source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 19, 2026
Hacker News3703X 主题热门3540CNBC71MacRumors679to5Mac57YahooFinance48Kotaku47IGN37Verge36aihot34NintendoLife309to5Google25Gematsu25TechCrunch25BusinessInsider23Eurogamer23Engadget17Polygon15PushSquare15Guardian15NBC14SeekingAlpha14bgr13Fortune13USAToday13Gizmodo12NPR12FoxBusiness11Mashable11WarhammerCommunity11Wccftech11AndroidAuthority10ArsTechnica10ABC9CNET9Fox9Notebookcheck9TechPowerUp9AppleInsider8GameInformer8PureXbox8WindowsCentral8CNN7Variety7VideoGamesChronicle7WIRED7BleepingComputer6CoinDesk6Investor'sBusinessDaily6XBOXWire6NintendoEverything6NewYorkPost6PetaPixel6CBS5DigitalFoundry5GSMArena5SamMobile5VideoCardz5Deadline4GameRant4Pokemon4RPGSite4SlashGear4Conversation4Register4Yahoo4404Media3Aftermath3AlJazeera3AndroidCentral3AndroidPolice3CTech3GearPatrol3Hodinkee3Jalopnik3LosAngelesTimes3Lifehacker3Motor13Blizzard3CrudeOilPricesToday3RockPaperShotgun3SeattleTimes3Space3TweakTown3WindowsLatest3YourTango380Level2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GamesIndustry.biz2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2qz2SouthChinaMorningPost2SFGATE2Intercept2UploadVR2WSB-TV2ABC7LosAngeles1AboveLaw1BusinessInsiderAfrica1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1CalMatters1ChromeUnboxed1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1DCRainmaker1Defector1Defense1denver71DenverPost1DigitalCameraWorld1Draftsim1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GameDeveloper1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1HuffPost1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1MakeUseOf1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1SemiAnalysis1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1QuantaMagazine1Road&Track1RoadtoVR1RockstarINTEL1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1Hacker1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1VisualCapitalist1WOWT1
  1. 001X 主题热门SEP · 19English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-19 08:27 UTC

    SlowMist and OKX security teams discovered that FomoPeek App versions 1.1–1.2 contain malicious code including an iOS kernel exploitation framework capable of escaping sandboxes and accessing private keys and sensitive data. The affected iOS versions range from 12.0–18.7 and 26.0–26.1, with users advised to check accounts, create new wallets, and stop using the app immediately.

  2. 002Hacker NewsSEP · 18English

    Not in My Git Yard: Catching Backdoors at Commit and Release Time

    Lily is an automated approach that detects code-level backdoors in open-source software by integrating backdoor detection into CI pipelines and release vetting workflows. It uses enhanced fuzzing to identify suspicious behavior triggers and combines code analysis with fuzzing data to pinpoint malicious code regions, achieving high detection accuracy while resisting adversarial evasion attempts.

    By Kokkonis; Dimitri; Marcozzi; Michaël; Zacchiroli; Stefano
  3. 003Hacker NewsSEP · 18English

    An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

    Google's threat intelligence team infiltrated the hacker group TeamPCP with an undercover analyst from Mandiant, monitoring their supply-chain attacks on hundreds of open-source programs and over 1,000 companies. Two alleged members were arrested in Australia in a joint FBI investigation after Google identified operational security mistakes and shared intelligence with law enforcement. The group deployed malware and a self-spreading worm called Mini Shai-Hulud to compromise developer accounts and breach major targets including OpenAI and Github.

    By Andy Greenberg
  4. 004BleepingComputerSEP · 18English

    New RatHat Android malware uses AI to automate device control

    RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.

    By Bill Toulas
  5. 005Hacker NewsSEP · 18English

    ThinkNode M9 MicroSD Card and Virus Notice

    ThinkNode M9 units shipped with infected MicroSD cards containing a worm virus that exploits Windows Autorun features. The virus remains dormant on the card and poses no risk to the device itself, but can infect Windows PCs if activated. Affected customers can replace their device, remove the virus manually, or request a refund.

    By Sign In
  6. 006Hacker NewsSEP · 18English

    Alibi: Adversarial Legitimacy Injection in Binaries Against LLM Malware

    Researchers present ALIBI, an attack that injects false security narratives into binaries to deceive LLM-based malware analyzers into misclassifying malicious samples as benign. The attack successfully flips verdicts on major models like Gemini and GPT, highlighting the need for provenance verification in LLM malware analysis systems.

    By Choi; Hyeongjun; Jung; Wonyoung; Seo; Haehoon; Nam; Sungyup