. 0029to5GoogleSEP · 16English

    Google confirms Pixel phones were exploited in ‘targeted’ attack related to modem

    Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in Google's September 2026 security update, which addressed over 200 vulnerabilities total.

    By Ben Schoon
  3. 003HackerSEP · 16English

    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem that shows signs of limited targeted exploitation. The vulnerability allows remote privilege escalation without user interaction and can be exploited in zero-click attacks. Google also released patches for 109 other security flaws in September 2026, with CISA adding the modem flaw to its Known Exploited Vulnerabilities catalog.

    By The Hacker News
  4. 004Hacker NewsSEP · 16English

    Google confirms Pixel phones exploited in 'targeted' modem based attack

    Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in September 2026 security update and CISA designated it a known exploited vulnerability used in targeted attacks.

    By Ben Schoon
  5. 005BleepingComputerSEP · 14English

    CISA: Hackers now exploit max severity GitLab flaw in attacks

    CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.

    By Sergiu Gatlan
  6. 006Hacker NewsSEP · 13English

    U.S. agencies say top Chinese AI companies systematically copied American models

    U.S. intelligence agencies reported Tuesday that top Chinese AI companies have systematically copied advanced American AI models like Claude, ChatGPT, Gemini, and Grok since 2024 through a practice called distillation. The FBI, NSA, and CISA identified six Chinese developers—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as conducting large-scale distillation campaigns likely with Chinese government awareness. China's Foreign Ministry rejected the accusations, stating its AI development reflects technological self-reliance and called for cooperation rather than confrontation.

    By Kevin Collier; Jared Perlo
  7. 007CyberSecurityNewsSEP · 12English

    Remote Desktop Services Failures on Windows Servers Following September Update

    Windows administrators are experiencing widespread Remote Desktop Services freezes following Microsoft's September 2026 Patch Tuesday updates for Server 2019, 2022, and 2025. The bug, triggered by session disconnects, causes RDP connections to hang and prevents new logins, with kernel-level analysis pointing to a deadlock in RDPSERVERBASE!WDLIB_Close. Organizations face a dilemma: rolling back restores stability but removes critical security patches including fixes for actively exploited zero-days.

    By Guru Baran
  8. 008BleepingComputerSEP · 12English

    GitLab urges users to patch max severity path traversal flaw

    GitLab urged users to immediately patch a maximum-severity path traversal vulnerability (CVE-2026-85706) in its repository commits API that allows unauthenticated attackers to read arbitrary data from vulnerable servers. Cybersecurity firm watchTowr reported that attackers are already probing for unpatched GitLab instances. The company also patched a second critical deserialization vulnerability (CVE-2026-87719) affecting GitLab Enterprise Edition.

    By Sergiu Gatlan
  9. 009Hacker NewsSEP · 11English

    Circia Covered Entity Criteria: Does the Rule Apply to You?

    CISA targets September 2026 for the final CIRCIA rule, which will require incident reporting from covered entities in sixteen critical infrastructure sectors. An organization is covered if it either exceeds SBA size standards for its industry or meets sector-based criteria, regardless of size. The rule applies broadly to any entity with U.S. legal presence participating in critical infrastructure sectors, not just owners and operators.

    By TheWiggles