Find notable cyber news and cases, enriched with sources, timelines, and signals.

GoBalance Tor-format key-recovery actively exploited security flaw

Vulnerability
First reported
Last updated
Happening score
H score 18
1 unique sources, 1 articles

Summary

Hide ▲

A GoBalance flaw is letting attackers recover the private key behind a site's .onion address, enabling takeover of affected dark-web sites. Searchlight Cyber said the bug sits in the signing step and can be abused from public descriptors alone, so attackers do not need server access. The issue has already been tied to takeovers of Dread and at least one other site, and a public proof-of-concept plus patch have been published. There is still no official fix, so exposed sites need to move to a new .onion address.

Related Happenings

Chrome Google Password Manager passkey post-compromise techniques on Windows

Technical Analysis
H score3 First: 03.08.2026 19:24 Last: 03.08.2026 19:24 Sources 1

About this happening: Unit 42 expanded the Chrome Google Password Manager passkey happening with Pass-ta-key research that shows how malware already on a Windows endpoint can manipulate...

ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)

Vulnerability
H score43 First: 20.07.2026 12:29 Last: 20.07.2026 12:29 Sources 1

About this happening: CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is...

Timeline

  1. 09.10.2026 12:03 1 articles · 2h ago

    Dread migrates to a new .onion address after key exposure

    Victim Impact Update

    On October 7, Dread's operators said the forum had migrated permanently after onion private key exposure in third-party software, told users to change passwords on Dread and other potentially affected sites, and warned that the old address was unsafe.

    Show sources
  2. 09.10.2026 12:03 2 articles · 2h ago

    Searchlight Cyber discloses the GoBalance key-recovery flaw

    Initial Disclosure

    Searchlight Cyber disclosed on October 8 that GoBalance can let an attacker recover a site's secret key from public information and take over its .onion address, and Omega said it took its old address offline and moved to a new one because of the GoBalance bug.

    Show sources