BTC$84,644-0.31% LTC$70.01+1.79% XMR$542.22-0.81%
TorPortal TorPortalMarkets, mirrors, dark web news

Tor and dark web news

Stories from trusted sources, picked for people who actually use Tor.

Latest dark web stories

International alert spotlights Russia-linked attacks on Zimbra webmail
The Record · Jul 23, 2026 · 2 min read

International alert spotlights Russia-linked attacks on Zimbra webmail

A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer · Jul 23, 2026 · 1 min read

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a…
Hackers abuse Notepad++ plugins to stealthily install malware
BleepingComputer · Jul 23, 2026 · 1 min read

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
State Department imposes visa restrictions on foreign cyber scammers
The Record · Jul 23, 2026 · 2 min read

State Department imposes visa restrictions on foreign cyber scammers

Individuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.
Microsoft 365 outage affects Teams, SharePoint and other services
BleepingComputer · Jul 23, 2026 · 1 min read

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America.
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
BleepingComputer · Jul 23, 2026 · 1 min read

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can…
Major Australian energy supplier confirms customer data compromised
The Record · Jul 23, 2026 · 1 min read

Major Australian energy supplier confirms customer data compromised

Origin Energy said it was working to figure out how many Australians were affected by a recent data breach.
EU fines Google $1 billion for search, app store antitrust violations
BleepingComputer · Jul 23, 2026 · 1 min read

EU fines Google $1 billion for search, app store antitrust violations

The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition.
New RefluXFS Linux flaw lets attackers gain root privileges
BleepingComputer · Jul 23, 2026 · 1 min read

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
BleepingComputer · Jul 23, 2026 · 1 min read

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
Microsoft working to fix Exchange Online mailbox quarantine issue
BleepingComputer · Jul 23, 2026 · 1 min read

Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday.
Check Point warns of SmartConsole zero-day exploited in attacks
BleepingComputer · Jul 23, 2026 · 1 min read

Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
The Record · Jul 22, 2026 · 2 min read

Swiss train maker Stadler refuses Everest $12 million ransomware demand

Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier's file-sharing platform.
Upbound says hack caused $13 million in fraudulent Acima leases
BleepingComputer · Jul 22, 2026 · 1 min read

Upbound says hack caused $13 million in fraudulent Acima leases

The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases.
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
The Record · Jul 22, 2026 · 2 min read

Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill

A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House's fiscal 2027 defense authorization bill.