Tor Browser is a technology platform tracked across 15 threat clusters and 18 intelligence report mentions on ThreatCluster. First observed November 25, 2025; most recent activity July 22, 2026.
Tor Browser is a privacy-focused technology platform that enables anonymous communication by routing user traffic through the Tor network's distributed onion relays. It uses layered onion encryption and a rotating set of cryptographic primitives, with updates designed to strengthen anonymity and resilience. The latest report notes Tor's adoption of a new Counter Galois Onion relay encryption algorithm, marking a modernization of its onion-relay cryptography.
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
On April 15, 2026, Tails released version 7.6.2 as an emergency update to address a significant security vulnerability in the Tor Browser's confinement. This vulnerability could potentially be exploited by an attacker…
An emergency update for Tails, the Linux distribution for anonymous browsing, has been released to fix a critical vulnerability in the Linux kernel known as DirtyFrag (CVE-2026-43284). This vulnerability could allow…
The JanaWare ransomware campaign has emerged, targeting users in Turkey through a customized variant of the Adwind RAT. The malware is distributed via phishing emails containing malicious JAR files, which, when…
Tata Electronics confirmed a cybersecurity incident after the ransomware group World Leaks posted over 200,000 files on the dark web, totaling more than 630GB. The leaked data allegedly includes sensitive component…
The US government has announced measures to combat Chinese 'distillation attacks' aimed at stealing proprietary AI capabilities from American companies. Distillation attacks involve training less capable models using…
A newly discovered vulnerability, CVE-2026-6770, allows attackers to fingerprint users of Firefox and Tor browsers, even in Private Browsing mode. The flaw, identified in the IndexedDB API, enables the creation of a…
The Nexus Darkweb platform has evolved its security measures to combat phishing and clone site attacks. Users must navigate the Tor network safely and authenticate .onion addresses using PGP signatures. The platform has…