source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 26, 2026
X 主题热门3538Hacker News3476CNBC67YahooFinance58aihot54Verge529to5Mac43IGN42MacRumors40Kotaku35Engadget28TechCrunch279to5Google24NintendoLife21AndroidAuthority20Eurogamer18Guardian18ArsTechnica16PushSquare15Wccftech14BusinessInsider13FoxBusiness13Investor'sBusinessDaily13Polygon13TechPowerUp13Fortune12USAToday12Gematsu11Gizmodo11VideoGamesChronicle10CNN9NintendoEverything9NPR9CBS8CNET8MotleyFool8GSMArena8Mashable8NBC8SeekingAlpha8AndroidPolice7BleepingComputer7Notebookcheck7PureXbox7VideoCardz7WarhammerCommunity7ABC6bgr6Fox6AlJazeera5AppleInsider5CoinDesk5DroidLife5GamesIndustry.biz5HollywoodReporter5NewYorkPost5PetaPixel5PokeBeach5Tom'sGuide5Yahoo5AndroidCentral4GameInformer4InsiderGaming4PlayStationLifeStyle4SlashGear4TechSpot4Conversation4Hacker4WIRED4Aftermath3BellofLostSouls3Deadline3Electrek3EventHubs3Futurism3GAMINGbible3GearPatrol3Hackaday3HuffPost3Lifehacker3Motor13XBOXWire3PCMag3RockPaperShotgun3SamMobile3SouthChinaMorningPost3UploadVR3WhatHi-Fi?3WindowsCentral3WSB-TV3404Media26abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2DCRainmaker2Draftsim2HouseDigest2Jalopnik2MyNintendo2Nature2CrudeOilPricesToday2Pokemon2RoadtoVR2RPGSite2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown2Variety224/7WallSt.180Level1ageofempires1Alternet1Anthropic1Apple1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CarandDriver1CarBuzz1cbn1CineD1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1ChristianScienceMonitor1Currently1DailyKos1DaringFireball1DarkHorizons1Decrypt1Deseret1Designboom1Dezeen1DigitalCameraWorld1DirtonDirt1DSOGaming1GameGPU1erictopol.substack1ForexFactory1franchisetimes1Futurity1GameRant1GameWorldObserver1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1HoustonChronicle1iLovetheUpperWestSide1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1KCRA1MacObserver1Magic:Gathering1MakeUseOf1Mashed1MLive1MortgageDaily1Motorsport1MP1st1mtgrocks1NBC5Chicago1BloombergLaw1Newsweek1NintendoWire1NYT1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1Psyche1qz1Realtor1Road&Track1Salon1ScienceDaily1SeattleRed1SeattleTimes1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SlowBoring1SoraNews241SpaceNews1statnews1YahooTech1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Register1Times1TimesofIndia1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1
  1. 001BleepingComputerSEP · 24English

    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability allowing unauthenticated remote code execution through path traversal. After initial reconnaissance probes following the patch release on September 22, malicious activity increased tenfold as attackers progressed to writing executable files to disk. WordPress 7.1.2 addresses the flaw across all supported versions.

    By Bill Toulas
  2. 002HackerSEP · 24English

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    cPanel disclosed three security flaws, including a critical vulnerability in its CalDAV/CardDAV service that allows any hosting account holder to execute code as root and gain full server control. A second flaw in the WP Toolkit plugin enables users to modify databases belonging to other accounts, while a third permits reading other accounts' calendar data. cPanel has released patched versions for all three issues.

    By The Hacker News
  3. 003Hacker NewsSEP · 22English

    A WordPress vulnerability scored 9.2/10 is present in all versions since 2016

    A critical unauthenticated path traversal vulnerability (CVSS 9.2) affects all WordPress versions since 2016, allowing attackers to include arbitrary PHP files and potentially execute code if specific theme and server conditions are met. WordPress 7.1.2 patches the issue, with fixes backported to all versions from 4.7 onward.

    By WordPress