Search/tor project
Vendor

tor project

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
tor
Connections
13 relationships
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. He says little about his work at the NSA, only that “My first year was on the red team, and in the second year, it was more externally facing.” He had been recommended to the NSA by an Air Force guy he never met face-to-face and whose ‘handle’ he no longer remembers. But being recruited by such an organization in such a manner at such an early age would indicate a prodigious hacker. This is not the image he projects. “I hadn’t been engaged in hacking in anything like a grand scale, like some scattered spider. But I spent a lot of time learning how systems worked and figuring out how to set systems up and take them down. I’ve always been more on the white hat side. I think that’s probably what caught their attention – I wasn’t trying to break into things for the thrill of it; I was just trying to learn.” His earlier understanding of computers and programming came from an older sister who was away at college. “She would come home from college every now and then with books or materials, and I would just devour them. I found them fascinating. She’d come home with these various programming books, and I would just think ‘Oh, what’s that?’ So, I’d try to figure it out.” He was less than 10 years old and already displaying some of the key characteristics of a hacker: an intense curiosity and desire to understand. But he had no concept of hacking or hackers. His motivation was simply to do what he enjoyed and have fun doing it – a motivation that has stayed with him through life. Later, in high school, he started to learn about computers and computing. He clearly excelled since he was recruited by the NSA before even working toward a degree. He understood the concept of hacking, and obviously dabbled, but solely out of curiosity and the desire to have fun. “I had been spending a lot of time on IRC,” he explains, and it was here that he met the Air Force guy who recommended him to the NSA. Asked if he did anything ‘shady’ with his growing knowledge, he said ‘No’. Pressed on the subject (‘What – not even breaking into the school’s computer network?’), he simply replied, “I don’t think that’s shady – it’s just de rigueur if you’re into programming and at school.” He doesn’t say he did do this, but clearly implies he did this or similar. “My definition of a hacker is somebody who likes to find a way around a control or a security system to get things to behave in ways that were unintended.” Note that he doesn’t specify any motivating purpose for hacking. For Liu, the act of hacking stands alone. It is the purpose of the hacker that differentiates between black and white hat hacking. “I think intent is really important. There’s exploring, and then there’s exploring for the purpose of destroying or hurting or harming. There’s a distinction between those two things.” Liu liked to explore constantly, freely, for fun – but never harm. It is perhaps this total absence of any malicious intent from Liu that makes him reticent about his own hacking career. Asked if he had ever considered selling his discoveries on the dark web, he replied that he couldn’t because it didn’t exist at the time. “When I started, in the first half of the 1990s, there was no dark web.” Again, we have this minor evasion of the point of the question – he didn’t, not because he wouldn’t, but because he couldn’t. But his answer was accurate: the dark web didn’t really evolve until after the Tor project software was released in 2002 and the Tor browser arrived around 2008. Despite the apparent slight contradictions in his history (being involved in hacking within the NSA and considering breaking into school computer networks just par for the course), Liu clearly has a strong moral compass. He got into hacking solely for the purpose of having fun. He could do it, he enjoyed it, but he never had any malicious intent. This moral compass came, he believes, “From both my parents and early educators, who I think were very good role models.” This suggests he believes that morality is something learned, not something innate. Statistically, many hackers are neurodiverse. Neurodiversity simply indicates a brain and thought processes that are out of the norm. For hackers, it is often evident in ADHD and ASD (the latter was formerly called ‘Asperger’s syndrome’). It helps with what ‘normies’ (the majority of non-neurodiverse people) might consider to be thinking outside of the box, and engaging in long periods of sustained and deep concentration – both of which are clearly beneficial attributes for a hacker. Is Liu neurodiverse? “No. I don’t consider myself to be neurodiverse,” he says. “My wife would call me nuts, but I don’t think I’m neurodiverse in the traditional sense. I just really enjoy what I do.” Liu was only 17 when he took his first formal employment working for the NSA. This was in 1999. “I was a full-time employee,” he explains, “but they let me take classes.” It is difficult to classify what he did within the NSA, which he merely states as ‘externally facing’. Let’s assume he was a hacker for the NSA. Could that be considered black hat, since it would clearly intend some form of harm to the target? Or is any form of hacking for the good guys automatically white hat? Either way, his career after the NSA was clearly and increasingly white hat. During his two years at the NSA, the commercial ‘civilian’ security industry went through a rapid expansion, and “They started hiring a lot of my colleagues, especially the ones I really got along with.” @stake was founded in 1999, the same year he joined the NSA. A year later, @stake acquired Lopht Heavy Industries, an organization that had been a major magnet for serious and well-known hackers (including Weld Pond, Kingpin and Space Rogue). By 2001, he realized that everyone was leaving to join private industry. “I decided to do the same. I left the NSA but first wanted to complete my degree course. That took another couple of years.” By the time he was 21, he had two years’ experience working for the NSA, a recently acquired degree in Computer Science, and considerable knowledge of what we should politely call offensive security. “In a lot of cases,” he comments, “hackers [by which he means both internal red teamers and external attackers] wind up understanding a system better than the original developers; because they’ve thought so deeply about the system and how to subvert its behavior.” This is by no means a simple process – and hackers are as prone to burnout as any other security practitioner. “I’ve seen a lot of brilliant, brilliant hackers – I mean real next level folks – burn out and just lose it.” With his CV, he was never likely to have difficulty finding employment in the private sector. In 2003 he started work as a Security Consultant at the Advanced Security Center, Ernst & Young LLP, where he re-acquainted with Fran Brown. He and Brown had been in the same hall in college freshman year, and they took the same courses. Within 18 months they were both recruited by Honeywell. Together they led Honeywell’s global penetration testing team. This time, he, well they, stayed for just 16 months. They began to get additional sub-contracting work on the side, “from friends who needed help”. They were already thinking about what to do next, and decided, “Hey, yeah, why not?” Bishop Fox was the ultimate answer to this question, although the precise route is difficult to plot. Both Liu and Brown indicate they left Honeywell and moved immediately into Bishop Fox, which they co-founded. Liu’s LinkedIn profile suggests he did this the year before leaving Honeywell. Brown’s profile suggests it was concurrent with leaving Honeywell. But the name Bishop Fox is a rebranding of the firm Stach & Liu LLC, which happened in 2014. Stach and Liu was itself not founded, according to Dun & Bradstreet, until 2011. It was rebranded to Bishop Fox in 2013 – possibly because the former sounds more like a law firm while the latter symbolizes both the protective and aggressive aspects of penetration testing and red teaming. Nevertheless, regardless of the circuitous route to Bishop Fox, Liu and Brown founded a company that is now widely considered to be a top-tier authority in offensive security. Liu, as its CEO, has progressed from an offensive security performer to an offensive security ringmaster. Is he still a hacker? “I’d like to think so. And certainly I would have given you a very affirmative ‘Yes’ 10 years ago. These days, I think my team thinks I’m a little out of date, but I’ve spent a large part of my career hacking into things. More recently I spend time managing the firm, but, yeah, I would like to think I’m still a hacker.” Still this slight reticence in clearly stating he is a hacker. He clearly is a hacker – and since hacking is as much a state of mind as physical process, once a hacker, always a hacker. The clarity, however, is that he, Fran Brown, and the entire Bishop Fox organization are hackers for good. Related: Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker Related: Hacker Conversations: Joey Melo on Hacking AI Related: Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
securityweek.comSep 10, 2026extracted
Tor Browser: cos’è, come funziona e come navigare nel Dark Web in sicurezza
Tor non è sinonimo di Dark Web. È innanzitutto una rete progettata per rendere più difficile ricostruire l’origine e la destinazione delle comunicazioni online, proteggendo privacy e anonimato attraverso un’infrastruttura distribuita di relay e una cifratura a più livelli. È però anche la tecnologia che consente di raggiungere i servizi con dominio .onion, ed è proprio questa caratteristica ad averne legato nell’immaginario collettivo il nome alla parte più nascosta della Rete. A distanza di anni dalla sua nascita, Tor continua intanto a evolversi: cambiano il browser, le tecnologie per aggirare la censura e le difese della rete, ma non cambia una regola fondamentale. Anonimato non significa invulnerabilità e la sicurezza dipende tanto dalla tecnologia quanto dal comportamento di chi la utilizza. Indice degli argomenti Navigazione anonima e Dark Web: di cosa parliamo Cominciamo innanzitutto col dire che la navigazione nel Dark Web è sostanzialmente diversa dalla navigazione in incognito (detta anche navigazione privata) che viene offerta come opzione su tutti i browser. È bene puntualizzare questo argomento, oggetto di alcune false credenze: la navigazione in incognito ha semplicemente il vantaggio di non salvare la cronologia di navigazione, i cookie e i dati dei siti e le informazioni inserite nei moduli dei siti. Ma è molto lontana dal garantire un reale anonimato al navigatore. Questi viene tracciato comunque dal provider dei servizi Internet, che conosce il suo indirizzo IP e può identificare la sua posizione. Potrebbe essere tracciato anche dal datore di lavoro (o comunque da chi gli fornisce gli strumenti per navigare). Inoltre, la navigazione in incognito non ci permette in alcun modo di entrare nel Dark Web, che rappresenta un mondo a parte rispetto al Web che tutti noi navighiamo. Deep Web e Dark Web non sono la stessa cosa Prima di “entrare” nel Dark Web è necessaria un’ulteriore puntualizzazione su cosa sia realmente il Dark Web, che molto spesso viene confuso con il Deep Web. Sono due mondi molto diversi e in un certo senso non comunicanti tra loro. Tutti noi navighiamo tutti i giorni nel Deep Web: questa definizione indica l’insieme delle pagine presenti sul web e non indicizzate dai comuni motori di ricerca (ad es. Google, Bing ecc.): ne fanno parte nuovi siti, pagine web a contenuto dinamico, web software, siti privati aziendali, reti peer-to-peer. L’opposto del Deep Web si chiama Surface Web (o Visible Web o Indexed Web): sono le pagine indicizzate dai motori di ricerca. Quindi, Deep e Surface Web sono due aree dello stesso mondo, con la discriminante che la prima non è indicizzata (quindi potremo raggiungerla solo se ne conosciamo l’URL). È Deep Web la pagina del nostro profilo Facebook, così come la pagina web della nostra casella Gmail e i siti dei Cloud Service Provider dove sono archiviati i nostri file. Oppure le tante pagine aziendali, governative, finanziarie ad uso interno, presenti sul web, ma non indicizzate. L’immagine seguente, dove il web nella sua totalità è rappresentato come un iceberg, illustra in modo efficace questi concetti. Il Dark Web è invece una frazione molto piccola del web: un mondo separato e poco accessibile, che si appoggia sulle Darknet, che sono reti chiuse. Per accedervi sono necessarie particolari configurazioni, come vedremo in seguito. Le principali Darknet sono: Freenet (ormai poco usata), I2P ed in particolare proprio Tor (The Onion Router), che è ormai diventata la più famosa e usata tra queste reti. Navigare nel Dark Web, dunque, non ha nulla a che vedere con la navigazione in incognito dei browser. I browser tradizionali, infatti, non permettono di accedere al Dark Web. Per entrare nel Dark Web servono strumenti (browser) appositi. Il browser più noto ed utilizzato è Tor: vediamo ora di conoscerlo meglio e di capire come usarlo, precisando che navigare nel Dark Web non è illegale, salvo che non lo si utilizzi per azioni illecite. Cos’è il browser Tor La Darknet Tor esiste perché è stata costruita un’infrastruttura hardware, costituita dai server che la ospitano. La rete Tor è stata creata dalla US Navy nel 1998 utilizzando la tecnologia onion routing sviluppata per garantire l’anonimato sulle reti di computer. Nel 2006 è stata resa di pubblico dominio e nello stesso anno è nata Tor Project Inc., che è un’organizzazione no profit con sede in USA. Secondo la legge americana è classificata come organizzazione 501(c)3, cioè un’organizzazione senza fini di lucro che gode delle esenzioni fiscali che si applicano agli enti dedicati esclusivamente a fini religiosi, di beneficenza, scientifici, letterari o educativi. Tor Project è formato da una pluralità di organizzazioni, tra le quali figurano l’US Department of State Bureau of Democracy, lo Human Rights e il Labor, uno dei maggiori sostenitori del progetto. È supportata fin dalla sua nascita anche dalla Electronic Frontier Foundation (EFF). I molti finanziatori (sponsor) di Tor sono elencati sul sito di Tor Project. Tra le organizzazioni che sostengono Tor ci sono anche istituzioni del governo USA, quali la DARPA (Defense Advanced Research Projects Agency). Quindi è del tutto evidente come Tor Project non sia un’associazione clandestina o – ancor peggio – finalizzata al crimine informatico. È anzi uno strumento che – come si può leggere nel sito: “Defend yourself against tracking and surveillance. Circumvent censorship”. Per questi motivi, Tor è una rete di comunicazione usata da giornalisti, attivisti politici e whistleblowers per aggirare la censura e la sorveglianza nei paesi meno democratici. Il fatto che sia usata anche dai “cattivi” non ne inficia il valore. Il browser Tor è utilizzabile anche da chiavetta USB o da CD, senza bisogno di installare nulla. Tor non è una tecnologia rimasta immobile. L’aggiornamento continuo del browser rappresenta una componente essenziale del suo modello di sicurezza, perché l’anonimato offerto dalla rete perderebbe gran parte del proprio valore se il software utilizzato dall’utente presentasse vulnerabilità sfruttabili per comprometterne il dispositivo o identificarlo. A settembre 2026 Tor Project ha rilasciato la versione 15.0.22 di Tor Browser, aggiornando anche il componente Tor sottostante. Gli aggiornamenti precedenti avevano inoltre incorporato nuove versioni di Firefox ESR, OpenSSL e NoScript insieme alle relative correzioni di sicurezza. È un aspetto da non sottovalutare: usare Tor Browser senza mantenerlo aggiornato può vanificare una parte delle protezioni che la stessa architettura Tor cerca di offrire. Parallelamente sta evolvendo anche il cuore tecnologico della rete. Tor Project lavora da tempo ad Arti, implementazione di nuova generazione di Tor scritta in Rust. Con Arti 2.6.0, pubblicato nel settembre 2026, il progetto ha compiuto ulteriori passi verso il suo utilizzo come relay e directory authority, integrando anche evoluzioni nel controllo della congestione e nelle difese crittografiche. L’obiettivo di lungo periodo è quindi più ampio del semplice aggiornamento del browser: modernizzare progressivamente l’infrastruttura Tor e renderla più robusta rispetto a vulnerabilità, attacchi e nuove tecniche di analisi del traffico. I numeri della rete Tor: un’infrastruttura globale Misurare con precisione quanti utenti utilizzino Tor non è semplice, proprio per la natura della rete. Tor Project pubblica tuttavia attraverso Tor Metrics stime elaborate analizzando le richieste generate dai client verso relay e bridge. I dati mostrano una rete utilizzata su scala globale, con centinaia di migliaia di connessioni giornaliere provenienti dai principali Paesi. Ma il dato più importante va letto al di là dei numeri: utilizzare Tor non significa necessariamente navigare nel Dark Web. La rete viene infatti impiegata anche per raggiungere il normale Web cercando di ridurre tracciamento e sorveglianza, oltre che per aggirare blocchi e censura. Giornalisti, ricercatori, attivisti, whistleblower e cittadini che vivono in Paesi nei quali l’accesso a Internet è sottoposto a restrizioni rappresentano alcuni dei casi d’uso legittimi più significativi. Per questo, più che fotografare Tor attraverso un numero assoluto di utenti destinato inevitabilmente a cambiare nel tempo, è utile considerarlo come una vera e propria infrastruttura globale per la privacy e la libertà di accesso alle informazioni. Come funziona la rete Tor Per capire come usare Tor è necessario conoscere come è fatta la sua infrastruttura. La rete Tor è un network decentralizzato costituito da alcune migliaia di server (sono i “relay”: a publicly-listed server in the Tor network) sparsi nel mondo. In particolare, dovrebbero essere circa 6.000-8.000 i relay (nodi) e quasi 3.000 i bridge (ponti), quasi tutti gestiti da volontari. I dati di navigazione non transitano direttamente dal client al server, come accade per la navigazione normale. I pacchetti di dati passano invece attraverso i relay Tor che agiscono da router (chiamati anche “nodi”) e realizzano un circuito virtuale crittografato a strati (come una “cipolla”, da cui il nome Onion). Per questo motivo gli URL della rete Tor hanno il TLD (Top Level Domain) che non è il classico .com o .it, ma .onion. Quando si avvia la navigazione aprendo il browser Tor (spiegheremo più avanti come ottenerlo), questo sceglie dall’elenco Directory server una lista di nodi e da queste individua tre nodi (tre è la configurazione standard, salvo eccezioni che vedremo in seguito) in modo casuale, che costituiscono una catena di navigazione. Nella pagina del browser possiamo vedere – in tempo reale – il percorso (definito “circuito”) che viene fatto e anche cambiarlo con il pulsante che si trova alla sinistra della barra dell’URL. In ciascun passaggio, la comunicazione viene crittografata e questo si ripete per ciascun nodo (a strati come la cipolla). Ogni nodo della rete conosce solo il precedente e il successivo, nessun altro. Questo rende pressoché impossibile (o comunque molto complicato) risalire al client di partenza. Ci sono tre tipi di relay nel sistema di navigazione Tor: guard/middle relay; exit relay; bridge. Come abbiamo detto, per ragioni di sicurezza il traffico Tor passa attraverso almeno tre relay prima di raggiungere la sua destinazione. Il primo è il guard relay (o entry relay o “nodo di guardia”), il secondo è un middle relay (intermedio) che riceve il traffico e lo passa all’exit relay (figura sottostante). I relay intermedi (guard e middle) sono visibili solo all’interno della rete Tor e, a differenza del relay d’uscita, non fanno apparire il proprietario del relay come la fonte del traffico. Ciò significa che un relay intermedio è generalmente sicuro (lo potremmo avere anche nel server di casa nostra, partecipando così all’infrastruttura Tor). Il relay di uscita è l’ultimo nodo che il traffico Tor attraversa prima di raggiungere la sua destinazione. I servizi a cui i client Tor si connettono (sito web, servizio di chat, provider di posta elettronica ecc.) vedranno l’indirizzo IP del relay di uscita invece dell’indirizzo IP reale dell’utente Tor. In altre parole, è l’indirizzo IP del relay di uscita che viene interpretato come la fonte del traffico. Per questo motivo, è possibile incorrere in un inconveniente piuttosto buffo durante la navigazione: se il relay d’uscita si trova in Svezia, il sito che si sta consultando potrebbe presentarsi in lingua svedese, supponendo che sia questa la lingua del visitatore. Bridges (ponti) È importante sapere che la struttura della rete Tor prevede che gli indirizzi IP dei relay Tor siano pubblici. Ed uno dei modi in cui il Tor può essere bloccato dai governi o dagli ISP è quello di inserire nelle blacklist gli indirizzi IP di questi nodi Tor pubblici. Per questo esistono i Bridges: sono nodi che non sono indicati nell’elenco pubblico come parte della rete Tor, il che rende più difficile per gli ISP e i governi bloccarli. I bridges sono quindi strumenti essenziali per l’elusione della censura nei paesi che bloccano regolarmente gli indirizzi IP di tutti i relay Tor elencati pubblicamente, come Cina, Turchia e Iran. La rete Tor si affida a volontari che offrono i loro server e la loro banda: chiunque, quindi, può mettere a disposizione un proprio computer per creare un relay della rete Tor. L’attuale rete Tor è piuttosto sottodimensionata rispetto al numero di persone che la utilizzano, il che significa che Tor ha bisogno di più volontari per accrescere il numero dei relay. Gestendo un relay Tor, come viene spiegato nella pagina dedicata del sito Tor Project, si può contribuire a migliorare la rete Tor rendendola: più veloce (e quindi più utilizzabile); più robusta contro gli attacchi; più stabile in caso di interruzioni; più sicura per i suoi utenti (spiare più relay è più difficile che farlo su pochi). Per i motivi che abbiamo spiegato, un utente potrà fornire un relay di tipo guard/middle (cioè un non-exit Tor relay) mentre non è opportuno che attivi un exit relay perché più esposto. Per attivare un guard relay si deve disporre di una connessione stabile e veloce (almeno 2 MByte/s), altrimenti si potrà creare un middle relay, che è il nodo intermedio tra guard ed exit ed è quello che richiede i requisiti più ridotti: 10 Mbit/s (Mbps). Infine, è da considerare un aspetto peculiare di Tor, che rappresenta un problema non trascurabile: la sicurezza va a scapito della velocità. Il “giro del mondo” che dovrà fare il flusso dei dati (come abbiamo spiegato) renderà la navigazione inevitabilmente latenza introducendo overhead e latenza rispetto a una connessione diretta; ma occorre precisare che la prestazione effettiva dipende però da circuito, congestione, relay e destinazione. Inoltre, l’attuale rete Tor è sottodimensionata rispetto al numero di persone che cercano di usarla. Non bisogna quindi pensare di usare Tor per lo streaming, il file sharing o per attività che richiedano grandi flussi di dati. La partita tra strumenti di anonimizzazione e sistemi di censura della Rete è però in continua evoluzione. Bloccare gli indirizzi IP dei relay pubblici è infatti soltanto una delle tecniche con cui governi e provider possono cercare di impedire l’accesso a Tor. Per questo Tor Project sviluppa anche i cosiddetti pluggable transports, tecnologie progettate per rendere più difficile identificare e bloccare il traffico diretto verso la rete. Tra queste c’è WebTunnel, un particolare tipo di bridge che cerca di far apparire le comunicazioni Tor simili al normale traffico Web HTTPS. L’obiettivo è consentire alla connessione di confondersi con quella generata dalla normale navigazione, rendendo più complesso applicare blocchi selettivi senza interferire anche con servizi Web legittimi. Un’altra tecnologia è Snowflake, che utilizza proxy temporanei messi a disposizione da volontari per consentire agli utenti di raggiungere la rete Tor anche quando l’accesso diretto è sottoposto a restrizioni. Nel 2026 il progetto ha continuato a investire su entrambe le tecnologie, a conferma di come la capacità di aggirare la censura sia ormai una componente strutturale dell’evoluzione di Tor e, contemporaneamente, una sfida destinata a cambiare insieme alle tecniche utilizzate per identificarne e bloccarne il traffico. Iniziamo a navigare nel Dark Web: come installare Tor Browser Tor Project sconsiglia di usare Tor con altri browser perché “pericoloso e non raccomandato. Utilizzare Tor in un altro browser può farti rimanere vulnerabile e senza le protezioni privacy implementate in Tor Browser”. Tor Browser è una versione modificata di Firefox (utilizza Firefox ESR) progettata specificamente per essere utilizzata con Tor: dobbiamo quindi prima di tutto scaricare Tor Browser disponibile in 30 lingue diverse. Ogni file della pagina Download è firmato con OpenPGP: si può vedere il corrispondente file .asc, che è la firma OpenPGP, che permette di verificare che il file che abbiamo scaricato è esattamente quello da noi previsto. Tor Browser è disponibile per Windows, macOS, Linux e, da qualche tempo, anche per i dispositivi mobili. Per Android è possibile scaricare dal sito Tor Project il file .apk dell’applicazione, oppure più semplicemente andare sul Google Play Store e scaricare l’app ufficiale. Questa app rappresenta l’unico browser mobile ufficiale supportato e sviluppato dal Tor Project. Non è presente un’app ufficiale per iPhone: tuttavia, sul sito Tor Project, nella pagina dedicata alla versione Android del software, compare il messaggio: “Sei un utente iOS? Ti incoraggiamo a provare Onion Browser”, che rimanda all’applicazione consigliata Onion Browser che può essere scaricata direttamente anche da App Store. Peraltro, sul sito Tor Project compare anche questo avviso: “Noi raccomandiamo di utilizzare un’applicazione iOS chiamata Onion Browser: è open source, utilizza Tor ed è sviluppata da una persona che collabora strettamente con il Tor Project (Mike Tigas, sviluppatore e giornalista investigativo, n.d.A). Tuttavia, Apple richiede ai browser che girano su iOS di utilizzare una cosa chiamata Webkit, che impedisce a Onion Browser di avere le stesse protezioni per la privacy di Tor Browser”. Sia su Android che su iOS si trovano molte altre app non ufficiali di Tor Browser, che è sconsigliabile usare. L’installazione di Tor Browser è molto semplice ed assistita da un ampio tutorial presente sul sito ufficiale del progetto. Quando si avvia Tor Browser per la prima volta, compare la finestra Impostazioni di Rete Tor. Questa finestra permette di connettersi direttamente alla rete Tor o di personalizzare la configurazione di Tor Browser. Nella maggior parte dei casi, è sufficiente cliccare su Connetti e collegarsi alla rete Tor senza ulteriori configurazioni. L’opzione Configura diventa invece necessaria se ci troviamo in un paese che censura Tor (come Egitto, Cina Turchia) e se ci stiamo connettendo da una rete privata che richiede un proxy. Poiché l’accesso diretto alla rete Tor a volte può essere bloccato dal fornitore di servizi Internet o da un governo, Tor Browser include alcuni strumenti di elusione per aggirare tali blocchi. Questi strumenti sono chiamati pluggable transports. In ogni caso, è possibile anche settare il livello di protezione, cliccando sull’icona a forma di scudo che si trova in alto a sinistra e selezionando Impostazioni di Sicurezza Avanzate. Nella schermata che appare potremo scegliere tra i livelli Standard, Sicuro e Molto sicuro. Livelli di sicurezza alti possono causare problemi di funzionamento di Tor Browser: più alto il livello, più limitata sarà anche inevitabilmente l’esperienza di navigazione. Navigare con Tor Browser Una volta installato Tor Browser, siamo pronti per iniziare a navigare nel Dark Web. Ovviamente possiamo utilizzarlo anche come un normale browser per accedere ai siti del surface web. Tor riduce la possibilità di ricondurre la connessione all’indirizzo IP dell’utente. Nella pagina del browser possiamo vedere – in tempo reale – il percorso (definito “circuito”) che viene fatto: è sufficiente cliccare sull’icona posta a sinistra della barra della URL. Di regola la lunghezza del percorso è impostata a 3, più il numero di nodi che durante il percorso sono sensibili. Ciò significa che normalmente i nodi sono 3 (se siamo su un sito del surface web), ma se – per esempio – si accede ad un servizio .onion o ad un indirizzo “.exit” potrebbero essercene di più (e li vedremo indicati nel circuito con il termine “ripetitori”). Con l’opzione Nuovo Circuito potremo anche cambiare il percorso, sempre cliccando sul pulsante che si trova alla sinistra della barra della URL. Non possiamo stabilire noi i relay, ma solo fare in modo che Tor ne scelga altri tre. Questo serve se l’exit relay che stiamo utilizzando non è in grado di connettersi al sito che visitare, o non lo sta caricando correttamente. Selezionando questa opzione si ricaricheranno tutte le schede attive o le finestre utilizzando un nuovo circuito Tor. Un’altra opzione che potremmo usare è Nuova Identità (disponibile dal menu in alto a destra rappresentato da un’icona con tre linee orizzontali). Questa è utile se si vuole evitare che le successive attività del browser siano correlabili a quanto fatto in precedenza. Selezionando questa opzione, si chiuderanno tutte le schede e le finestre, si puliranno le informazioni personali come i cookie e la cronologia di navigazione e verrà instaurato un nuovo circuito Tor per le connessioni. Tor Browser avviserà che tutte le attività e i download saranno interrotti e le sessioni aperte andranno perse. Con Tor Browser possiamo – soprattutto – accedere al Dark web dove, invece, non è possibile utilizzare i browser classici, quali Chrome, Safari, Firefox: digitando su questi una URL .onion non avremo nessuna risposta. Una volta entrati con Tor nel Dark Web, si potrà navigare tra i vari siti, di cui ovviamente bisogna conoscere gli indirizzi. Fra questi siti si può trovare di tutto, inclusi mercati della droga, killer a pagamento, comunità di vario tipo; ma si trovano anche molti siti presenti già sulla Rete in chiaro. La garanzia dell’anonimato rende la navigazione su Tor Browser molto utile e molto sicura in paesi con regimi autoritari. Permette a gruppi di opinione, dissidenti e attivisti politici di comunicare tra loro senza rischiare di essere controllati ed intercettati dai governi e dalle polizie. Lo prova il fatto che nella rete Tor non si trovano solo siti clandestini o illegali: abbiamo anche le versioni .onion di siti famosi. Esiste, per esempio, il sito Tor del The New York Times (dal 2017, ma non funziona con i browser abituali, solo con Tor browser). Provando ad accedere alla sua home page e alle pagine interne, troveremo esattamente il sito ufficiale del New York Times, semplicemente ospitato nel Dark Web. La stessa cosa vale per il sito di BBC News o per Facebook. Ed infine il sito di Tor nella rete Tor. Perché esistono? Proprio per permettere di accedere a Facebook o leggere il New York Times in quei paesi dove questi siti sono “bannati” e quindi non accessibili. Consigli per navigare nel Dark Web C’è il rischio di rimanere delusi dal Dark Web, scoprendo che è un luogo ben più modesto di quello che si racconta e si favoleggia. Il Dark Web è molto piccolo: si ritiene (ma è una stima molto approssimativa) che contenga non più di 100.000 siti, che rappresentano probabilmente meno dello 0,005% delle dimensioni dell’intero World Wide Web. In realtà, i siti .onion attivi potrebbero essere ancora meno: si tratta in genere di siti che sono molto “volatili”, perché nascono e spariscono rapidamente (spesso chiusi dalla polizia). Quindi difficili da censire. Ha provato a farlo Recorded Future: dal punto di vista linguistico, i siti Tor (.onion) sono più omogenei del web di superficie con l’86% dei siti che ha l’inglese come lingua principale, seguita dal russo con il 2,8% e il tedesco con l’1,6%; numeri di visite: mentre nel web di superficie, i siti più popolari attirano milioni di visite, nei siti .onion quello con il più alto numero di link in entrata è stato un black market con circa 3.585 link in entrata; vita media dei siti .onion: i risultati di un rapporto di Onionscan del 2017 riporta che su 30.000 siti interrogati, poco più di 4.400 erano effettivamente online. Anche se queste analisi hanno un livello di incertezza elevato, possiamo dire che il “rapporto tra vivi e morti” continua ad essere simile a quello di altre ricerche precedenti, con appena il 15% dei siti .onion in vita. Meglio utilizzare un computer secondario, nel quale non abbiate in archivio documenti e informazioni importanti (non si sa mai…). Usare esclusivamente Tor Browser. Il browser Tor è basato su Firefox, questo permette di utilizzare add-ons e temi compatibili con Firefox anche nel browser Tor (dal menù delle Impostazioni in Estensioni e Temi). Tuttavia, gli unici componenti aggiuntivi che sono stati testati per l’utilizzo con il browser Tor sono quelli inclusi di default (HTTPS Everywhere e NoScript). È fortemente sconsigliato installare altri componenti aggiuntivi (estensioni) in Tor Browser, perché possono comprometterne la privacy e la sicurezza. Usare un motore di ricerca sicuro, come DuckDuckGo, che non traccia i suoi utenti né memorizza alcun dato riguardo le loro ricerche. È il motore di ricerca predefinito in Tor Browser. Tor Browser nella sua modalità predefinita inizia con una finestra arrotondata a un multiplo di 200px x 100px per impedire l’impronta digitale (fingerprint) delle dimensioni dello schermo. Evitare quindi di mettere la finestra a tutto schermo, per non agevolare la ricostruzione della fingerprint, che ci potrebbe individuare in modo univoco. Per lo stesso motivo sarebbe consigliabile impostare la lingua inglese (quella di default) invece dell’italiano. Come trovare i siti? Se non conoscete l’URL, potete utilizzare raccolte di indirizzi .onion che sono disponibili. Uno dei più conosciuti è The Hidden Wiki: . Un’altra raccolta (solitamente accessibile) è TorLinks. Ed anche TorGate – A Darknet Link Directory. Non sono sempre affidabili, perché – come abbiamo spiegato – i siti .onion nascono e muoiono molto velocemente, quindi i link indicati (anche quelli che trovate su The Hidden Wiki o su TorLinks), potrebbero non funzionare più. È una delle tante caratteristiche “scomode” del Dark Web… La navigazione potrebbe risultare frustrante perché molti siti linkati possono essere offline o non esistere più. Molti siti non sono liberamente accessibili, si può entrare solo se invitati. Ma non è un problema, lasciateli perdere. Non registrarsi con account di posta elettronica e non utilizzare nomi utente o nomi che possono essere utilizzati per identificarci. Eventualmente consiglio di creare una email temporanea con un nome utente di fantasia: esistono molti servizi web per questo. Si sconsiglia di usare Tor con BitTorrent. Evitare, ovviamente, di compiere nel Dark Web azioni illegali. Ed infine, meglio lasciar perdere la leggenda delle Red Room! Le Red Room sarebbero degli spettacoli di tortura in live streaming. Per assistere bisogna pagare cifre molto alte in Bitcoin. Non ci sono prove concrete che dimostrino l’esistenza delle Red Room e se ci fossero pagine web che si spacciano per “Stanze Rosse”, sarebbero probabilmente solo siti fake creati per spillare soldi. E poi, considerata la lentezza della navigazione, un filmato in streaming su Tor sarebbe impossibile da vedere. Quanto è sicuro e anonimo Tor? Tor aumenta significativamente la difficoltà di collegare un utente alla propria attività online, ma non deve essere interpretato come una garanzia assoluta di anonimato. L’architettura onion impedisce al singolo relay di conoscere contemporaneamente origine e destinazione della comunicazione, ma esistono altri livelli sui quali l’anonimato può essere compromesso: vulnerabilità del browser, malware sul dispositivo, errori dell’utente, autenticazione con account riconducibili alla propria identità, download e apertura di documenti con applicazioni esterne oppure avversari capaci di osservare porzioni sufficientemente ampie della rete. Anche il ruolo degli exit relay va interpretato correttamente. Quando si visita un normale sito Internet, l’exit relay rappresenta il punto in cui il traffico lascia la rete Tor. Se la connessione verso il sito utilizza HTTPS, tuttavia, il contenuto applicativo resta protetto dalla cifratura TLS tra browser e server. Per questo è importante verificare sempre l’uso di HTTPS e prestare particolare attenzione ai siti che richiedono credenziali o informazioni sensibili. Il rischio più concreto resta quindi quello di attribuire a Tor proprietà che non possiede. La rete può nascondere l’indirizzo IP di origine e rendere molto più difficile correlare sorgente e destinazione, ma non può proteggere un utente che rivela volontariamente la propria identità, utilizza software vulnerabile o porta fuori dal browser contenuti capaci di stabilire connessioni indipendenti. In altre parole, Tor offre anonimato a livello di rete, non l’invisibilità dell’utente. Ed è proprio questa distinzione che dovrebbe guidarne l’utilizzo in sicurezza.
cybersecurity360.itSep 9, 2026extracted
Firefox Vulnerability Allows Tor User Fingerprinting
Researchers have discovered a vulnerability that could allow threat actors to fingerprint Firefox users, even in Private Browsing mode. The issue also affects the Tor anonymity browser, which is based on Firefox. The vulnerability, tracked as CVE-2026-6770, is related to the IndexedDB browser API, which is used for storing structured data on the client side. Firefox stores IndexedDB database names using internal UUID mappings, and when a website lists those databases, the order they come back in remains the same across different sites while the same browser process is running. [ Read: Claude Mythos Finds 271 Firefox Vulnerabilities ] This enables unrelated sites to independently observe the same ordering and use it to link a user’s activity across domains without any cookies or shared storage. The fingerprint persists across reloads and new private sessions, until the browser is fully restarted. Threat actors could exploit this to fingerprint users in Firefox’s Private Browsing mode and even when Tor’s New Identity feature is used. The New Identity feature in Tor is specifically designed to prevent a user’s activity across different sites from being linked by clearing browsing history, cookies, and active connections. “In Tor Browser, the stable identifier effectively defeats Tor Browser’s ‘New Identity’ isolation within a running browser process, allowing websites to link sessions that are expected to be fully isolated from one another,” the researchers explained. Mozilla patched CVE-2026-6770 with the release of Firefox 150. The organization assigned the flaw a ‘medium severity’ rating and described it only as “other issue in the Storage: IndexedDB component”. The Tor Project has also adopted the patch, rolling it out to users last week with the release of Tor Browser 15.0.10. Related: Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities Related: GhostPoster Firefox Extensions Hide Malware in Icons Related: New Firefox Protections Halve the Number of Trackable Users
securityweek.comApr 27, 2026extracted
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packages
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packages Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: NIST updates its DNS security guidance for the first time in over a decade DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more than twelve years. NIST published SP 800-81r3, the Secure Domain Name System Deployment Guide, superseding a version that dates to 2013. The document covers three main areas: using DNS as an active security control, securing the DNS protocol itself, and protecting the servers and infrastructure that run DNS services. Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521) A critical unauthenticated remote code execution vulnerability (CVE-2025-53521) in F5’s BIG-IP Access Policy Manager (APM) solution is under active exploitation, the US Cybersecurity and Infrastructure Security Agency warned on Friday. Your AI agents are moving sensitive data. Do you know where? In this Help Net Security interview, Gidi Cohen, CEO at Bonfy.AI, addresses what he sees as the most pressing gap in AI agent security: data-layer risk. While the industry focuses on prompt injection and model behavior, Cohen argues the deeper threat is autonomous AI agents operating across systems with no visibility into what data they access, combine, or expose. Quantum threats are already active and the defense response remains fragmented Enterprises are moving toward post-quantum security at uneven speeds, and the gap between organizations that have built crypto-agility into their infrastructure and those that have adopted the label without the underlying capability is widening. Dr. Tan Teik Guan, CEO of Singapore-based cybersecurity company pQCee, draws a sharp line between the two. Crypto-agility, in his view, requires more than support for multiple algorithms or protocol-level negotiation. Measuring security performance in real-time, not once a quarter Most organizations have invested heavily in security products over the past decade. The assumption embedded in that spending is that more tools equal better protection. Tim Nan, CEO of digiDations, says that assumption is the most persistent misconception he encounters when working with security leaders across industries. NVIDIA puts GPU orchestration in community hands GPU-accelerated AI workloads now run on Kubernetes in the large majority of enterprise environments. Managing those workloads at scale has required specialized tooling that, until now, remained under vendor control. NVIDIA moved to change that at KubeCon Europe in Amsterdam this week, donating its Dynamic Resource Allocation (DRA) Driver for GPUs to the Cloud Native Computing Foundation (CNCF). TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malware TeamPCP continues is supply chain compromise rampage, with telnyx on PyPI being the latest maliciously modified package. The AI safety conversation is focused on the wrong layer Organizations have spent years accumulating fragmented identity systems: too many roles, too many credentials, too many disconnected tools. For a workforce of humans, that fragmentation was manageable. Humans log in, log out, and make decisions slowly enough that gaps in control rarely turned into immediate incidents. AI agents operate differently. Training an AI agent to attack LLM applications like a real adversary Most enterprise software development teams now ship AI-powered applications faster than traditional penetration testing can keep up with. A security team with 500 applications may test each one once a year, or less. In the time between tests, the underlying models, integrations, and behaviors can change, with no corresponding security review. Novee launched a product it calls AI Red Teaming for LLM Applications, an AI pentesting agent built specifically to probe LLM-powered software. Your facilities run on fragile supply chains and nobody wants to admit it In this Help Net Security interview, Christa Dodoo, Global Chair at IFMA, discusses how facility managers are managing supply chain risk in critical building systems. She explains how sourcing, localized redundancy, and flexible infrastructure design are being integrated into resilience planning. A nearly undetectable LLM attack needs only a handful of poisoned samples Prompt engineering has become a standard part of how large language models are deployed in production, and it introduces an attack surface most organizations have not yet addressed. Researchers have developed and tested a prompt-based backdoor attack method, called ProAttack, that achieves attack success rates approaching 100% on multiple text classification benchmarks without altering sample labels or injecting external trigger words. AI SOC vendors are selling a future that production deployments haven’t reached yet Vendors selling AI-powered security operations platforms have built their pitches around a consistent set of promises: autonomous threat investigation, dramatic reductions in analyst workload, and an accelerating path toward humanless operations. Practitioners buying and deploying those platforms describe something different. Top product launches at RSAC 2026 RSAC 2026 showcased a wave of innovation, with vendors unveiling technologies poised to redefine cybersecurity. From AI-powered defense to breakthroughs in identity protection, this year’s conference delivered a glimpse into the future. Here are the most interesting products that caught our attention, and could shape what’s next. Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whether the vulnerability has been exploited as a zero-day, but has urged customers to apply the updates or provided mitigations as soon as possible. GitHub-hosted malware campaign uses split payload to evade detection A large-scale malware delivery campaign has been targeting developers, gamers, and general users through fake tools hosted on GitHub, Netskope researchers have warned. These “lures” are highly polished and appear legitimate, occasionally mimicking real projects, thus making them difficult to distinguish from safe software. Critical NetScaler ADC, Gateway flaw may soon be exploited (CVE-2026-3055) Citrix has fixed two vulnerabilities in NetScaler ADC and NetScaler Gateway, with the more serious flaw (CVE-2026-3055) potentially allowing attackers to extract active session tokens from the memory of affected devices. LiteLLM PyPI packages compromised in expanding TeamPCP supply chain attacks A slew of supply chain attacks against popular open source tools and packages appears to have been orchestrated by TeamPCP, a cybercriminal group that rose to prominence in late 2025. The latest victim of the group is BerryAI’s popular LiteLLM library, a unified interface that makes it easier for apps to switch between various LLMs: on March 24, TeamPCP uploaded two compromised versions (1.82.7 and 1.82.8) on PyPI that included a credential stealer and a malware dropper. Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks Telecommunications providers around the world have been dealing with the burrowing efforts of the China-linked APTs for many years now. To help them identify hard-to-detect implants used by the China-based group dubbed Red Menshen, Rapid7 researchers have released a scanning script. CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner. Product showcase: Cross-platform and third-party endpoint patching with Action1 Keeping endpoints patched is one of the more annoying chores in IT operations. Action1 is a cloud-based autonomous endpoint management platform that addresses this challenge head-on, covering third-party apps and OS updates (Windows, macOS, and now Linux) from a single, centralized console. You don’t have to choose between BAS or automated pentesting, you shouldn’t There’s a debate making the rounds in security circles that sounds reasonable on the surface but falls apart under operational scrutiny: Which is better, breach and attack simulation (BAS) or automated penetration testing (APT)? Security vendors have stoked this debate for obvious reasons, with some even explicitly arguing that automated pentesting should replace BAS entirely. But for practitioners responsible for defending an organization, this framing is the problem. It represents a coverage regression disguised as simplification. Why your phishing simulations aren’t building a security culture Security culture isn’t built by phishing simulations. In this Help Net Security video, Dan Potter, VP of Cyber Resilience at Immersive, argues that annual training videos and quarterly phishing tests happen in calm, controlled settings that tell us nothing about how people perform when a real incident hits. Russian hackers go after high-value targets through Signal Russian intelligence-linked hackers are targeting commercial messaging platforms, with Signal a primary focus, the FBI and CISA warn. The campaign is aimed at individuals of intelligence interest, including government personnel, journalists, and others with access to sensitive communications. The devices winning the race to get hacked in 2026 Enterprise networks keep adding connected devices, expanding the attack surface as threat actors target a wider range of systems, many of which are difficult to inventory, secure, and patch consistently. Forescout’s 2026 Riskiest Devices research maps that shift in IT, IoT, OT, and IoMT environments, with 11 new riskiest asset types entering the list this year. GitHub just made it much harder to ship a vulnerable pull request GitHub is expanding its application security capabilities with AI-powered security detections designed to identify risks earlier in the development process, with public preview planned for early Q2. The update is intended to improve code scanning, secret detection, and dependency analysis within repositories hosted on the platform. 32% of top-exploited vulnerabilities are over a decade old Exploitation timelines continued to compress in enterprise environments, with newly disclosed flaws reaching active use almost immediately and older weaknesses remaining active years after disclosure. Findings from Cisco Talos’ 2025 Year in Review show how attackers combined rapid weaponization with long-term exposure spanning infrastructure, identity systems, and user workflows. Russian initial access broker helped ransomware gangs extort millions, sentenced to 81 months A Russian citizen, Aleksei Volkov, was sentenced to 81 months in prison for helping ransomware groups carry out attacks causing over $9 million in actual losses and over $24 million in intended losses, after being arrested in Italy and extradited to the United States where he pleaded guilty. Uncle Sam closes the door on all new foreign-made routers The US Federal Communications Commission (FCC) has imposed a ban on all new routers manufactured overseas being imported into and sold within the United States. The move follows a determination by a White House-led interagency group that consumer-grade routers produced outside the United States pose what officials described as an “unacceptable risk” to national security and public safety. Anthropic trims action approval loop, lets Claude Code make the call Auto mode is a new permissions feature in the Claude Code system that allows the AI to make approval decisions on a user’s behalf while safeguards review actions before execution. The feature is available on Team plans and requires administrator approval before use, with support for Enterprise and API users expected soon. Gemini picks up criminal activity buried in dark web noise To help teams make faster and more accurate decisions on emerging threats, Google has introduced a dark web intelligence capability in Google Threat Intelligence. Powered by Gemini, the feature analyzes millions of dark web events each day and surfaces threats relevant to an organization’s operations. Botnet operator behind $14 million in ransomware extortion payments gets 24 months behind bars A Russian national has been sentenced to 24 months in prison after admitting he managed a botnet used to launch ransomware attacks against dozens of U.S. companies. The judge also imposed a $100,000 fine and ordered him to forfeit $1.6 million linked to the scheme. Google races to secure encryption before quantum threats arrive Google is preparing for the quantum era, a turning point in digital security, with a 2029 timeline for post-quantum cryptography (PQC) migration. Security professionals warn that current encryption could be broken by large-scale quantum computers in the coming years. This risk is already relevant due to store-now-decrypt-later attacks. Mission to smuggle $170 million worth of AI tech to China collapsed for three men Three individuals, Stanley Yi Zheng, Matthew Kelly, and Tommy Shad English, have been charged with conspiracy to commit smuggling and export control violations after allegedly attempting to procure millions of dollars’ worth of restricted computer chips from a California-based hardware company. Second RedLine infostealer operator ends up in US custody Hambardzum Minasyan, an Armenian man extradited to the United States, is accused of conspiring with others to develop and operate the RedLine infostealer malware used to steal sensitive data, including login credentials, from victims’ computers. Ajax data breach exposed season tickets, supporter bans open to tampering AFC Ajax, the Dutch football club from Amsterdam, disclosed that an unknown hacker gained access to parts of its IT systems and obtained the email addresses of a few hundred people. The hack exploited vulnerabilities in Ajax’s app and website, including exposed APIs and shared access keys. Plumber: Open-source scanner of GitLab CI/CD pipelines for compliance gaps GitLab CI/CD pipelines often accumulate configuration decisions that drift from security baselines over time. Container images get pinned to mutable tags, branches lose protection settings, and required templates go missing. An open-source tool called Plumber automates the detection of those conditions by scanning pipeline configuration and repository settings directly. Attackers are handing off access in 22 seconds, Mandiant finds Exploits remain the leading entry point for attackers for the sixth consecutive year, according to Mandiant’s M-Trends 2026 report, which draws on more than 500,000 hours of incident response work conducted in 2025. The data shows attackers speeding up their internal hand-offs, shifting away from email phishing, and targeting backup and virtualization infrastructure with greater precision. Microsoft details AI prompt abuse techniques targeting AI assistants Prompt abuse occurs when crafted inputs manipulate an AI system into producing unintended behavior, such as attempting to access sensitive information or overriding built-in safety instructions. Prompt injection is also recognized as one of the top risks in the 2025 OWASP guidance for LLM applications. Kali Linux 2026.1 ships BackTrack mode, eight new tools, and a kernel upgrade to 6.18 Penetration testers running Kali Linux have a new release to work with. Version 2026.1 delivers the annual theme refresh, a new BackTrack-inspired mode in kali-undercover, eight tools added to the network repositories, a kernel bump to 6.18, and several Kali NetHunter changes. Your security stack looks fine from the dashboard and that’s the problem One in five enterprise endpoints is operating outside a protected and enforceable state on any given day, according to device telemetry collected across tens of millions of corporate PCs. That figure, drawn from Absolute Security’s 2026 Resilience Risk Index, has barely moved in a year, even as organizations continue to add security tools and increase spending. Google’s TurboQuant cuts AI memory use without losing accuracy Large language models carry a persistent scaling problem. As context windows grow, the memory required to store key-value (KV) caches expands proportionally, consuming GPU memory and slowing inference. A team at Google Research has developed three compression algorithms: TurboQuant, PolarQuant, and Quantized Johnson-Lindenstrauss (QJL). All three are designed to compress those caches aggressively without degrading model output quality. Microsoft hands Entra ID users new option for MFA Organizations rely on MFA to enforce identity checks before granting access to systems and services. Microsoft has made external MFA generally available in Microsoft Entra ID, expanding support for third-party identity providers. External MFA supports organizations that use third-party MFA solutions to meet regulatory or business requirements, handle scenarios such as mergers and acquisitions, or maintain a consistent MFA approach within Microsoft Entra ID. Unbreakable Enterprise Kernel 8.2 ships with confidential computing support, XFS live repair Many enterprise Linux deployments rely on hardware-level memory isolation to protect sensitive workloads from co-tenants and compromised hypervisors. Oracle’s Unbreakable Enterprise Kernel 8.2 (UEK 8.2) extends that capability on Oracle Linux with support for Intel Trust Domain Extensions, along with a set of file system and memory management changes intended to reduce downtime and improve diagnostic visibility. Who owns AI agent access? At most companies, nobody knows AI agents are operating across production enterprise environments at scale, and the identity infrastructure managing their access has not kept up with their deployment. A January 2026 survey of 228 IT and security professionals, conducted by the Cloud Security Alliance, finds that the majority of organizations have AI agents active in core systems, with fragmented ownership of how those agents authenticate and what they can access. Reddit declares war on bad bot activity Reddit is introducing changes to support interactions between people. The company is taking a bottom-up approach to help users understand when they are engaging with another person unless an account is labeled otherwise. Reddit plans to verify that users are human without requiring disclosure of real-world identity. GitHub jumps on the bandwagon and will use your data to train AI GitHub updated how it uses data to improve AI-powered coding assistance. Starting April 24, interaction data from Copilot Free, Pro, and Pro+ users may be used to train and improve GitHub’s models unless users opt out. Copilot Business and Copilot Enterprise users are not included in this change. Tails 7.6 ships automatic Tor bridge retrieval and a new password manager Tails 7.6 is out, and for users operating on networks that block Tor, the most consequential addition is built-in bridge retrieval. The Tor Connection assistant can now detect when a direct connection to Tor is restricted and automatically request bridges suited to the user’s region. The request goes through the Tor Project’s Moat API, and the connection to that API is disguised via domain fronting, making it appear as traffic to an ordinary website. Make OpenAI’s models misbehave and earn a reward OpenAI’s public Safety Bug Bounty program focuses on AI abuse and safety risks across its products. The goal is to support safe and secure systems and reduce the risk of misuse that could lead to harm. This program complements the Security Bug Bounty. It accepts reports of abuse and safety risks that do not meet the criteria for a security vulnerability. AI frenzy feeds credential chaos, secrets leak through code, tools, and infrastructure Code keeps moving through pipelines, and credentials continue to surface alongside it. GitGuardian’s State of Secrets Sprawl 2026 puts the count at 28.65 million new hardcoded secrets in public GitHub commits in 2025, extending a multi-year rise in exposed access keys, tokens, and passwords. Cybersecurity jobs available right now: March 24, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
helpnetsecurity.comMar 29, 2026extracted
Tails 7.6 ships automatic Tor bridge retrieval and a new password manager
Tails 7.6 ships automatic Tor bridge retrieval and a new password manager Tails 7.6 is out, and for users operating on networks that block Tor, the most consequential addition is built-in bridge retrieval. The Tor Connection assistant can now detect when a direct connection to Tor is restricted and automatically request bridges suited to the user’s region. The request goes through the Tor Project’s Moat API, and the connection to that API is disguised via domain fronting, making it appear as traffic to an ordinary website. Previously, users on censored networks had to obtain bridges manually and enter them by hand. The feature closes a long-standing gap in Tails’ censorship-circumvention capability. Users who prefer to take action themselves can also select the option to request region-specific bridges directly from the connection assistant screen. Password manager switches from KeePassXC to Secrets Tails 7.6 replaces KeePassXC with the GNOME Secrets password manager as the default credential storage tool. Secrets has a simpler interface and integrates more tightly with the GNOME desktop environment. Accessibility features that were broken under KeePassXC, including the on-screen keyboard and cursor size adjustments, work again with Secrets. Existing KeePassXC database files are compatible with Secrets’ format, so stored credentials carry over without any conversion step. Users who depend on features specific to KeePassXC can still install it manually. Component upgrades and Qt5 removal The kernel moves to Linux 6.12.74. Tor Browser advances to 15.0.8, built on Firefox ESR 140.9. Thunderbird reaches 140.8.0esr. Electrum moves to 4.7.0, and that upgrade is tied directly to the removal of Qt5 from the distribution. The changelog confirms that Qt5 support packages have been stripped out entirely, and tests now verify that no Qt5 package ships with the build. The base distribution advances to Debian 13.4 (Trixie). Firmware packages also receive an update: firmware-nonfree moves to version 20260110-1, improving hardware support for graphics cards and wireless adapters on newer machines. The forge.js library, used in Tails’ web-facing components, upgrades to v1.3.3. The update includes a step to make it harder for external CDNs to target the project, and it brings the project’s license documentation into compliance with BSD 3-clause terms. Bug fixes targeting localization and upgrade reliability Three user-facing bugs are resolved in this release. Automated upgrades failed for users running Tails with the language set to Turkish; that problem is fixed. A broken link in the Thunderbird migration notification, the “Learn More” button that was supposed to point users to documentation, is restored. The confirmation dialog displayed when saving a language and keyboard layout to the USB stick in unencrypted form was not honoring available translations; it now renders in the user’s selected language. Upgrading Automatic upgrades are available for any installation running Tails 7.0 or later. The upgrade preserves data stored in Persistent Storage. Users whose automatic upgrade fails, or whose system does not start after an update, can follow the manual upgrade path available on the Tails documentation site.
helpnetsecurity.comMar 26, 2026extracted
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams
Google on Thursday announced a new "advanced flow" for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt to balance openness with safety. The new changes come against the backdrop of a developer verification mandate the tech giant announced last year that requires all Android apps to be registered by verified developers to be installed on certified Android devices. The move, it added, was done to flag bad actors faster and prevent them from distributing malware. This also includes potential scenarios where cybercriminals trick unsuspecting users who sideload such apps into granting them elevated privileges that make it possible to turn off Play Protect, the anti-malware feature built into all Google-certified Android devices. However, the mandatory registration requirements have been met with criticism from over 50 app developers and marketplaces, including F-Droid, Brave, The Electronic Frontier Foundation, Proton, The Tor Project, Vivaldi, who say they risk creating friction and barriers to entry, and raise privacy and surveillance concerns in the absence of clarity about what personal information developers must provide, how this data will be stored, secured, and used, and if it could be subject to government requests or legal processes. As a way of quelling some of these thorny issues, Google has emphasized that the newly developed advanced flow allows power users to maintain the ability to sideload apps from unverified developers with a one-time process that requires them to follow the steps below - Enable developer mode in system settings. Confirm that they are taking this step of their own volition and are not being coached. Restart the phone and re-authenticate so as to prevent a scammer from monitoring what actions a user is taking. Wait for a 24-hour period and confirm that they are really making this change with biometric authentication or device PIN. Install apps from unverified developers once users understand the risks, either indefinitely or for a period of seven days. "In that 24-hour period, we think it becomes much harder for attackers to persist their attack," Android Ecosystem President, Sameer Samat, was quoted as saying to Ars Technica. "In that time, you can probably find out that your loved one isn’t really being held in jail or that your bank account isn’t really under attack." Google also said it plans to offer free "limited distribution accounts" that let hobbyist developers and students share apps with up to 20 devices without having to "provide a government-issued ID or pay a registration fee." It's worth noting that the aforementioned process does not apply to installs via the Android Debug Bridge (ADB). Limited distribution accounts for students and hobbyists, as well as advanced flow for users, will be available in August 2026, before the new developer verification requirements take effect the month after. "We know a 'one size fits all' approach doesn't work for our diverse ecosystem," Google said. "We want to ensure that identity verification isn't a barrier to entry, so we’re providing different paths to fit your specific needs." The development coincides with the emergence of a new Android malware called Perseus that's actively targeting users in Turkey and Italy with an aim to conduct device takeover (DTO) and financial fraud. Over the four months, at least 17 Android malware families have been detected in the wild. They include FvncBot, SeedSnatcher, ClayRat, Wonderland, Cellik, Frogblight, NexusRoute, ZeroDayRAT, Arsink (and its improved variant SURXRAT), deVixor, Phantom, Massiv, PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT.
thehackernews.comMar 20, 2026extracted
Week in review: Fake “Windows Update” fuels malware, Salesforce details Gainsight breach
Week in review: Fake “Windows Update” fuels malware, Salesforce details Gainsight breach Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Quantum encryption is pushing satellite hardware to its limits In this Help Net Security interview, Colonel Ludovic Monnerat, Commander Space Command, Swiss Armed Forces, discusses how securing space assets is advancing in response to emerging quantum threats. He explains why satellite systems must move beyond traditional cryptography to remain protected. Monnerat also describes how future communication architectures will need to integrate quantum-safe methods without disrupting operations. How an AI meltdown could reset enterprise expectations In this Help Net Security interview, Graham McMillan, CTO at Redgate Software, discusses AI, security, and the future of enterprise oversight. He explains why past incidents haven’t pushed the industry to mature. McMillan also outlines the structural shifts he expects once failures start to have business impact. Heineken CISO champions a new risk mindset to unlock innovation In this Help Net Security interview, Marina Marceta, CISO at Heineken, discusses what it takes for CISOs to be seen as business-aligned leaders rather than technical overseers. She shares how connecting security to business impact can shift perceptions and strengthen partnerships across the company. Marceta focuses on the value of a security culture that supports innovation while keeping risk in check. Fake “Windows Update” screens fuels new wave of ClickFix attacks A convincing (but fake) “Windows Update” screen can be the perfect lure for tricking users into infecting their computers with malware. Add a multi-stage delivery chain with some offbeat techniques, and infostealer operators have everything they need to slip past defenses. Popular code formatting sites are exposing credentials and other secrets Widely used code formatting sites JSONFormatter and CodeBeautify are exposing sensitive credentials, API keys, private keys, configuration files and other secrets, watchTowr researchers discovered. New “HashJack” attack can hijack AI browsers and assistants Security researchers at Cato Networks have uncovered a new indirect prompt injection technique that can force popular AI browsers and assistants to deliver phishing links or disinformation (e.g., incorrect medicine dosage guidance or investment advice), send sensitive data to the attacker, or push users to perform risky actions. Gainsight breach: Salesforce details attack window, issues investigation guidance The number of Salesforce customers affected by the recent compromise of Gainsight-published applications is yet to be publicly confirmed, but Salesforce released indicators of compromise (IoCs) and simultaneously shed some light on when the attack likely started. The provided list includes IP addresses and User Agents, showing that the first reconnaissance and unauthorized access activity started on November 8. Black Friday 2025 for InfoSec: How to spot real value and avoid the noise Your inbox is probably drowning in Black Friday emails right now. Another “limited time offer” that’ll reappear next month, countdown timer creating artificial urgency. You’re right to be skeptical — most of it is noise. But buried beneath the marketing chaos, Black Friday can represent genuine opportunities to save significantly. How board members think about cyber risk and what CISOs should tell them In this Help Net Security video, Jonathan Trull, EVP & CISO at Qualys, discusses which cybersecurity metrics matter most to a board of directors. Drawing on more than two decades in the field, he explains how boards think about their duty to oversee risk and how CISOs can present information in a way that supports that duty. cnspec: Open-source, cloud-native security and policy project cnspec is an open source tool that helps when you are trying to keep a sprawling setup of clouds, containers, APIs and endpoints under control. It checks security and compliance across all of it, which makes it easier to see what needs attention. Aircraft cabin IoT leaves vendor and passenger data exposed The expansion of IoT devices in shared, multi-vendor environments, such as aircraft cabins, has created tension between the benefits of data collaboration and the risks to passenger privacy, vendor intellectual property, and regulatory compliance. Microsoft cracks down on malicious meeting invites Phishing is shifting into places people rarely check. Meeting invites that plant themselves on calendars can survive long after the malicious email is gone. That leaves a quiet opening for attackers. Microsoft has updated Defender for Office 365 so that security teams can now remove those leftover calendar entries when they perform a Hard Delete. Microsoft also added stronger domain blocking for phishing links. Tor Project is rolling out Counter Galois Onion encryption People who rely on Tor expect their traffic to move through the network without giving away who they are. That trust depends on the strength of the encryption that protects each hop. Tor developers are preparing a major upgrade called Counter Galois Onion, or CGO, which replaces the long-standing relay encryption method used across the network. DeepTeam: Open-source LLM red teaming framework Security teams are pushing large language models into products faster than they can test them, which makes any new red teaming method worth paying attention to. DeepTeam is an open-source framework built to probe these systems before they reach users, and it takes a direct approach to exposing weaknesses. Small language models step into the fight against phishing sites Phishing sites keep rising, and security teams are searching for ways to sort suspicious pages at speed. A recent study explores whether small language models (SLMs) can scan raw HTML to catch these threats. The work reviews a range of model sizes and tests how they handle detection tasks while keeping compute demands in check. Why password management defines PCI DSS success Most CISOs spend their days dealing with noisy dashboards and vendor pitches that all promise a shortcut to compliance. It can be overwhelming to sort out what matters. When you dig into real incidents involving payment data, a surprising number come down to poor password hygiene. PCI DSS v4.0 raised the bar for authentication, and the responsibility sits with security leaders to turn those requirements into workable daily habits for users and admins. A password manager is one of the few tools that can make this shift possible without adding friction. New observational auditing framework takes aim at machine learning privacy leaks Machine learning (ML) privacy concerns continue to surface, as audits show that models can reveal parts of the labels (the user’s choice, expressed preference, or the result of an action) used during training. A new research paper explores a different way to measure this risk, and the authors present findings that may change how companies test their models for leaks. Email blind spots are back to bite security teams The threat landscape is forcing CISOs to rethink what they consider normal. The latest Cybersecurity Report 2026 by Hornetsecurity, based on analysis of more than 70 billion emails and broad threat telemetry, shows attackers adopting automation, AI driven social engineering, and new evasion techniques at scale. What happens when vulnerability scores fall apart? Security leaders depend on vulnerability data to guide decisions, but the system supplying that data is struggling. An analysis from Sonatype shows that core vulnerability indexes no longer deliver the consistency or speed needed for the current software environment. The privacy tension driving the medical data shift nobody wants to talk about Most people assume their medical data sits in quiet storage, protected by familiar rules. That belief gives a sense of safety, but new research argues that the world around healthcare data has changed faster than the policies meant to guide it. As a result, the system is stuck, and the cost of that stagnation is rising for patients, researchers, and innovators. Supply chain sprawl is rewriting security priorities Organizations depend on long chains of vendors, but many cybersecurity professionals say these relationships create gaps they cannot see or control. A new ISC2 survey of more than 1,000 cybersecurity professionals shows that supply chain risk sits near the top of their concerns. Criminal networks industrialize payment fraud operations Fraud operations are expanding faster than payment defenses can adjust. Criminal groups function like coordinated businesses that develop tools, automate tasks, and scale attacks. New data from a Visa report shows how these shifts are reshaping risk across the financial sector. The identity mess your customers feel before you do Customer identity has become one of the most brittle parts of the enterprise security stack. Teams know authentication matters, but organizations keep using methods that frustrate users and increase risk. New research from Descope shows how companies manage customer identity and the issues that have been building in the background. Your critical infrastructure is running out of time Cyber attackers often succeed not because they are inventive, but because the systems they target are old. A new report by Cisco shows how unsupported technology inside national infrastructure creates openings that attackers can exploit repeatedly. The findings show how widespread this problem has become and how much it influences national resilience. Hottest cybersecurity open-source tools of the month: November 2025 This month’s roundup features exceptional open-source cybersecurity tools that are gaining attention for strengthening security across various environments. Fragmented tooling slows vulnerability management Security leaders know vulnerability backlogs are rising, but new data shows how quickly the gap between exposures and available resources is widening, according to a new report by Hackuity. Social data puts user passwords at risk in unexpected ways Many CISOs already assume that social media creates new openings for password guessing, but new research helps show what that risk looks like in practice. The findings reveal how much information can be reconstructed from public profiles and how that data influences the strength of user passwords. The study also examines how LLMs behave when asked to generate or evaluate passwords based on that same personal information. Black Friday 2025 cybersecurity deals to explore Black Friday 2025 is shaping up to be a good moment for anyone thinking about tightening their cybersecurity. A few solid deals are popping up that make it easier to improve protection for systems and data without stretching your budget. If you have been waiting for the right time to upgrade or add new tools, these four offers are simple, practical options that are worth a look. The breaches everyone gets hit by (and how to stop them) Headlines scream about zero-days and nation-state attacks, but the reality is far less glamorous. The majority of breaches start with predictable, low-tech methods: stolen credentials, phishing, and unpatched systems. These aren’t rare, they’re routine, and they’re winning. Cybersecurity jobs available right now: November 25, 2025 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. Infosec products of the month: November 2025 Here’s a look at the most interesting products from the past month, featuring releases from: 1touch.io, Action1, Barracuda Networks, Bedrock Data, Bitdefender, Cyware, Firewalla, Forescout, Immersive, Kentik, Komodor, Minimus, Nokod Security, and Synack.
helpnetsecurity.comNov 30, 2025extracted
ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories
Hackers have been busy again this week. From fake voice calls and AI-powered malware to huge money-laundering busts and new scams, there’s a lot happening in the cyber world. Criminals are getting creative — using smart tricks to steal data, sound real, and hide in plain sight. But they’re not the only ones moving fast. Governments and security teams are fighting back, shutting down fake networks, banning risky projects, and tightening digital defenses. Here’s a quick look at what’s making waves this week — the biggest hacks, the new threats, and the wins worth knowing about. Mirai-based malware resurfaces with new IoT campaignThe threat actors behind the Mirai-based ShadowV2 botnet have been observed infecting IoT devices across industries and continents. The campaign is said to have been active only during the Amazon Web Services (AWS) outage in late October 2025. It's assessed that the activity was "likely a test run conducted in preparation for future attacks," per Fortinet. The botnet exploited several flaws, including CVE-2009-2765 (DDWRT), CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915 (D-Link), CVE-2023-52163 (DigiEver), CVE-2024-3721 (TBK), and CVE-2024-53375 (TP-Link), to recruit susceptible gear into a zombie army of IoT devices. A successful exploitation is followed by the execution of a downloader shell script that delivers the ShadowV2 malware for subsequent DDoS attacks. "IoT devices remain a weak link in the broader cybersecurity landscape," the company said. "The evolution of ShadowV2 suggests a strategic shift in the targeting behavior of threat actors toward IoT environments." It's not just ShadowV2. Another DDoS botnet named RondoDox, also based on Mirai, has weaponized over a dozen exploits to target IoT devices. "Attackers are not only motivated to target vulnerable IoT devices, but also how, if successful, they will take over previously infected devices to add them to their own botnets," F5 said. Singapore tightens messaging rules to fight spoof scamsSingapore has ordered Apple and Google to block or filter messages on iMessage and RCS-supported Messages app for Android that masquerade as government agencies, requiring the company to implement new anti-spoofing protections starting December 2025 as part of efforts to curb rising online scams. According to Straits Times, Apple has been issued a directive under the Online Criminal Harms Act, requiring the tech giant to prevent iMessage accounts and group chats from using names that mimic Singapore government agencies or the "gov.sg" sender ID. Tor bolsters privacy with new encryption upgradeThe developers behind the Tor project are preparing a major upgrade called Counter Galois Onion (CGO), which replaces the long-standing relay encryption method used across the anonymity network. "It's based on a kind of construction called a Rugged Pseudorandom Permutation (RPRP): essentially, it's a design for a wide-block cipher that resists malleability in one direction (for the encrypt operation, but not the decrypt operation)," the Tor Project said. "If we deploy this so that clients always decrypt and relays always encrypt, then we have a tagging-resistant cipher at less cost than a full SPRP [strong pseudorandom permutation]!" The updates aim to raise the cost of active attacks along a circuit, such as tagging and traffic-interception attacks, as well as prevent bad actors from tampering with encrypted traffic, add forward secrecy, and make the network more resilient. Report shows surge in phishing during 2025 shopping seasonKaspersky said it identified nearly 6.4 million phishing attacks, which targeted users of online stores, payment systems, and banks in the first ten months of 2025. "As many as 48.2% of these attacks were directed at online shoppers," it said, adding it "detected more than 2 million phishing attacks related to online gaming" and "blocked more than 146,000 Black Friday-themed spam messages in the first two weeks of November." Stealthy malware targets OpenFind mail serversESET has disclosed details of a new toolset dubbed QuietEnvelope that's specifically developed to target the MailGates email protection system of OpenFind email servers. The toolset comprises Perl scripts and three stealthy backdoors, among other miscellaneous files. "The Perl scripts are mainly responsible for deploying three passive backdoors as a loadable kernel module (LKM), an Apache module, and an injected shellcode," ESET said. "Together, they enable the attackers to have remote access to a compromised server." The LKM component ("smtp_backdoor") monitors ingress TCP traffic on port 6400 and triggers when packets contain the magic string EXEC_OPENFIND to execute the command. "The Apache module expects the command, which is executed via popen, in the custom HTTP header OpenfindMaster," it added. "The third backdoor is injected into a running mgsmtpd process. It is capable of retrieving file content and executing commands. By default, it responds with 250 OK, suggesting that the backdoor is hooked into the code that is maybe responsible for generating the SMTP response." The tool is believed to be the work of an unknown state-sponsored threat actor, given the sophistication and its ability to blend in. ESET said it found debug strings written in simplified Chinese, which is mainly used in Mainland China. Russia-linked hackers abuse MSC flaw for stealthy infectionA Bing search for "belay" leads to the website "belaysolutions[.]com," which is said to have been compromised with malicious JavaScript that performs a silent redirect to "belaysolutions[.]link" that hosts a double-extension RAR payload disguised as a PDF. Opening the initial payload exploits MSC EvilTwin (CVE-2025-26633) to inject code into mmc.exe, ultimately leading to the deployment of a loader executable that's capable of installing backdoors or stealers. "When run, mmc.exe resolves MUI paths that load the malicious snap-in instead of the legitimate one, triggering embedded TaskPad commands with an encoded PowerShell payload," Zscaler said. "Decoded via -EncodedCommand, this script downloads UnRAR[.]exe and a password-protected RAR, extracts the next stage, waits briefly, then Invoke-Expression on the extracted script." The second script displays a decoy PDF and downloads and executes the loader binary. The exact nature of the payload is unclear due to the fact that the command-and-control (C2) infrastructure is unresponsive. The attack chain has been attributed to a Russia-aligned APT group known as Water Gamayun (aka EncryptHub). NCA uncovers crypto laundering tied to Russian sanctions evasionThe U.K. has exposed two companies, Smart and TGR, which laundered money from cybercrime, drugs trade, firearms smuggling, and immigration crime for a fee, to create "clean" cryptocurrency that the Russian state could then use to evade international sanctions. The National Crime Agency (NCA) said the two entities acquired a bank in Kyrgyzstan to pose as legitimate operations. The network is known to operate in at least 28 U.K. cities and towns. "Smart and TGR collaborated to launder money for transnational crime groups involved in cybercrime, drugs, and firearms smuggling," the NCA said. "They also helped their Russian clients to illegally bypass financial restrictions to invest money in the U.K., threatening the integrity of our economy." Defender update removes lingering malicious invitesMicrosoft said it has updated Defender for Office 365 to help security teams remove calendar entries automatically created by Outlook during email delivery. While remediation actions such as Move to Junk, Delete, Soft Delete, and Hard Delete can be used to eliminate email threats from users' inboxes, the actions did not touch the calendar entry created by the original invite. "With this update, we're taking the first step toward closing that gap," the company said. "Hard Delete will now also remove the associated calendar entry for any meeting invite email. This ensures threats are fully eradicated—not just from the inbox but also from the calendar—reducing the risk of user interaction with malicious content." Thailand cracks down on Worldcoin-style biometric collectionData regulators in Thailand have ordered TIDC Worldverse, which presents the Sam Altman-founded startup, Tools for Humanity, in the country, to stop the collection of iris biometrics in exchange for World (formerly Worldcoin) cryptocurrency payments. It has also demanded the deletion of biometric data already collected from 1.2 million Thai citizens. The project has witnessed similar bans in Brazil, the Philippines, Indonesia, and Kenya. 21-year-old cybersecurity specialist detained over state criticismTimur Kilin, a 21-year-old tech entrepreneur and cybersecurity specialist, was arrested in Moscow on treason charges late last week. While the details of the case are unknown, it's suspected that Kilin may have attracted the attention of authorities after criticizing the state-backed messaging app Max and the government's anti-cybercrime legislation. Chinese-speaking group expands global smishing reach to EgyptThreat actors associated with the Smishing Triad have expanded their focus to target Egypt by setting up malicious domains impersonating major Egyptian service providers, including Fawry, the Egypt Post, and Careem. The Smishing Triad is a Chinese-speaking cybercriminal group specializing in large-scale smishing campaigns across the world using a phishing kit named Panda. "Beyond U.S. service impersonation, the smishing kit offers a wide range of international templates, including those that mimic prominent ISPs such as Du (U.A.E.)," Dark Atlas said. "These templates are designed to harvest PII from victims across different regions, significantly expanding the campaign’s global reach." Recently, Google filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against a massive Phishing-as-a-Service (PhaaS) platform called Lighthouse that has ensnared over 1 million users across 120 countries. Lighthouse is one of the PhaaS services used by the Smishing Triad. The PhaaS kits are primarily distributed through Telegram by a threat actor named Wang Duo Yu (@wangduoyu8). Privacy service ends after ties to data broker controversyMozilla has announced plans to shut down Monitor Plus, a service that allowed user data to be removed from data broker portals. The service will wind down on December 17, 2025. It was offered through a partnership with Onerep, a controversial company whose Belarusian CEO, Dimitiri Shelest, was caught running dozens of people search engine services since 2010. "Mozilla Monitor's free monitoring service will continue to provide real-time alerts and step-by-step guides to mitigate the risks of a data breach," Mozilla said. Phishing campaigns drop RATs on Russian corporate targetsA new threat actor named NetMedved is targeting Russian companies with phishing emails containing ZIP archives that include a LNK file masquerading as a purchase request, along with other decoy documents. Opening the LNK file triggers a multi-stage infection sequence that drops NetSupport RAT. The activity, per Positive Technologies, was observed in mid-October 2025. The development comes as F6 detailed new attacks mounted by VasyGrek (aka Fluffy Wolf), a Russian-speaking e-crime actor known for striking Russian companies since 2016 to deliver remote access trojans (RATs) and stealer malware. The latest set of attacks recorded between August and November 2025 involved the use of the Pay2Key ransomware, as well as malware developed by PureCoder, including PureCrypter, PureHVNC, and PureLogs Stealer. Blockchain-hosted payloads deliver AMOS, Vidar, Lumma stealersThreat actors are using legitimate websites compromised with malicious JavaScript injects to serve site visitors fake CAPTCHA checks that contain a Base64-encoded payload to display a ClickFix lure that's appropriate for the operating system by using the EtherHiding technique. This involves hiding intermediate JavaScript payloads on the blockchain and using four smart contracts deployed on the Binance Smart Chain (BSC) to ensure that the victim is not a bot and direct them to an operating system (OS)-specific contract. However, the OS-specific JavaScript is delivered only after a call to a gate contract that responds either "yes" or another value. "This gate provides the attacker with a remotely controlled feature flag," Censys said. "By altering on-chain state, the operator can selectively enable or disable delivery for specific victims, throttle execution, or temporarily disable the entire campaign." The payloads distributed throughout chains include common stealers like AMOS and Vidar. Similar drive-by compromise attacks have also been found to display counterfeit CAPTCHA verifications that leverage the ClickFix tactic to drop Lumma Stealer, according to NCC Group. Microsoft links 13M phishing emails to top PhaaS operationMicrosoft said the PhaaS toolkit known as Tycoon 2FA (aka Storm-1747) has emerged as the most prolific platform observed by the company this year. In October 2025 alone, Microsoft Defender for Office 365 blocked more than 13 million malicious emails linked to Tycoon 2FA. "More than 44% of all CAPTCHA-gated phishing attacks blocked by Microsoft were attributed to Tycoon 2FA," it said. "Tycoon2FA was also directly linked to nearly 25% of all QR code phishing attacks detected in October." First discovered in 2023, Tycoon 2FA has evolved into a potent tool that leverages real-time Adversary-in-the-Middle (AitM) techniques to capture credentials, steal session tokens, and one-time codes. "The platform delivers high-fidelity phishing pages for Microsoft 365, Gmail, and Outlook, and has become a preferred tool among threat actors due to its subscription-based, low-barrier operational model," CYFIRMA said. Malware uses AI mimicry to bypass behavioral defensesA new version of Xillen Stealer has introduced advanced features to evade AI-based detection systems by mimicking legitimate users and adjusting CPU and memory usage to imitate normal apps. Its main goal is to steal credentials, cryptocurrency, and sensitive data across browsers, password managers, and cloud environments. It's marketed on Telegram for anywhere between $99 to $599 per month. The latest iteration also includes code to use AI to detect high-value targets based on weighted indicators and relevant keywords defined in a dictionary. These include cryptocurrency wallets, banking data, premium accounts, developer accounts, and business emails, along with location indicators that include high-value countries such as the U.S., the U.K., Germany, and Japan, and other cryptocurrency-friendly countries and financial hubs. While the feature is not fully implemented by its authors, Xillen Killers, the development shows how threat actors could be leveraging AI in future campaigns, Darktrace said. FCC reverses course on telecom cybersecurity policyThe Federal Communications Commission (FCC) has scrapped a set of telecom cybersecurity rules introduced after the Salt Typhoon espionage campaign came to light last year to prevent state-sponsored hackers from breaching American carriers. The ruling came into effect in January 2025. The course reversal comes after what the FCC said were "extensive, urgent, and coordinated efforts" from carriers to mitigate operational risks and better protect consumers. The action follows "months-long engagement with communications service providers where they have demonstrated a strengthened cybersecurity posture following Salt Typhoon," the agency added, adding it has "taken a series of actions to harden communications networks and improve their security posture to enhance the agency's investigative process into communications networks outages that result from cyber incidents." This included establishing a Council on National Security and adopting rules to address cybersecurity risks to critical communications infrastructure without "imposing inflexible and ambiguous requirements." However, the FCC's announcement offers no details on how those improvements will be monitored or enforced. Teen suspects deny charges in Transport for London hackTwo British teenagers who were charged with Computer Misuse Act offenses over a cyber attack on Transport for London (TfL) last year pleaded not guilty during a court appearance last week. Thalha Jubair, 19, and Owen Flowers, 18, were arrested at their homes in East London and Walsall, respectively, by officers from the National Crime Agency (NCA) in September 2025. Unpatched flaw lets AI voice agents enable large-scale scamsA security vulnerability has been disclosed in the Retell AI API, which creates AI voice agents that have excessive permissions and functionality. This stems from a lack of sufficient guardrails that causes its large language model (LLM) to deliver unintended outputs. An attacker could exploit this behavior to stage large-scale social engineering, phishing, and misinformation campaigns. "The vulnerability targets Retell AI's ease of deployment and customizability to perform scalable phishing/social engineering attacks," the CERT Coordination Center (CERT/CC) said. "Attackers can feed publicly available resources as well as some instructions to Retell AI’s API to generate high-volume and automated fake calls. These fake calls could lead to unauthorized actions, security breaches, data leaks, and other forms of manipulation." The issue remains unpatched. Study shows cybercriminal job market mirrors real-world economyA new analysis from Kaspersky has revealed that the dark web continues to serve as a parallel labor market with its own rules, recruitment practices, and salary expectations, while also being influenced by current economic forces. "The majority of job seekers do not specify a professional field, with 69% expressing willingness to take any available work," the company said. "At the same time, a wide range of roles are represented, particularly in IT. Developers, penetration testers, and money launderers remain the most in-demand specialists, with reverse engineers commanding the highest average salaries. We also observe a significant presence of teenagers in the market, many seeking small, fast earnings and often already familiar with fraudulent schemes." Android malware hides traffic behind hacked legitimate sitesAhnLab said it discovered an Android APK malware ("com.golfpang.golfpanggolfpang") impersonating a famous Korean delivery service, while taking steps to evade security controls using obfuscation and packing techniques. The data stolen by the malware is exfiltrated to a breached legitimate site that's used for C2. "When the app is launched, it requests the permissions required to perform malicious behaviors from the user," AhnLab said. In a similar development, a malicious program disguised as SteamCleaner is being propagated via websites that advertise cracked software to deliver a Node.js script capable of communicating with a C2 server periodically and executing commands issued by the attacker. While it's not known what commands are sent via the C2 channel, AhnLab said the activity could lead to the installation of proxyware and other payloads. The counterfeit installers are hosted on GitHub repositories managed by the threat actor. ASIO chief warns of state-backed cyber threats to critical systemsDirector-General of Security Mike Burgess, the head of Australia's Security Intelligence Organisation (ASIO), disclosed that threat actors operating on behalf of China's government and military probed the country's telecoms network and key infrastructure. Burgess warned that authoritarian regimes "are growing more willing to disrupt or destroy critical infrastructure" using cyber sabotage. Espionage is estimated to have cost the country A$12.5 billion ($8.1 billion) in 2024. However, China has dismissed the remarks, stating they "spread false narratives and deliberately provoked confrontation." Fake mayor jailed for life over massive cyber scam ringAlice Guo, a 35-year-old Chinese woman who posed as a local and was elected as mayor for the city of Bamban in 2022, was sentenced to life in prison after she was found guilty of human trafficking for her role in running a huge cyber scam compound that was operating under online casinos, known locally as Philippine Offshore Gaming Operations (Pogo). Guo, along with three others, was sentenced to life in prison and a fine of 2 million pesos ($33,832). Old Windows protocol remains key target for credential theftMultiple vulnerabilities in Microsoft Windows have been exploited by threat actors to leak NTLM hashes and augment their post-exploitation efforts. These include CVE-2024-43451, which has been abused by BlindEagle and Head Mare, CVE-2025-24054, which has been abused in phishing attacks targeting Russia to deliver Warzone RAT, and CVE-2025-33073, which has been abused in "suspicious activity" against an unnamed target belonging to the financial sector in Uzbekistan. In this attack, the threat actor exploited the flaw to check if they had sufficient privileges to execute code using batch files that ran reconnaissance commands, establish persistence, dump LSASS memory, and unsuccessfully attempt to move laterally to the administrative share of another host. No further activity was detected. "While Microsoft has announced plans to phase it out, the protocol’s pervasive presence across legacy systems and enterprise networks keeps it relevant and vulnerable," Kaspersky said. "Threat actors are actively leveraging newly disclosed flaws to refine credential relay attacks, escalate privileges, and move laterally within networks, underscoring that NTLM still represents a major security liability." That’s a wrap for this week’s ThreatsDay. The big picture? Cybercrime is getting faster, smarter, and harder to spot — but awareness still beats panic. Keep your software updated, stay alert for anything that feels off, and don’t click in a hurry. The more we all stay sharp, the harder it gets for attackers to win.
thehackernews.comNov 27, 2025extracted
Tor switches to new Counter Galois Onion relay encryption algorithm
Tor has announced improved encryption and security for the circuit traffic by replacing the old tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO). One reason behind this decision is to make the network more resilient against modern traffic-interception attacks that could compromise data security and undermine Tor user anonymity. The Tor network is a global system consisting of thousands of relays that create a circuit for data packets to travel to their destination through three relays (entry, middle, and exit), each hop adding a layer of encryption (onion routing). Users of the Tor Browser, a hardened version of Firefox built for browsing the Tor network, benefit from this onion routing to communicate privately, share or access information anonymously, bypass censorship, and evade ISP-level tracking. Typically, Tor is used by dissidents, activists, whistleblowers, journalists, researchers, and generally privacy-conscious people, including cybercriminals looking to access darknet markets. As the Tor team explains in an announcement, Tor1 was developed at a time when cryptography was far less advanced than today, and the standards have improved significantly since then. One issue with the tor1 design is that it uses AES-CTR encryption without hop-by-hop authentication, which leads to malleable relay encryption. This means that an adversary could modify traffic between relays they control and observe predictable changes - a tagging attack that is part of the internal covert channel class of attacks. Another problem is that tor1 uses partial forward secrecy by reusing the same AES keys throughout a circuit’s lifetime, enabling decryption in the event of key theft. A third security concern is that tor1 uses a 4-byte SHA-1 digest for cell authentication, giving attackers a one-in-4 billion probability to forge a cell without being detected. The Tor project notes that only the first attack in the list is more severe, and the last two examples were mentioned "for the sake of completeness." Introducing CGO CGO addresses the above problems. It is built on a Rugged Pseudorandom Permutation (RPRP) construction called UIV+, designed by cryptography researchers Jean Paul Degabriele, Alessandro Melloni, Jean-Pierre Münch, and Martijn Stam. Tor says that this system has been verified to meet specific security requirements, including protection against "tagging resistance, immediate forward secrecy, longer authentication tags, limited bandwidth overhead, relatively efficient operation, and modernized cryptography." Specifically, CGO improves on the following compared to Tor1: Tagging protection: CGO uses wide-block encryption and tag chaining, so any modification makes the entire cell and future cells unrecoverable, blocking tagging attacks. Forward secrecy: CGO updates keys after every cell, so past traffic cannot be decrypted even if current keys are exposed. Stronger authentication: SHA-1 is removed from relay encryption entirely, and CGO uses a 16-byte authenticator, which the Tor team comments is what “sensible people use.” Circuit integrity: CGO chains T’ (encrypted tag) and N (initial nonce) across cells, so each cell depends on all previous cells, ensuring tampering resistance. Overall, CGO is a modern, research-based encryption and authentication system that addresses many of Tor1’s problems without incurring large bandwidth penalties. The project maintainers say that adding CGO into the C Tor implementation and its Rust-based client, Arti, is underway, and the feature is marked as experimental. Pending work includes the addition of onion service negotiation and performance optimizations. Tor browser users do not need to do anything to benefit from CGO, as the change will happen automatically once the new system can be fully deployed. However, a timeline for when it will become the default option has not been provided. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 25, 2025extracted
Tor Project is rolling out Counter Galois Onion encryption
Tor Project is rolling out Counter Galois Onion encryption People who rely on Tor expect their traffic to move through the network without giving away who they are. That trust depends on the strength of the encryption that protects each hop. Tor developers are preparing a major upgrade called Counter Galois Onion, or CGO, which replaces the long-standing relay encryption method used across the network. Why Tor is changing how relays handle encryption The older tor1 relay encryption scheme has been in use for many years and shows its age. One long known problem is the risk of tagging attacks. In this scenario, an attacker who controls a relay can alter encrypted data in small ways. If the same attacker controls another relay later in the circuit, those changes might appear again and reveal a link between a user and their activity. Tor developers describe this as “the most important attack we are solving with CGO.” There are other weaknesses. Tor1 maintains the same symmetric key for the entire life of a circuit, which weakens forward secrecy. It also includes only a 4 byte authenticator on each relay cell, which limits tamper detection. What CGO brings to the network CGO introduces a new structure known as a rigid pseudorandom permutation, built from a component called UIV+. This reshapes how each cell is protected as it passes from relay to relay. The approach is designed to detect tampering more reliably and limit what an attacker can learn from any compromised keys. Several changes stand out: A 16 byte authenticator replaces the old 4 byte digest. Keys evolve as each cell is processed. Once a cell moves through a relay, the local key state changes, which makes it harder to study earlier traffic through later compromise. Tag chaining links the integrity of each cell to the next one. If a single cell is altered, later cells cannot be recovered. Together, these updates aim to raise the cost of active attacks along a circuit and strengthen the privacy protections that users depend on. How deployment is progressing CGO is still under active development in both Arti, Tor’s Rust based implementation, and the C Tor codebase. It is present in Arti, though marked as experimental. Developers plan to enable it by default once testing is complete. Work is also underway to support CGO for onion services. This addition is expected to appear first in Arti before it reaches other components. Because relays and clients need to share a common method, rollout will take time and depends on wide adoption across the network. The Tor Project notes that CGO is a new design and invites scrutiny. The developers write, “It is reasonable to ask whether there could be weaknesses in it,” while also describing the steps taken to evaluate the construction. CGO represents one of the most significant changes to Tor’s core cryptography in years. As development continues, users and operators should watch for upcoming releases and prepare for the transition once CGO is ready for general use.
helpnetsecurity.comNov 25, 2025extracted
Who's watching the watchers? This Mozilla fellow, and her Surveillance Watch map
INTERVIEW Digital rights activist Esra'a Al Shafei found FinFisher spyware on her device more than a decade ago. Now she's made it her mission to surveil the companies providing surveillanceware, their customers, and their funders. "You cannot resist what you do not know, and the more you know, the better you can protect yourself and resist against the normalization of mass surveillance today," she told The Register. To this end, the Mozilla fellow founded Surveillance Watch last year. It's an interactive map that documents the growing number of surveillance software providers, which regions use the various products, and the investors funding them. Since its launch, the project has grown from mapping connections between 220 spyware and surveillance entities to 695 today. These include the very well known spy tech like NSO Group's Pegasus and Cytrox's Predator, both famously used to monitor politicians, journalists and activists in the US, UK, and around the world. They also include companies with US and UK government contracts, like Palantir, which recently inked a $10 billion deal with the US Army and pledged a £1.5 billion ($2 billion) investment in the UK after winning a new Ministry of Defense contract. Then there's Paragon, an Israeli company with a $2 million Immigration and Customs Enforcement (ICE) contract for its Graphite spyware, which lets law enforcement hack smartphones to access content from encrypted messaging apps once the device is compromised. Even LexisNexis made the list. "People think of LexisNexis and academia," Al Shafei said. "They don't immediately draw the connection to their product called Accurint, which collects data from both public and non-public sources and offers them for sale, primarily to government agencies and law enforcement." Surveillance is a global trade. It's not just being used in Iran, China, North Korea Accurint compiles information from government databases, utility bills, phone records, license plate tracking, and other sources, and it also integrates analytics tools to create detailed location mapping and pattern recognition. "And they're also an ICE contractor, so that's another company that you wouldn't typically associate with surveillance, but they are one of the biggest surveillance agencies out there," Al Shafei said. It also tracks funders. Paragon's spyware is boosted by AE Industrial Partners, a Florida-based investment group specializing in "national security" portfolios. Other major backers of surveillance technologies include CIA-affiliated VC firm In-Q-Tel, Andreessen Horowitz (also known as a16z), and mega investment firm BlackRock. This illustrates another trend: It's not just authoritarian countries using and investing in these snooping tools. In fact, America now leads the world in surveillance investment, with the Atlantic Council think tank identifying 20 new US investors in the past year. "Surveillance is a global trade," Al Shafei said. "It's not just being used in Iran, China, North Korea. And a lot of the time you don't even have to be doing or saying anything: a hotel lobby uses smart cameras that detect unusual behavior, and if you pause too long in a hallway, your movements are flagged and logged, and sometimes automatically sent to police." "This could be happening in New York. You don't have to be in Beijing for something like this to happen," she added. "You exit the building, cameras with facial recognition and gait analysis identify you automatically. Sensors track your phone's location. If a crime happened nearby, they say, 'Well, maybe [you] did it.'" 'It completely changes how you interact online' Twelve years ago, Al Shafei received what looked like a Firefox browser update notification. In reality, it was a ploy to trick her into downloading FinFisher (aka FinSpy) on her computer - part of a larger campaign targeting her and her team of social justice advocates across Asia and North Africa. In addition to Surveillance Watch, she is also co-founder of feminist-tech-focused Numun Fund, is a founding director of social justice not-for-profit org Majal, and serves on the boards of the Wikimedia Foundation, the Tor Project, and Mastodon. Developed by Gamma Group, FinFisher has been used by governments and law enforcement agencies around the world to monitor and intercept communications, gather intelligence, and track individuals' activities. It provides a whole range of snooping capabilities, giving users remote access to victims' machines, keylogging to capture passwords and account info, audio and video recording, and real-time monitoring of targets' communications and online activities. In 2013, Mozilla accused Gamma of violating its Firefox trademark in a cease-and-desist demand. That experience fundamentally changed Al Shafei's views on data privacy - and her digital activity, which can be tricky for someone very much in the public eye. "My first feeling was guilt," she said, adding that she wasn't just worried about her own safety. "I worried about the fact that, by monitoring me, surveilling me, I had exposed everybody now in my network to this, so that guilt carries a lot of weight." It creates a troubling pattern of isolation, feelings of guilt, feelings of not being able to express myself, feelings of being targeted and controlled It also required her to alert everybody in her orbit that she had been surveilled, and that meant that the snoops may have collected personal details about her family, friends, coworkers - everyone in her network, too. "The second thing is: it completely changes how you interact online. Period. I don't have social media profiles anymore," Al Shafei said, with one exception: she has a Mastodon profile because she's a board member. "But I don't share anything very sensitive or controversial." While Al Shafei knows her biometric data is easily accessible because she travels frequently, she doesn't post any photos or videos of herself online, and doesn't use any applications that require biometric identification. "It changed how I use the web," Al Shafei continued. "It changed who I interact with on the web. It changed how much I'm willing to do on the web while protecting myself, because I don't want to put myself at any further risk. It changed how I express my views, how I access information, whether or not I would be comfortable accessing specific types of information if I felt like I could not do so safely." And all of this "creates a troubling pattern of isolation, feelings of guilt, feelings of not being able to express myself, feelings of being targeted and controlled." 'They know who you are' The Surveillance Watch homepage announces: "They know who you are. It's time to uncover who they are." It's creepy and accurate, and portrays all of the feelings that Al Shafei has around her spyware encounters. Her Majal team has "faced persistent targeting by sophisticated spyware technologies, firsthand, for a very long time, and this direct exposure to surveillance threats really led us to launch Surveillance Watch," she said. "We think it's very important for people to understand exactly how they're being surveilled, regardless of the why." The reality is, everybody - not just activists and politicians - is subject to surveillance, whether it's from smart-city technologies, Ring doorbell cameras, or connected cars. Users will always choose simplicity over security, and the same can be said for data privacy. "We want to show that when surveillance goes not just unnoticed, but when we start normalizing it in our everyday habits, we look at a new, shiny AI tool, and we say, 'Yes, of course, take access to all my data,'" Al Shafei said. "There's a convenience that comes with using all of these apps, tracking all these transactions, and people don't realize that this data can and does get weaponized against you, and not just against you, but also your loved ones." ®
go.theregister.comNov 8, 2025extracted