source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
FRIDAY, SEPTEMBER 25, 2026
Hacker News3587X 主题热门3526CNBC67YahooFinance62aihot55Verge529to5Mac48IGN46MacRumors40Kotaku37TechCrunch27Engadget25AndroidAuthority239to5Google22NintendoLife20ArsTechnica17Eurogamer17Guardian17Wccftech15BusinessInsider14Investor'sBusinessDaily14USAToday14FoxBusiness13PushSquare13WarhammerCommunity13Polygon12TechPowerUp12Fortune11Gizmodo10Mashable10SeekingAlpha10CBS9CNET9Gematsu9NBC9NPR9VideoGamesChronicle9CNN8MotleyFool8GSMArena8NintendoEverything8Notebookcheck8PureXbox8VideoCardz8ABC7bgr7BleepingComputer7AppleInsider6CoinDesk6Fox6NewYorkPost6WIRED6Yahoo6AlJazeera5DroidLife5HollywoodReporter5InsiderGaming5PlayStationLifeStyle5TechSpot5Tom'sGuide5Aftermath4AndroidCentral4Deadline4GamesIndustry.biz4PetaPixel4SamMobile4SlashGear4Conversation4Hacker4UploadVR4Variety4WindowsCentral4404Media3AndroidPolice3BellofLostSouls3EventHubs3GameInformer3GearPatrol3Hackaday3HuffPost3Lifehacker3Motor13PCMag3PokeBeach3RockPaperShotgun3RPGSite3SouthChinaMorningPost3WhatHi-Fi?3WSB-TV36abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2Currently2DaringFireball2DCRainmaker2Futurism2GAMINGbible2HouseDigest2Jalopnik2MyNintendo2Nature2XBOXWire2Pokemon2qz2Road&Track2RoadtoVR2SeattleTimes2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown224/7WallSt.180Level1ageofempires1Alternet1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CalMatters1CarBuzz1cbn1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1ChristianScienceMonitor1DailyKos1DarkHorizons1Decrypt1Defense1denver71Designboom1DigitalCameraWorld1DigitalFoundry1DirtonDirt1Draftsim1DSOGaming1Electrek1empireonline1GameGPU1erictopol.substack1Fangoria1ForexFactory1franchisetimes1DetroitFreePress1GameRant1GameWorldObserver1GamingOnLinux1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1Hodinkee1HoustonChronicle1Independent1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1LosAngelesTimes1MacObserver1MakeUseOf1Mashed1MLive1MorningBrew1MortgageDaily1Motorsport1MP1st1NBC5Chicago1BloombergLaw1SemiAnalysis1Newsshooter1Newsweek1NintendoWire1nrn1NYT1CrudeOilPricesToday1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1QuantaMagazine1Realtor1RockstarINTEL1Salon1SeattleRed1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SoraNews241SpaceNews1statnews1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Times1TimesofIndia1TimesUnion1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1YourTango1
  1. 001X 主题热门SEP · 25English

    crypto wallet phishing · X 热门 · 2026-09-25 05:48 UTC

    A cryptocurrency privacy service called FortressName allows users to register a single name to receive funds across multiple blockchains while mapping each payment to a fresh stealth address, reducing exposure to phishing and wallet history tracking. The service provider Americanfort_io is promoting the platform at cryptocurrency conferences in Seoul and Singapore in October 2026.

  2. 002X 主题热门SEP · 25English

    crypto wallet phishing · X 热门 · 2026-09-25 02:31 UTC

    Bitget exchange suffered a $351.6M hack on September 24, 2026, with unauthorized transfers from hot and warm wallets. The exchange claims its Protection Fund covers the loss, though withdrawals remain frozen while the incident is investigated. The post also discusses address poisoning risks in crypto transactions and mentions Americanfort_io's alternative security approach using unique stealth addresses.

  3. 003BleepingComputerSEP · 24English

    New RemControl Android banking malware targets users in Europe and Canada

    RemControl, a new Android banking malware-as-a-service platform, targets users in Europe and Canada through malvertising campaigns impersonating the TVTap IPTV app. The malware uses over 30 phishing overlays to steal banking credentials and can perform remote actions including screenshot capture and keystroke logging. It evades detection by blocking Google Play Protect and uses Telegram channels to dynamically rotate its command-and-control infrastructure.

    By Bill Toulas
  4. 004X 主题热门SEP · 24English

    crypto wallet phishing · X 热门 · 2026-09-24 23:15 UTC

    Two X users discuss AmericanFortress, a privacy infrastructure platform that replaces complex crypto wallet addresses with human-readable @names while generating unique stealth addresses for each transaction to reduce phishing risk and enhance on-chain privacy.

  5. 005X 主题热门SEP · 24English

    crypto wallet phishing · X 热门 · 2026-09-24 19:58 UTC

    A social media post highlights security and privacy issues in cryptocurrency transactions, including address poisoning and phishing attacks, and promotes Americanfort_io as a wallet solution that uses stealth addresses and FortressNames to enable private transactions without exposing balances or transaction history.

  6. 006BleepingComputerSEP · 24English

    Placeholder domain used in dev docs now serves ClickFix attacks

    The placeholder domain third-party.com, widely used in developer documentation as an example hostname, is now serving ClickFix attacks that impersonate Cloudflare verification pages to trick Windows users into executing malicious PowerShell commands. Unlike IANA-reserved documentation domains, third-party.com is a normally registered domain whose owner can control its content, creating a security vulnerability for developers who copy example code literally.

    By Lawrence Abrams
  7. 007Hacker NewsSEP · 24English

    Dutch intelligence services warn AI is making cyberattacks faster and easier

    Dutch intelligence services AIVD and MIVD, along with five other organizations, warn that AI is making cyberattacks faster and easier by automating attacks and lowering barriers for malicious actors. They urge businesses and institutions to strengthen cybersecurity measures, keep systems updated, monitor networks, and invest in employee awareness and training.

    By warrenmiller
  8. 008X 主题热门SEP · 24English

    crypto wallet phishing · X 热门 · 2026-09-24 04:06 UTC

    Nano Labs founder Jack Kong's X account was hacked and used to post phishing links impersonating a new crypto project. Users are warned not to connect wallets or sign transactions from the compromised account without official verification.

  9. 009Hacker NewsSEP · 23English

    What are passkeys? A simple guide for friends and family

    Passkeys are digital keys that replace passwords, using your device's biometric or PIN verification to securely sign in without transmitting passwords. Each service gets a unique passkey based on public key cryptography, protecting against password reuse, theft, and phishing attacks.

    By timmyc123
  10. 010X 主题热门SEP · 23English

    "address poisoning" · X 热门 · 2026-09-23 17:44 UTC

    AmericanFortress promotes Send-to-Name technology that generates unique stealth addresses for transactions to prevent address poisoning and phishing attacks while maintaining privacy between sender and recipient.

  11. 011X 主题热门SEP · 23Chinese

    crypto wallet phishing · X 热门 · 2026-09-23 16:39 UTC

    A Binance promotional post invites users to share crypto stories and creative content for a Mid-Autumn Festival campaign, emphasizing themes of global financial connectivity and trading across time zones.

  12. 012HackerSEP · 23English

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    Chinese threat actor UTA0565 exploited a Chrome-Windows zero-day chain to deploy CLEANGULP malware through fake websites impersonating media organizations and NGOs. Attacks targeting Asian government entities used phishing emails referencing Hong Kong activist Chow Hang-tung and spoofed the Center for American Progress. The malware supports remote command execution, file operations, and process enumeration via a C2 domain mimicking a legitimate media outlet.

    By The Hacker News
  13. 013Hacker NewsSEP · 23English

    Anthropic-linked CVEs pile up, attackers mostly shrug

    Anthropic faces mounting CVEs with limited attacker response, while the tech industry navigates AI model releases, security vulnerabilities in enterprise software, and evolving cybersecurity threats including ransomware and phishing campaigns.

    By Jessica Lyons
  14. 014X 主题热门SEP · 23English

    crypto wallet phishing · X 热门 · 2026-09-23 07:20 UTC

    A social media post discusses Tangem's cryptocurrency hardware wallet ecosystem, explaining self-custody concepts and how Tangem's products—wallet cards, rings, apps, and payment solutions—integrate security with practical everyday usage for crypto users.

  15. 015Hacker NewsSEP · 23English

    Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

    Microsoft disrupted EvilTokens, an AI-powered subscription scam platform that compromised 12,000 accounts across 10,000 organizations globally. The platform, introduced via Telegram in February, charged $1,500 upfront plus $500 monthly, using an AI chatbot to analyze victim inboxes and recommend fraud strategies. Microsoft seized 50 websites and 150 domains, and UK police arrested two suspects.

    By Dan Goodin
  16. 016X 主题热门SEP · 23English

    crypto wallet phishing · X 热门 · 2026-09-23 04:04 UTC

    A user warned about receiving a suspicious unsolicited crypto interview pitch on X from an account that requested credentials through a Google Sites link with an Apps Script login flow, exhibiting multiple phishing indicators.

  17. 017X 主题热门SEP · 23English

    Robinhood · X 热门 · 2026-09-23 04:03 UTC

    A crypto user lost $20,000 from their MetaMask wallet after being socially engineered by scammers posing as NPR's "The Indicator" podcast. The attackers gained credentials through a fake interview, compromised multiple accounts, and drained the wallet containing funds from a newly launched $JERRY token on Robinhood Chain.

  18. 018BleepingComputerSEP · 22English

    Microsoft reminds admins to migrate Entra ID users to passkeys

    Microsoft is retiring SMS and voice as first-factor authentication methods for Entra ID starting February 2027, requiring administrators to migrate users to phishing-resistant alternatives like passkeys, FIDO2 security keys, or QR code authentication. The company has already ended SMS sign-in for free tenants and is rolling out passkeys as the default authentication method. Organizations must complete migration before the deadline to avoid sign-in disruptions.

    By Sergiu Gatlan
  19. 019ArsTechnicaSEP · 22English

    Microsoft disrupts AI-assisted platform that compromised 12,000

    Microsoft disrupted EvilTokens, an AI-powered subscription scam platform charged $1,500 initially plus $500 monthly that compromised 12,000 accounts across 10,000 organizations globally using a chatbot to analyze inboxes and craft fraud schemes. Microsoft seized 50 websites and 150 domains; UK police arrested two suspects.

    By Dan Goodin
  20. 020Hacker NewsSEP · 22English

    How do you best protect against copycats?

    A website owner discovered pixel-perfect copies of their site (prepfully.com) using similar domains with different TLDs (.live, .info), likely for phishing or adversarial SEO purposes. They plan to warn users about credential theft and implement CORS policies to prevent backend endpoint abuse, while seeking additional protective measures.

    By thereisnotry