BTC$84,624+0.05% LTC$70.53+2.62% XMR$540.87-0.41%
TorPortal TorPortalMarkets, mirrors, dark web news

Tor and dark web news

Stories from trusted sources, picked for people who actually use Tor.

Latest dark web stories

Hugging Face warns an autonomous AI agent hacked its network
BleepingComputer · Jul 20, 2026 · 1 min read

Hugging Face warns an autonomous AI agent hacked its network

The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
The Record · Jul 20, 2026 · 2 min read

Software provider to more than 2,000 US hospitals says hackers stole employee and customer data

Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.
Microsoft confirms Windows Server Update Services sync delays
BleepingComputer · Jul 20, 2026 · 1 min read

Microsoft confirms Windows Server Update Services sync delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
BleepingComputer · Jul 20, 2026 · 1 min read

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates.
Critical ServiceNow code execution flaw now exploited in attacks
BleepingComputer · Jul 20, 2026 · 1 min read

Critical ServiceNow code execution flaw now exploited in attacks

Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Hackers abuse ViPNet software to target Russian govt agencies
BleepingComputer · Jul 19, 2026 · 1 min read

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
BleepingComputer · Jul 18, 2026 · 1 min read

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
BleepingComputer · Jul 18, 2026 · 1 min read

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
Microsoft warns of surge in ACR Stealer attacks on customers
BleepingComputer · Jul 18, 2026 · 1 min read

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
The Future of Age Verification: Your Face Never Leaves Your Device
BleepingComputer · Jul 18, 2026 · 1 min read

The Future of Age Verification: Your Face Never Leaves Your Device

As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing…
Two Jailed Over Record-Breaking TfL Cyberattack
DarkDotWeb · Jul 18, 2026 · 2 min read

Two Jailed Over Record-Breaking TfL Cyberattack

Thalha Jubair and Owen Flowers were jailed after the 2024 TfL cyberattack caused £29 million in losses.
GoldenEyeDog Linked to DigiCert Certificate Theft
DarkDotWeb · Jul 18, 2026 · 2 min read

GoldenEyeDog Linked to DigiCert Certificate Theft

Researchers link a GoldenEyeDog subgroup to DigiCert's April 2026 breach involving stolen code-signing certificates.
Abbott probes two cyber incidents amid extortion claims
BleepingComputer · Jul 17, 2026 · 1 min read

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that…
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
BleepingComputer · Jul 17, 2026 · 1 min read

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
Ernst & Young discloses data breach after support system hack
BleepingComputer · Jul 17, 2026 · 1 min read

Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.