GoBalance Tor-format key-recovery actively exploited security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A GoBalance flaw is letting attackers recover the private key behind a site's .onion address, enabling takeover of affected dark-web sites. Searchlight Cyber said the bug sits in the signing step and can be abused from public descriptors alone, so attackers do not need server access. The issue has already been tied to takeovers of Dread and at least one other site, and a public proof-of-concept plus patch have been published. There is still no official fix, so exposed sites need to move to a new .onion address.
Related Happenings
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical Analysis
H score3
First: 03.08.2026 19:24
Last: 03.08.2026 19:24
Sources 1
About this happening:
Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
Chrome Google Password Manager passkey post-compromise techniques on Windows
Technical AnalysisAbout this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...
ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)
Vulnerability
H score43
First: 20.07.2026 12:29
Last: 20.07.2026 12:29
Sources 1
About this happening:
CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is...
ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)
VulnerabilityAbout this happening: CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is...
Timeline
-
09.10.2026 12:03 1 articles · 2h ago
Dread's main .onion key is exposed in a GoBalance update
Victim Impact UpdateDread's main onion private key was exposed after Paris said he had uploaded it into a GoBalance update, putting the forum's main .onion address at risk of takeover.
Show sources
- GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys — thehackernews.com — 09.10.2026 12:03
-
09.10.2026 12:03 1 articles · 2h ago
Dread migrates to a new .onion address after key exposure
Victim Impact UpdateOn October 7, Dread's operators said the forum had migrated permanently after onion private key exposure in third-party software, told users to change passwords on Dread and other potentially affected sites, and warned that the old address was unsafe.
Show sources
- GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys — thehackernews.com — 09.10.2026 12:03
-
09.10.2026 12:03 2 articles · 2h ago
Searchlight Cyber discloses the GoBalance key-recovery flaw
Initial DisclosureSearchlight Cyber disclosed on October 8 that GoBalance can let an attacker recover a site's secret key from public information and take over its .onion address, and Omega said it took its old address offline and moved to a new one because of the GoBalance bug.
Show sources
- GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys — thehackernews.com — 09.10.2026 12:03
- GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys — thehackernews.com — 09.10.2026 12:03