source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 18, 2026
Hacker News3963X 主题热门3791CNBC76MacRumors679to5Mac61YahooFinance55Kotaku45IGN38Verge38aihot33NintendoLife319to5Google29Gematsu27BusinessInsider26Eurogamer24TechCrunch24Engadget22Guardian17NBC16Polygon16SeekingAlpha15USAToday15Wccftech15Fortune14PushSquare14bgr13CNET13Mashable13NPR13Gizmodo12FoxBusiness10Notebookcheck10ABC9AppleInsider9CBS9Fox9AndroidAuthority8ArsTechnica8GameInformer8Investor'sBusinessDaily8TechPowerUp8WindowsCentral8WIRED8BleepingComputer7PureXbox7Variety7VideoGamesChronicle7CNN6CoinDesk6XBOXWire6NewYorkPost6PetaPixel6SamMobile6DigitalFoundry5GSMArena5NintendoEverything5CrudeOilPricesToday5Yahoo5GameRant4Lifehacker4Motor14Pokemon4RPGSite4SeattleTimes4SlashGear4Register4VideoCardz4404Media3AlJazeera3AndroidCentral3AndroidPolice3CTech3ChromeUnboxed3GamesIndustry.biz3Hodinkee3Jalopnik3LosAngelesTimes3Blizzard3RockPaperShotgun3SouthChinaMorningPost3Space3Conversation3TweakTown3UploadVR3WarhammerCommunity3WindowsLatest3YourTango380Level2Aftermath2AOL2AwfulAnnouncing2BleedingCool2BloodyDisgusting2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DualShockers2DW2EventHubs2MotleyFool2FratelloWatches2GameDeveloper2GearPatrol2Independent2InsiderGaming2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Nature2Newser2PCWorld2PokémonGOHub2QuantaMagazine2RoadtoVR2SFGATE2Hacker2Intercept2ABC111AboveLaw1BusinessInsiderAfrica1ageofempires1AVClub1Benzinga1BikeRadar1Billboard1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1Chron1CineD1comicbook1CreativeBloq1Currently1Cyclingnews1DailyDownforce1DailyKos1DaringFireball1Defector1Defense1DenverPost1DigitalCameraWorld1Draftsim1DroidLife1CNN1empireonline1Euronews1Fangoria1flatpanelshd1FOX191DetroitFreePress1FrequentMiler1Futurism1GAMINGbible1GamingOnLinux1AAAGasPrices1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1InterestingEngineering1KITCO1KSL1Lloyd'sList1Macworld1Magic:Gathering1Mediaite1Mercury1MonochromeWatches1MorningBrew1MortgageDaily1Newsshooter1Newsweek1nrn1NYT1OregonLive1PageSix1PaulKrugman1PCMag1PlayStationLifeStyle1politico.eu1PittsburghPost-Gazette1qz1Road&Track1RockstarINTEL1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooSingapore1SportsIllustrated1SimpleFlying1Slate1supercarblondie1YahooTech1TechSpot1Tedium1TelecomTalk1TheGamer1NextWeb1TimeExtension1LongmontTimes-Call1TimesUnion1TmoNews1TwistedVoxel1YahooFinanceUK1UnHerd1VisualCapitalist1WOWT1WRAL1WSB-TV1YGOrganization1ZDNET1
  1. 001Hacker NewsSEP · 18English

    An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

    Google's threat intelligence team infiltrated the hacker group TeamPCP with an undercover analyst from Mandiant, monitoring their supply-chain attacks on hundreds of open-source programs and over 1,000 companies. Two alleged members were arrested in Australia in a joint FBI investigation after Google identified operational security mistakes and shared intelligence with law enforcement. The group deployed malware and a self-spreading worm called Mini Shai-Hulud to compromise developer accounts and breach major targets including OpenAI and Github.

    By Andy Greenberg
  2. 002BleepingComputerSEP · 18English

    New RatHat Android malware uses AI to automate device control

    RatHat, a new Android malware linked to Chinese threat actors, uses AI to automate remote device control by serializing the accessibility tree into XML and leveraging an AI assistant for intelligent interface navigation. Distributed via malvertising and phishing, it abuses Accessibility permissions and enables Developer Options to gain shell-level execution, deploying Go-based agents for persistence and credential theft from banking and cryptocurrency apps.

    By Bill Toulas
  3. 003Hacker NewsSEP · 18English

    ThinkNode M9 MicroSD Card and Virus Notice

    ThinkNode M9 units shipped with infected MicroSD cards containing a worm virus that exploits Windows Autorun features. The virus remains dormant on the card and poses no risk to the device itself, but can infect Windows PCs if activated. Affected customers can replace their device, remove the virus manually, or request a refund.

    By Sign In
  4. 004Hacker NewsSEP · 18English

    Alibi: Adversarial Legitimacy Injection in Binaries Against LLM Malware

    Researchers present ALIBI, an attack that injects false security narratives into binaries to deceive LLM-based malware analyzers into misclassifying malicious samples as benign. The attack successfully flips verdicts on major models like Gemini and GPT, highlighting the need for provenance verification in LLM malware analysis systems.

    By Choi; Hyeongjun; Jung; Wonyoung; Seo; Haehoon; Nam; Sungyup
  5. 005Hacker NewsSEP · 18English

    Researchers find way to listen in on headphones from afar

    The article is a news digest covering multiple tech topics including security vulnerabilities, AI developments, cybersecurity incidents, and software updates. Key stories include Microsoft SharePoint zero-day attacks, Russian phishing via Signal impersonation, AI-aided cyber attacks in Spain, and various hardware and software releases.

    By Thomas Claburn
  6. 006Hacker NewsSEP · 18English

    Shai-Hulud: Whoever controls your package registry controls your pipeline

    Starting September 2025, npm packages began self-updating with malware variants named Shai-Hulud, Shai-Hulud 2.0, Mini Shai-Hulud, and ChainDrop that steal developer credentials and automatically republish poisoned versions across hundreds of packages. These worms exploit the trust assumption in package managers by using compromised credentials to automate publishing without human intervention, with later variants targeting AI coding tool credentials and using cryptographic signatures and smart contracts to evade detection.

    By Zeen Rachidi
  7. 007X 主题热门SEP · 18English

    crypto wallet phishing · X 热门 · 2026-09-18 04:04 UTC

    A dark web actor is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across major blockchain networks including Ethereum, Bitcoin, and Solana, with features like phishing endpoints and admin panels. The claim remains unverified.

  8. 008Hacker NewsSEP · 18English

    Be alert: targeted attacks on prominent Rustaceans

    Prominent Rust developers and crate owners are being targeted in an ongoing campaign using social engineering via fake video calls to compromise devices and accounts for publishing malware. Attackers create legitimate-seeming company profiles and LinkedIn presences to gain trust. This attack style is attributed to DPRK and has previously compromised Rust developers in June and the arrayref crate last month.

    By Sept ; Security Response Working Group
  9. 009X 主题热门SEP · 18English

    crypto wallet drainer · X 热门 · 2026-09-18 02:59 UTC

    A dark web actor named 'vendoir' is advertising multi-chain cryptocurrency drainer source code for $210, claiming support for over 610 wallets across Ethereum, Bitcoin, Solana, and other blockchains with features including phishing endpoints and a web admin panel. The claim remains unverified.

  10. 010Hacker NewsSEP · 17English

    Brevo supply-chain attack injected ClickFix scripts on customer sites

    Brevo confirmed attackers stole a Cloudflare API key and injected malicious ClickFix scripts into its websites and customer sites for 5.5 hours on September 14, affecting approximately 100,000 websites. The hardcoded credential allowed attackers to create a Cloudflare Worker that modified content at the CDN edge, distributing malware including a WordPress backdoor plugin disguised as 'Web Media Optimizer.'

    By Bill Toulas
  11. 011X 主题热门SEP · 17English

    malicious approval · X 热门 · 2026-09-17 02:59 UTC

    SlowMist disclosed KREMLIN, a Brazilian banking malware operation active since May 2025, which uses multi-stage loaders and malicious browser extensions to steal credentials and data. The malware bypasses Chromium security mechanisms and leverages Ethereum smart contracts as dead-drop resolvers for C2 infrastructure, with 1,515 infected hosts primarily in Brazil.

  12. 012RegisterSEP · 17English

    Google Pixel phones pwned in zero-click attacks

    Google Pixel phones have been compromised in zero-click attacks, according to security reports. The vulnerability allows attackers to gain access without requiring user interaction. This represents a significant security concern for the Android device line.

    By Jessica Lyons
  13. 013Hacker NewsSEP · 17English

    Page Shield ML caught 4 storefront malware campaigns scanners missed

    Cloudflare's Page Shield ML detected four malicious JavaScript campaigns on storefronts that security scanners like VirusTotal and URLScan missed. The ML model uses graph neural networks and large language models to analyze JavaScript behavior patterns in live traffic, catching obfuscated scripts designed to steal affiliate revenue, hijack clicks, and tamper with analytics without relying on known signatures.

    By iamsyr
  14. 014Hacker NewsSEP · 17English

    Supply Chain Compromise of Korean-Language Windows 11 Installation Media

    A supply chain compromise of Korean-language Windows 11 installation media created with Microsoft's official Media Creation Tool distributed infostealer malware through a scheduled task that activated in July 2025 after nine months dormant. The tampering affected only Korean-language media on physical machines, not English versions or virtual environments, and was later linked to the JSCEAL campaign targeting cryptocurrency users.

    By ledoge
  15. 015X 主题热门SEP · 16English

    malicious approval · X 热门 · 2026-09-16 16:05 UTC

    A developer attending GISEC conference discusses eyebrow, a security tool for monitoring AI agents. The tool inventories agent artifacts, validates content hashes, maps host access, and flags unauthorized changes to prevent malicious code execution in both web2 and web3 environments. Presentations from Google Cloud Security and Microsoft highlighted similar concerns about autonomous exploitation and supply chain risks.

  16. 016Hacker NewsSEP · 16English

    Show HN: Check an NPM package or MCP server for malicious code before install

    A security analysis tool that scans NPM packages and MCP servers for malicious code before installation, checking for risky install scripts, credential access, data exfiltration, and hidden instructions without executing any code.

    By nader
  17. 017BleepingComputerSEP · 15English

    Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

    Hackers compromised HBO Max's verified Reddit account and posted 108 malicious ads using ClickFix social engineering to distribute information-stealing malware to Windows and macOS users. The campaign, linked to a broader operation called PasteSwitch, tricked victims into pasting commands into their terminals to install fake applications, including counterfeit HBO Max apps and cryptocurrency wallets.

    By Lawrence Abrams
  18. 018Hacker NewsSEP · 15English

    Who bankrolls the AI agent swarm?

    Anthropic CEO Dario Amodei warned that AI agent swarms could potentially compromise internet infrastructure within 6–12 months through recursive self-improvement. However, both plausible attack scenarios—distributing malware or self-replicating onto infrastructure—require enormous computational resources and funding, creating a significant practical barrier that makes such an attack difficult to execute without detection.

    By noperator
  19. 019X 主题热门SEP · 15English

    "private key" (compromised OR stolen OR leaked) · X 热门 · 2026-09-15 09:30 UTC

    Researchers at UC Santa Barbara discovered that LLM API routers used to reduce costs and balance loads are vulnerable to man-in-the-middle attacks. They found that 9 routers inject malicious code into AI responses and 17 steal credentials, with autonomous agent execution enabling immediate code exploitation without human approval.

  20. 020X 主题热门SEP · 15English

    bridge exploit · X 热门 · 2026-09-15 01:19 UTC

    Check Point and academic researchers discovered critical vulnerabilities in smart bulbs including Philips Hue and TP-Link Tapo models that enable attackers to inject malware into home networks through buffer overflows and credential theft. Millions of IoT devices are publicly exposed on Shodan, and attackers exploit known CVEs at scale; users should update firmware, isolate smart bulbs on separate networks, and replace devices with unpatched vulnerabilities.