source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
TUESDAY, SEPTEMBER 29, 2026
X 主题热门3965Hacker News3961CNBC82YahooFinance80aihot77Verge64IGN509to5Mac419to5Google39MacRumors38Engadget37Kotaku36TechCrunch34AndroidAuthority30PushSquare25Eurogamer21Guardian21NintendoLife20ArsTechnica19Investor'sBusinessDaily19Mashable19TechPowerUp17FoxBusiness14Polygon14Wccftech14Gematsu13SeekingAlpha13BusinessInsider12Fortune11Gizmodo11NBC11NPR11WIRED11bgr10CNN10VideoGamesChronicle10GSMArena9USAToday9AlJazeera8AndroidPolice8CNET8DroidLife8GameGPU8GameInformer8NewYorkPost8PureXbox8CBS7MotleyFool7Fox7GamesIndustry.biz7XBOXWire7BleepingComputer6HollywoodReporter6Jalopnik6NintendoEverything6Hacker6VideoCardz6Yahoo6ABC5AndroidCentral5AppleInsider5InsiderGaming5Tom'sGuide5Draftsim4GAMINGbible4NYT4CrudeOilPricesToday4PokeBeach4SamMobile4Space4UploadVR4WarhammerCommunity4WhatHi-Fi?4WindowsCentral4404Media3Aftermath3Electrek3EventHubs3Futurism3Hackaday3Lifehacker3Motor13Nature3Notebookcheck3PCMag3PetaPixel3PlayStationLifeStyle3SouthChinaMorningPost3Yahoo3YahooTech3TechSpot3Conversation3Register324/7WallSt.2AndroidHeadlines2Anthropic2Autonocion2AZFamily2BostonGlobe2BuzzFeed2ChromeUnboxed2CoinDesk2Currently2DCRainmaker2Deadline2DigitalFoundry2Euronews2GameRant2GearPatrol2GeekyGadgets2iLovetheUpperWestSide2LosAngelesTimes2MP1st2mtgrocks2MyNintendo2Phoronix2Pokemon2politico.eu2RoadtoVR2RockPaperShotgun2RPGSite2SeattleTimes2SFGATE2SimpleFlying2SimsCommunity2SlashGear2Slate2Autopian2TimeExtension2TODAY2ynetnews26abcPhiladelphia180Level1WXLV1ageofempires1airlive1AJC1AlaskaBeacon1Apple1AVClub1AviationWeek1Benzinga1BoingBoing1Yahoo!FinanceCanada1YahooLifestyleCanada1CarandDriver1CineD1CnEVPost1comicbookmovie1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1DailyKos1DaringFireball1Deseret1Designboom1Dezeen1DigitalCameraWorld1DSOGaming1DiarioAS1Finbold1ForexFactory1FOX13Seattle1franchisetimes1Futurity1GameFile1GameWorldObserver1garymarcus.substack1GeekWire1GosuGamers1Gothamist1Hackster.io1HuffPost1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1I/OFund1iPhoneinCanada1KCRA1KOMO1MacObserver1Magic:Gathering1MakeUseOf1Mashed1Minecraft1MLive1MortgageDaily1Motorsport1MyNorthwest1NBCBayArea1NBC5Chicago1NBC7SanDiego1BloombergLaw1Newser1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1Nokiamob1OregonPublicBroadcasting1OregonLive1PageSix1PCGamesN1PersonaCentral1PickupTruck+SUVTalk1Psyche1QuantaMagazine1Realtor1RichmondTimes-Dispatch1Richmonder1Road&Track1ScienceDaily1ScreenRant1SeattleRed1SanFranciscoChronicle1YahooFinanceSingapore1GhostHowls1SlowBoring1SoraNews241SpaceNews1statnews1svg1TampaBayTimes1the5krunner1DailyBeast1Intercept1NextWeb1https://tipswatch.com/1TMZ1TopGear1TweakTown1YahooFinanceUK1PCMagUK1Variety1Vulture1WCVB1WFMZ1WHYY1WindowsLatest1WrestlingInc.195.5WSB1YGOrganization1
  1. 001X 主题热门SEP · 29English

    bridge exploit · X 热门 · 2026-09-29 22:57 UTC

    Payy's bridge contract was exploited on September 24, 2026, with an attacker submitting an invalid burn proof that the Noir/Barretenberg verifier accepted, draining approximately 1.9 million USDC. The vulnerability appears to stem from the proving-system in Aztec's verifier, and Payy has paused all network transactions while investigating.

  2. 002X 主题热门SEP · 29English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-29 22:24 UTC

    Payy's bridge contract was exploited on September 24, 2026, when an attacker submitted an invalid burn proof that the Noir/Barretenberg verifier accepted, draining approximately 1.9 million USDC. The vulnerability appears to stem from the proving-system in Aztec's Noir/Barretenberg verifier, and Payy has paused all network transactions pending investigation.

  3. 003X 主题热门SEP · 29English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-29 22:24 UTC

    A post about giving an agent a pulse, shared on X (formerly Twitter) on September 29, 2026. The content appears to reference smart contract security concerns based on the search keywords, but specific details are not provided in the body.

  4. 004KotakuSEP · 29English

    PS5 Jailbreak Exploit For Systems Running July 2026 Firmware

    Hackers discovered the "Relapse" jailbreak exploit that works on all PS5 firmware versions except the latest (14.00.00), released September 16, 2026. The exploit affects retail PS5 consoles and older games like Marvel's Wolverine, potentially enabling widespread piracy since it can be implemented in under a minute.

    By Lewis Parker
  5. 005X 主题热门SEP · 29English

    Ethereum · X 热门 · 2026-09-29 17:29 UTC

    Social media discussion about Ethereum price movements and technical analysis, with mentions of a PPV2 exploit affecting token approvals. Traders discuss ETH price levels around $2,550-$2,800 and potential breakout zones, with attention to upcoming ISM economic data.

  6. 006Hacker NewsSEP · 29English

    New PlayStation 5 Console Jailbreak Released

    A PlayStation 5 jailbreak exploit supporting firmware versions 7.00 through 13.60 has been released. The exploit uses webkit vulnerabilities and kernel race conditions to achieve read-write access, with instructions for local deployment and payload execution via an ELF loader.

    By Ntfargo
  7. 007Hacker NewsSEP · 29English

    Kestra Unauthenticated Remote Code Execution CVE-2026-49869

    CVE-2026-49869 is an authentication bypass vulnerability in Kestra OSS that allows unauthenticated remote code execution. The defect exploits AuthenticationFilter treating any path ending in /configs as public, enabling attackers to create and execute workflows with shell tasks in the worker container. Users should upgrade to version 1.0.45 or 1.3.21 and restrict API access until patched.

    By EQSTLab
  8. 008X 主题热门SEP · 29English

    protocol exploit · X 热门 · 2026-09-29 07:06 UTC

    At Exploit Summit in Montreal on September 29, 2026, speakers discussed advances in distributed AI computing, subnet incentives, and open-source infrastructure across Bittensor's ecosystem. Earlier, the Bitget exploiter's attempt to route stolen funds through Chainflip was blocked when the protocol rejected the transaction at the broker interface and refunded the deposit.

  9. 009Hacker NewsSEP · 29English

    CVE-2026-85706 (CVSS 10.0)

    CVE-2026-85706 is a critical vulnerability (CVSS 10.0) in GitLab that allows unauthenticated attackers to read arbitrary files from the server by URL-encoding a single character in API requests, bypassing authentication entirely. The flaw has been exploited in the wild and is tracked in CISA's KEV catalog. Self-hosted GitLab installations must update to versions 19.1.8, 19.2.6, or 19.3.2 immediately.

    By soltanov
  10. 010X 主题热门SEP · 29English

    protocol exploit · X 热门 · 2026-09-29 00:33 UTC

    During a May 2026 exploit on THORChain, attackers stole $10.7M from liquidity pools. A protocol halt was used as an emergency security measure rather than selectively freezing specific funds or preventing the attackers from swapping, reflecting THORChain's design as a permissionless, non-censoring protocol.

  11. 011X 主题热门SEP · 28English

    protocol exploit · X 热门 · 2026-09-28 21:17 UTC

    A $387 million Bitget exploit sparked debate over whether THORChain should blacklist the attacker's addresses, raising fundamental questions about whether decentralized protocols should prioritize immutability and neutrality or intervene to protect victims and prevent theft.

  12. 012X 主题热门SEP · 28English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-28 20:45 UTC

    A social media post discusses Jevscan, a continuous on-chain monitoring tool, shared in the context of smart contract exploits and security incidents.

  13. 013Hacker NewsSEP · 28English

    Show HN: OpenSecurityTraining2

    OpenSecurityTraining2 is a collection of security training courses covering architecture, debugging, reverse engineering, vulnerability analysis, exploit development, secure development, and other defensive security topics.

    By therepanic
  14. 014X 主题热门SEP · 28English

    protocol exploit · X 热门 · 2026-09-28 18:01 UTC

    A $387M theft from Bitget exchange was routed through THORChain, prompting CEO Gracy Chen to request the protocol blacklist the stolen funds. THORChain declined, citing decentralization principles, but critics note the protocol previously halted operations for a month during its own $10.7M exploit, suggesting selective application of emergency powers.

  15. 015X 主题热门SEP · 28English

    "post-mortem" (exploit OR hack) · X 热门 · 2026-09-28 17:29 UTC

    Users report drained Farcaster in-app wallets with transactions signed by the wallet's own key and funds bridged to Solana, though the cause remains unconfirmed. The incident highlights risks of embedded wallets where users may not control their keys directly. Security researchers advise moving funds to self-custodied wallets as a precaution.

  16. 016X 主题热门SEP · 28English

    "smart contract" (exploit OR hacked OR drained) · X 热门 · 2026-09-28 17:28 UTC

    A post from Tashi Network discussing robots, chains, and emerging technologies, trending on X as of September 28, 2026.

  17. 017Hacker NewsSEP · 28English

    Hijacking the PS5's RTMP Stream

    A developer created a method to hijack the PS5's RTMP streaming protocol by spoofing DNS records, allowing them to stream PS5 gameplay to Discord without purchasing an expensive capture card. The solution uses dnsmasq and nginx-rtmp to redirect the PS5's stream from Twitch's servers to a local Mac, bypassing Sony's streaming restrictions.

    By Yash Garg
  18. 018X 主题热门SEP · 28English

    protocol exploit · X 热门 · 2026-09-28 14:44 UTC

    X discussions analyze a protocol exploit affecting THORChain, comparing its security vulnerabilities and inconsistent decentralization principles to NEAR Protocol's more stable infrastructure approach. A $1.7M exploit in May 2026 prompted network intervention, contradicting the protocol's permissionless philosophy, while stolen Bitget funds now flow through THORChain's fee mechanisms to cover past losses.

  19. 019X 主题热门SEP · 28English

    bridge exploit · X 热门 · 2026-09-28 12:00 UTC

    A $292M bridge exploit has triggered litigation between KelpDAO and LayerZero over security risk disclosure, while Hedera demonstrates strong institutional adoption through its Governing Council of Fortune 500 companies, enterprise applications on IBM Cloud, and contribution of its cross-ledger protocol to the Linux Foundation, though its token trades below its 2018 ICO price.

  20. 020X 主题热门SEP · 28English

    protocol exploit · X 热门 · 2026-09-28 10:22 UTC

    THORChain declined Bitget's request to block addresses associated with attackers from a $387.5 million September security breach, citing its permissionless design and network halt mechanism's purpose to protect the protocol rather than freeze individual addresses.