BTC$84,600-0.15% LTC$71.18+3.56% XMR$539.99-1.09%
TorPortal TorPortalMarkets, mirrors, dark web news

Tor and dark web news

Stories from trusted sources, picked for people who actually use Tor.

Latest dark web stories

California Man Sentenced After Distributing CSAM on Dark Web
DarkDotWeb · Sep 14, 2026 · 2 min read

California Man Sentenced After Distributing CSAM on Dark Web

James David Johnson was sentenced to 151 months for distributing child sexual abuse material through multiple dark web communities.
Malicious Twitch Extension Exposes 31,000 OAuth Tokens
DarkDotWeb · Sep 14, 2026 · 3 min read

Malicious Twitch Extension Exposes 31,000 OAuth Tokens

A Twitch browser extension sent OAuth tokens from nearly 31,000 users to proxy servers operated by the JeetBot service.
Revolut discloses data breach exposing financial info, passports
BleepingComputer · Sep 14, 2026 · 1 min read

Revolut discloses data breach exposing financial info, passports

Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.
Microsoft: September updates break audio on some Windows PCs
BleepingComputer · Sep 14, 2026 · 1 min read

Microsoft: September updates break audio on some Windows PCs

Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates.
CISA: Hackers now exploit max severity GitLab flaw in attacks
BleepingComputer · Sep 14, 2026 · 2 min read

CISA: Hackers now exploit max severity GitLab flaw in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI
The Record · Sep 13, 2026 · 3 min read

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

The largest electronic spy agency in the world is reorganizing. And fast.
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
BleepingComputer · Sep 13, 2026 · 2 min read

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BleepingComputer · Sep 12, 2026 · 2 min read

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Hackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer · Sep 11, 2026 · 4 min read

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
The Record · Sep 11, 2026 · 2 min read

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
Florida confirms DMV database breached via stolen police account
BleepingComputer · Sep 11, 2026 · 1 min read

Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee.
Microsoft sees some new wrinkles in invoice-scam emails
The Record · Sep 11, 2026 · 2 min read

Microsoft sees some new wrinkles in invoice-scam emails

Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
Passkey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer · Sep 11, 2026 · 1 min read

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365…
Artifactory flaws chained in attacks deploying backdoor malware
BleepingComputer · Sep 11, 2026 · 2 min read

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer · Sep 11, 2026 · 1 min read

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI…