source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
SATURDAY, SEPTEMBER 26, 2026
X 主题热门3549Hacker News3487CNBC67YahooFinance58aihot54Verge529to5Mac44IGN42MacRumors40Kotaku35Engadget28TechCrunch279to5Google24NintendoLife21AndroidAuthority20Eurogamer18Guardian18ArsTechnica16PushSquare15Wccftech14BusinessInsider13FoxBusiness13Investor'sBusinessDaily13Polygon13TechPowerUp13Fortune12USAToday12Gematsu11Gizmodo11VideoGamesChronicle10CNN9NintendoEverything9NPR9CBS8CNET8MotleyFool8GSMArena8Mashable8NBC8SeekingAlpha8AndroidPolice7BleepingComputer7Notebookcheck7PureXbox7VideoCardz7WarhammerCommunity7ABC6bgr6Fox6AlJazeera5AppleInsider5CoinDesk5DroidLife5GamesIndustry.biz5HollywoodReporter5NewYorkPost5PetaPixel5PokeBeach5Tom'sGuide5Yahoo5AndroidCentral4GameInformer4InsiderGaming4PlayStationLifeStyle4SlashGear4TechSpot4Conversation4Hacker4WIRED4Aftermath3BellofLostSouls3Deadline3Electrek3EventHubs3Futurism3GAMINGbible3GearPatrol3Hackaday3HuffPost3Lifehacker3Motor13XBOXWire3PCMag3RockPaperShotgun3SamMobile3SouthChinaMorningPost3UploadVR3WhatHi-Fi?3WindowsCentral3WSB-TV3404Media26abcPhiladelphia2ABC7LosAngeles2AndroidHeadlines2AZFamily2Benzinga2ChromeUnboxed2DCRainmaker2Draftsim2HouseDigest2Jalopnik2MyNintendo2Nature2CrudeOilPricesToday2Pokemon2RoadtoVR2RPGSite2SFGATE2SimsCommunity2TimeExtension2TODAY2TweakTown2Variety224/7WallSt.180Level1ageofempires1Alternet1Anthropic1Apple1ArizonaSports1BostonGlobe1BusinessTimes1BuzzFeed1Yahoo!FinanceCanada1CarandDriver1CarBuzz1cbn1CineD1ClaimDepot1ColoradoSun1Skin.ClubCommunity1consequence1CreativeBloq1YahooCreators1ChristianScienceMonitor1Currently1DailyKos1DaringFireball1DarkHorizons1Decrypt1Deseret1Designboom1Dezeen1DigitalCameraWorld1DirtonDirt1DSOGaming1GameGPU1erictopol.substack1ForexFactory1franchisetimes1Futurity1GameRant1GameWorldObserver1GeekWire1GeekyGadgets1Global1GosuGamers1Gothamist1Hackster.io1HoustonChronicle1iLovetheUpperWestSide1InsideEVs1InterestingEngineering1investor.costco1Invezz1iPhoneinCanada1KCRA1MacObserver1Magic:Gathering1MakeUseOf1Mashed1MLive1MortgageDaily1Motorsport1MP1st1mtgrocks1NBC5Chicago1BloombergLaw1Newsweek1NintendoWire1NYT1OneMileataTime1OregonPublicBroadcasting1OregonLive1PersonaCentral1Phoronix1PickupTruck+SUVTalk1politico.eu1Psyche1qz1Realtor1Road&Track1Salon1ScienceDaily1SeattleRed1SeattleTimes1Semafor1SanFranciscoChronicle1YahooFinanceSingapore1SimpleFlying1GhostHowls1Slate1SlippedDisc1SlowBoring1SoraNews241SpaceNews1statnews1YahooTech1the5krunner1DailyBeast1DailyMeal1Drive1Hindu1Intercept1Register1Times1TimesofIndia1TMZ1TopGear1YahooFinanceUK1PCMagUK1Vulture1WCVB1WFMZ1WHYY1WKYT1YGOrganization1
  1. 001Hacker NewsSEP · 26English

    Malicious Twitch chat messages can trigger code execution on OBS Studio

    A malicious Twitch chat message could trigger native code execution on a streamer's Windows PC running OBS Studio 32.2.2 or older by exploiting an unsanitized XSS vulnerability in a custom chat overlay combined with CVE-2024-7971, a V8 vulnerability in the bundled Chromium engine. The attack chain was discovered by Orange researchers and disclosed after coordination with the OBS team. OBS is addressing the issue by upgrading to Chromium 128 and testing sandbox re-enablement.

    By Alex Lekander
  2. 002Hacker NewsSEP · 24English

    Sourcehut account takeover via build logs (XSS in ansi2html)

    A security researcher discovered an account takeover vulnerability in Sourcehut's build logs caused by improper XSS protection in the ansi2html library. The vulnerability allows attackers to craft malicious ANSI escape sequences that generate unsafe HTML links with JavaScript execution capabilities, potentially compromising user accounts accessing build logs.

    By Arusekk
  3. 003Hacker NewsSEP · 23English

    Critical GitLab Auth RCE via Double-Free in Regex Parser

    GitLab released critical security patches (19.4.1, 19.3.3, 19.2.7) on September 23, 2026 to address multiple high-severity vulnerabilities including a double-free in the regex parser (CVE-2026-89078) and integer overflow (CVE-2026-93577) that could allow authenticated users to execute arbitrary code via malicious CI/CD configurations. Additional vulnerabilities in the merge request diff viewer and Duo AI feature were also patched.

    By Miguel Jimeno
  4. 004Hacker NewsSEP · 23English

    Early insights from lawa, my web crawler

    A web crawler named lawa discovered significant HTTP header inconsistencies across millions of requests, including variable capitalization patterns, frequent misspellings in headers with limited valid values, and numerous security issues such as exposed RFC 1918 addresses and request header echo-back vulnerabilities that revealed other crawlers' IP addresses.

    By robinpie