chiprook
← Security
SecurityOctober 9, 2026, 16:03

GoBalance Flaw Lets Attackers Hijack .onion Addresses via Public Data

Searchlight Cyber disclosed on October 8 a flaw in GoBalance, a tool dark-web sites use to stay reachable during attacks. The bug lets anyone recover the secret key behind a site's .onion address from public information and redirect visitors to an attacker-controlled copy.

GoBalance Flaw Lets Attackers Hijack .onion Addresses via Public Data
#GoBalance#Tor#SearchlightCyber
Read next
Security

Leaked GitLab issue email address lets anyone push code and run CI jobs as you

Security

CVE-2026-92941: vm2 sandbox escape lets code hijack Node.js TLS trust store

Security

CVE-2026-92940: vm2 flaw lets sandboxed code steal tokens and hijack sockets

Security

Undocumented Meta Muse Setting Let Attackers Hijack AI Assistant