<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0"><channel><title>Cyber Kendra</title><description>Tech Hub</description><managingEditor>noreply@blogger.com (Root)</managingEditor><pubDate>Tue, 18 Aug 2026 08:51:20 +0530</pubDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">3605</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/">25</openSearch:itemsPerPage><link>https://www.cyberkendra.com/</link><language>en-us</language><itunes:explicit>no</itunes:explicit><copyright>All the content is copyright of cyberkendra.com</copyright><itunes:image href="http://2.bp.blogspot.com/-svYWW7Cp8JI/UDUgofD9kUI/AAAAAAAAAEY/ina7VZi4ZRg/s1600/webprotal.png"/><itunes:keywords>Computer,technology,tech,IT,security,Gadgets,Telecom</itunes:keywords><itunes:summary>All about Computer and technology. </itunes:summary><itunes:subtitle>Cyber kendra</itunes:subtitle><itunes:category text="Technology"><itunes:category text="Tech News"/></itunes:category><itunes:author>Vivek Gurung</itunes:author><itunes:owner><itunes:email>protalweb@gmail.com</itunes:email><itunes:name>Vivek Gurung</itunes:name></itunes:owner><item><title>Apple Patches 122 Flaws including macOS Screen Sharing Flaw (CVE-2026-65400)</title><link>https://www.cyberkendra.com/2026/08/apple-patches-122-flaws-including-macos.html</link><category>Apple</category><category>iOS</category><category>Security</category><pubDate>Tue, 18 Aug 2026 08:24:26 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3667440587235484952</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="iOS Software Update" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTs1QCUfpIIeQbHBvcusqZ-T306c-yeXVPauFunhoOYEPi4Bn8R8pLOxuEBo_VQIVikchXs3Gy0XEHU9lRZQwLvXz6Kc-YlV-00FWEsBrPYUReOSqkQMglpeuFQZXxXtzNUmkmymaWJGPJ256cFfvmSNqTepcfExmUDNTAc3orjBqecmIddbyLGRMrwsc/s1600/apple-software-update.webp" title="iOS Software Update" /&gt;&lt;/div&gt;&lt;p&gt;Apple shipped four security updates on August 17, 2026, fixing 122 vulnerabilities in iOS 18.7.10 and iPadOS 18.7.10, 29 in iOS 26.6.1 and iPadOS 26.6.1, and 28 in macOS Tahoe 26.6.2. None of the flaws in this batch are known to have been exploited — but a separate macOS bug Apple patched eleven days earlier is being used right now to plant cryptominers on internet-facing Macs.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The standout new issue is CVE-2026-65329, a Telephony flaw that only affects iPhone 11 and later. Apple describes it as an authentication issue that lets an attacker in a privileged network position bypass IPSec authentication and intercept network traffic, and credits Bedran Karakoc, Tobias Funke, Jacopo Clark and Katharina Kohls of Ruhr University Bochum. It is the single vulnerability that separates iOS 26.6.1 from macOS Tahoe 26.6.2 — the other 28 fixes are identical across both.&lt;/p&gt;

&lt;h2&gt;What Apple Released on August 17, 2026&lt;/h2&gt;

&lt;p&gt;Apple published three security advisories and shipped a fourth update with no advisory attached. As of August 18, 2026, visionOS 26.6.1 is listed on Apple's security releases page with the note that details are coming soon.&lt;/p&gt;
&lt;div class='table noWrap w100'&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Update&lt;/th&gt;&lt;th&gt;Devices covered&lt;/th&gt;&lt;th&gt;CVEs fixed&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;iOS 26.6.1 and iPadOS 26.6.1&lt;/td&gt;&lt;td&gt;iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later&lt;/td&gt;&lt;td&gt;29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;iOS 18.7.10 and iPadOS 18.7.10&lt;/td&gt;&lt;td&gt;iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation&lt;/td&gt;&lt;td&gt;122&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;macOS Tahoe 26.6.2&lt;/td&gt;&lt;td&gt;macOS Tahoe&lt;/td&gt;&lt;td&gt;28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;visionOS 26.6.1&lt;/td&gt;&lt;td&gt;Apple Vision Pro&lt;/td&gt;&lt;td&gt;Not yet published&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
  &lt;/table&gt;&lt;/div&gt;

&lt;p&gt;There is no watchOS, tvOS, Safari or Xcode update in this round. macOS Sequoia and macOS Sonoma also sat this one out — those branches last received fixes on August 6, 2026, in macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.&lt;/p&gt;

&lt;h2&gt;Are Any of These Vulnerabilities Being Exploited?&lt;/h2&gt;

&lt;p&gt;No. Apple's advisories for iOS 26.6.1, iOS 18.7.10 and macOS Tahoe 26.6.2 contain none of the language Apple normally uses when a flaw has been attacked in the wild, and no CVE in the August 17 batch carries an exploitation note. There are no zero-days here.&lt;/p&gt;

&lt;p&gt;That is not the same as saying Apple users are safe this week. A macOS flaw Apple patched on August 6, 2026 — CVE-2026-65400 in Screen Sharing — is under active exploitation, and it is the bug Mac administrators should be chasing today.&lt;/p&gt;

&lt;h2&gt;CVE-2026-65400: The Screen Sharing Flaw That Is Actually Being Attacked&lt;/h2&gt;

&lt;p&gt;CVE-2026-65400 is an authentication bypass in &lt;code&gt;screensharingd&lt;/code&gt;, the daemon behind macOS Screen Sharing, which exposes remote desktop access over the VNC protocol on TCP port 5900. Apple fixed it on August 6, 2026, in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, crediting Alfredo Pesoli (@__rev) via Bynario Atlas.&lt;/p&gt;

&lt;p&gt;The Netherlands' National Cyber Security Centre (NCSC-NL) updated its advisory NCSC-2026-0280 on August 12, 2026, to report active exploitation. According to NCSC-NL, attackers hit multiple systems with port 5900 reachable from the internet, and in every confirmed case, "root had been accessed on the affected system" before a Monero cryptocurrency miner was installed.&lt;/p&gt;

&lt;p&gt;Because the bypass happens before authentication, the hardening steps most Mac administrators would reach for do not help. Removing approved Screen Sharing users, disabling legacy VNC password access and rotating the VNC password all sit downstream of the check the flaw defeats. Security firm Calif, which analysed the bug, noted that the attack needs only a valid account name, and that "a username is not a secret" on macOS.&lt;/p&gt;

&lt;h3&gt;How the assessment of CVE-2026-65400 changed over 12 days&lt;/h3&gt;

&lt;p&gt;The public record on this vulnerability moved faster than most tracking systems did, and the sources still disagree. Cyber Kendra assembled the following timeline from Apple's advisory, the NVD change log and NCSC-NL's advisory.&lt;/p&gt;
&lt;div class='table noWrap w100'&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Date&lt;/th&gt;&lt;th&gt;Source&lt;/th&gt;&lt;th&gt;Assessment&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;6 Aug 2026&lt;/td&gt;&lt;td&gt;Apple advisory HT148170&lt;/td&gt;&lt;td&gt;Patch shipped, no exploitation noted&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;7 Aug 2026&lt;/td&gt;&lt;td&gt;NVD (CISA-ADP)&lt;/td&gt;&lt;td&gt;CVSS 3.1 scored 7.1 High, CWE-287, impact partial&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;7 Aug 2026&lt;/td&gt;&lt;td&gt;NCSC-NL advisory NCSC-2026-0280&lt;/td&gt;&lt;td&gt;Advisory published, no exploitation reported&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;12 Aug 2026&lt;/td&gt;&lt;td&gt;NCSC-NL advisory update&lt;/td&gt;&lt;td&gt;Active exploitation observed, root access and Monero miner&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;14 Aug 2026&lt;/td&gt;&lt;td&gt;NVD (CISA-ADP)&lt;/td&gt;&lt;td&gt;CVSS 3.1 raised to 9.8 Critical, attack rated automatable&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;15 Aug 2026&lt;/td&gt;&lt;td&gt;CISA SSVC record&lt;/td&gt;&lt;td&gt;The exploitation decision point is still recorded as "none"&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;18 Aug 2026&lt;/td&gt;&lt;td&gt;&lt;a href="https://tools.cyberkendra.com/tracker/cisa-kev/" target="_blank"&gt;CISA KEV catalog&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not listed at time of writing&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
  &lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The gap matters operationally. A team that filters patch priority on CISA KEV membership alone would not have flagged CVE-2026-65400 as of August 18, 2026, even though a European national CERT has documented root compromise in the wild and the CVSS vector was rewritten to reflect no privileges required and full compromise of confidentiality, integrity and availability.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Cyber Kendra has not independently verified the exploitation reports and is relying on NCSC-NL's published advisory.&lt;/p&gt;

&lt;p&gt;If you cannot patch immediately, disable &lt;a href="https://www.cyberkendra.com/2026/08/macos-screen-sharing-bug-handed-hackers.html" target="_blank"&gt;Screen Sharing in System&lt;/a&gt; Settings under General, then Sharing, and block TCP port 5900 at the network edge. CVE-2026-65400 is also distinct from CVE-2026-43760, a separate Screen Sharing issue that requires the attacker to already know a configured VNC password.&lt;/p&gt;

&lt;h2&gt;What iOS 26.6.1 and macOS Tahoe 26.6.2 Actually Fix&lt;/h2&gt;

&lt;p&gt;iOS 26.6.1 and macOS Tahoe 26.6.2 patch the same 28 vulnerabilities, with the iPhone-only Telephony flaw making up iOS's 29th. Both updates are unusually browser-heavy: 21 of the 29 CVEs in iOS 26.6.1 sit in WebKit, WebKit History or WebKit Storage.&lt;/p&gt;

&lt;p&gt;The fixes worth knowing about outside WebKit:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-65346 (ImageIO)&lt;/strong&gt; — an integer overflow where processing an image may lead to arbitrary code execution. Credited to Meta Red Team X's Nik Tsytsarkin.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-65339 (Audio)&lt;/strong&gt; — a logic issue that could let an app leak sensitive user information. Also credited to Meta Red Team X.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-65343 (Kernel)&lt;/strong&gt; — a use-after-free that a remote attacker could use to cause unexpected system termination.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-65330 and CVE-2026-65349 (Kernel)&lt;/strong&gt; — memory corruption and out-of-bounds read issues reachable from an app.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-64788 (IOGPUFamily)&lt;/strong&gt; — memory corruption triggered by maliciously crafted web content, which pairs a browser entry point with a graphics driver bug.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2026-65347 (ImageIO)&lt;/strong&gt; — a denial-of-service when processing an image.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Apple does not publish CVSS scores in its advisories, so severity ratings for these CVEs will only appear once NVD analysts enrich them.&lt;/p&gt;

&lt;h2&gt;Why iOS 18.7.10 Fixes 122 Bugs When iOS 26.6.1 Fixes Only 29&lt;/h2&gt;

&lt;p&gt;The 122 figure is the headline number this round, and it is widely misread. iOS 18.7.10 is not a bigger or more urgent update than iOS 26.6.1 — it is a backport that closes a two-release backlog for legacy hardware in one go.&lt;/p&gt;

&lt;p&gt;Apple states in the advisory that iOS 18.7.10 delivers fixes first made available in the iOS 26.6 and 27 betas. iOS 26.6 shipped to modern devices on July 27, 2026, and iOS 26.6.1 shipped on August 17. Devices still on the iOS 18 branch missed both, so Apple rolled roughly six weeks of accumulated fixes into a single release.&lt;/p&gt;

&lt;p&gt;iOS 18.7.10 also covers a much smaller device set than earlier iOS 18.7.x releases did: only iPhone XS, iPhone XS Max, iPhone XR and the 7th-generation iPad. As recently as iOS 18.7.8 in April 2026, that branch still served iPhones through the iPhone 16 range.&lt;/p&gt;

&lt;p&gt;Here is where the 122 CVEs land by component:&lt;/p&gt;
&lt;div class='table noWrap w100'&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Component&lt;/th&gt;&lt;th&gt;CVEs in iOS 18.7.10&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;WebKit (including Canvas, History, Process Model, Storage)&lt;/td&gt;&lt;td&gt;42&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Kernel&lt;/td&gt;&lt;td&gt;18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Model I/O&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;ImageIO&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;SceneKit&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;WebRTC&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;CoreAudio&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Contacts&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;All other components&lt;/td&gt;&lt;td&gt;35&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
  &lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Forty-five of the 122 CVEs — WebKit plus WebRTC — are browser-engine bugs. That is the reachable-from-a-web-page attack surface, and it is why an old iPhone left unpatched is a meaningfully worse place to browse the web than a current one.&lt;/p&gt;

&lt;h2&gt;AI Tooling Now Accounts for a Third of Apple's WebKit Credits&lt;/h2&gt;

&lt;p&gt;The most durable story in this release is not a single CVE. It is who found the bugs. Nine of the 29 CVEs in iOS 26.6.1 are credited to OpenAI Codex Security, all to researcher Amy Burnett, and the same nine appear in macOS Tahoe 26.6.2.&lt;/p&gt;

&lt;p&gt;Widen the view to iOS 18.7.10, which carries the full two-release backlog, and the pattern becomes clearer. Cyber Kendra counted the AI-lab and AI-tooling credits across all 122 entries:&lt;/p&gt;
&lt;div class='table noWrap w100'&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Credited to&lt;/th&gt;&lt;th&gt;CVEs in iOS 18.7.10&lt;/th&gt;&lt;th&gt;Example&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;OpenAI Codex Security — Amy Burnett&lt;/td&gt;&lt;td&gt;10&lt;/td&gt;&lt;td&gt;CVE-2026-65331&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Milad Nasr and Nicholas Carlini with Claude, Anthropic&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;CVE-2026-64757&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Trail of Bits via Anthropic CVD&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;CVE-2026-28984&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Z.AI GLM&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;CVE-2026-43663&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;NVIDIA AI Red Team — Aaron Grattafiori&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;CVE-2026-43701&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
  &lt;/table&gt;&lt;/div&gt;

&lt;p&gt;That is 14 CVEs, all of them in the WebKit family, out of 45 browser-engine bugs in the release — roughly 31 percent. Some of those credits are shared with human researchers, so the correct reading is that AI-assisted review contributed to about a third of Apple's browser-engine findings this cycle, not that it found them alone.&lt;/p&gt;

&lt;p&gt;We would treat this as the leading indicator to watch across Apple's next few releases. WebKit is a large, fuzzable, memory-unsafe C++ codebase with a clear crash oracle, which makes it close to a best case for automated bug discovery. If the share holds or grows in iOS 27, the volume of WebKit CVEs per release is likely to keep climbing — and a rising CVE count will say more about detection capacity than about code quality getting worse.&lt;/p&gt;

&lt;h2&gt;Apple Confirms macOS 27 Is Called Golden Gate&lt;/h2&gt;

&lt;p&gt;Apple's own advisory text for macOS Tahoe 26.6.2 says the update delivers &lt;a href="https://support.apple.com/en-us/148281" rel="noopener" target="_blank"&gt;"security fixes that were first made available in the macOS Golden Gate 27 beta"&lt;/a&gt;. The iOS 26.6.1 advisory makes the matching reference to the iOS 27 and iPadOS 27 betas.&lt;/p&gt;

&lt;p&gt;That is Apple naming its next macOS release in a support document rather than at an event. Following Sequoia, Sonoma and Tahoe, Golden Gate continues Apple's California landmark naming convention. Apple has not published a release date for macOS 27 or iOS 27.&lt;/p&gt;

&lt;h2&gt;Which Update Should You Install?&lt;/h2&gt;

&lt;p&gt;Your device will only offer the one build that applies to it. There is no choice to make and no reason to delay.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;iPhone 11 or newer&lt;/strong&gt; — install iOS 26.6.1.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;iPhone XS, XS Max or XR&lt;/strong&gt; — install iOS 18.7.10. These devices cannot run iOS 26.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;iPad 7th generation&lt;/strong&gt; — install iPadOS 18.7.10. All newer iPads get iPadOS 26.6.1.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mac on macOS Tahoe&lt;/strong&gt; — install macOS Tahoe 26.6.2.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mac on macOS Sequoia or Sonoma&lt;/strong&gt; — you are on 15.7.9 or 14.8.9 from August 6. Confirm you took that update, because it carries the CVE-2026-65400 Screen Sharing fix.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apple Vision Pro&lt;/strong&gt; — install visionOS 26.6.1.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;How to install&lt;/h3&gt;

&lt;ol&gt;
&lt;li&gt;On iPhone or iPad, open Settings, tap General, then Software Update.&lt;/li&gt;
&lt;li&gt;On Mac, open System Settings, click General, then Software Update.&lt;/li&gt;
&lt;li&gt;On Apple Vision Pro, open Settings, tap General, then Software Update.&lt;/li&gt;
&lt;li&gt;Turn on Automatic Updates on the same screen so future security fixes install without you checking.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Note that iOS, iPadOS, tvOS, watchOS and visionOS cannot be downgraded once a software update is installed.&lt;/p&gt;

&lt;h2&gt;Frequently Asked Questions&lt;/h2&gt;

&lt;h3&gt;Is there a zero-day in the August 17, 2026 Apple updates?&lt;/h3&gt;

&lt;p&gt;No. Apple's advisories for iOS 26.6.1, iOS 18.7.10 and macOS Tahoe 26.6.2 do not mark any CVE as exploited in the wild, and none of the 122, 29 or 28 fixes carries an exploitation note.&lt;/p&gt;

&lt;h3&gt;What is CVE-2026-65400 and am I affected?&lt;/h3&gt;

&lt;p&gt;CVE-2026-65400 is an authentication bypass in macOS Screen Sharing that lets a network attacker connect without valid credentials. You are affected if you run macOS Sonoma before 14.8.9, macOS Sequoia before 15.7.9 or macOS Tahoe before 26.6.1 with Screen Sharing enabled. NCSC-NL reported active exploitation against Macs exposing TCP port 5900 to the internet.&lt;/p&gt;

&lt;h3&gt;Why does iOS 18.7.10 fix 122 vulnerabilities?&lt;/h3&gt;

&lt;p&gt;iOS 18.7.10 backports fixes that Apple first shipped in the iOS 26.6 and 27 betas. Devices on the iOS 18 branch missed both the July 27 and August 17 releases, so Apple bundled roughly six weeks of accumulated fixes into one update.&lt;/p&gt;

&lt;h3&gt;Do I need to update if I never use Screen Sharing?&lt;/h3&gt;

&lt;p&gt;Yes. Screen Sharing is only one of the issues fixed this month, and the August 17 updates patch kernel, ImageIO, Audio and WebKit flaws that are reachable without it. Disabling Screen Sharing is a stopgap for unpatched Macs, not a substitute for updating.&lt;/p&gt;

&lt;h3&gt;Which Apple devices are no longer getting security updates?&lt;/h3&gt;

&lt;p&gt;Apple still ships fixes to the iOS 18, iOS 16 and iOS 15 branches for older hardware, though coverage narrows with each release. iOS 18.7.10 now covers only iPhone XS, iPhone XS Max, iPhone XR and the 7th-generation iPad.&lt;/p&gt;

&lt;h3&gt;What does visionOS 26.6.1 fix?&lt;/h3&gt;

&lt;p&gt;Apple has not published the security content for visionOS 26.6.1. As of August 18, 2026 the release is listed on Apple's security releases page with details marked as coming soon.&lt;/p&gt;

&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is there a zero-day in the August 17, 2026 Apple updates?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Apple's advisories for iOS 26.6.1, iOS 18.7.10 and macOS Tahoe 26.6.2 do not mark any CVE as exploited in the wild, and none of the 122, 29 or 28 fixes carries an exploitation note."
          }
        },
        {
          "@type": "Question",
          "name": "What is CVE-2026-65400 and am I affected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "CVE-2026-65400 is an authentication bypass in macOS Screen Sharing that lets a network attacker connect without valid credentials. You are affected if you run macOS Sonoma before 14.8.9, macOS Sequoia before 15.7.9 or macOS Tahoe before 26.6.1 with Screen Sharing enabled. NCSC-NL reported active exploitation against Macs exposing TCP port 5900 to the internet."
          }
        },
        {
          "@type": "Question",
          "name": "Why does iOS 18.7.10 fix 122 vulnerabilities?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "iOS 18.7.10 backports fixes that Apple first shipped in the iOS 26.6 and 27 betas. Devices on the iOS 18 branch missed both the July 27 and August 17 releases, so Apple bundled roughly six weeks of accumulated fixes into one update."
          }
        },
        {
          "@type": "Question",
          "name": "Do I need to update if I never use Screen Sharing?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Screen Sharing is only one of the issues fixed this month, and the August 17 updates patch kernel, ImageIO, Audio and WebKit flaws that are reachable without it. Disabling Screen Sharing is a stopgap for unpatched Macs, not a substitute for updating."
          }
        },
        {
          "@type": "Question",
          "name": "Which Apple devices are no longer getting security updates?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Apple still ships fixes to the iOS 18, iOS 16 and iOS 15 branches for older hardware, though coverage narrows with each release. iOS 18.7.10 now covers only iPhone XS, iPhone XS Max, iPhone XR and the 7th-generation iPad."
          }
        },
        {
          "@type": "Question",
          "name": "What does visionOS 26.6.1 fix?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Apple has not published the security content for visionOS 26.6.1. As of August 18, 2026 the release is listed on Apple's security releases page with details marked as coming soon."
          }
        }
      ]
    },
    {
      "@type": "ItemList",
      "name": "Apple security updates released August 17, 2026",
      "itemListOrder": "https://schema.org/ItemListUnordered",
      "numberOfItems": 4,
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "iOS 26.6.1 and iPadOS 26.6.1",
          "url": "https://support.apple.com/en-us/148282"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "iOS 18.7.10 and iPadOS 18.7.10",
          "url": "https://support.apple.com/en-us/148287"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "macOS Tahoe 26.6.2",
          "url": "https://support.apple.com/en-us/148281"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "visionOS 26.6.1",
          "url": "https://support.apple.com/en-us/100100"
        }
      ]
    },
    {
      "@type": "SoftwareApplication",
      "name": "iOS",
      "operatingSystem": "iOS",
      "applicationCategory": "OperatingSystem",
      "softwareVersion": "26.6.1",
      "datePublished": "2026-08-17",
      "publisher": {
        "@type": "Organization",
        "name": "Apple Inc."
      },
      "offers": {
        "@type": "Offer",
        "price": "0",
        "priceCurrency": "USD"
      }
    },
    {
      "@type": "SoftwareApplication",
      "name": "macOS Tahoe",
      "operatingSystem": "macOS",
      "applicationCategory": "OperatingSystem",
      "softwareVersion": "26.6.2",
      "datePublished": "2026-08-17",
      "publisher": {
        "@type": "Organization",
        "name": "Apple Inc."
      },
      "offers": {
        "@type": "Offer",
        "price": "0",
        "priceCurrency": "USD"
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTs1QCUfpIIeQbHBvcusqZ-T306c-yeXVPauFunhoOYEPi4Bn8R8pLOxuEBo_VQIVikchXs3Gy0XEHU9lRZQwLvXz6Kc-YlV-00FWEsBrPYUReOSqkQMglpeuFQZXxXtzNUmkmymaWJGPJ256cFfvmSNqTepcfExmUDNTAc3orjBqecmIddbyLGRMrwsc/s72-c/apple-software-update.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Amazon Scans and Destroys Rare Books for AI Training - Report</title><link>https://www.cyberkendra.com/2026/08/amazon-scans-and-destroys-rare-books.html</link><category>AI</category><category>Amazon</category><category>Tech</category><pubDate>Tue, 18 Aug 2026 08:49:06 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4510715214786972921</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="AI company buying and destroying rare books for training data" border="0" data-original-height="467" data-original-width="700" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsh44nY0kUI3IJZjueAVb15IhqrnABPYL38wNspmlOz_yq6n-ap9RYYG5xrBOgP8Jvo8Rgo4D-7TnvXi5toOX2koYO3SvTGKsDZqmQDlCQxy3ix9KnKW00grGE2Eo5NuQVrseoc0YYd-z3f-k79ld_J-Lcd6ftCq5P-79BUCgGl_vM2Uptbdv7Dqe-iq0/s1600/AI_destroying-books.webp" title="AI company buying and destroying rare books for training data" /&gt;&lt;/div&gt;&lt;p&gt;Amazon is buying printed books in bulk, cutting the bindings off, scanning the pages for AI training data and discarding the paper, according to a &lt;a href="https://www.404media.co/we-tracked-a-shipment-of-rare-books-it-ended-at-an-amazon-ai-training-facility/" rel="nofollow" target="_blank"&gt;404 Media investigation&lt;/a&gt; published on 17 August 2026. Reporter Emanuel Maiberg confirmed the operation by hiding an Apple AirTag inside one book in a 1,000-title order and tracking it across the United States.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The tracker's final stop was LAS8, an Amazon warehouse in north-east Las Vegas, Nevada. The book-scanning unit inside LAS8 is called VGT3, and the logo at its entrance is a Tyrannosaurus rex holding an open book.&lt;/p&gt;

&lt;h2&gt;What the AirTag Investigation Found&lt;/h2&gt;

&lt;p&gt;The 1,000-book order was placed through Biblio, a rare and used book marketplace that keeps buyer identities anonymous. An anonymous bookseller working with 404 Media planted the AirTag, which moved through several states before arriving in Las Vegas.&lt;/p&gt;

&lt;p&gt;Amazon employees describing VGT3 on worker forums said their entire job is receiving pallets of books, scanning barcodes and cutting bindings so the pages feed through scanners faster. Amazon told 404 Media it "purchases books through commercial channels" to improve its products, and named no model. Secondary coverage of the investigation has tied the data to Amazon's Nova model family; Amazon has not confirmed that.&lt;/p&gt;

&lt;h2&gt;Why AI Companies Want Printed Books&lt;/h2&gt;

&lt;p&gt;Printed text published before 2022 is the scarcest training resource in AI right now. Much of it was never digitised, so it escaped the web scrapes every large model has already consumed — and nothing printed before 2022 can contain AI-generated text. That second point matters because training a model on other models' output degrades it, a failure researchers call model collapse.&lt;/p&gt;

&lt;p&gt;Booksellers told 404 Media the buyers scan every ISBN (the serial number unique to each edition), which supports their theory that AI firms are working through printed books by serial number.&lt;/p&gt;

&lt;h2&gt;How Amazon Compares With Anthropic's Project Panama&lt;/h2&gt;

&lt;p&gt;Amazon is not the first company to do this. Court exhibits in Bartz v Anthropic PBC described an internal effort to &lt;a href="https://www.theguardian.com/commentisfree/2026/aug/05/anthropic-ai-destroying-books" rel="nofollow" target="_blank"&gt;"destructively scan all the books in the world"&lt;/a&gt;, codenamed Project Panama. Judge William Alsup ruled that scanning lawfully purchased books to train a model was transformative fair use, partly because the printed original was destroyed rather than resold.&lt;/p&gt;
&lt;div class='table noWrap w100'&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;&lt;b&gt;Detail&lt;/b&gt;&lt;/th&gt;&lt;th&gt;&lt;b&gt;Amazon (VGT3)&lt;/b&gt;&lt;/th&gt;&lt;th&gt;&lt;b&gt;Anthropic (Project Panama)&lt;/b&gt;&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Revealed by&lt;/td&gt;&lt;td&gt;404 Media AirTag investigation, 17 Aug 2026&lt;/td&gt;&lt;td&gt;Court exhibits, Bartz v Anthropic PBC&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Site&lt;/td&gt;&lt;td&gt;LAS8 warehouse, Las Vegas, Nevada&lt;/td&gt;&lt;td&gt;Third-party digitisation vendors&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Method&lt;/td&gt;&lt;td&gt;Bindings cut, pages scanned, originals discarded&lt;/td&gt;&lt;td&gt;Spines cut, pages trimmed, originals discarded&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Legal status&lt;/td&gt;&lt;td&gt;No court ruling as of 18 August 2026&lt;/td&gt;&lt;td&gt;Ruled transformative fair use by Judge Alsup&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
  &lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;What This Means in India&lt;/h2&gt;

&lt;p&gt;No Indian court has ruled on destructive scanning. On 24 July 2026, Justice Amit Bansal of the Delhi High Court refused ANI Media an interim injunction against OpenAI, holding on a prima facie basis that storing news content to train a large language model falls under the fair dealing exception in Section 52(1)(a) of the Copyright Act, 1957. India's exceptions are a closed statutory list rather than the flexible US fair use test, and the physical destruction of a copy was never at issue there. The main ANI suit continues.&lt;/p&gt;

&lt;h2&gt;Quick Answers&lt;/h2&gt;

&lt;h3&gt;Which Amazon facility scans books for AI training?&lt;/h3&gt;
&lt;p&gt;LAS8, an Amazon warehouse in north-east Las Vegas, Nevada. The scanning unit inside it is called VGT3.&lt;/p&gt;

&lt;h3&gt;Does Amazon destroy the books it scans?&lt;/h3&gt;
&lt;p&gt;Yes. Workers at VGT3 told 404 Media the bindings are cut off to speed up scanning, which destroys the printed copy.&lt;/p&gt;

&lt;h3&gt;Is destructive book scanning legal in India?&lt;/h3&gt;
&lt;p&gt;No Indian court has ruled on it as of 18 August 2026. The Delhi High Court's July 2026 interim order covered AI training on text, not the destruction of physical books.&lt;/p&gt;

&lt;p&gt;The bookseller who worked with 404 Media put the objection plainly: &lt;a href="https://futurism.com/artificial-intelligence/amazon-destroying-rare-books-ai" rel="nofollow" target="_blank"&gt;"They just want the content as a bunch of words strung together."&lt;/a&gt;&lt;/p&gt;&lt;ul&gt;
&lt;/ul&gt;

&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Which Amazon facility scans books for AI training?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "LAS8, an Amazon warehouse in north-east Las Vegas, Nevada. The scanning unit inside it is called VGT3."
      }
    },
    {
      "@type": "Question",
      "name": "Does Amazon destroy the books it scans?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. Workers at VGT3 told 404 Media the bindings are cut off to speed up scanning, which destroys the printed copy."
      }
    },
    {
      "@type": "Question",
      "name": "Is destructive book scanning legal in India?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No Indian court has ruled on it as of 18 August 2026. The Delhi High Court's July 2026 interim order covered AI training on text, not the destruction of physical books."
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsh44nY0kUI3IJZjueAVb15IhqrnABPYL38wNspmlOz_yq6n-ap9RYYG5xrBOgP8Jvo8Rgo4D-7TnvXi5toOX2koYO3SvTGKsDZqmQDlCQxy3ix9KnKW00grGE2Eo5NuQVrseoc0YYd-z3f-k79ld_J-Lcd6ftCq5P-79BUCgGl_vM2Uptbdv7Dqe-iq0/s72-c/AI_destroying-books.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>The Role of an SEO Agency in Long-Term Organic Growth</title><link>https://www.cyberkendra.com/2026/08/the-role-of-seo-agency-in-long-term.html</link><category>SEO</category><category>Tips</category><pubDate>Tue, 18 Aug 2026 07:55:42 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4421706470442511268</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="SEO boosting ranking" border="0" data-original-height="2800" data-original-width="4096" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFbIP41X6hv3MTjN4zhX15I63qbwldw6aoALoMByATanlyQ6siWgHW2QO6Hmky09V-PtyAlHeWOaYpgdKjw4KdNY1kYjU_EzbI5HCvUZV-Y11H7zMExLx5H_nZ3C19k28dwRyslNqiRL_iFi7rhXFfYK1re6L3Frxlw_Fx4kQ2NfoNAwLpMkztuXtidUs/s1600/boost-citation.webp" title="SEO boosting ranking" /&gt;&lt;/div&gt;&lt;p&gt;Organic growth rarely happens by accident. A website may publish useful content, attract a few backlinks, and rank for several keywords, but maintaining consistent visibility in search requires a structured, long-term strategy. This is where an SEO agency can make a significant difference.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Unlike short-term marketing tactics that focus on immediate traffic or conversions, search engine optimization is designed to build a sustainable digital presence. A professional team can combine technical optimization, content strategy, keyword research, authority building, and performance analysis to help a business compete consistently in organic search.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Why Long-Term SEO Matters&lt;/h2&gt;&lt;p&gt;Search engines continually evolve, and user behavior changes alongside them. Businesses that rely on outdated optimization techniques can gradually lose rankings and organic traffic. Long-term SEO focuses on creating a website that remains useful to both search engines and users as these changes occur.&lt;/p&gt;&lt;p&gt;A sustainable strategy typically involves improving website architecture, creating valuable content, targeting relevant search intent, strengthening authority, and monitoring performance over time. These activities compound. A well-optimized article can continue attracting visitors months or even years after publication, while improvements to site structure can benefit multiple pages simultaneously.&lt;/p&gt;&lt;p&gt;This makes SEO different from many paid advertising campaigns. When an advertising budget stops, the traffic generated through those campaigns can decline immediately. Organic visibility, when built correctly, can continue generating qualified visitors without paying for every click.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What an SEO Agency Actually Does&lt;/h2&gt;&lt;p&gt;An experienced SEO agency does more than add keywords to web pages. Its role is to identify opportunities, solve technical problems, improve content quality, and develop a strategy aligned with business objectives.&lt;/p&gt;&lt;p&gt;Common SEO agency services include:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Technical SEO audits and optimization&lt;/li&gt;&lt;li&gt;Keyword and search-intent research&lt;/li&gt;&lt;li&gt;On-page SEO&lt;/li&gt;&lt;li&gt;Content strategy and optimization&lt;/li&gt;&lt;li&gt;Internal linking&lt;/li&gt;&lt;li&gt;Website structure improvements&lt;/li&gt;&lt;li&gt;Local SEO&lt;/li&gt;&lt;li&gt;Link-building and digital PR&lt;/li&gt;&lt;li&gt;Competitor analysis&lt;/li&gt;&lt;li&gt;SEO performance tracking&lt;/li&gt;&lt;li&gt;Conversion-focused optimization&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The exact combination depends on the website, industry, competition, and business goals. An eCommerce store, for example, may require extensive product-page optimization and technical work, while a B2B company may benefit more from topic clusters, thought leadership content, and authority building.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Building a Strong Technical Foundation&lt;/h2&gt;&lt;p&gt;Technical SEO provides the foundation for sustainable organic performance. Search engines need to be able to discover, crawl, understand, and index a website efficiently.&lt;/p&gt;&lt;p&gt;A professional SEO team may analyze factors such as site architecture, crawlability, indexing, redirects, canonicalization, structured data, mobile usability, page experience, and website speed.&lt;/p&gt;&lt;p&gt;Technical improvements are particularly valuable because they can affect an entire website rather than just one page. Fixing duplicate content or improving internal linking, for example, can help search engines understand the relationship between important pages.&lt;/p&gt;&lt;p&gt;The &lt;a href="https://prarambh360.com/" target="_blank"&gt;best digital marketing company&lt;/a&gt; can also monitor technical issues continuously. This matters because websites are rarely static. New pages are added, old pages are removed, platforms change, and developers make updates that can unintentionally affect organic visibility.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Creating Content Around Search Intent&lt;/h2&gt;&lt;p&gt;Content is another major component of long-term SEO. However, simply publishing large quantities of articles does not guarantee results.&lt;/p&gt;&lt;p&gt;Modern SEO requires understanding why someone performs a search and what information they expect to find. An effective content strategy, therefore, considers informational, commercial, navigational, and transactional search intent.&lt;/p&gt;&lt;p&gt;A strong SEO strategy may organize related topics into content clusters. A central page can cover a broad subject while supporting articles answer more specific questions. Internal links then connect these resources, helping users navigate the site while providing search engines with additional context.&lt;/p&gt;&lt;p&gt;This approach also allows businesses to demonstrate depth within their areas of expertise. Instead of chasing disconnected keywords, they can build a comprehensive resource around topics that matter to their audience&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Developing Authority and Trust&lt;/h2&gt;&lt;p&gt;High-quality content needs visibility and credibility. Authority building helps establish a website as a reliable resource within its industry.&lt;/p&gt;&lt;p&gt;An SEO team may support this through relevant backlinks, digital PR, expert contributions, partnerships, original research, and other legitimate forms of online promotion. The goal should not be to acquire as many links as possible, but to earn relevant mentions from trustworthy sources.&lt;/p&gt;&lt;p&gt;This is another reason businesses often work with a professional SEO agency. Sustainable link acquisition requires research, relationship building, content development, and careful evaluation of opportunities. Poor-quality or manipulative tactics can create unnecessary risks rather than sustainable growth.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Measuring SEO Beyond Rankings&lt;/h3&gt;&lt;p&gt;Rankings remain useful, but they should not be the only measure of SEO success.&lt;/p&gt;&lt;p&gt;A comprehensive SEO measurement framework can examine organic traffic, impressions, click-through rates, conversions, qualified leads, revenue, engagement, and the performance of individual landing pages. Businesses can then identify which activities contribute to meaningful commercial outcomes.&lt;/p&gt;&lt;p&gt;For example, ranking first for a high-volume keyword may look impressive, but a lower-volume keyword that generates qualified leads could be more valuable. The &lt;a href="https://prarambh360.com/services/seo-search-engine-optimization" target="_blank"&gt;best SEO agency&lt;/a&gt; for a business should therefore focus on business impact rather than vanity metrics alone.&lt;/p&gt;&lt;p&gt;Regular reporting also allows strategies to evolve. If a content category attracts traffic but produces few conversions, the team can investigate search intent, improve calls to action, or adjust the targeting strategy.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Adapting to Search in an AI-Driven Era&lt;/h2&gt;&lt;p&gt;Search is becoming increasingly complex as AI-generated answers, conversational search experiences, and new discovery platforms influence how people find information.&lt;/p&gt;&lt;p&gt;This does not make traditional SEO irrelevant. Instead, it increases the importance of creating content that is genuinely useful, well-structured, authoritative, and easy for search systems to understand.&lt;/p&gt;&lt;p&gt;Businesses should focus on answering real customer questions, demonstrating expertise, maintaining accurate information, and building a strong overall digital presence. An SEO team can help monitor these developments and adjust the strategy as search experiences change.&lt;/p&gt;&lt;p&gt;The goal is not to optimize for a single feature or algorithm. It is to build a digital asset capable of attracting users through multiple organic discovery paths.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Choosing the Right SEO Partner&lt;/h2&gt;&lt;p&gt;Not every provider approaches SEO in the same way. When comparing SEO company services, businesses should look beyond promises of instant rankings or guaranteed positions.&lt;/p&gt;&lt;p&gt;A reliable partner should explain its methodology clearly, establish measurable objectives, communicate regularly, and connect SEO activities to business outcomes. It should also be willing to prioritize sustainable improvements over shortcuts.&lt;/p&gt;&lt;p&gt;Businesses can evaluate potential partners by reviewing their experience, case studies, reporting processes, technical capabilities, content expertise, and understanding of the relevant industry.&lt;/p&gt;&lt;p&gt;The right partnership should feel less like outsourcing a checklist and more like working with an extension of the internal marketing team.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;SEO Is an Investment, Not a One-Time Task&lt;/h2&gt;&lt;p&gt;Long-term organic growth requires consistency. Search visibility can take time to develop, particularly in competitive industries, but the cumulative value can be substantial.&lt;/p&gt;&lt;p&gt;A business that continually improves its website, publishes useful resources, earns authority, fixes technical issues, and measures outcomes is building an organic marketing asset. Each improvement can support future performance.&lt;/p&gt;&lt;p&gt;That is the central role of an SEO agency: not simply to help a website rank for keywords, but to create a repeatable strategy for attracting relevant audiences through search.&lt;/p&gt;&lt;p&gt;When SEO is treated as an ongoing investment rather than a one-time project, businesses can build stronger visibility, more qualified traffic, and a foundation for sustainable digital growth.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;FAQs&lt;/h2&gt;&lt;h3 style="text-align: left;"&gt;1. What does an SEO agency do?&lt;/h3&gt;&lt;p&gt;An SEO agency improves a website’s visibility in search engines through technical SEO, keyword research, content optimization, link building, competitor analysis, and ongoing performance monitoring.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;2. How long does SEO take to show results?&lt;/h3&gt;&lt;p&gt;SEO typically takes several months to produce significant results. The timeline depends on factors such as website authority, competition, technical condition, content quality, and the SEO strategy being implemented.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;3. Why should a business hire a professional SEO agency?&lt;/h3&gt;&lt;p&gt;A professional SEO agency brings specialized expertise, tools, and experience to identify opportunities and technical issues that may be difficult to find internally. It can also provide a consistent long-term strategy.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;4. What SEO services should an agency provide?&lt;/h3&gt;&lt;p&gt;Common SEO services include technical SEO, keyword research, on-page optimization, content strategy, internal linking, local SEO, link building, competitor research, and performance reporting.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;5. How do I choose the best SEO agency?&lt;/h3&gt;&lt;p&gt;Look for an agency with a transparent process, relevant industry experience, measurable reporting, realistic expectations, and a focus on sustainable growth rather than guaranteed rankings or quick fixes.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFbIP41X6hv3MTjN4zhX15I63qbwldw6aoALoMByATanlyQ6siWgHW2QO6Hmky09V-PtyAlHeWOaYpgdKjw4KdNY1kYjU_EzbI5HCvUZV-Y11H7zMExLx5H_nZ3C19k28dwRyslNqiRL_iFi7rhXFfYK1re6L3Frxlw_Fx4kQ2NfoNAwLpMkztuXtidUs/s72-c/boost-citation.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Copilot Autofix Bug Exposed Snowflake's Internal Jira</title><link>https://www.cyberkendra.com/2026/08/copilot-autofix-snowflake-jira-github-actions.html</link><category>AI</category><category>Security</category><pubDate>Mon, 17 Aug 2026 23:08:40 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4701922351370819155</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Snowflake leak" border="0" data-original-height="800" data-original-width="1200" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKIgGsZYQSI0i1lOu4W5XG9ELFKDPIQGmephe8A8iC2uSDQOdU9Yl11jIZXGmINae_CaM_3xD7DyiFQWBaS1QRCbgHq6prdN2VmMvbzXqTtFtQ0P7yOawz-S-Bdde_ThEiy19FCc1cwwDtlztMLzDivF7y9i0uVFes03jm4mvrd15pt1gjrRHPj1GCDNo/s1600/Snowflake.webp" title="Snowflake leak" /&gt;&lt;/div&gt;&lt;p&gt;Wiz Research's autonomous "Red Agent" found and exploited a script injection flaw in Snowflake's public &lt;code&gt;snowflake-connector-net&lt;/code&gt; repository, using nothing but a crafted GitHub issue title to steal credentials for Snowflake's internal Jira.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The vulnerability had been introduced five days earlier by GitHub Copilot Autofix — an AI tool built to &lt;em&gt;fix&lt;/em&gt; security bugs.&lt;/p&gt;

&lt;p&gt;No CVE ID has been assigned. Wiz &lt;a href="https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug" rel="nofollow" target="_blank"&gt;reported&lt;/a&gt; the issue through Snowflake's HackerOne program as report #3819931. The bug sat in the &lt;code&gt;jira_issue.yml&lt;/code&gt; workflow, which fired on &lt;code&gt;issues: opened&lt;/code&gt; and interpolated the attacker-controlled title straight into a &lt;code&gt;run:&lt;/code&gt; block — arbitrary command execution on the Actions runner for any unauthenticated GitHub user.&lt;/p&gt;

&lt;h2&gt;How an AI "Autofix" Created the Flaw&lt;/h2&gt;

&lt;p&gt;Commit &lt;code&gt;4a1b8ce&lt;/code&gt; (&lt;a href="https://github.com/snowflakedb/snowflake-connector-net/pull/1218" rel="nofollow" target="_blank"&gt;PR #1218&lt;/a&gt;), co-authored by &lt;code&gt;Copilot Autofix powered by AI&lt;/code&gt;, deleted the repository's safe pattern — the issue title passed through an &lt;code&gt;env:&lt;/code&gt; variable and built into JSON with &lt;code&gt;jq --arg&lt;/code&gt; — and replaced it with direct string expansion:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;- env:
-   ISSUE_TITLE: ${{ github.event.issue.title }}
- run: jq -n --arg title "$ISSUE_TITLE" ...
+ run: TITLE=$(echo '${{ github.event.issue.title }}' | sed ...)&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;The &lt;code&gt;sed&lt;/code&gt; escaping runs &lt;em&gt;after&lt;/em&gt; GitHub expands the template, so a single quote in the title breaks out of &lt;code&gt;echo '...'&lt;/code&gt;. Red Agent's first payload triggered a bash EOF error; the agent analysed the failure, rewrote the payload, and exfiltrated &lt;code&gt;JIRA_API_TOKEN&lt;/code&gt;, &lt;code&gt;JIRA_USER_EMAIL&lt;/code&gt; and &lt;code&gt;JIRA_BASE_URL&lt;/code&gt; as base64 to an out-of-band listener.&lt;/p&gt;

&lt;h2&gt;Why the Workflow's Security Gate Did Nothing&lt;/h2&gt;

&lt;p&gt;The workflow's &lt;code&gt;if:&lt;/code&gt; condition is compared &lt;code&gt;github.event.pull_request.user.login&lt;/code&gt; against a bot account. In &lt;code&gt;issues&lt;/code&gt; events that object is always &lt;strong&gt;null&lt;/strong&gt;, reducing the check to &lt;code&gt;null != 'whitesource-for-github-com[bot]'&lt;/code&gt; — permanently true. Every GitHub user passed the gate.&lt;/p&gt;&lt;ul&gt;
&lt;/ul&gt;

&lt;p&gt;The stolen token was authenticated as &lt;code&gt;qa@snowflake.net&lt;/code&gt; to &lt;code&gt;snowflakecomputing.atlassian.net&lt;/code&gt;, granting read access to engineering, security compliance and bug bounty projects. Snowflake's audit logs matched every anomalous query to Wiz's testing IPs and found no evidence of unauthorised third-party access.&lt;/p&gt;

&lt;h2&gt;How to Check Your Own Workflows&lt;/h2&gt;

&lt;p&gt;Any workflow triggered by &lt;code&gt;issues&lt;/code&gt;, &lt;code&gt;issue_comment&lt;/code&gt;, &lt;code&gt;pull_request_target&lt;/code&gt; or &lt;code&gt;discussion&lt;/code&gt; that places &lt;code&gt;${{ github.event.* }}&lt;/code&gt; inside a &lt;code&gt;run:&lt;/code&gt; block is exploitable the same way. The open-source Actions auditor &lt;a href="https://github.com/zizmorcore/zizmor" rel="nofollow"&gt;zizmor&lt;/a&gt; flags this exact line under its &lt;code&gt;template-injection&lt;/code&gt; rule. Pass untrusted input through &lt;code&gt;env:&lt;/code&gt; variables, quote it as &lt;code&gt;"$VAR"&lt;/code&gt;, and treat AI-generated workflow commits as untrusted code requiring the same review as any external contribution.&lt;/p&gt;

&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Is there a CVE ID for the Snowflake GitHub Actions vulnerability?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No CVE was assigned. Wiz reported the script injection flaw through Snowflake's HackerOne vulnerability disclosure program as report #3819931, and Snowflake patched it the same day."
      }
    },
    {
      "@type": "Question",
      "name": "How did GitHub Copilot Autofix introduce the vulnerability?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Commit 4a1b8ce in PR #1218 removed the repository's safe pattern, which passed the GitHub issue title through an env: variable and built the JSON payload with jq --arg. Copilot Autofix replaced it with direct string expansion of the issue title inside a shell command, creating a script injection vector."
      }
    },
    {
      "@type": "Question",
      "name": "Was Snowflake customer data affected?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. The exfiltrated token gave read access to Snowflake's internal Jira projects covering engineering, security compliance and bug bounty tracking. Snowflake's audit log analysis found no evidence of unauthorised access, with all anomalous queries matched to Wiz's testing IPs."
      }
    },
    {
      "@type": "Question",
      "name": "How do I check if my GitHub Actions workflows are vulnerable?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Look for workflows triggered by issues, issue_comment, pull_request_target or discussion events that interpolate ${{ github.event.* }} expressions directly into run: blocks. The open-source auditor zizmor flags this pattern under its template-injection rule."
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKIgGsZYQSI0i1lOu4W5XG9ELFKDPIQGmephe8A8iC2uSDQOdU9Yl11jIZXGmINae_CaM_3xD7DyiFQWBaS1QRCbgHq6prdN2VmMvbzXqTtFtQ0P7yOawz-S-Bdde_ThEiy19FCc1cwwDtlztMLzDivF7y9i0uVFes03jm4mvrd15pt1gjrRHPj1GCDNo/s72-c/Snowflake.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>GitHub Down as Outage Hits Actions, API and Copilot</title><link>https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html</link><category>GitHub</category><category>Internet</category><pubDate>Mon, 17 Aug 2026 21:37:37 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-6903612215571852160</guid><description>&lt;style&gt;
.ck-post{line-height:1.7}
.ck-post .ck-status{border:1px solid #e0e0e0;border-left:5px solid #d73a49;background:#fff8f8;padding:16px 18px;margin:0 0 24px;border-radius:4px}
.ck-post .ck-status p{margin:0 0 8px}
.ck-post .ck-status p:last-child{margin:0}
.ck-post .ck-status .ck-stamp{font-size:14px;color:#666}
.ck-post table{width:100%;border-collapse:collapse;margin:18px 0;font-size:15px}
.ck-post th,.ck-post td{border:1px solid #e0e0e0;padding:9px 12px;text-align:left;vertical-align:top}
.ck-post th{background:#f6f8fa;font-weight:600}
.ck-post .ck-major{color:#b31d28;font-weight:600}
.ck-post .ck-deg{color:#b08800;font-weight:600}
.ck-post .ck-ok{color:#1a7f37;font-weight:600}
.ck-post .ck-tl{list-style:none;padding:0;margin:18px 0}
.ck-post .ck-tl li{border-left:2px solid #e0e0e0;padding:0 0 14px 18px;margin:0;position:relative}
.ck-post .ck-tl li:before{content:"";position:absolute;left:-6px;top:7px;width:10px;height:10px;background:#586069;border-radius:50%}
.ck-post .ck-tl b{display:block;font-size:14px;color:#586069;font-weight:600}
.ck-post .ck-updates{border:1px solid #e0e0e0;background:#f6f8fa;padding:14px 18px;border-radius:4px}
&lt;/style&gt;
&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="GitHub Hit by Major Outag" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhk-g_BWkajsubQCx9Y4B-t_Gx3prS-uiBsa1nFKY3rNp_bhf5JrG2mL7EQ0YbXcvHdinKOTvyWA2Nqltz1RMcjoCKWDe90boOqx_1cLLVlj_d4Pw_dZf74dczSK8S_vmgRPE1hGMBWc425pn8cUgN8nWj9m9Xqku0ToZrlsf-N0tYdKf587YP_v7Djxc/s1600/GitHub-Outage.webp" title="GitHub Hit by Major Outag" /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;
&lt;div class="ck-post"&gt;

&lt;div class="ck-status"&gt;
&lt;p&gt;&lt;strong&gt;Status: MOSTLY RECOVERED — COPILOT STILL DOWN.&lt;/strong&gt; At 16:59 UTC GitHub declared the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks, and all seven are back to Operational. Copilot was not named in that update and is still marked as a Major Outage. The incident remains open while GitHub monitors for stability.
&lt;p class="ck-stamp"&gt;Last confirmed: 17 August 2026, 16:59 UTC (22:29 IST). This post is updated as GitHub posts new information.&lt;/p&gt;
&lt;/div&gt;

  &lt;p class="note"&gt;&lt;b&gt;Is it broken for you too?&lt;/b&gt; Report what's failing on our &lt;a href="https://downbits.com/services/github" target="_blank"&gt;Downbits GitHub tracker&lt;/a&gt; — API, login, website or DNS. The more reports come in, the faster everyone else can tell whether it's GitHub or their own setup.&lt;/p&gt;
  
&lt;p&gt;GitHub broke for developers worldwide for three hours and nineteen minutes, with roughly one in five requests to the website and the API returning errors, and about half of all archive downloads and raw repository content requests failing outright. The incident opened at 13:40 UTC (19:10 IST) on 17 August 2026 and widened steadily until GitHub declared seven of the eight affected services mitigated at 16:59 UTC. Copilot was not one of them.&lt;/p&gt;

&lt;p&gt;The practical effect was larger than the error percentages suggest. A 50% failure rate on archive downloads and raw content means package installs that pull from GitHub, Docker builds that fetch files over raw github user content, and Go module downloads were all failing intermittently. Combined with a Major Outage on Actions, most CI/CD pipelines that touch GitHub in any way were unreliable for the entire affected window.&lt;/p&gt;

&lt;h2&gt;Is GitHub Down Right Now?&lt;/h2&gt;

&lt;p&gt;Not any more, with one exception. GitHub's own &lt;a href="https://www.githubstatus.com/" rel="nofollow"&gt;status page&lt;/a&gt; now shows every affected service back to Operational except Copilot, which is still marked as a Major Outage. Here is the component-by-component state as of the most recent check:&lt;/p&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Service&lt;/th&gt;&lt;th&gt;Current state&lt;/th&gt;&lt;th&gt;90-day uptime&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Copilot&lt;/td&gt;&lt;td class="ck-major"&gt;Major Outage&lt;/td&gt;&lt;td&gt;99.84%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;API Requests&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.82%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Issues&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.88%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Pull Requests&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.88%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Actions&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.33%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Git Operations&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.99%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Webhooks&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.99%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Pages&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.65%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Packages&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;100.0%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Codespaces&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.97%&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Copilot AI Model Providers&lt;/td&gt;&lt;td class="ck-ok"&gt;Operational&lt;/td&gt;&lt;td&gt;99.88%&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Those uptime figures moved measurably across the afternoon. Actions fell from 99.39% to 99.33%, API Requests from 99.87% to 99.82%, and Issues and Pull Requests from 99.94% to 99.88%. Roughly three hours of downtime was written into GitHub's 90-day record in a single sitting.&lt;/p&gt;

&lt;p&gt;The omission is worth dwelling on. GitHub's 16:59 update named seven services individually and said nothing about Copilot, yet Copilot is the one component its own dashboard still flags as a Major Outage. Either it recovered on a separate track that GitHub has not described, or it was left out by oversight. GitHub has not clarified which.&lt;/p&gt;

&lt;h2&gt;What Is Broken and What Still Works&lt;/h2&gt;

&lt;p&gt;Beyond the headline services, GitHub confirmed during the incident that SAML and OIDC authentication, SCIM provisioning, and Team Sync were affected. For enterprise customers that was the most disruptive part — organisations using single sign-on saw developers unable to authenticate at all, and automated user provisioning stopped flowing. GitHub's mitigation update did not address these separately, so treat SSO as recovered alongside the core services rather than confirmed independently.&lt;/p&gt;

&lt;p&gt;Copilot is now the outlier. The Copilot AI model providers stayed operational for the whole incident, so whatever is keeping Copilot itself down sits in GitHub's own authorisation and routing layer rather than with any upstream AI provider. Packages and Codespaces were never affected at all.	&lt;/p&gt;

&lt;h2&gt;Full Timeline of the GitHub Outage&lt;/h2&gt;

&lt;p&gt;All times 17 August 2026. UTC first, IST in brackets.&lt;/p&gt;

&lt;ul class="ck-tl"&gt;
&lt;li&gt;&lt;b&gt;13:40 UTC (19:10 IST)&lt;/b&gt; GitHub opens the incident, reporting impacted performance for some services.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:41 UTC (19:11 IST)&lt;/b&gt; API Requests degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:42 UTC (19:12 IST)&lt;/b&gt; Actions degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:44 UTC (19:14 IST)&lt;/b&gt; Webhooks degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:45 UTC (19:15 IST)&lt;/b&gt; GitHub quantifies it for the first time — a roughly 20% error rate across Pull Requests, Issues and other experiences.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:46 UTC (19:16 IST)&lt;/b&gt; Issues degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;13:58 UTC (19:28 IST)&lt;/b&gt; Pull Requests degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;14:04 UTC (19:34 IST)&lt;/b&gt; Scope widens: 20% error rate on web and API traffic, and around 50% on archive downloads and raw repository content. Root cause still unknown.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;14:24 UTC (19:54 IST)&lt;/b&gt; SAML and OIDC authentication, SCIM and Team Sync added to the impact list.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;14:31 UTC (20:01 IST)&lt;/b&gt; Copilot degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;14:45–14:58 UTC (20:15–20:28 IST)&lt;/b&gt; Pull Requests, Issues, Actions and Webhooks are each escalated from degraded performance to degraded availability.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;14:58 UTC (20:28 IST)&lt;/b&gt; GitHub says it is applying mitigations based on its investigation so far and monitoring for improvement.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;15:01 UTC (20:31 IST)&lt;/b&gt; API Requests escalated to degraded availability.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;15:10 UTC (20:40 IST)&lt;/b&gt; Pages degraded.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;15:21 UTC (20:51 IST)&lt;/b&gt; Git Operations degraded — the first sign that core clone, fetch and push traffic is affected.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;15:42 UTC (21:12 IST)&lt;/b&gt; Impact figures unchanged. GitHub says it is applying mitigations.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;16:16 UTC (21:46 IST)&lt;/b&gt; More than two and a half hours in, GitHub states it is still working to identify the root cause — the error rates are unchanged from the 14:04 update.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;16:36 UTC (22:06 IST)&lt;/b&gt; The turn. GitHub says it has identified the problematic component, taken corrective action, and is seeing &lt;a href="https://www.githubstatus.com/incidents/zkxwbgr0cnmx" rel="nofollow"&gt;"strong signs of recovery"&lt;/a&gt;, with error rates still slightly elevated. &lt;/li&gt;
  &lt;li&gt;The incident remains open.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;16:59 UTC (22:29 IST)&lt;/b&gt; GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated, and moves to monitoring. All seven return to Operational. Copilot is absent from the update and stays at Major Outage.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Has GitHub Said What Caused It?&lt;/h2&gt;

&lt;p&gt;Partly. At 16:36 UTC, nearly three hours into the incident, GitHub said it had identified the problematic component and applied corrective action. It has not said what that component is.&lt;/p&gt;

&lt;p&gt;The wording matters. Twenty minutes earlier, at 16:16 UTC, GitHub was still reporting that it was working to identify the root cause, with error rates unchanged from where they had sat since 14:04. Between those two updates, engineers found something and pulled it. Identifying a faulty component is not the same as understanding why it failed, so a full root cause analysis is still pending — GitHub publishes these for most significant incidents, usually within a few days.&lt;/p&gt;

&lt;p&gt;The shape of the failure was informative even before that. Error rates were partial rather than total, consistent at around 20% for web and API traffic, with content-serving paths failing at more than double that rate. That pattern points to a subset of infrastructure — a shard, a cluster, a region or a degraded dependency — rather than a total collapse, which is why some users reported GitHub working normally while others could not load a pull request.&lt;/p&gt;

&lt;h2&gt;GitHub's August 2026 Reliability Record&lt;/h2&gt;

&lt;p&gt;This is not an isolated bad day. Today's incident is the &lt;strong&gt;13th &lt;a href="https://www.cyberkendra.com/2026/08/github-source-code-allegedly-up-for.html" target="_blank"&gt;separate incident GitHub &lt;/a&gt;has logged in the first 17 days of August 2026&lt;/strong&gt;, spread across nine different days. The pattern is more revealing than any single outage:&lt;/p&gt;

&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th&gt;Date&lt;/th&gt;&lt;th&gt;Incident&lt;/th&gt;&lt;th&gt;Documented cause&lt;/th&gt;&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;3 Aug&lt;/td&gt;&lt;td&gt;Copilot chat and agent errors, ~4,066 users affected in one hour&lt;/td&gt;&lt;td&gt;Model-list requests exceeded an internal rate limit&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;5 Aug&lt;/td&gt;&lt;td&gt;100% of new Copilot cloud agent jobs are delayed for 52 minutes&lt;/td&gt;&lt;td&gt;Rate limit applied more broadly than intended&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;6 Aug&lt;/td&gt;&lt;td&gt;GitHub Pages — around 128,000 deployments not processed&lt;/td&gt;&lt;td&gt;The configuration change cut processing capacity&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;6–7 Aug&lt;/td&gt;&lt;td&gt;Actions down over 9 hours; 71% of workflow runs failing at peak&lt;/td&gt;&lt;td&gt;Routine deployment exposed a capacity and concurrency weakness&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;10 Aug&lt;/td&gt;&lt;td&gt;Fine-grained personal access tokens silently failed to create&lt;/td&gt;&lt;td&gt;The front-end JavaScript change broke the confirmation step&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;11 Aug&lt;/td&gt;&lt;td&gt;GraphQL API timeouts&lt;/td&gt;&lt;td&gt;Resource contention from high utilisation at one site&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;12 Aug&lt;/td&gt;&lt;td&gt;500 errors on Pull Requests, Issues, and Search&lt;/td&gt;&lt;td&gt;Query hint pointed at an index that a migration had removed&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;12 Aug&lt;/td&gt;&lt;td&gt;Log in and release asset download failures&lt;/td&gt;&lt;td&gt;Not published&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;13 Aug&lt;/td&gt;&lt;td&gt;Three incidents — Webhooks, Copilot models, GHEC Team Sync&lt;/td&gt;&lt;td&gt;Background job, upstream provider, sync degradation&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Two themes run through almost all of them: capacity headroom and change management. Configuration changes and routine deployments repeatedly pushed services past limits that were not being monitored closely enough to catch before customers did. GitHub's own write-up of the 6 August Actions failure conceded that its availability metrics had not fully captured the impact.&lt;/p&gt;

&lt;p&gt;The cost shows in the 90-day uptime figures. Actions sits at 99.33%, which works out to roughly 14 and a half hours of downtime in 90 days — an order of magnitude worse than the 99.99% that Git Operations and Webhooks maintain. Pages at 99.65% translates to about seven and a half hours. For teams whose deployment pipeline runs entirely on Actions, that is a meaningful business risk, not a rounding error.&lt;/p&gt;

&lt;h2&gt;What Developers Should Do Right Now&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Check Copilot separately.&lt;/strong&gt; Everything else is mitigated, but Copilot is still marked as a Major Outage and GitHub has given no timeline for it. If chat or agent features are failing in your IDE, that is the incident, not your configuration.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Assume workflow triggers are being lost.&lt;/strong&gt; In the 6 August Actions incident, GitHub confirmed that push and pull request events dropped during the outage could not be replayed automatically — affected users had to push a new commit or re-run workflows manually. Audit your workflow runs from the 13:40–16:59 UTC window now and re-trigger anything that never fired.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pin your dependencies elsewhere if you can.&lt;/strong&gt; Builds that fetch tarballs or raw files from GitHub during the build step are failing roughly half the time. If you have a package registry mirror or vendored dependencies, use them until this clears.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Enterprise SSO admins should hold off on user provisioning changes.&lt;/strong&gt; SCIM and Team Sync are affected, so team membership changes made now may not apply correctly or may apply late.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not force-push or run migrations against a repository during degraded Git operations.&lt;/strong&gt; Partial failures during write operations are the worst time to be doing anything irreversible.&lt;/p&gt;

&lt;h2&gt;How to Check GitHub Status Yourself&lt;/h2&gt;

&lt;p&gt;The canonical source is GitHub status. GitHub Enterprise Cloud customers should check their regional page instead, because these track separate infrastructure: &lt;a href="https://us.githubstatus.com/" rel="nofollow" target="_blank"&gt;GitHub US&lt;/a&gt;, &lt;a href="https://eu.githubstatus.com" rel="nofollow" target="_blank"&gt;GitHub EU&lt;/a&gt;, &lt;a href="https://au.githubstatus.com" rel="nofollow" target="_blank"&gt;GitHub AU&lt;/a&gt;, and &lt;a href="https://jp.githubstatus.com" rel="nofollow" target="_blank"&gt;GitHub JP&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;For automated monitoring, GitHub publishes an &lt;a href="https://www.githubstatus.com/history.atom" rel="nofollow" target="_blank"&gt;Atom feed&lt;/a&gt; and an &lt;a href="https://www.githubstatus.com/history.rss" rel="nofollow" target="_blank"&gt;RSS feed&lt;/a&gt; of incident history, and supports email, SMS, Slack, and webhook notifications. Teams that depend on GitHub for deployments should wire the webhook into their own alerting rather than finding out from a failed build.&lt;/p&gt;
  
  &lt;p&gt;Official status pages tell you what a vendor has admitted to. They do not tell you what is breaking for people in your region, on your ISP, or in the specific corner of the product you happen to use. For that side of the picture, our sister site Downbits runs a &lt;a href="https://downbits.com/services/github" target="_blank"&gt;GitHub outage tracker&lt;/a&gt; where you can see what other developers are reporting and add your own report — API, login, website or DNS. If Git operations are failing for you but the status page still says degraded rather than down, that gap is worth logging.&lt;/p&gt;
 
&lt;p class="ck-note"&gt;Disclosure: Downbits is operated by the Cyber Kendra team.&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Related:&lt;/strong&gt; this is the second major infrastructure failure to hit developers and site owners this month. See our full coverage of the &lt;a href="https://www.cyberkendra.com/2026/08/namecheap-outage-hits-hosting-dns-and.html" target="_blank"&gt;Namecheap outage&lt;/a&gt;, which took hosting and DNS offline for more than 30 hours after a cooling failure at its Phoenix data centre.&lt;/p&gt;

&lt;h2&gt;Frequently Asked Questions&lt;/h2&gt;

&lt;h3&gt;Is GitHub down for everyone?&lt;/h3&gt;
&lt;p&gt;No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are.&lt;/p&gt;

&lt;h3&gt;When will GitHub be back up?&lt;/h3&gt;
&lt;p&gt;Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a Major Outage, with no separate timeline given.&lt;/p&gt;

&lt;h3&gt;Are git push and git clone working?&lt;/h3&gt;
&lt;p&gt;Yes. Git Operations was degraded from 15:21 UTC and confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down.&lt;/p&gt;

&lt;h3&gt;Are my repositories or data at risk?&lt;/h3&gt;
&lt;p&gt;Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated.&lt;/p&gt;

&lt;h3&gt;Why is GitHub Copilot not working?&lt;/h3&gt;
&lt;p&gt;Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a Major Outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models.&lt;/p&gt;

&lt;h3&gt;Is this related to Microsoft or Azure?&lt;/h3&gt;
&lt;p&gt;GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis.&lt;/p&gt;

&lt;h2&gt;Updates&lt;/h2&gt;

&lt;div class="ck-updates"&gt;
&lt;p&gt;&lt;strong&gt;2026-08-17, 16:59 UTC (22:29 IST)&lt;/strong&gt; — GitHub declares the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks and moves to monitoring. All seven show Operational. Copilot is not mentioned and remains at Major Outage. The incident is not yet resolved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2026-08-17, 16:36 UTC (22:06 IST)&lt;/strong&gt; — GitHub has identified the problematic component and applied corrective action, reporting strong signs of recovery with error rates still slightly elevated. The component it found has not been named. The incident remains open and the status dashboard still shows five services in Major Outage.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2026-08-17, 16:16 UTC (21:46 IST)&lt;/strong&gt; — GitHub says it is still working to identify the root cause. Error rates unchanged.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2026-08-17, 15:42 UTC (21:12 IST)&lt;/strong&gt; — Incident ongoing. Five services in Major Outage. GitHub applying mitigations, no root cause published. Error rates approximately 20% for web and API, and 50% for archive downloads and raw content.&lt;/p&gt;
&lt;/div&gt;

&lt;p&gt;&lt;em&gt;This is a developing story. We are tracking GitHub's status page and will update this post as recovery continues and when GitHub publishes its root cause analysis.&lt;/em&gt;&lt;/p&gt;



&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://www.cyberkendra.com/#organization",
      "name": "Cyber Kendra",
      "url": "https://www.cyberkendra.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIgn6vzwMn1jkfnu3_AXyeoitNmd76ph5miQM8m4-qg2GlMRtVviTx-OSdr24ytbn7sGgqA6eZUL44jlSyuf3fyv__hAQuIN0bmtqidhSdjs2Nv6Qrw7Dn7cZKEJuW4PLNfSlHzoeRkOElRuk65Zz5DithTWiLDecJOTISotSf94f7IazQRLbsJHwWFtg/s600/cyberkendra.webp"
      },
      "sameAs": [
        "https://twitter.com/cyberkendra",
        "https://facebook.com/cyberkendra",
        "https://www.youtube.com/channel/UC1U6oox57l8NZvULSaLc0cw"
      ]
    },

    {
      "@type": ["NewsArticle", "LiveBlogPosting"],
      "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#article",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html"
      },
      "url": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html",
      "headline": "GitHub Down as Outage Hits Actions, API and Copilot",
      "description": "GitHub is down with Actions, API, Issues and Copilot in major outage. Live status, full timeline and what developers should do right now.",
      "image": [
        "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhk-g_BWkajsubQCx9Y4B-t_Gx3prS-uiBsa1nFKY3rNp_bhf5JrG2mL7EQ0YbXcvHdinKOTvyWA2Nqltz1RMcjoCKWDe90boOqx_1cLLVlj_d4Pw_dZf74dczSK8S_vmgRPE1hGMBWc425pn8cUgN8nWj9m9Xqku0ToZrlsf-N0tYdKf587YP_v7Djxc/w1600/GitHub-Outage.webp"
      ],
      "datePublished": "2026-08-17T16:00:00+00:00",
      "dateModified": "2026-08-17T17:10:00+00:00",
      "coverageStartTime": "2026-08-17T13:40:00+00:00",
      "coverageEndTime": "2026-08-17T20:00:00+00:00",
      "author": {
        "@type": "Person",
        "name": "Vivek Gurung",
        "url": "https://in.linkedin.com/in/vivekgurung"
      },
      "publisher": {
        "@id": "https://www.cyberkendra.com/#organization"
      },
      "articleSection": "News",
      "keywords": [
        "GitHub outage",
        "GitHub down",
        "GitHub outage 2026",
        "GitHub Actions outage",
        "GitHub API outage",
        "GitHub Copilot outage",
        "GitHub status",
        "GitHub downtime"
      ],
      "about": {
        "@type": "Organization",
        "name": "GitHub",
        "url": "https://github.com/"
      },
      "isAccessibleForFree": true,
      "liveBlogUpdate": [
        {
          "@type": "BlogPosting",
          "headline": "Seven services mitigated, Copilot still in major outage",
          "datePublished": "2026-08-17T16:59:00+00:00",
          "articleBody": "GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated and moves to monitoring. All seven return to Operational. Copilot is absent from the update and remains marked as a major outage. The incident is not yet resolved."
        },
        {
          "@type": "BlogPosting",
          "headline": "GitHub identifies faulty component, reports strong signs of recovery",
          "datePublished": "2026-08-17T16:36:00+00:00",
          "articleBody": "GitHub says it has identified the problematic component and taken corrective action, and is seeing strong signs of recovery. Error rates remain slightly elevated. The component has not been named."
        },
        {
          "@type": "BlogPosting",
          "headline": "GitHub still working to identify root cause",
          "datePublished": "2026-08-17T16:16:00+00:00",
          "articleBody": "More than two and a half hours in, GitHub reports it is still working to identify the root cause. Error rates are unchanged."
        },
        {
          "@type": "BlogPosting",
          "headline": "GitHub applying mitigations, no root cause published",
          "datePublished": "2026-08-17T15:42:00+00:00",
          "articleBody": "Five services are in a major outage. GitHub is applying mitigations; no root cause has been published. Error rates are approximately 20% for web and API, and 50% for archive downloads and raw content."
        },
        {
          "@type": "BlogPosting",
          "headline": "Git Operations degraded",
          "datePublished": "2026-08-17T15:21:00+00:00",
          "articleBody": "Git Operations degraded, marking the first sign that core clone, fetch and push traffic is affected."
        },
        {
          "@type": "BlogPosting",
          "headline": "SAML, OIDC, SCIM and Team Sync impacted",
          "datePublished": "2026-08-17T14:24:00+00:00",
          "articleBody": "SAML and OIDC authentication, SCIM provisioning and Team Sync were added to the impact list."
        },
        {
          "@type": "BlogPosting",
          "headline": "GitHub opens incident",
          "datePublished": "2026-08-17T13:40:00+00:00",
          "articleBody": "GitHub opened the incident and reported impacted performance for some services."
        }
      ]
    },

    {
      "@type": "FAQPage",
      "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#faq",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is GitHub down for everyone?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are."
          }
        },
        {
          "@type": "Question",
          "name": "When will GitHub be back up?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a major outage, with no separate timeline given for it."
          }
        },
        {
          "@type": "Question",
          "name": "Are git push and git clone working?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Git Operations was degraded from 15:21 UTC and was confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down."
          }
        },
        {
          "@type": "Question",
          "name": "Are my repositories or data at risk?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated."
          }
        },
        {
          "@type": "Question",
          "name": "Why is GitHub Copilot not working?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a major outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models."
          }
        },
        {
          "@type": "Question",
          "name": "Is this related to Microsoft or Azure?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis."
          }
        }
      ]
    }
  ]
}
&lt;/script&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhk-g_BWkajsubQCx9Y4B-t_Gx3prS-uiBsa1nFKY3rNp_bhf5JrG2mL7EQ0YbXcvHdinKOTvyWA2Nqltz1RMcjoCKWDe90boOqx_1cLLVlj_d4Pw_dZf74dczSK8S_vmgRPE1hGMBWc425pn8cUgN8nWj9m9Xqku0ToZrlsf-N0tYdKf587YP_v7Djxc/s72-c/GitHub-Outage.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author><enclosure length="89227" type="application/atom+xml; charset=utf-8" url="https://www.githubstatus.com/history.atom"/><itunes:explicit>no</itunes:explicit><itunes:subtitle>.ck-post{line-height:1.7} .ck-post .ck-status{border:1px solid #e0e0e0;border-left:5px solid #d73a49;background:#fff8f8;padding:16px 18px;margin:0 0 24px;border-radius:4px} .ck-post .ck-status p{margin:0 0 8px} .ck-post .ck-status p:last-child{margin:0} .ck-post .ck-status .ck-stamp{font-size:14px;color:#666} .ck-post table{width:100%;border-collapse:collapse;margin:18px 0;font-size:15px} .ck-post th,.ck-post td{border:1px solid #e0e0e0;padding:9px 12px;text-align:left;vertical-align:top} .ck-post th{background:#f6f8fa;font-weight:600} .ck-post .ck-major{color:#b31d28;font-weight:600} .ck-post .ck-deg{color:#b08800;font-weight:600} .ck-post .ck-ok{color:#1a7f37;font-weight:600} .ck-post .ck-tl{list-style:none;padding:0;margin:18px 0} .ck-post .ck-tl li{border-left:2px solid #e0e0e0;padding:0 0 14px 18px;margin:0;position:relative} .ck-post .ck-tl li:before{content:"";position:absolute;left:-6px;top:7px;width:10px;height:10px;background:#586069;border-radius:50%} .ck-post .ck-tl b{display:block;font-size:14px;color:#586069;font-weight:600} .ck-post .ck-updates{border:1px solid #e0e0e0;background:#f6f8fa;padding:14px 18px;border-radius:4px} Status: MOSTLY RECOVERED — COPILOT STILL DOWN. At 16:59 UTC GitHub declared the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks, and all seven are back to Operational. Copilot was not named in that update and is still marked as a Major Outage. The incident remains open while GitHub monitors for stability. Last confirmed: 17 August 2026, 16:59 UTC (22:29 IST). This post is updated as GitHub posts new information. Is it broken for you too? Report what's failing on our Downbits GitHub tracker — API, login, website or DNS. The more reports come in, the faster everyone else can tell whether it's GitHub or their own setup. GitHub broke for developers worldwide for three hours and nineteen minutes, with roughly one in five requests to the website and the API returning errors, and about half of all archive downloads and raw repository content requests failing outright. The incident opened at 13:40 UTC (19:10 IST) on 17 August 2026 and widened steadily until GitHub declared seven of the eight affected services mitigated at 16:59 UTC. Copilot was not one of them. The practical effect was larger than the error percentages suggest. A 50% failure rate on archive downloads and raw content means package installs that pull from GitHub, Docker builds that fetch files over raw github user content, and Go module downloads were all failing intermittently. Combined with a Major Outage on Actions, most CI/CD pipelines that touch GitHub in any way were unreliable for the entire affected window. Is GitHub Down Right Now? Not any more, with one exception. GitHub's own status page now shows every affected service back to Operational except Copilot, which is still marked as a Major Outage. Here is the component-by-component state as of the most recent check: ServiceCurrent state90-day uptime CopilotMajor Outage99.84% API RequestsOperational99.82% IssuesOperational99.88% Pull RequestsOperational99.88% ActionsOperational99.33% Git OperationsOperational99.99% WebhooksOperational99.99% PagesOperational99.65% PackagesOperational100.0% CodespacesOperational99.97% Copilot AI Model ProvidersOperational99.88% Those uptime figures moved measurably across the afternoon. Actions fell from 99.39% to 99.33%, API Requests from 99.87% to 99.82%, and Issues and Pull Requests from 99.94% to 99.88%. Roughly three hours of downtime was written into GitHub's 90-day record in a single sitting. The omission is worth dwelling on. GitHub's 16:59 update named seven services individually and said nothing about Copilot, yet Copilot is the one component its own dashboard still flags as a Major Outage. Either it recovered on a separate track that GitHub has not described, or it was left out by oversight. GitHub has not clarified which. What Is Broken and What Still Works Beyond the headline services, GitHub confirmed during the incident that SAML and OIDC authentication, SCIM provisioning, and Team Sync were affected. For enterprise customers that was the most disruptive part — organisations using single sign-on saw developers unable to authenticate at all, and automated user provisioning stopped flowing. GitHub's mitigation update did not address these separately, so treat SSO as recovered alongside the core services rather than confirmed independently. Copilot is now the outlier. The Copilot AI model providers stayed operational for the whole incident, so whatever is keeping Copilot itself down sits in GitHub's own authorisation and routing layer rather than with any upstream AI provider. Packages and Codespaces were never affected at all. Full Timeline of the GitHub Outage All times 17 August 2026. UTC first, IST in brackets. 13:40 UTC (19:10 IST) GitHub opens the incident, reporting impacted performance for some services. 13:41 UTC (19:11 IST) API Requests degraded. 13:42 UTC (19:12 IST) Actions degraded. 13:44 UTC (19:14 IST) Webhooks degraded. 13:45 UTC (19:15 IST) GitHub quantifies it for the first time — a roughly 20% error rate across Pull Requests, Issues and other experiences. 13:46 UTC (19:16 IST) Issues degraded. 13:58 UTC (19:28 IST) Pull Requests degraded. 14:04 UTC (19:34 IST) Scope widens: 20% error rate on web and API traffic, and around 50% on archive downloads and raw repository content. Root cause still unknown. 14:24 UTC (19:54 IST) SAML and OIDC authentication, SCIM and Team Sync added to the impact list. 14:31 UTC (20:01 IST) Copilot degraded. 14:45–14:58 UTC (20:15–20:28 IST) Pull Requests, Issues, Actions and Webhooks are each escalated from degraded performance to degraded availability. 14:58 UTC (20:28 IST) GitHub says it is applying mitigations based on its investigation so far and monitoring for improvement. 15:01 UTC (20:31 IST) API Requests escalated to degraded availability. 15:10 UTC (20:40 IST) Pages degraded. 15:21 UTC (20:51 IST) Git Operations degraded — the first sign that core clone, fetch and push traffic is affected. 15:42 UTC (21:12 IST) Impact figures unchanged. GitHub says it is applying mitigations. 16:16 UTC (21:46 IST) More than two and a half hours in, GitHub states it is still working to identify the root cause — the error rates are unchanged from the 14:04 update. 16:36 UTC (22:06 IST) The turn. GitHub says it has identified the problematic component, taken corrective action, and is seeing "strong signs of recovery", with error rates still slightly elevated. The incident remains open. 16:59 UTC (22:29 IST) GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated, and moves to monitoring. All seven return to Operational. Copilot is absent from the update and stays at Major Outage. Has GitHub Said What Caused It? Partly. At 16:36 UTC, nearly three hours into the incident, GitHub said it had identified the problematic component and applied corrective action. It has not said what that component is. The wording matters. Twenty minutes earlier, at 16:16 UTC, GitHub was still reporting that it was working to identify the root cause, with error rates unchanged from where they had sat since 14:04. Between those two updates, engineers found something and pulled it. Identifying a faulty component is not the same as understanding why it failed, so a full root cause analysis is still pending — GitHub publishes these for most significant incidents, usually within a few days. The shape of the failure was informative even before that. Error rates were partial rather than total, consistent at around 20% for web and API traffic, with content-serving paths failing at more than double that rate. That pattern points to a subset of infrastructure — a shard, a cluster, a region or a degraded dependency — rather than a total collapse, which is why some users reported GitHub working normally while others could not load a pull request. GitHub's August 2026 Reliability Record This is not an isolated bad day. Today's incident is the 13th separate incident GitHub has logged in the first 17 days of August 2026, spread across nine different days. The pattern is more revealing than any single outage: DateIncidentDocumented cause 3 AugCopilot chat and agent errors, ~4,066 users affected in one hourModel-list requests exceeded an internal rate limit 5 Aug100% of new Copilot cloud agent jobs are delayed for 52 minutesRate limit applied more broadly than intended 6 AugGitHub Pages — around 128,000 deployments not processedThe configuration change cut processing capacity 6–7 AugActions down over 9 hours; 71% of workflow runs failing at peakRoutine deployment exposed a capacity and concurrency weakness 10 AugFine-grained personal access tokens silently failed to createThe front-end JavaScript change broke the confirmation step 11 AugGraphQL API timeoutsResource contention from high utilisation at one site 12 Aug500 errors on Pull Requests, Issues, and SearchQuery hint pointed at an index that a migration had removed 12 AugLog in and release asset download failuresNot published 13 AugThree incidents — Webhooks, Copilot models, GHEC Team SyncBackground job, upstream provider, sync degradation Two themes run through almost all of them: capacity headroom and change management. Configuration changes and routine deployments repeatedly pushed services past limits that were not being monitored closely enough to catch before customers did. GitHub's own write-up of the 6 August Actions failure conceded that its availability metrics had not fully captured the impact. The cost shows in the 90-day uptime figures. Actions sits at 99.33%, which works out to roughly 14 and a half hours of downtime in 90 days — an order of magnitude worse than the 99.99% that Git Operations and Webhooks maintain. Pages at 99.65% translates to about seven and a half hours. For teams whose deployment pipeline runs entirely on Actions, that is a meaningful business risk, not a rounding error. What Developers Should Do Right Now Check Copilot separately. Everything else is mitigated, but Copilot is still marked as a Major Outage and GitHub has given no timeline for it. If chat or agent features are failing in your IDE, that is the incident, not your configuration. Assume workflow triggers are being lost. In the 6 August Actions incident, GitHub confirmed that push and pull request events dropped during the outage could not be replayed automatically — affected users had to push a new commit or re-run workflows manually. Audit your workflow runs from the 13:40–16:59 UTC window now and re-trigger anything that never fired. Pin your dependencies elsewhere if you can. Builds that fetch tarballs or raw files from GitHub during the build step are failing roughly half the time. If you have a package registry mirror or vendored dependencies, use them until this clears. Enterprise SSO admins should hold off on user provisioning changes. SCIM and Team Sync are affected, so team membership changes made now may not apply correctly or may apply late. Do not force-push or run migrations against a repository during degraded Git operations. Partial failures during write operations are the worst time to be doing anything irreversible. How to Check GitHub Status Yourself The canonical source is GitHub status. GitHub Enterprise Cloud customers should check their regional page instead, because these track separate infrastructure: GitHub US, GitHub EU, GitHub AU, and GitHub JP. For automated monitoring, GitHub publishes an Atom feed and an RSS feed of incident history, and supports email, SMS, Slack, and webhook notifications. Teams that depend on GitHub for deployments should wire the webhook into their own alerting rather than finding out from a failed build. Official status pages tell you what a vendor has admitted to. They do not tell you what is breaking for people in your region, on your ISP, or in the specific corner of the product you happen to use. For that side of the picture, our sister site Downbits runs a GitHub outage tracker where you can see what other developers are reporting and add your own report — API, login, website or DNS. If Git operations are failing for you but the status page still says degraded rather than down, that gap is worth logging. Disclosure: Downbits is operated by the Cyber Kendra team. Related: this is the second major infrastructure failure to hit developers and site owners this month. See our full coverage of the Namecheap outage, which took hosting and DNS offline for more than 30 hours after a cooling failure at its Phoenix data centre. Frequently Asked Questions Is GitHub down for everyone? No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are. When will GitHub be back up? Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a Major Outage, with no separate timeline given. Are git push and git clone working? Yes. Git Operations was degraded from 15:21 UTC and confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down. Are my repositories or data at risk? Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated. Why is GitHub Copilot not working? Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a Major Outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models. Is this related to Microsoft or Azure? GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis. Updates 2026-08-17, 16:59 UTC (22:29 IST) — GitHub declares the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks and moves to monitoring. All seven show Operational. Copilot is not mentioned and remains at Major Outage. The incident is not yet resolved. 2026-08-17, 16:36 UTC (22:06 IST) — GitHub has identified the problematic component and applied corrective action, reporting strong signs of recovery with error rates still slightly elevated. The component it found has not been named. The incident remains open and the status dashboard still shows five services in Major Outage. 2026-08-17, 16:16 UTC (21:46 IST) — GitHub says it is still working to identify the root cause. Error rates unchanged. 2026-08-17, 15:42 UTC (21:12 IST) — Incident ongoing. Five services in Major Outage. GitHub applying mitigations, no root cause published. Error rates approximately 20% for web and API, and 50% for archive downloads and raw content. This is a developing story. We are tracking GitHub's status page and will update this post as recovery continues and when GitHub publishes its root cause analysis. { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://www.cyberkendra.com/#organization", "name": "Cyber Kendra", "url": "https://www.cyberkendra.com/", "logo": { "@type": "ImageObject", "url": "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIgn6vzwMn1jkfnu3_AXyeoitNmd76ph5miQM8m4-qg2GlMRtVviTx-OSdr24ytbn7sGgqA6eZUL44jlSyuf3fyv__hAQuIN0bmtqidhSdjs2Nv6Qrw7Dn7cZKEJuW4PLNfSlHzoeRkOElRuk65Zz5DithTWiLDecJOTISotSf94f7IazQRLbsJHwWFtg/s600/cyberkendra.webp" }, "sameAs": [ "https://twitter.com/cyberkendra", "https://facebook.com/cyberkendra", "https://www.youtube.com/channel/UC1U6oox57l8NZvULSaLc0cw" ] }, { "@type": ["NewsArticle", "LiveBlogPosting"], "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#article", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html" }, "url": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html", "headline": "GitHub Down as Outage Hits Actions, API and Copilot", "description": "GitHub is down with Actions, API, Issues and Copilot in major outage. Live status, full timeline and what developers should do right now.", "image": [ "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhk-g_BWkajsubQCx9Y4B-t_Gx3prS-uiBsa1nFKY3rNp_bhf5JrG2mL7EQ0YbXcvHdinKOTvyWA2Nqltz1RMcjoCKWDe90boOqx_1cLLVlj_d4Pw_dZf74dczSK8S_vmgRPE1hGMBWc425pn8cUgN8nWj9m9Xqku0ToZrlsf-N0tYdKf587YP_v7Djxc/w1600/GitHub-Outage.webp" ], "datePublished": "2026-08-17T16:00:00+00:00", "dateModified": "2026-08-17T17:10:00+00:00", "coverageStartTime": "2026-08-17T13:40:00+00:00", "coverageEndTime": "2026-08-17T20:00:00+00:00", "author": { "@type": "Person", "name": "Vivek Gurung", "url": "https://in.linkedin.com/in/vivekgurung" }, "publisher": { "@id": "https://www.cyberkendra.com/#organization" }, "articleSection": "News", "keywords": [ "GitHub outage", "GitHub down", "GitHub outage 2026", "GitHub Actions outage", "GitHub API outage", "GitHub Copilot outage", "GitHub status", "GitHub downtime" ], "about": { "@type": "Organization", "name": "GitHub", "url": "https://github.com/" }, "isAccessibleForFree": true, "liveBlogUpdate": [ { "@type": "BlogPosting", "headline": "Seven services mitigated, Copilot still in major outage", "datePublished": "2026-08-17T16:59:00+00:00", "articleBody": "GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated and moves to monitoring. All seven return to Operational. Copilot is absent from the update and remains marked as a major outage. The incident is not yet resolved." }, { "@type": "BlogPosting", "headline": "GitHub identifies faulty component, reports strong signs of recovery", "datePublished": "2026-08-17T16:36:00+00:00", "articleBody": "GitHub says it has identified the problematic component and taken corrective action, and is seeing strong signs of recovery. Error rates remain slightly elevated. The component has not been named." }, { "@type": "BlogPosting", "headline": "GitHub still working to identify root cause", "datePublished": "2026-08-17T16:16:00+00:00", "articleBody": "More than two and a half hours in, GitHub reports it is still working to identify the root cause. Error rates are unchanged." }, { "@type": "BlogPosting", "headline": "GitHub applying mitigations, no root cause published", "datePublished": "2026-08-17T15:42:00+00:00", "articleBody": "Five services are in a major outage. GitHub is applying mitigations; no root cause has been published. Error rates are approximately 20% for web and API, and 50% for archive downloads and raw content." }, { "@type": "BlogPosting", "headline": "Git Operations degraded", "datePublished": "2026-08-17T15:21:00+00:00", "articleBody": "Git Operations degraded, marking the first sign that core clone, fetch and push traffic is affected." }, { "@type": "BlogPosting", "headline": "SAML, OIDC, SCIM and Team Sync impacted", "datePublished": "2026-08-17T14:24:00+00:00", "articleBody": "SAML and OIDC authentication, SCIM provisioning and Team Sync were added to the impact list." }, { "@type": "BlogPosting", "headline": "GitHub opens incident", "datePublished": "2026-08-17T13:40:00+00:00", "articleBody": "GitHub opened the incident and reported impacted performance for some services." } ] }, { "@type": "FAQPage", "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#faq", "mainEntity": [ { "@type": "Question", "name": "Is GitHub down for everyone?", "acceptedAnswer": { "@type": "Answer", "text": "No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are." } }, { "@type": "Question", "name": "When will GitHub be back up?", "acceptedAnswer": { "@type": "Answer", "text": "Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a major outage, with no separate timeline given for it." } }, { "@type": "Question", "name": "Are git push and git clone working?", "acceptedAnswer": { "@type": "Answer", "text": "Yes. Git Operations was degraded from 15:21 UTC and was confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down." } }, { "@type": "Question", "name": "Are my repositories or data at risk?", "acceptedAnswer": { "@type": "Answer", "text": "Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated." } }, { "@type": "Question", "name": "Why is GitHub Copilot not working?", "acceptedAnswer": { "@type": "Answer", "text": "Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a major outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models." } }, { "@type": "Question", "name": "Is this related to Microsoft or Azure?", "acceptedAnswer": { "@type": "Answer", "text": "GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis." } } ] } ] }</itunes:subtitle><itunes:author>Vivek Gurung</itunes:author><itunes:summary>.ck-post{line-height:1.7} .ck-post .ck-status{border:1px solid #e0e0e0;border-left:5px solid #d73a49;background:#fff8f8;padding:16px 18px;margin:0 0 24px;border-radius:4px} .ck-post .ck-status p{margin:0 0 8px} .ck-post .ck-status p:last-child{margin:0} .ck-post .ck-status .ck-stamp{font-size:14px;color:#666} .ck-post table{width:100%;border-collapse:collapse;margin:18px 0;font-size:15px} .ck-post th,.ck-post td{border:1px solid #e0e0e0;padding:9px 12px;text-align:left;vertical-align:top} .ck-post th{background:#f6f8fa;font-weight:600} .ck-post .ck-major{color:#b31d28;font-weight:600} .ck-post .ck-deg{color:#b08800;font-weight:600} .ck-post .ck-ok{color:#1a7f37;font-weight:600} .ck-post .ck-tl{list-style:none;padding:0;margin:18px 0} .ck-post .ck-tl li{border-left:2px solid #e0e0e0;padding:0 0 14px 18px;margin:0;position:relative} .ck-post .ck-tl li:before{content:"";position:absolute;left:-6px;top:7px;width:10px;height:10px;background:#586069;border-radius:50%} .ck-post .ck-tl b{display:block;font-size:14px;color:#586069;font-weight:600} .ck-post .ck-updates{border:1px solid #e0e0e0;background:#f6f8fa;padding:14px 18px;border-radius:4px} Status: MOSTLY RECOVERED — COPILOT STILL DOWN. At 16:59 UTC GitHub declared the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks, and all seven are back to Operational. Copilot was not named in that update and is still marked as a Major Outage. The incident remains open while GitHub monitors for stability. Last confirmed: 17 August 2026, 16:59 UTC (22:29 IST). This post is updated as GitHub posts new information. Is it broken for you too? Report what's failing on our Downbits GitHub tracker — API, login, website or DNS. The more reports come in, the faster everyone else can tell whether it's GitHub or their own setup. GitHub broke for developers worldwide for three hours and nineteen minutes, with roughly one in five requests to the website and the API returning errors, and about half of all archive downloads and raw repository content requests failing outright. The incident opened at 13:40 UTC (19:10 IST) on 17 August 2026 and widened steadily until GitHub declared seven of the eight affected services mitigated at 16:59 UTC. Copilot was not one of them. The practical effect was larger than the error percentages suggest. A 50% failure rate on archive downloads and raw content means package installs that pull from GitHub, Docker builds that fetch files over raw github user content, and Go module downloads were all failing intermittently. Combined with a Major Outage on Actions, most CI/CD pipelines that touch GitHub in any way were unreliable for the entire affected window. Is GitHub Down Right Now? Not any more, with one exception. GitHub's own status page now shows every affected service back to Operational except Copilot, which is still marked as a Major Outage. Here is the component-by-component state as of the most recent check: ServiceCurrent state90-day uptime CopilotMajor Outage99.84% API RequestsOperational99.82% IssuesOperational99.88% Pull RequestsOperational99.88% ActionsOperational99.33% Git OperationsOperational99.99% WebhooksOperational99.99% PagesOperational99.65% PackagesOperational100.0% CodespacesOperational99.97% Copilot AI Model ProvidersOperational99.88% Those uptime figures moved measurably across the afternoon. Actions fell from 99.39% to 99.33%, API Requests from 99.87% to 99.82%, and Issues and Pull Requests from 99.94% to 99.88%. Roughly three hours of downtime was written into GitHub's 90-day record in a single sitting. The omission is worth dwelling on. GitHub's 16:59 update named seven services individually and said nothing about Copilot, yet Copilot is the one component its own dashboard still flags as a Major Outage. Either it recovered on a separate track that GitHub has not described, or it was left out by oversight. GitHub has not clarified which. What Is Broken and What Still Works Beyond the headline services, GitHub confirmed during the incident that SAML and OIDC authentication, SCIM provisioning, and Team Sync were affected. For enterprise customers that was the most disruptive part — organisations using single sign-on saw developers unable to authenticate at all, and automated user provisioning stopped flowing. GitHub's mitigation update did not address these separately, so treat SSO as recovered alongside the core services rather than confirmed independently. Copilot is now the outlier. The Copilot AI model providers stayed operational for the whole incident, so whatever is keeping Copilot itself down sits in GitHub's own authorisation and routing layer rather than with any upstream AI provider. Packages and Codespaces were never affected at all. Full Timeline of the GitHub Outage All times 17 August 2026. UTC first, IST in brackets. 13:40 UTC (19:10 IST) GitHub opens the incident, reporting impacted performance for some services. 13:41 UTC (19:11 IST) API Requests degraded. 13:42 UTC (19:12 IST) Actions degraded. 13:44 UTC (19:14 IST) Webhooks degraded. 13:45 UTC (19:15 IST) GitHub quantifies it for the first time — a roughly 20% error rate across Pull Requests, Issues and other experiences. 13:46 UTC (19:16 IST) Issues degraded. 13:58 UTC (19:28 IST) Pull Requests degraded. 14:04 UTC (19:34 IST) Scope widens: 20% error rate on web and API traffic, and around 50% on archive downloads and raw repository content. Root cause still unknown. 14:24 UTC (19:54 IST) SAML and OIDC authentication, SCIM and Team Sync added to the impact list. 14:31 UTC (20:01 IST) Copilot degraded. 14:45–14:58 UTC (20:15–20:28 IST) Pull Requests, Issues, Actions and Webhooks are each escalated from degraded performance to degraded availability. 14:58 UTC (20:28 IST) GitHub says it is applying mitigations based on its investigation so far and monitoring for improvement. 15:01 UTC (20:31 IST) API Requests escalated to degraded availability. 15:10 UTC (20:40 IST) Pages degraded. 15:21 UTC (20:51 IST) Git Operations degraded — the first sign that core clone, fetch and push traffic is affected. 15:42 UTC (21:12 IST) Impact figures unchanged. GitHub says it is applying mitigations. 16:16 UTC (21:46 IST) More than two and a half hours in, GitHub states it is still working to identify the root cause — the error rates are unchanged from the 14:04 update. 16:36 UTC (22:06 IST) The turn. GitHub says it has identified the problematic component, taken corrective action, and is seeing "strong signs of recovery", with error rates still slightly elevated. The incident remains open. 16:59 UTC (22:29 IST) GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated, and moves to monitoring. All seven return to Operational. Copilot is absent from the update and stays at Major Outage. Has GitHub Said What Caused It? Partly. At 16:36 UTC, nearly three hours into the incident, GitHub said it had identified the problematic component and applied corrective action. It has not said what that component is. The wording matters. Twenty minutes earlier, at 16:16 UTC, GitHub was still reporting that it was working to identify the root cause, with error rates unchanged from where they had sat since 14:04. Between those two updates, engineers found something and pulled it. Identifying a faulty component is not the same as understanding why it failed, so a full root cause analysis is still pending — GitHub publishes these for most significant incidents, usually within a few days. The shape of the failure was informative even before that. Error rates were partial rather than total, consistent at around 20% for web and API traffic, with content-serving paths failing at more than double that rate. That pattern points to a subset of infrastructure — a shard, a cluster, a region or a degraded dependency — rather than a total collapse, which is why some users reported GitHub working normally while others could not load a pull request. GitHub's August 2026 Reliability Record This is not an isolated bad day. Today's incident is the 13th separate incident GitHub has logged in the first 17 days of August 2026, spread across nine different days. The pattern is more revealing than any single outage: DateIncidentDocumented cause 3 AugCopilot chat and agent errors, ~4,066 users affected in one hourModel-list requests exceeded an internal rate limit 5 Aug100% of new Copilot cloud agent jobs are delayed for 52 minutesRate limit applied more broadly than intended 6 AugGitHub Pages — around 128,000 deployments not processedThe configuration change cut processing capacity 6–7 AugActions down over 9 hours; 71% of workflow runs failing at peakRoutine deployment exposed a capacity and concurrency weakness 10 AugFine-grained personal access tokens silently failed to createThe front-end JavaScript change broke the confirmation step 11 AugGraphQL API timeoutsResource contention from high utilisation at one site 12 Aug500 errors on Pull Requests, Issues, and SearchQuery hint pointed at an index that a migration had removed 12 AugLog in and release asset download failuresNot published 13 AugThree incidents — Webhooks, Copilot models, GHEC Team SyncBackground job, upstream provider, sync degradation Two themes run through almost all of them: capacity headroom and change management. Configuration changes and routine deployments repeatedly pushed services past limits that were not being monitored closely enough to catch before customers did. GitHub's own write-up of the 6 August Actions failure conceded that its availability metrics had not fully captured the impact. The cost shows in the 90-day uptime figures. Actions sits at 99.33%, which works out to roughly 14 and a half hours of downtime in 90 days — an order of magnitude worse than the 99.99% that Git Operations and Webhooks maintain. Pages at 99.65% translates to about seven and a half hours. For teams whose deployment pipeline runs entirely on Actions, that is a meaningful business risk, not a rounding error. What Developers Should Do Right Now Check Copilot separately. Everything else is mitigated, but Copilot is still marked as a Major Outage and GitHub has given no timeline for it. If chat or agent features are failing in your IDE, that is the incident, not your configuration. Assume workflow triggers are being lost. In the 6 August Actions incident, GitHub confirmed that push and pull request events dropped during the outage could not be replayed automatically — affected users had to push a new commit or re-run workflows manually. Audit your workflow runs from the 13:40–16:59 UTC window now and re-trigger anything that never fired. Pin your dependencies elsewhere if you can. Builds that fetch tarballs or raw files from GitHub during the build step are failing roughly half the time. If you have a package registry mirror or vendored dependencies, use them until this clears. Enterprise SSO admins should hold off on user provisioning changes. SCIM and Team Sync are affected, so team membership changes made now may not apply correctly or may apply late. Do not force-push or run migrations against a repository during degraded Git operations. Partial failures during write operations are the worst time to be doing anything irreversible. How to Check GitHub Status Yourself The canonical source is GitHub status. GitHub Enterprise Cloud customers should check their regional page instead, because these track separate infrastructure: GitHub US, GitHub EU, GitHub AU, and GitHub JP. For automated monitoring, GitHub publishes an Atom feed and an RSS feed of incident history, and supports email, SMS, Slack, and webhook notifications. Teams that depend on GitHub for deployments should wire the webhook into their own alerting rather than finding out from a failed build. Official status pages tell you what a vendor has admitted to. They do not tell you what is breaking for people in your region, on your ISP, or in the specific corner of the product you happen to use. For that side of the picture, our sister site Downbits runs a GitHub outage tracker where you can see what other developers are reporting and add your own report — API, login, website or DNS. If Git operations are failing for you but the status page still says degraded rather than down, that gap is worth logging. Disclosure: Downbits is operated by the Cyber Kendra team. Related: this is the second major infrastructure failure to hit developers and site owners this month. See our full coverage of the Namecheap outage, which took hosting and DNS offline for more than 30 hours after a cooling failure at its Phoenix data centre. Frequently Asked Questions Is GitHub down for everyone? No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are. When will GitHub be back up? Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a Major Outage, with no separate timeline given. Are git push and git clone working? Yes. Git Operations was degraded from 15:21 UTC and confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down. Are my repositories or data at risk? Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated. Why is GitHub Copilot not working? Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a Major Outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models. Is this related to Microsoft or Azure? GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis. Updates 2026-08-17, 16:59 UTC (22:29 IST) — GitHub declares the degradation mitigated across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks and moves to monitoring. All seven show Operational. Copilot is not mentioned and remains at Major Outage. The incident is not yet resolved. 2026-08-17, 16:36 UTC (22:06 IST) — GitHub has identified the problematic component and applied corrective action, reporting strong signs of recovery with error rates still slightly elevated. The component it found has not been named. The incident remains open and the status dashboard still shows five services in Major Outage. 2026-08-17, 16:16 UTC (21:46 IST) — GitHub says it is still working to identify the root cause. Error rates unchanged. 2026-08-17, 15:42 UTC (21:12 IST) — Incident ongoing. Five services in Major Outage. GitHub applying mitigations, no root cause published. Error rates approximately 20% for web and API, and 50% for archive downloads and raw content. This is a developing story. We are tracking GitHub's status page and will update this post as recovery continues and when GitHub publishes its root cause analysis. { "@context": "https://schema.org", "@graph": [ { "@type": "Organization", "@id": "https://www.cyberkendra.com/#organization", "name": "Cyber Kendra", "url": "https://www.cyberkendra.com/", "logo": { "@type": "ImageObject", "url": "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIgn6vzwMn1jkfnu3_AXyeoitNmd76ph5miQM8m4-qg2GlMRtVviTx-OSdr24ytbn7sGgqA6eZUL44jlSyuf3fyv__hAQuIN0bmtqidhSdjs2Nv6Qrw7Dn7cZKEJuW4PLNfSlHzoeRkOElRuk65Zz5DithTWiLDecJOTISotSf94f7IazQRLbsJHwWFtg/s600/cyberkendra.webp" }, "sameAs": [ "https://twitter.com/cyberkendra", "https://facebook.com/cyberkendra", "https://www.youtube.com/channel/UC1U6oox57l8NZvULSaLc0cw" ] }, { "@type": ["NewsArticle", "LiveBlogPosting"], "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#article", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html" }, "url": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html", "headline": "GitHub Down as Outage Hits Actions, API and Copilot", "description": "GitHub is down with Actions, API, Issues and Copilot in major outage. Live status, full timeline and what developers should do right now.", "image": [ "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhk-g_BWkajsubQCx9Y4B-t_Gx3prS-uiBsa1nFKY3rNp_bhf5JrG2mL7EQ0YbXcvHdinKOTvyWA2Nqltz1RMcjoCKWDe90boOqx_1cLLVlj_d4Pw_dZf74dczSK8S_vmgRPE1hGMBWc425pn8cUgN8nWj9m9Xqku0ToZrlsf-N0tYdKf587YP_v7Djxc/w1600/GitHub-Outage.webp" ], "datePublished": "2026-08-17T16:00:00+00:00", "dateModified": "2026-08-17T17:10:00+00:00", "coverageStartTime": "2026-08-17T13:40:00+00:00", "coverageEndTime": "2026-08-17T20:00:00+00:00", "author": { "@type": "Person", "name": "Vivek Gurung", "url": "https://in.linkedin.com/in/vivekgurung" }, "publisher": { "@id": "https://www.cyberkendra.com/#organization" }, "articleSection": "News", "keywords": [ "GitHub outage", "GitHub down", "GitHub outage 2026", "GitHub Actions outage", "GitHub API outage", "GitHub Copilot outage", "GitHub status", "GitHub downtime" ], "about": { "@type": "Organization", "name": "GitHub", "url": "https://github.com/" }, "isAccessibleForFree": true, "liveBlogUpdate": [ { "@type": "BlogPosting", "headline": "Seven services mitigated, Copilot still in major outage", "datePublished": "2026-08-17T16:59:00+00:00", "articleBody": "GitHub declares the degradation affecting API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks mitigated and moves to monitoring. All seven return to Operational. Copilot is absent from the update and remains marked as a major outage. The incident is not yet resolved." }, { "@type": "BlogPosting", "headline": "GitHub identifies faulty component, reports strong signs of recovery", "datePublished": "2026-08-17T16:36:00+00:00", "articleBody": "GitHub says it has identified the problematic component and taken corrective action, and is seeing strong signs of recovery. Error rates remain slightly elevated. The component has not been named." }, { "@type": "BlogPosting", "headline": "GitHub still working to identify root cause", "datePublished": "2026-08-17T16:16:00+00:00", "articleBody": "More than two and a half hours in, GitHub reports it is still working to identify the root cause. Error rates are unchanged." }, { "@type": "BlogPosting", "headline": "GitHub applying mitigations, no root cause published", "datePublished": "2026-08-17T15:42:00+00:00", "articleBody": "Five services are in a major outage. GitHub is applying mitigations; no root cause has been published. Error rates are approximately 20% for web and API, and 50% for archive downloads and raw content." }, { "@type": "BlogPosting", "headline": "Git Operations degraded", "datePublished": "2026-08-17T15:21:00+00:00", "articleBody": "Git Operations degraded, marking the first sign that core clone, fetch and push traffic is affected." }, { "@type": "BlogPosting", "headline": "SAML, OIDC, SCIM and Team Sync impacted", "datePublished": "2026-08-17T14:24:00+00:00", "articleBody": "SAML and OIDC authentication, SCIM provisioning and Team Sync were added to the impact list." }, { "@type": "BlogPosting", "headline": "GitHub opens incident", "datePublished": "2026-08-17T13:40:00+00:00", "articleBody": "GitHub opened the incident and reported impacted performance for some services." } ] }, { "@type": "FAQPage", "@id": "https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html#faq", "mainEntity": [ { "@type": "Question", "name": "Is GitHub down for everyone?", "acceptedAnswer": { "@type": "Answer", "text": "No. This is a partial outage with roughly a 20% error rate on web and API traffic, so many requests still succeed. Whether you notice it depends on which service you are using and how lucky your individual requests are." } }, { "@type": "Question", "name": "When will GitHub be back up?", "acceptedAnswer": { "@type": "Answer", "text": "Most of it already is. GitHub mitigated the degradation across API Requests, Actions, Git Operations, Issues, Pages, Pull Requests and Webhooks at 16:59 UTC and moved to monitoring. Copilot was left out of that update and is still marked as a major outage, with no separate timeline given for it." } }, { "@type": "Question", "name": "Are git push and git clone working?", "acceptedAnswer": { "@type": "Answer", "text": "Yes. Git Operations was degraded from 15:21 UTC and was confirmed mitigated at 16:59 UTC. Clone, fetch and push are back to normal, and were never fully down." } }, { "@type": "Question", "name": "Are my repositories or data at risk?", "acceptedAnswer": { "@type": "Answer", "text": "Nothing GitHub has published points to data loss or a security incident. This is an availability problem, and no breach or compromise has been indicated." } }, { "@type": "Question", "name": "Why is GitHub Copilot not working?", "acceptedAnswer": { "@type": "Answer", "text": "Copilot is the one service that has not recovered. GitHub's 16:59 mitigation update covered seven other services and omitted Copilot, which is still marked as a major outage. The Copilot AI model providers are operational, so the failure is in GitHub's own service layer rather than the underlying models." } }, { "@type": "Question", "name": "Is this related to Microsoft or Azure?", "acceptedAnswer": { "@type": "Answer", "text": "GitHub has not attributed the incident to any upstream provider, and no Azure connection has been stated. Treat any such claim as unconfirmed until GitHub publishes a root cause analysis." } } ] } ] }</itunes:summary><itunes:keywords>Computer,technology,tech,IT,security,Gadgets,Telecom</itunes:keywords></item><item><title>Microsoft's SCCM Hotfix Fixes Only One of Four RCE Bugs</title><link>https://www.cyberkendra.com/2026/08/microsofts-sccm-hotfix-fixes-only-one.html</link><category>Microsoft</category><category>Security</category><pubDate>Sun, 16 Aug 2026 21:49:36 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3146853943601388820</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Microsoft Patches SCCM Flaw CVE-2026-47301, Chain Unfixed" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8Cs4l1JNxaOMLaqLOFtrr-eNmHveAPhHeQ6s_aJ-cxLW1wPtTbVBgzK0efQndY08tEsyRSEQjVto7pkU6UaQtp6ml2hv5hpVQ-uvAomeB1GLriVqDETqd7ZpoHrT4PtPbvqBP7JpkS0IIeSM6rHuXEbq4rcELwKmw12YBWd654-ITBb19L-najGWdk2Y/s1600/%F0%9D%97%96%F0%9D%97%A9%F0%9D%97%98-%F0%9D%9F%AE%F0%9D%9F%AC%F0%9D%9F%AE%F0%9D%9F%B2-%F0%9D%9F%B0%F0%9D%9F%B3%F0%9D%9F%AF%F0%9D%9F%AC%F0%9D%9F%AD.webp" title="Microsoft Patches SCCM Flaw CVE-2026-47301, Chain Unfixed" /&gt;&lt;/div&gt;&lt;p&gt;Security researcher Omri Baso has &lt;a href="https://medium.com/@omribaso/from-domain-user-to-enterprise-control-microsoft-configuration-manager-rce-0-day-exploit-chain-393c63c680ca" rel="nofollow" target="_blank"&gt;disclosed&lt;/a&gt; a remote code execution chain in &lt;strong&gt;Microsoft Configuration Manager (SCCM/ConfigMgr)&lt;/strong&gt; that lets an ordinary Active Directory user seize SYSTEM control of a Primary Site Server — and every client it manages. Microsoft has patched only one link in that chain, &lt;strong&gt;CVE-2026-47301&lt;/strong&gt;, leaving the full path to code execution open until a later release.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CVE-2026-47301&lt;/b&gt; is a missing role-based access control (RBAC) check in the SCCM AdminService REST API. SentinelOne's advisory rates it at CVSS 8.8 (High) under CWE-284, improper access control; Microsoft rates&amp;nbsp;it as an elevation-of-privilege flaw.&amp;nbsp;&lt;/p&gt;&lt;p&gt;On its own, it is the entry point, Baso — a researcher at XM Cyber — chained with three still-unpatched bugs to run code as &lt;code&gt;NT AUTHORITY\SYSTEM&lt;/code&gt;. He reported the chain to Microsoft on 23 May 2026 and says roughly 100 million SCCM clients are managed worldwide.&lt;/p&gt;

&lt;h2&gt;How the SCCM Exploit Chain Works&lt;/h2&gt;
&lt;p&gt;The AdminService exposes two console-extension upload endpoints. &lt;code&gt;UploadExtension&lt;/code&gt; enforces a permission check; its chunked twin, &lt;code&gt;UploadExtensionInChunks&lt;/code&gt;, does not — that gap is CVE-2026-47301, and it lets any authenticated domain user submit a malicious CAB archive without holding a single SCCM role.&lt;/p&gt;
&lt;p&gt;From there, the chain runs through three flaws Baso detailed publicly: a path-traversal bug he named &lt;strong&gt;CabSlip&lt;/strong&gt;, which lets files inside the CAB escape the extraction folder and write anywhere the service can reach; weak Authenticode validation that accepts any non-revoked code-signing certificate — including a $58 commercial one — because revocation checking is skipped on that path; and an insecurely loaded DLL&amp;nbsp;&lt;code&gt;adsource.dll&lt;/code&gt;, pulled in every few minutes by the SYSTEM-level &lt;code&gt;smsexec.exe&lt;/code&gt; (SMS Executive) process. Planting a malicious &lt;code&gt;adsource.dll&lt;/code&gt; in the install directory turns the file write into reliable SYSTEM code execution on the site server. It mirrors the partial-fix pattern seen in Microsoft's recent &lt;a href="https://www.cyberkendra.com/2026/08/cve-2026-63520-sharepoint-rce-patched.html" target="_blank"&gt;SharePoint RCE chain (CVE-2026-63520)&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;Which SCCM Versions Are Affected?&lt;/h2&gt;
&lt;table border="1" cellpadding="8" cellspacing="0"&gt;
&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Configuration Manager (current branch)&lt;/th&gt;&lt;th&gt;Status&lt;/th&gt;&lt;th&gt;Fix&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;&lt;td&gt;Version 2603&lt;/td&gt;&lt;td&gt;Affected&lt;/td&gt;&lt;td&gt;KB38232642 (in-console)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Version 2509&lt;/td&gt;&lt;td&gt;Affected&lt;/td&gt;&lt;td&gt;Second 2509 update rollup (KB37864969)&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;Version 2503&lt;/td&gt;&lt;td&gt;Affected&lt;/td&gt;&lt;td&gt;KB38232642, requires rollup KB32851084&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;h2&gt;Has Microsoft Patched It?&lt;/h2&gt;
&lt;p&gt;Microsoft addressed the broken-access flaw in &lt;a href="https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642" rel="nofollow" target="_blank"&gt;hotfix&lt;/a&gt; &lt;strong&gt;KB38232642&lt;/strong&gt;, available in the Updates and Servicing node for version 2603, for 2503 with update rollup KB32851084 installed, and rolled into the second 2509 update rollup — no separate out-of-band hotfix is needed there. The update requires no computer restart or site reset.&lt;/p&gt;
&lt;p&gt;The fix removes the any-domain-user route, but not the chain. The other three flaws stay unpatched until &lt;strong&gt;ConfigMgr 2609&lt;/strong&gt;, expected in October 2026. A user holding the built-in &lt;strong&gt;Operations Administrator&lt;/strong&gt; role — or any custom role with Create (1024) on &lt;code&gt;SMS_ConsoleExtensionData&lt;/code&gt; — can still reach the same RCE through &lt;code&gt;UploadExtension&lt;/code&gt;. XM Cyber judges that route lower risk, since Operations Administrator is already a highly privileged role. It is the second time in weeks that Microsoft has shipped a fix that closes only part of a disclosed issue, after it left a &lt;a href="https://www.cyberkendra.com/2026/08/microsoft-leaves-windows-passkey-prompt.html" target="_blank"&gt;Windows passkey prompt spoofing flaw unaddressed&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;How to Detect SCCM CVE-2026-47301 Exploitation&lt;/h2&gt;
&lt;p&gt;Failed extraction attempts leave a trail. Check &lt;code&gt;&amp;lt;InstallationDir&amp;gt;\Logs\AdminService.log&lt;/code&gt; for a &lt;code&gt;System.IO.DirectoryNotFoundException&lt;/code&gt; followed by a &lt;code&gt;500 Internal Server Error&lt;/code&gt; — the folder GUID changes on each run, so match the pattern, not the exact string. Beyond that, forward SMS Provider and AdminService logs to your SIEM and alert on authenticated AdminService requests from non-administrative hosts, console role or security-scope changes made by low-privileged accounts, and unexpected new administrative assignments.&lt;/p&gt;
&lt;p&gt;There is no public report of in-the-wild exploitation, and the flaw is not in CISA's KEV catalog, though Baso's full exploit suite is on GitHub. Both Microsoft's guidance and the researcher recommend restricting access to the AdminService port on administrative subnets via a firewall as the most reliable containment measure until the chain is fully closed.&lt;/p&gt;

&lt;h2&gt;Frequently Asked Questions&lt;/h2&gt;
&lt;h3&gt;What is CVE-2026-47301?&lt;/h3&gt;
&lt;p&gt;It is a missing RBAC check in the SCCM AdminService's chunked console-extension upload endpoint, allowing any domain user to submit a CAB archive without an SCCM role. It is one link in a four-flaw RCE chain.&lt;/p&gt;
&lt;h3&gt;Does KB38232642 fully fix the SCCM RCE?&lt;/h3&gt;
&lt;p&gt;No. KB38232642 patches only CVE-2026-47301 — the broken-access entry point. The path traversal, weak signature check, and DLL hijack remain unpatched until ConfigMgr 2609 in October 2026.&lt;/p&gt;
&lt;h3&gt;Which SCCM versions need patching?&lt;/h3&gt;
&lt;p&gt;Configuration Manager current branch versions 2503 (with rollup KB32851084), 2509, and 2603.&lt;/p&gt;

&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What is CVE-2026-47301?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "CVE-2026-47301 is a missing RBAC check in the SCCM AdminService's chunked console-extension upload endpoint, letting any domain user submit a CAB archive with no SCCM role. It is one link in a four-flaw remote code execution chain disclosed by researcher Omri Baso."
      }
    },
    {
      "@type": "Question",
      "name": "Does KB38232642 fully fix the SCCM RCE?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. KB38232642 patches only CVE-2026-47301, the broken-access entry point. The path traversal, weak signature check and DLL hijack that complete the chain remain unpatched until Configuration Manager version 2609, expected October 2026."
      }
    },
    {
      "@type": "Question",
      "name": "Which SCCM versions are affected by CVE-2026-47301?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Microsoft Configuration Manager current branch versions 2503 (with update rollup KB32851084 installed), 2509, and 2603."
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8Cs4l1JNxaOMLaqLOFtrr-eNmHveAPhHeQ6s_aJ-cxLW1wPtTbVBgzK0efQndY08tEsyRSEQjVto7pkU6UaQtp6ml2hv5hpVQ-uvAomeB1GLriVqDETqd7ZpoHrT4PtPbvqBP7JpkS0IIeSM6rHuXEbq4rcELwKmw12YBWd654-ITBb19L-najGWdk2Y/s72-c/%F0%9D%97%96%F0%9D%97%A9%F0%9D%97%98-%F0%9D%9F%AE%F0%9D%9F%AC%F0%9D%9F%AE%F0%9D%9F%B2-%F0%9D%9F%B0%F0%9D%9F%B3%F0%9D%9F%AF%F0%9D%9F%AC%F0%9D%9F%AD.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Namecheap Outage Hits Hosting, DNS and Private Email</title><link>https://www.cyberkendra.com/2026/08/namecheap-outage-hits-hosting-dns-and.html</link><category>Internet</category><category>Namecheap</category><pubDate>Fri, 14 Aug 2026 00:25:46 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2078213034699037468</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Namecheap Down" border="0" data-original-height="737" data-original-width="1776" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHa4ccrCxSfYQ5PGrfiKqv90vM1R6erPWAPWTyPk5uuvZoGBat09OfnyAi3-2IFt4dgCjiUDltUqbHuNQ3-hMuxodVabZQdwLM55Vf0Oz51uHSmvUyOPODmibqxw2__IcXtLTySku9VUIeYu1QOzbRSx1jOoriSZnwpcAsnllpe4PiABwZB6eEClIkMN8/s1600/namecheap-down.webp" title="Namecheap Down" /&gt;&lt;/div&gt;
&lt;p class= 'note'&gt;&lt;strong&gt;INCIDENT RESOLVED &amp;mdash; updated 14 August 2026&lt;/strong&gt;&lt;br/&gt;
&lt;strong&gt;RESOLVED &amp;mdash; 14 August 2026, 17:00 UTC.&lt;/strong&gt; Namecheap has declared the incident closed. All hosting, EasyWP, DNS, Private Email and support services are back online after &lt;strong&gt;30 hours 32 minutes&lt;/strong&gt;.&lt;br/&gt;
The cause was a major storm that knocked out cooling at the RadiusDC Phoenix data center. RadiusDC instructed Namecheap to power services down to protect hardware. Namecheap reports no data loss and says it will add redundancy across its US, European and Asian data centers. Full &lt;a href="#updates"&gt;timeline and updates&lt;/a&gt; below.

&lt;p&gt;Websites, business email, and DNS for a large slice of Namecheap's customer base went dark on 13 August 2026 after the cooling system at the Phoenix data center hosting the company's core infrastructure failed. By Namecheap's own count, &lt;strong&gt;more than 5,000 servers&lt;/strong&gt; were taken offline — not by the failure itself, but by a deliberate shutdown to stop hardware cooking in a data hall that had lost its chillers.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The blast radius is wider than that of most outages at a hosting provider because Namecheap's authoritative DNS servers sit within the same failure domain. That means sites hosted elsewhere broke too, as long as their nameservers pointed to Namecheap. And because the support helpdesk lives in that same building, customers could not open a ticket to ask what was happening.&lt;/p&gt;

&lt;h2&gt;What Is Actually Broken&lt;/h2&gt;

&lt;p&gt;Namecheap's status post explicitly lists the affected services. This is the full scope as the company described it:&lt;/p&gt;
&lt;div class="table noWrap w100"&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;th&gt;Service&lt;/th&gt;
&lt;th&gt;Reported impact&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;namecheap.com&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Site under emergency maintenance; account dashboard unreachable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Shared, VPS &amp;amp; Dedicated hosting&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Sites unavailable, slow, or returning 503 errors; cPanel/hosting panel inaccessible&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Namecheap DNS&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Zone resolution &lt;em&gt;and&lt;/em&gt; zone management unavailable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;EasyWP&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Entire platform affected — EasyWP.com, the dashboard, and customer sites&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Private Email&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Intermittent; incoming and outgoing delivery both disrupted&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Mail forwarding&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Free Email Forwarding and Domain Privacy forwarding both hit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;URL Redirect&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Affected on both BasicDNS and PremiumDNS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Support helpdesk&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Unable to process email tickets; live chat pushed as the fallback&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Hosting operations&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Activations, renewals, and plan changes are being processed with delays&lt;/td&gt;
&lt;/tr&gt;
  &lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;p&gt;One detail from the original advisory went largely unreported: with both live chat and email ticketing down, Namecheap moved customer support to &lt;strong&gt;Microsoft Teams&lt;/strong&gt;, publishing a list of backup Teams accounts split by department — separate handles for domains, hosting, SSL, transfers, managed WordPress, Private Email, billing and abuse. It was an improvised channel for an outage that had taken out the normal ones, and most customers never saw it because the page announcing it was itself hard to reach.&lt;/p&gt;

&lt;p&gt;Independent outage trackers put the user-reported breakdown at roughly 60% hosting, 30% domains, and 10% cloud services, with reports arriving from Mexico, Vietnam, Uruguay, and across Europe — consistent with a single-origin failure rather than a regional network problem. Live user reports are aggregated on &lt;a href="https://downbits.com/services/namecheap" target="_blank"&gt;Downbits' Namecheap status page&lt;/a&gt;, which also lets you file a report if your own services are affected.&lt;/p&gt;

&lt;h2&gt;Timeline of the Namecheap Outage&lt;/h2&gt;

&lt;p&gt;All times below are UTC, with Indian Standard Time in brackets. The sequence matters because the data center operator flagged the problem roughly two hours before Namecheap told customers anything.&lt;/p&gt;
&lt;div class="table noWrap w100"&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;th&gt;Time&lt;/th&gt;
&lt;th&gt;Event&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;10:28 UTC (15:58 IST)&lt;/td&gt;
&lt;td&gt;PhoenixNAP opens an incident titled “Higher ambient temperature in the Phoenix DC”, noting no critical service impact&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11:28 UTC (16:58 IST)&lt;/td&gt;
&lt;td&gt;PhoenixNAP moves the incident to &lt;em&gt;Identified&lt;/em&gt;, warning that the equipment may reboot&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;11:42 UTC (17:12 IST)&lt;/td&gt;
&lt;td&gt;Namecheap posts a separate notice about EasyWP servers being unreachable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;~12:20 UTC (17:50 IST)&lt;/td&gt;
&lt;td&gt;Third-party trackers register the start of mass user reports&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12:35 UTC (18:05 IST)&lt;/td&gt;
&lt;td&gt;Namecheap publishes its emergency maintenance status post, citing a power outage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;~12:40 UTC (18:10 IST)&lt;/td&gt;
&lt;td&gt;Namecheap confirms the disruption on X; states there is no ETA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13:04 UTC (18:34 IST)&lt;/td&gt;
&lt;td&gt;PhoenixNAP reports its facilities team is working with an on-site vendor, still no ETA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Later, 13 Aug&lt;/td&gt;
&lt;td&gt;CEO Hillan Klein states 2 of 4 chillers are back, temperatures are dropping, and a third is expected within roughly three hours&lt;/td&gt;
&lt;/tr&gt;
  &lt;tr&gt;
&lt;td&gt;21:30 UTC (03:00 IST, 14 Aug)&lt;/td&gt;
&lt;td&gt;Status page confirms core databases, core virtualisation, most core network equipment, internal source control and all major load balancers back online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;22:10 UTC (03:40 IST, 14 Aug)&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Namecheap.com and Live Chat back online&lt;/strong&gt; &amp;mdash; 11 hours 42 minutes after the first data centre alert&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;23:50 UTC (05:20 IST, 14 Aug)&lt;/td&gt;
&lt;td&gt;Account access, domains and DNS management restored. Shared hosting past 50%, VPS past 30%, dedicated servers returning. Email still down, no ETA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td&gt;01:34 UTC, 14 Aug (07:04 IST)&lt;/td&gt;
&lt;td&gt;Email help system up. Private Email sending and receiving operational on legacy and new plans. Dedicated servers fully back. VPS past 90%, shared hosting past 80%. EasyWP.com and Dashboard operational, client websites still affected&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;03:00 UTC, 14 Aug (08:30 IST)&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;All affected VPS packages up and running.&lt;/strong&gt; Shared and reseller hosting past 90%. Many EasyWP client sites accessible; sites on two named ALIAS records still affected&lt;/td&gt;
&lt;/tr&gt;
  
  &lt;tr&gt;
&lt;td&gt;07:50 UTC, 14 Aug (13:20 IST)&lt;/td&gt;
&lt;td&gt;All EasyWP services up. Shared and Reseller Hosting fully back online. Namecheap begins reviewing all services&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;09:05 UTC (14:35 IST)&lt;/td&gt;
&lt;td&gt;MySQL stopped for maintenance on Premium Server 126 and Premium Server 247; sites on those hosts show database errors. Window given as 4–6 hours per host&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;12:55 UTC (18:25 IST)&lt;/td&gt;
&lt;td&gt;Some VPS and dedicated servers found still unreachable or returning 503 errors; VPS investigated globally, dedicated case by case&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;13:19–13:34 UTC (18:49–19:04 IST)&lt;/td&gt;
&lt;td&gt;MySQL recovered on both Premium Servers, with no data loss&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;15:15 UTC (20:45 IST)&lt;/td&gt;
&lt;td&gt;All affected VPS Hosting packages back online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="background:#e8f5e9;"&gt;
&lt;td&gt;17:00 UTC (22:30 IST)&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Namecheap declares the incident resolved&lt;/strong&gt; — 30 hours 32 minutes after the first data centre alert&lt;/td&gt;
&lt;/tr&gt;
  &lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;How Long Was Namecheap Down?&lt;/h2&gt;

&lt;p&gt;For the main site, &lt;strong&gt;11 hours 42 minutes&lt;/strong&gt; &amp;mdash; from PhoenixNAP's first temperature alert at 10:28 UTC on 13 August to Namecheap confirming namecheap.com back online at 22:10 UTC. Measured from Namecheap's own first customer notice at 12:35 UTC, it is 9 hours 35 minutes.&lt;/p&gt;

&lt;p&gt;End to end, the incident ran &lt;strong&gt;30 hours 32 minutes&lt;/strong&gt; — from 10:28 UTC on 13 August to Namecheap declaring it resolved at 17:00 UTC on 14 August. Measured from Namecheap's own first customer notice, 28 hours 25 minutes.&lt;/p&gt;

&lt;p&gt;Recovery was staggered, so no single number describes what any given customer experienced. Live Chat was unreachable for roughly ten hours. Namecheap.com returned at 11 hours 42 minutes. EasyWP client sites took until 07:50 UTC on 14 August. Some VPS and dedicated servers were still unreachable at 12:55 UTC, more than 26 hours in, and shared hosting customers on two Premium Servers hit a fresh database outage on the second day. If you need a figure for an SLA claim, use your own monitoring timestamps rather than any headline number.&lt;/p&gt;

&lt;h2&gt;Restoration Progress by Service&lt;/h2&gt;
&lt;div class="table noWrap w100"&gt;
&lt;table style="width:100%;border-collapse:collapse;margin:16px 0;font-size:15px;"&gt;
&lt;tr style="background:#f4f4f4;"&gt;
&lt;th style="text-align:left;padding:10px;border:1px solid #ddd;"&gt;Service&lt;/th&gt;
&lt;th style="text-align:left;padding:10px;border:1px solid #ddd;"&gt;Status&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;namecheap.com&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Online since 22:10 UTC. Account access, domains and DNS management restored&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Live Chat&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Online since 22:10 UTC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Email help system&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Up and running &amp;mdash; ticket submission working again&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Dedicated Servers&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Back online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;VPS Hosting&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;All affected packages up and running&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Shared Hosting&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;More than 90% back online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Reseller Hosting&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;More than 90% back online&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Private Email&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Outgoing and incoming delivery operational on legacy and new plans (Launch, Scale, Expand). Outage-period mail may still arrive delayed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="background:#fff8e1;"&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;EasyWP&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Partly affected.&lt;/strong&gt; EasyWP.com and Dashboard fully operational, many client sites accessible. Sites on two specific ALIAS records still down&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;&lt;strong&gt;Spaceship VPS, Shared &amp;amp; Spacemail&lt;/strong&gt;&lt;/td&gt;
&lt;td style="padding:10px;border:1px solid #ddd;"&gt;Back online&lt;/td&gt;
  &lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Everything in the table above is now restored. Recovery ran roughly in inverse order of abstraction: raw dedicated hardware and VPS returned first, shared and reseller hosting followed, and EasyWP — the most heavily managed platform, with the most layers between customer and metal — came last, in two stages.&lt;/p&gt;

&lt;h2 id="easywp"&gt;EasyWP Database Connection Errors Explained&lt;/h2&gt;

&lt;p&gt;EasyWP recovered in two stages, and the gap between them confused a lot of customers. EasyWP.com and the Dashboard came back at 01:34 UTC while client websites were still down — so people logged in, saw their site listed as running, loaded the domain, and got nothing.&lt;/p&gt;

&lt;p&gt;At 03:00 UTC Namecheap did something unusually specific: it named the exact infrastructure still affected. Sites pointed at these ALIAS records were the ones returning &lt;em&gt;Error establishing a database connection&lt;/em&gt;:&lt;/p&gt;
&lt;div class="table noWrap w100"&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;th&gt;ALIAS record&lt;/th&gt;
&lt;th&gt;Resolves to&lt;/th&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ingress-baronn.ewp.live&lt;/td&gt;
&lt;td&gt;63.250.43.9 | 63.250.43.10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ingress-cinna.ewp.live&lt;/td&gt;
&lt;td&gt;63.250.43.11 | 63.250.43.12&lt;/td&gt;
&lt;/tr&gt;
  &lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;All EasyWP services were confirmed fully restored at 07:50 UTC on 14 August. If your EasyWP site is still unreachable now, it falls outside what Namecheap has described and is worth a ticket rather than self-diagnosis.&lt;/p&gt;

&lt;p&gt;Two separate MySQL incidents followed on shared hosting: Premium Server 126 and Premium Server 247 had MySQL stopped for maintenance at 09:05 UTC, with sites on those hosts showing database errors for several hours. Both recovered by 13:34 UTC, and Namecheap confirmed no data was lost in either case.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Do not restore from a backup.&lt;/strong&gt; Your files and database are almost certainly intact; the serving layer is what is missing. A restore solves nothing and risks overwriting good data with older data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do not delete and recreate the site&lt;/strong&gt; from the dashboard.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do not repoint DNS away from EasyWP&lt;/strong&gt; mid-restoration. You will chase propagation for hours on a site that would have come back on its own.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do not reinstall plugins or WordPress core&lt;/strong&gt; to fix a site you cannot reach.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Restoring from a backup during that window was the single worst thing an affected owner could have done. A database connection error means the database layer is unreachable, not that data is damaged &amp;mdash; a restore would have overwritten intact data with older data for no benefit.&lt;/p&gt;

&lt;h2&gt;What Actually Caused the Namecheap Outage&lt;/h2&gt;

&lt;p&gt;During the incident Namecheap gave customers two different causes, and the discrepancy went uncorrected for more than a day. Its post-incident communication finally reconciled them.&lt;/p&gt;

&lt;p&gt;One naming note worth clearing up first, because coverage has split on it. The facility is the same building under two names: RadiusDC acquired PhoenixNAP's Phoenix data center and colocation business in a deal announced on 12 March 2026, with the site becoming RadiusDC's Phoenix I campus and PhoenixNAP remaining as a tenant. That is why PhoenixNAP's own status page logged the same ambient-temperature incident while Namecheap's communications name RadiusDC. There is no indication the ownership change contributed to the failure.&lt;/p&gt;

&lt;p&gt;The status post and the company's X account both attribute the incident to &lt;a href="https://www.namecheap.com/status-updates/namecheap-com-and-hosting-services-emergency-maintenance-2/" rel="nofollow" target="_blank"&gt;“emergency maintenance due to a power outage affecting our datacenter in Phoenix”&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Namecheap CEO Hillan Klein, posting publicly the same day, described something different: an infrastructure incident at PhoenixNAP where &lt;a href="https://x.com/NamecheapCEO/status/2087931259389464611" rel="nofollow" target="_blank"&gt;“the facility has suffered a failure of its cooling systems”&lt;/a&gt;. He said Namecheap then chose to power services down to prevent overheating and long-term hardware damage.&lt;/p&gt;

&lt;p&gt;PhoenixNAP's own status page supports the CEO's version, not the status post's. Its incident is titled around ambient temperature, and its updates describe chillers and a cooling vendor — there is no mention of a utility power failure.&lt;/p&gt;

&lt;p&gt;Namecheap's post-incident communication settled it. A major storm knocked out cooling at the RadiusDC Phoenix facility, driving temperatures to unsafe levels. That reconciles both accounts: a storm-driven power event took the chillers down, and the chiller loss forced a thermal shutdown.&lt;/p&gt;

&lt;p&gt;Two details from that account correct what was reported during the incident, including here. First, the decision to power down was not Namecheap's own call &amp;mdash; &lt;strong&gt;RadiusDC instructed Namecheap to take services offline&lt;/strong&gt; to protect customer infrastructure. Second, staying offline until conditions were safe was itself part of the recovery strategy, not just a consequence of the failure.&lt;/p&gt;

&lt;p&gt;The distinction between a power outage and a cooling failure was never academic. A power outage implies infrastructure that returns when the lights do. A thermal shutdown is slower, because you cannot safely repower thousands of servers until the hall has actually cooled. That is why this ran for a day and a quarter rather than minutes.&lt;/p&gt;

&lt;p&gt;Namecheap's status post was also quietly revised. It originally attributed the incident to a power outage; the current version describes a cooling failure. No correction notice was attached to the change.&lt;/p&gt;

&lt;h2&gt;No, There Is No Confirmed DDoS Attack&lt;/h2&gt;

&lt;p&gt;Several outlets and aggregator sites have published headlines pairing this outage with a distributed denial-of-service attack. Some framed it as Namecheap being hit by a DDoS &lt;em&gt;and&lt;/em&gt; a power outage simultaneously.&lt;/p&gt;

&lt;p&gt;Cyber Kendra checked every primary source available for this incident: Namecheap's status post, its X account, its CEO's public statement, and PhoenixNAP's status page. &lt;strong&gt;None of them mentions a DDoS attack.&lt;/strong&gt; Every official account points to a facility-level cooling or power problem.&lt;/p&gt;

&lt;p&gt;The DDoS framing appears to be a carryover from a separate Namecheap incident in February 2024, when the company confirmed a DDoS affecting its main site and support systems. It has also experienced DDoS-related disruption on a dedicated server earlier in 2026. Those were real events. They are not this one.&lt;/p&gt;

&lt;p&gt;Some customers on social platforms have alleged that Namecheap initially communicated a DDoS before switching to the power-outage explanation. Cyber Kendra has not been able to verify that claim against any archived Namecheap communication, and it should be treated as unconfirmed. If you are reading a report that attributes this outage to an attack, check whether it cites a Namecheap source or another news article.&lt;/p&gt;

&lt;h2&gt;Will I Lose Email, Files, or Data?&lt;/h2&gt;

&lt;p&gt;On email, Namecheap has been specific, and the explanation is technically sound. Mail sent to affected addresses during the outage is not expected to be lost. When a receiving mail server is unreachable, the sending server queues the message and automatically retries over a period that can last for days. Once connectivity returns, the backlog delivers. What you should expect is &lt;strong&gt;delay, not loss&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The exceptions worth knowing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Senders whose mail servers give up early, or which bounce on the first timeout, may generate a delivery failure notice. Those messages will not arrive on their own.&lt;/li&gt;
&lt;li&gt;Anything time-sensitive that routed through Namecheap forwarding — password resets, OTPs, payment confirmations, calendar invites — may arrive too late to be usable, even if it eventually arrives.&lt;/li&gt;
&lt;li&gt;Mail you were composing in webmail at the moment of the cutoff is gone unless it was saved as a draft on the server.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;My Namecheap inbox is empty. Are my old emails gone?&lt;/h3&gt;

&lt;p&gt;As services returned, multiple users reported logging into webmail successfully and finding their mail missing. One asked CEO Hillan Klein publicly whether a day of incoming mail was simply gone, then confirmed after his reply that login and iOS access worked normally while nothing arrived.&lt;/p&gt;

&lt;p&gt;Klein's answer at the time was that email services were not fully back and mail would be restored once the remaining infrastructure came up. That is what happened. A staged restart brings authentication and webmail front-ends back before the mail storage behind them, so a login succeeds against a mail store that is not yet online and presents as an empty inbox. It was not deleted mail. Private Email is now sending and receiving on both legacy and new plans.&lt;/p&gt;

&lt;div style="background:#e8f5e9;border-left:4px solid #2e7d32;padding:14px 16px;margin:16px 0;border-radius:4px;"&gt;
&lt;p style="margin:0 0 8px;"&gt;&lt;strong&gt;If your mailbox still looks wrong:&lt;/strong&gt;&lt;/p&gt;
&lt;ul style="margin:0;padding-left:20px;"&gt;
&lt;li&gt;Give it time. Namecheap says outage-period mail may still be delayed, and queued backlogs from external senders deliver over hours, not seconds.&lt;/li&gt;
&lt;li&gt;Do not delete and re-add the account in Outlook, Thunderbird or Apple Mail while a backlog is landing &amp;mdash; your client's local cache may hold the most complete copy.&lt;/li&gt;
&lt;li&gt;If you use POP3 without leaving copies on the server, your local store is the authoritative copy. Back it up before touching anything.&lt;/li&gt;
&lt;li&gt;Shared hosting mailboxes are separate from Private Email. If your hosting is in the remaining percentage, your mail is too.&lt;/li&gt;
&lt;li&gt;If mail is still missing once the backlog settles, raise a ticket &amp;mdash; the email help system is working again.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;

&lt;h3&gt;What about my website data?&lt;/h3&gt;

&lt;p&gt;On hosting data, a thermal shutdown is a controlled power-down, which is the safest kind. Namecheap has not reported data loss and has not indicated that any storage was damaged. That said, an unplanned shutdown of thousands of machines can leave individual databases in an inconsistent state on restart. When your site comes back, check that recent writes — orders, form submissions, new posts — are actually present before assuming everything restored cleanly.&lt;/p&gt;

&lt;h2&gt;What Namecheap Users Should Do Right Now&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Do not start a domain transfer yet.&lt;/strong&gt; Transfers need working registrar systems and a reachable admin email. With mail backlogs still clearing, an auth code or approval message can arrive late enough to stall the transfer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Do not change nameservers in a panic.&lt;/strong&gt; A half-applied nameserver switch during propagation can extend your downtime well past the outage itself.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Support is working again.&lt;/strong&gt; Email ticketing was down for most of the incident and live chat was the only channel. Both are restored, so a ticket is now the better route for anything needing a paper trail &amp;mdash; particularly an SLA credit request.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tell your own customers before they tell you.&lt;/strong&gt; If you host client sites, a short factual notice naming the upstream cause protects you far better than silence. Link to the vendor status page, not to your own guesswork.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Screenshot everything.&lt;/strong&gt; Uptime monitor logs, error pages, timestamps, and lost transaction records. If you intend to ask for a credit, the case is built on evidence you collect now, not on your recollection next week.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check your recent data once you are back.&lt;/strong&gt; Verify the last few hours of database writes before the outage, and confirm scheduled jobs and cron tasks resumed.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;The Design Decision That Made This Worse&lt;/h2&gt;

&lt;p&gt;Most coverage of this outage stops at “data center had a problem”. The more useful question is why a single facility could take out this much surface area at once.&lt;/p&gt;

&lt;p&gt;Namecheap has been a major tenant of the same Phoenix building for years, first under PhoenixNAP and now under RadiusDC. In its own public post-mortem after a 2018 outage at the same facility, the company described itself as one of the site's largest tenants, drawing around half a megawatt and running thousands of servers there. The 5,000-plus figure cited this week suggests that concentration has not meaningfully changed.&lt;/p&gt;

&lt;p&gt;Concentrating hosting in one well-run facility is a defensible business decision. Concentrating &lt;em&gt;authoritative DNS&lt;/em&gt; in the same failure domain as the hosting it serves is a different matter. DNS is the one service in the stack that is supposed to be geographically distributed precisely so that it survives the loss of any single site. When Namecheap DNS went down, it did not just break Namecheap-hosted sites — it broke every site anywhere in the world whose nameservers pointed at Namecheap, including sites hosted on entirely unaffected providers.&lt;/p&gt;

&lt;p&gt;The support helpdesk sitting in the same building compounds the problem. The moment customers most needed to reach Namecheap was the moment Namecheap could not receive tickets. Status communication then falls back to X, which is not where most customers look first.&lt;/p&gt;

&lt;p&gt;For readers who host with Namecheap, the practical takeaway is narrower than “switch providers”. It is this: &lt;strong&gt;your DNS provider and your hosting provider should not be the same company on the same site.&lt;/strong&gt; Moving authoritative DNS to an independent, anycast provider costs nothing on most free tiers and decouples the two largest failure modes you are exposed to. Had that separation been in place, a large share of the sites that broke this week would have remained resolvable, served an error from their origin, and been fixable with a temporary redirect.&lt;/p&gt;

&lt;h2&gt;Namecheap's Track Record at Phoenix&lt;/h2&gt;

&lt;p&gt;This is not the first significant incident at the same facility, and the pattern is part of why the reaction from longtime customers was so sharp.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;November 2018&lt;/strong&gt; — A power failure at PhoenixNAP during UPS maintenance caused route flapping on Namecheap's core network. The company published a detailed post-mortem noting that some non-critical infrastructure was not designed to be power-redundant.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;August 2020&lt;/strong&gt; — A prolonged outage hit namecheap.com, shared hosting, VPS, EasyWP, and Private Email; Namecheap ultimately attributed it to a third-party upstream provider.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;September 2021&lt;/strong&gt; — A misconfiguration during network expansion triggered a network storm that took down a redundant firewall cluster. Namecheap's post-mortem conceded that its first response had been based on an incorrect assumption, costing it hours.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;February 2024&lt;/strong&gt; — A confirmed DDoS campaign affected the main site and customer support.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;July 2026&lt;/strong&gt; — Shared and VPS hosting in Phoenix experienced timeouts, with restoration staged across servers.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Read together, these are not all the same failure. But four of the five involve the Phoenix footprint, and the recurring theme in Namecheap's own post-mortems is redundancy that existed on paper failing to hold at the edges.&lt;/p&gt;

&lt;h2&gt;What Namecheap Says It Will Change&lt;/h2&gt;

&lt;p&gt;In the email sent to customers after resolution, Namecheap committed to examining the incident in detail and adding &lt;strong&gt;further redundancy across its data centers in the US, Europe and Asia&lt;/strong&gt;. It also said it would publish what it learns and the actions it takes.&lt;/p&gt;

&lt;p&gt;That is the right response to this failure mode, and it is worth holding the company to. The problem this outage exposed was not that a data center failed — data centers fail — but that too much sat in one of them, including services like authoritative DNS that exist specifically to survive the loss of any single site. Geographic redundancy across three continents addresses exactly that, if it is implemented for DNS and not only for hosting.&lt;/p&gt;

&lt;p&gt;Namecheap published detailed post-mortems after its 2018 and 2021 incidents. Whether a comparable document follows this one is the thing to watch, and Cyber Kendra will update this page when it appears.&lt;/p&gt;

&lt;h2&gt;Can You Claim Compensation?&lt;/h2&gt;

&lt;p&gt;Namecheap had not announced any compensation, service credit, or SLA payout at the time of writing, and customers were publicly asking for one.&lt;/p&gt;

&lt;p&gt;What is worth knowing before you ask: hosting SLA credits generally have to be requested rather than applied automatically, are usually calculated as a proportion of the monthly fee rather than your business losses, and are typically defined in the hosting terms rather than the general terms of service. Read the SLA terms attached to your specific plan — shared, VPS, dedicated, and EasyWP are not necessarily covered identically — and file the request through the ticket system once it is processing email again, with your monitoring logs attached.&lt;/p&gt;

&lt;p&gt;Cyber Kendra is not a legal advisor, and consequential losses from downtime are usually excluded by hosting contracts. If the sums involved are material to your business, that is a conversation for a lawyer rather than a support ticket.&lt;/p&gt;

&lt;h2&gt;Frequently Asked Questions&lt;/h2&gt;

&lt;h3&gt;Is Namecheap down right now?&lt;/h3&gt;
&lt;p&gt;Almost fully restored. Namecheap.com, Live Chat, the email help system, DNS management and Private Email are back. All affected VPS packages are running, dedicated servers are restored, and shared and reseller hosting are past 90%. Some EasyWP client websites remain affected. Namecheap has not declared the incident fully resolved. For crowd-sourced reports from other users, see &lt;a href="https://downbits.com/services/namecheap"&gt;Downbits&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;Why is Namecheap down?&lt;/h3&gt;
&lt;p&gt;A major storm knocked out cooling at the RadiusDC Phoenix data center, driving temperatures to unsafe levels. RadiusDC instructed Namecheap to take services offline to protect hardware, taking more than 5,000 servers down. The facility was acquired from PhoenixNAP earlier in 2026, which is why both names appear in coverage.&lt;/p&gt;

&lt;h3&gt;Was Namecheap hacked or hit by a DDoS attack?&lt;/h3&gt;
&lt;p&gt;No primary source from Namecheap or PhoenixNAP describes an attack for this incident. Reports linking it to a DDoS appear to conflate it with a separate, confirmed February 2024 Namecheap incident.&lt;/p&gt;

&lt;h3&gt;Will I lose emails sent during the Namecheap outage?&lt;/h3&gt;
&lt;p&gt;Namecheap says messages are not expected to be lost. Sending mail servers queue and retry automatically, so mail should deliver late rather than disappear. Hard bounces from senders that give up early are the exception.&lt;/p&gt;

&lt;h3&gt;Why is my Namecheap email inbox empty after the outage?&lt;/h3&gt;
&lt;p&gt;Email infrastructure was restored in stages, so webmail login returned before the mail storage behind it. That produced mailboxes that opened but appeared empty. Private Email is now sending and receiving on both legacy and new plans, though outage-period mail may still arrive delayed.&lt;/p&gt;

&lt;h3&gt;How long was Namecheap down?&lt;/h3&gt;
&lt;p&gt;30 hours 32 minutes end to end, from the first data centre alert at 10:28 UTC on 13 August to Namecheap declaring resolution at 17:00 UTC on 14 August. The main site itself was unreachable for 11 hours 42 minutes; EasyWP and some VPS and dedicated servers took considerably longer.&lt;/p&gt;

&lt;h3&gt;My EasyWP site shows “Error establishing a database connection”. Why?&lt;/h3&gt;
&lt;p&gt;Because your site sits on one of two ingress groups Namecheap has confirmed are still affected: ingress-baronn.ewp.live (63.250.43.9, 63.250.43.10) and ingress-cinna.ewp.live (63.250.43.11, 63.250.43.12). Run a DNS lookup on your domain to check. If it resolves to one of those addresses, it is a Namecheap-side problem &amp;mdash; do not restore from backup, recreate the site or repoint DNS.&lt;/p&gt;

&lt;h3&gt;Are my domain registrations at risk?&lt;/h3&gt;
&lt;p&gt;Domain registration records are stored at the registry, not on Namecheap's hosting servers, so ownership is unaffected by a data center outage. Renewals and transfers processed during the window may be delayed.&lt;/p&gt;

&lt;h3&gt;My site is hosted elsewhere, but it still went down. Why?&lt;/h3&gt;
&lt;p&gt;Because your domain's nameservers point at Namecheap DNS. Namecheap's authoritative DNS was in the same failure domain as its hosting, so name resolution failed regardless of where the site was served.&lt;/p&gt;

&lt;h3&gt;Should I move my domain away from Namecheap?&lt;/h3&gt;
&lt;p&gt;Moving registration mid-incident is more likely to create problems than solve them. The higher-value change, once services are stable, is to separate DNS from hosting so that a single provider outage cannot break both at once.&lt;/p&gt;

&lt;hr /&gt;
&lt;h2 id="updates"&gt;Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;2026-08-14, 17:00 UTC&lt;/strong&gt; &amp;mdash; &lt;strong&gt;Resolved.&lt;/strong&gt; Namecheap declared the incident closed, 30 hours 32 minutes after the first data centre alert. Cause confirmed as a major storm knocking out cooling at the RadiusDC Phoenix data center, with RadiusDC instructing Namecheap to power services down. No data loss reported. Namecheap has committed to adding redundancy across its US, European and Asian data centers. No compensation announcement; no post-incident report yet.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2026-08-14, 15:15 UTC&lt;/strong&gt; &amp;mdash; All affected VPS Hosting packages back online.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2026-08-14, 07:50 UTC&lt;/strong&gt; &amp;mdash; All EasyWP services restored. Shared and Reseller Hosting fully back. Separate MySQL maintenance on two Premium Servers followed, recovered by 13:34 UTC with no data loss.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2026-08-14, 03:00 UTC&lt;/strong&gt; &amp;mdash; All affected VPS Hosting packages up and running.

&lt;p&gt;&lt;strong&gt;2026-08-13&lt;/strong&gt; &amp;mdash; Article published during the active outage.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #666666;"&gt;&lt;span style="font-size: 14px;"&gt;&lt;b&gt;This page is updated as the incident progresses. Bookmark it rather than searching again.&amp;nbsp;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;strong style="color: #666666; font-size: 14px;"&gt;Disclosure:&lt;/strong&gt;&lt;span style="color: #666666;"&gt;&lt;span style="font-size: 14px;"&gt; Downbits, linked above, is operated by Cyber Kendra.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;




&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Is Namecheap down right now?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. Namecheap declared the incident resolved at 17:00 UTC on 14 August 2026. All hosting, EasyWP, DNS, Private Email and support services are back online."
      }
    },
    {
      "@type": "Question",
      "name": "Why was Namecheap down?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A major storm knocked out cooling at the RadiusDC Phoenix data center, driving temperatures to unsafe levels. RadiusDC instructed Namecheap to take services offline to protect hardware, taking more than 5,000 servers down. The facility was acquired from PhoenixNAP earlier in 2026, which is why both names appear in coverage."
      }
    },
    {
      "@type": "Question",
      "name": "Was Namecheap hacked or hit by a DDoS attack?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No primary Namecheap or PhoenixNAP source describes an attack for this incident. Reports linking it to a DDoS appear to conflate it with a separate, confirmed February 2024 Namecheap incident."
      }
    },
    {
      "@type": "Question",
      "name": "Will I lose emails sent during the Namecheap outage?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Namecheap says messages are not expected to be lost. Sending mail servers queue and retry automatically, so mail should deliver late rather than disappear. Hard bounces from senders that give up early are the exception."
      }
    },
    {
      "@type": "Question",
      "name": "Why is my Namecheap email inbox empty after the outage?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Email infrastructure was restored in stages, so webmail login returned before the mail storage behind it. That produced mailboxes that opened but appeared empty. Private Email is now sending and receiving on both legacy and new plans, though outage-period mail may still arrive delayed."
      }
    },
    {
      "@type": "Question",
      "name": "How long was Namecheap down?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "The main site was unreachable for 11 hours 42 minutes, from PhoenixNAP's first alert at 10:28 UTC on 13 August to namecheap.com returning at 22:10 UTC. Hosting, email and EasyWP took longer, with EasyWP client sites still affected afterwards."
      }
    },
    {
      "@type": "Question",
      "name": "My EasyWP site shows Error establishing a database connection. Why?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because your site sits on one of two ingress groups Namecheap has confirmed are still affected: ingress-baronn.ewp.live (63.250.43.9, 63.250.43.10) and ingress-cinna.ewp.live (63.250.43.11, 63.250.43.12). Run a DNS lookup on your domain to check. If it resolves to one of those addresses, it is a Namecheap-side problem &amp;mdash; do not restore from backup, recreate the site or repoint DNS."
      }
    },
    {
      "@type": "Question",
      "name": "Are my domain registrations at risk?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Domain registration records are held at the registry, not on Namecheap's hosting servers, so ownership is not affected by a data center outage. Renewals and transfers processed during the window may be delayed."
      }
    },
    {
      "@type": "Question",
      "name": "My site is hosted elsewhere but still went down. Why?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because your domain's nameservers point at Namecheap DNS. Namecheap's authoritative DNS was in the same failure domain as its hosting, so name resolution failed regardless of where the site itself was served from."
      }
    },
    {
      "@type": "Question",
      "name": "Should I move my domain away from Namecheap?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Moving registration mid-incident is more likely to create problems than solve them. The higher-value change, once services are stable, is separating DNS from hosting so a single provider outage cannot break both at once."
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHa4ccrCxSfYQ5PGrfiKqv90vM1R6erPWAPWTyPk5uuvZoGBat09OfnyAi3-2IFt4dgCjiUDltUqbHuNQ3-hMuxodVabZQdwLM55Vf0Oz51uHSmvUyOPODmibqxw2__IcXtLTySku9VUIeYu1QOzbRSx1jOoriSZnwpcAsnllpe4PiABwZB6eEClIkMN8/s72-c/namecheap-down.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Apple Warns iPhone Users of Mercenary Spyware Attacks</title><link>https://www.cyberkendra.com/2026/08/apple-threat-notification-mercenary-spyware.html</link><category>Apple</category><category>Privacy</category><category>Security</category><pubDate>Fri, 14 Aug 2026 09:23:36 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3241696481591955233</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Protect against mercenary spyware" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNMtbKNxgVs5-zcHBiYhursBhyiWuYi1EI1U9Tna11ILhUDk-yE_hJ2dAbnpJIbH2lJ3m4lS5F0fjMvb71FlBRr_V0W9Bh9u4ZFs6-UfgW68bEjiQI2vWkNpWsn1EPgUy60NOg2PeCAKsMEh9MOrc0mZgJguj4ZeZOI5NwQolTPqxY9hRCy64Akymq1gY/s1600/mercenary-spyware.webp" title="Protect against mercenary spyware" /&gt;&lt;/div&gt;&lt;p&gt;Apple sent a fresh round of mercenary spyware threat notifications to users in 110 countries on Thursday, and for the first time, the warning lands as a push alert on the iPhone Lock Screen instead of an email that can sit unread for a week. Apple confirmed the round's scale to TechCrunch and published a revised&amp;nbsp;support page describing the new delivery method the same day.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;The delivery change is the part that matters. Apple has issued these alerts since 2021 and has now reached users in more than 150 countries, but the warnings travelled through email, iMessage, and a banner buried on the Apple Account website — channels that at-risk people routinely miss, filter as spam, or dismiss as phishing. A Lock Screen banner backed by a permanent row in Settings removes that excuse. Whether someone acts on the alert is now a decision rather than an accident.&lt;/p&gt;

&lt;h2&gt;What Changed in How Apple Sends Threat Notifications&lt;/h2&gt;

&lt;p&gt;Apple's &lt;a href="https://support.apple.com/en-us/102174" rel="nofollow" target="_blank"&gt;updated support document&lt;/a&gt; lists four delivery channels for a threat notification:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;An &lt;strong&gt;Apple Threat Notification&lt;/strong&gt; alert on the iPhone Lock Screen&lt;/li&gt;
&lt;li&gt;A dedicated &lt;strong&gt;Apple Threat Notification&lt;/strong&gt; row near the top of Settings, carrying a red badge&lt;/li&gt;
&lt;li&gt;An &lt;strong&gt;email&lt;/strong&gt; from &lt;code&gt;threat-notifications@email.apple.com&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;banner&lt;/strong&gt; at the top of the user's Apple Account page after signing in at account.apple.com&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Two details on that page are easy to skim past. First, Apple states that notification types may vary by device model and software version, which means the Lock Screen alert is not guaranteed for everyone — users on older hardware or older iOS builds may still receive only the email notification. Second, Apple's current page no longer lists iMessage as a delivery channel, even though earlier rounds were sent that way. Apple told TechCrunch it had reworked the experience so that recipients can reach the recommended next steps more quickly.&lt;/p&gt;

&lt;p&gt;John Scott-Railton, a senior researcher at the University of Toronto's Citizen Lab, was the first to publicly flag the new round and described the push alerts as a significant improvement. He told TechCrunch that notifications &lt;a href="https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/" rel="nofollow noopener" target="_blank"&gt;"create a critical signal that a community is being targeted"&lt;/a&gt;, because a handful of recipients seek help, and those requests usually open investigations that surface far more victims than the original alert reached.&lt;/p&gt;

&lt;h2&gt;What the Apple Threat Notification Actually Says&lt;/h2&gt;

&lt;p&gt;The Lock Screen alert is titled &lt;strong&gt;Apple Threat Notification&lt;/strong&gt; and tells the recipient that "Apple detected a mercenary spyware attack targeted at your iPhone", followed by a line saying there are actions they can take now to help protect their data and device. Tapping it opens the full advisory with recommended steps, including enabling Lockdown Mode and contacting expert help.&lt;/p&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;img alt="Apple threat notification on the Lock Screen." border="0" data-original-height="663" data-original-width="951" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQS3IIIXIu8AEgaCe-u2qsr3u5bXwp-xSEn7h36E2vjoLLSEprAHVL0hvpTlmQGIwfNxdmcDjWzQGjigcSF1d-ghPyq7NIeJsXXrpaoy6-EMUqwepeZs5g9OS6bXI-Xl3SagnuagtgQ8Tnj6oMHjKMuCaLqk88qz5WfxFgqNS3QgDdXMGuBcmfubqNqM4/s1600/Apple%20threat%20notification.webp" style="margin-left: auto; margin-right: auto;" title="Apple threat notification on the Lock Screen." /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Apple threat notification on the Lock Screen | Image- Apple&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;Apple describes these as high-confidence alerts and says they should be taken very seriously, while conceding that its investigations can never reach absolute certainty. It will not explain what triggered any individual notification, because publishing detection criteria would allow spyware operators to tune their behavior to avoid detection. Apple also refuses to attribute the attacks to any government, company, or region — a deliberate position it has held through every round, including the politically explosive ones.&lt;/p&gt;

&lt;h2&gt;How to Tell a Real Apple Threat Notification From a Fake&lt;/h2&gt;

&lt;p&gt;This question matters more today than it did last week. The format of a genuine alert is now public, screenshots are circulating widely, and the population being targeted is exactly the population that will act quickly on a frightening message. Expect imitation — spoofed emails, forwarded WhatsApp screenshots, fake "spyware removal" services, and phishing pages built to look like the Apple Account banner.&lt;/p&gt;

&lt;p&gt;Apple's own rules make verification simple:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A real threat notification &lt;strong&gt;never&lt;/strong&gt; asks you to click a link, open a file, install an app or configuration profile, or supply your Apple Account password or a verification code — not by email, not on a phone call.&lt;/li&gt;
&lt;li&gt;To confirm one, type &lt;strong&gt;account.apple.com&lt;/strong&gt; into your browser yourself and sign in. If Apple sent you a notification, it appears as a banner at the top of the page. Do not use a link from the message you are checking.&lt;/li&gt;
&lt;li&gt;Check &lt;strong&gt;Settings&lt;/strong&gt; on the iPhone. A genuine notification creates its own row with a badge.&lt;/li&gt;
&lt;li&gt;The legitimate email comes from &lt;code&gt;threat-notifications@email.apple.com&lt;/code&gt;, but treat any sender address as weak evidence on its own. The account page is the check that settles it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Anyone who calls, messages, or emails offering to "clean" your device after an Apple alert should be treated as hostile until proven otherwise. Apple does not provide outbound support for this, and no one outside Apple knows why you were flagged.&lt;/p&gt;

&lt;h2&gt;What to Do If You Receive an Apple Threat Notification&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Do not factory reset the phone immediately.&lt;/strong&gt; A wipe destroys the forensic traces an investigator needs to confirm what happened. Digital security responders generally ask targets to preserve the device state first.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Turn on Lockdown Mode&lt;/strong&gt; — Settings &amp;gt; Privacy &amp;amp; Security &amp;gt; Lockdown Mode. Enable it on every Apple device signed into the same account, not just the iPhone.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Update to the current OS.&lt;/strong&gt; As of August 2026, that is iOS 26.6, released on 27 July. Turn on automatic updates if they are off.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Contact the Digital Security Helpline at Access Now.&lt;/strong&gt; It is free, runs 24 hours a day, seven days a week, and Apple points recipients to it by name. Outside organisations have no information about why Apple flagged you, but they can provide tailored advice and conduct a forensic analysis.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure the account from a different, trusted device.&lt;/strong&gt; Change the Apple Account password, review every device signed in, confirm your two-factor trusted numbers, and check Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management for configuration profiles you did not install.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Warn the people you talk to.&lt;/strong&gt; If a device was compromised, the exposure includes your conversations, which means it includes sources, colleagues and family who never got an alert of their own.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;A notification means Apple believes you were &lt;em&gt;targeted&lt;/em&gt;. It is not a confirmation that the attack succeeded. Both facts are worth holding at the same time.&lt;/p&gt;

&lt;h2&gt;Every Apple Threat Notification Round Since 2021&lt;/h2&gt;

&lt;p&gt;Apple has never published a running log of these rounds, so the picture has to be assembled from its support-page revisions and from the reporting each wave generated. Here is the sequence as it currently stands.&lt;/p&gt;

&lt;div style="overflow-x: auto;"&gt;
&lt;table style="border-collapse: collapse; font-size: 15px; width: 100%;"&gt;
&lt;thead&gt;
&lt;tr style="background: rgb(242, 242, 242);"&gt;
&lt;th style="border: 1px solid rgb(221, 221, 221); padding: 8px; text-align: left;"&gt;Date&lt;/th&gt;
&lt;th style="border: 1px solid rgb(221, 221, 221); padding: 8px; text-align: left;"&gt;Scope&lt;/th&gt;
&lt;th style="border: 1px solid rgb(221, 221, 221); padding: 8px; text-align: left;"&gt;Notable detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;November 2021&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;First round&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Programme launched weeks after Apple sued NSO Group; wording referred to "state-sponsored attackers"&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;31 October 2023&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Global, India prominent&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;More than 20 Indian opposition MPs and journalists went public, triggering a political confrontation in Delhi&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;10 April 2024&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;92 countries&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Apple switched its language from "state-sponsored attackers" to "mercenary spyware"&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;July 2024&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;98 countries&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Second round inside four months&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;29–30 April 2025&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;100 countries&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Italian journalist Ciro Pellegrino and Dutch activist Eva Vlaardingerbroek confirmed receiving alerts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Mid-2025&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;Iran&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;More than a dozen Iranian targets were alerted in the run-up to the war with Israel, as reported in July&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;&lt;strong&gt;13 August 2026&lt;/strong&gt;&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;&lt;strong&gt;110 countries&lt;/strong&gt;&lt;/td&gt;
&lt;td style="border: 1px solid rgb(221, 221, 221); padding: 8px;"&gt;&lt;strong&gt;First round delivered as an iPhone Lock Screen push; support page rewritten&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;/div&gt;

&lt;p&gt;Apple has never disclosed how many individuals it has notified in total, only how many countries they sit in. The country count has climbed every year the programme has run.&lt;/p&gt;

&lt;h2&gt;Does Lockdown Mode Actually Stop Mercenary Spyware?&lt;/h2&gt;

&lt;p&gt;The evidence is stronger than it was a year ago. In March 2026, an Apple spokesperson told TechCrunch the company is &lt;a href="https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/" rel="nofollow" target="_blank"&gt;not aware of any successful mercenary spyware attack&lt;/a&gt; against an Apple device with &lt;a href="https://www.cyberkendra.com/2022/07/apple-announced-lockdown-mode-on-ios-16.html" target="_blank"&gt;Lockdown Mode&lt;/a&gt; switched on — nearly four years after the feature shipped in iOS 16.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Donncha Ó Cearbhaill, who heads Amnesty International's Security Lab and has investigated dozens of these cases, said the same: there was no evidence that an iPhone was compromised while Lockdown Mode was active at the time of the attack. Citizen Lab has separately documented instances in which Lockdown Mode blocked live attempts, including one using &lt;a href="https://www.cyberkendra.com/2022/08/seifan-israel-polices-version-of.html" target="_blank"&gt;NSO Group's Pegasus&lt;/a&gt; and another using Predator.&lt;/p&gt;

&lt;p&gt;The most persuasive endorsement came from the attackers. When Google's Threat Intelligence Group dissected the &lt;a href="https://www.cyberkendra.com/2026/03/google-uncovers-coruna-ios-exploit-kit.html" target="_blank"&gt;Coruna iOS exploit kit&lt;/a&gt; in March 2026, it found the kit checks whether Lockdown Mode or private browsing is active and quietly declines to run if either is — a design choice that only makes sense if the operators expected to fail and did not want to burn their exploits proving it.&lt;/p&gt;

&lt;p&gt;The honest caveat: an absence of observed bypasses is not proof that none exist. Apple is tight-lipped, investigators see only what victims bring them, and a bypass held by one vendor against a handful of targets could stay invisible for years. What can be said with confidence is that Lockdown Mode removes entire classes of delivery — most message attachment types, several WebKit features, link previews, unsolicited FaceTime calls, configuration profile installation — and that shrinking the remotely reachable surface forces attackers into more expensive, more fragile chains.&lt;/p&gt;

&lt;p&gt;The cost to a normal user is real but modest: some links have to be copied into a browser manually, some attachments will not open, and shared albums stop working. For anyone who has received a threat notification, that trade is not close.&lt;/p&gt;

&lt;h2&gt;Why India Turns Up in Every Threat Notification Cycle&lt;/h2&gt;

&lt;p&gt;India has been the most politically charged destination for these alerts since 31 October 2023, when more than 20 opposition MPs and journalists said they had received them. The named recipients included Mahua Moitra of the Trinamool Congress, AIMIM chief Asaduddin Owaisi, Congress leaders Shashi Tharoor, Pawan Khera and Supriya Shrinate, Shiv Sena (UBT) MP Priyanka Chaturvedi, and &lt;em&gt;The Wire&lt;/em&gt; founding editor Siddharth Varadarajan.&lt;/p&gt;

&lt;p&gt;The government's response was to question the alerts rather than the targeting. IT ministry officials publicly cast doubt on Apple's findings and announced a CERT-In inquiry into device security. &lt;em&gt;The Washington Post&lt;/em&gt; subsequently reported that senior officials had summoned Apple representatives and pressed the company to offer alternative explanations for the warnings. Two months later, Amnesty International's Security Lab published forensic findings placing Pegasus on the iPhones of Indian journalists, including Varadarajan and Anand Mangnale of the Organized Crime and Corruption Reporting Project. When Apple ran its 92-country round in April 2024, Indian users were again among the recipients.&lt;/p&gt;

&lt;p&gt;The legal position has not moved much. The Pegasus petitions, heard as &lt;em&gt;Manohar Lal Sharma v. Union of India&lt;/em&gt;, remain before the Supreme Court, and the technical committee's report is still sealed. During hearings in April 2025 the bench observed orally that a country possessing spyware for security purposes is not itself objectionable and that the real question is who it is used against, while indicating the court may inform individuals whose privacy was breached rather than publish the report in full.&lt;/p&gt;

&lt;p&gt;Which leaves a practical asymmetry worth stating plainly. No Indian law requires anyone to tell you that your phone was targeted. There is no domestic notification mechanism, no regulator that issues these warnings, and no obligation on a telecom operator or agency to disclose after the fact. For an Indian journalist, lawyer or opposition worker, an Apple threat notification is very often the only notice they will ever get that someone spent money to read their messages.&lt;/p&gt;

&lt;h2&gt;What the Attacks Look Like in 2026&lt;/h2&gt;

&lt;p&gt;Two developments this year explain why Apple is pushing harder on delivery.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;February 2026 — &lt;a href="https://www.cyberkendra.com/2026/02/apple-rushes-patch-for-actively.html" target="_blank"&gt;CVE-2026-20700&lt;/a&gt;.&lt;/strong&gt; Apple patched a memory corruption flaw in &lt;code&gt;dyld&lt;/code&gt;, the dynamic linker that loads system libraries at runtime, in iOS 26.3 and the matching releases. Google's Threat Analysis Group reported it, and Apple's advisory said the issue may have been exploited in an &lt;a href="https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/" rel="nofollow" target="_blank"&gt;"extremely sophisticated attack against specific targeted individuals"&lt;/a&gt; on versions of iOS before iOS 26. Apple linked it to CVE-2025-14174 and CVE-2025-43529, the WebKit zero-days fixed in December 2025, indicating a chain rather than an isolated bug. CISA added it to the Known Exploited Vulnerabilities catalogue.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;March 2026 — the Coruna exploit kit.&lt;/strong&gt; Google's Threat Intelligence Group disclosed a JavaScript-delivered framework containing five complete iOS exploit chains and 23 individual exploits covering iOS 13.0 through 17.2.1. Its ownership history is the alarming part: GTIG tracked it from a commercial surveillance vendor's customer, to UNC6353, a suspected Russian espionage group running watering-hole attacks against Ukrainians, and finally to UNC6691, a financially motivated Chinese actor draining cryptocurrency wallets. iVerify called it the first observed mass exploitation against iOS devices. CISA added three of the underlying CVEs to KEV on 5 March.&lt;/p&gt;

&lt;p&gt;That trajectory is the real story of the year. A capability that cost millions and was reserved for a dozen targets ends up, a few resales later, spraying at anyone who visits the wrong website. The reasoning "I am not a journalist, so this does not concern me" held better in 2022 than it does now.&lt;/p&gt;

&lt;p&gt;Apple's structural answer arrived in September 2025 with &lt;a href="https://www.cyberkendra.com/2025/09/apple-unveils-advanced-spyware-with-new.html" target="_blank"&gt;Memory Integrity Enforcement&lt;/a&gt;, built on the A19 and A19 Pro chips in the iPhone 17 line and iPhone Air using Arm's Enhanced Memory Tagging Extension. It targets the memory-corruption class that every known iOS spyware chain has depended on, and Apple's argument is not that exploitation becomes impossible but that chains become too expensive and too fragile to maintain. That is a five-to-ten-year bet, and it does nothing for the hundreds of millions of older iPhones still in circulation, which is precisely the population Coruna went after.&lt;/p&gt;

&lt;h2&gt;Guidance for Everyone Who Did Not Get an Alert&lt;/h2&gt;

&lt;p&gt;Apple's position is that the vast majority of users will never be targeted by mercenary spyware, and that is accurate. Its baseline recommendations still apply:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Keep devices on the latest software, which carries the latest security fixes&lt;/li&gt;
&lt;li&gt;Protect the device with a passcode, Touch ID or Face ID&lt;/li&gt;
&lt;li&gt;Use two-factor authentication and a strong, unique Apple Account password&lt;/li&gt;
&lt;li&gt;Turn on Stolen Device Protection&lt;/li&gt;
&lt;li&gt;Install apps only from the App Store&lt;/li&gt;
&lt;li&gt;Use unique passwords and passkeys where available&lt;/li&gt;
&lt;li&gt;Do not open links or attachments from unknown senders&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;One addition of our own: turn on automatic updates and leave them on. The Coruna campaign showed that unpatched older iPhones are now bulk targets rather than individual ones, and the gap between a patch shipping and a device receiving it is the entire window an opportunistic operator needs.&lt;/p&gt;

&lt;p&gt;If you have not received a notification but have a concrete reason to believe you are a target — because of your reporting, your litigation, your organising or your office — Apple's advice is to enable Lockdown Mode without waiting for an alert.&lt;/p&gt;

&lt;h2&gt;Frequently Asked Questions&lt;/h2&gt;

&lt;h3&gt;Is the Apple Threat Notification real or a scam?&lt;/h3&gt;
&lt;p&gt;Genuine notifications exist, and Apple has sent them since 2021. To verify yours, sign in at account.apple.com by typing the address yourself. A real notification appears as a banner at the top of the page after sign-in, and also as a dedicated row in Settings on the iPhone. Apple never asks you to click a link, install a profile, or give up your password or verification code.&lt;/p&gt;

&lt;h3&gt;Does a threat notification mean my iPhone has already been hacked?&lt;/h3&gt;
&lt;p&gt;No. It means Apple has high confidence that you were individually targeted. The attempt may have failed. Apple does not tell recipients whether the attack succeeded, which is one reason it recommends contacting a specialist who can examine the device.&lt;/p&gt;

&lt;h3&gt;Why won't Apple tell me who attacked me?&lt;/h3&gt;
&lt;p&gt;Apple does not attribute threat notifications to any attacker, company or region, and will not describe what triggered a specific alert. Its stated reason is that publishing detection criteria would help spyware operators adapt and evade future detection.&lt;/p&gt;

&lt;h3&gt;Should I factory reset my iPhone after getting an alert?&lt;/h3&gt;
&lt;p&gt;Not as a first step. A reset destroys the evidence that an investigator would use to establish what happened and whether the compromise succeeded. Preserve the device, enable Lockdown Mode, and contact the Digital Security Helpline at Access Now before wiping anything.&lt;/p&gt;

&lt;h3&gt;Does Lockdown Mode slow down or break the iPhone?&lt;/h3&gt;
&lt;p&gt;It does not affect performance. It disables features commonly abused for delivery: most message attachment types, some web technologies, link previews, unsolicited FaceTime calls and configuration profile installation. Most people find the daily cost minor compared with the exposure it removes.&lt;/p&gt;

&lt;h3&gt;How much does an expert help cost after an Apple threat notification?&lt;/h3&gt;
&lt;p&gt;Nothing. The Digital Security Helpline run by the nonprofit Access Now is free and available 24 hours a day, seven days a week. Apple points notification recipients to it directly. Treat anyone charging money to "remove spyware" after an alert as a scam.&lt;/p&gt;

&lt;h3&gt;Can Android users get similar warnings?&lt;/h3&gt;
&lt;p&gt;Google and WhatsApp both operate their own notification programmes for government-backed attack targets, though the wording, delivery and frequency differ from Apple's. There is no cross-platform standard, which is why the same person can be alerted by one company and never hear from another.&lt;/p&gt;&lt;ul&gt;
&lt;/ul&gt;

&lt;!--================= FAQ SCHEMA =================
     Paste this along with the article. Cyber Kendra's Blogger theme
     already outputs Article schema with correct dates, so only the
     FAQPage block is added here. Delete if your theme already emits FAQ schema.
     ==============================================--&gt;
&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "Is the Apple Threat Notification real or a scam?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Genuine notifications exist and Apple has sent them since 2021. To verify yours, sign in at account.apple.com by typing the address yourself. A real notification appears as a banner at the top of the page after sign-in, and also as a dedicated row in Settings on the iPhone. Apple never asks you to click a link, install a profile, or give up your password or verification code."
      }
    },
    {
      "@type": "Question",
      "name": "Does a threat notification mean my iPhone has already been hacked?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. It means Apple has high confidence you were individually targeted. The attempt may have failed. Apple does not tell recipients whether the attack succeeded, which is one reason it recommends contacting a specialist who can examine the device."
      }
    },
    {
      "@type": "Question",
      "name": "Why won't Apple tell me who attacked me?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Apple does not attribute threat notifications to any attacker, company or region, and will not describe what triggered a specific alert. Its stated reason is that publishing detection criteria would help spyware operators adapt and evade future detection."
      }
    },
    {
      "@type": "Question",
      "name": "Should I factory reset my iPhone after getting an alert?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Not as a first step. A reset destroys the evidence an investigator would use to establish what happened and whether the compromise succeeded. Preserve the device, enable Lockdown Mode, and contact the Digital Security Helpline at Access Now before wiping anything."
      }
    },
    {
      "@type": "Question",
      "name": "Does Lockdown Mode slow down or break the iPhone?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It does not affect performance. It disables features commonly abused for delivery: most message attachment types, some web technologies, link previews, unsolicited FaceTime calls and configuration profile installation. Most people find the daily cost minor compared with the exposure it removes."
      }
    },
    {
      "@type": "Question",
      "name": "How much does expert help cost after an Apple threat notification?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Nothing. The Digital Security Helpline run by the nonprofit Access Now is free and available 24 hours a day, seven days a week. Apple points notification recipients to it directly. Treat anyone charging money to remove spyware after an alert as a scam."
      }
    },
    {
      "@type": "Question",
      "name": "Can Android users get similar warnings?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Google and WhatsApp both operate their own notification programmes for government-backed attack targets, though the wording, delivery and frequency differ from Apple's. There is no cross-platform standard, which is why the same person can be alerted by one company and never hear from another."
      }
    }
  ]
}
&lt;/script&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNMtbKNxgVs5-zcHBiYhursBhyiWuYi1EI1U9Tna11ILhUDk-yE_hJ2dAbnpJIbH2lJ3m4lS5F0fjMvb71FlBRr_V0W9Bh9u4ZFs6-UfgW68bEjiQI2vWkNpWsn1EPgUy60NOg2PeCAKsMEh9MOrc0mZgJguj4ZeZOI5NwQolTPqxY9hRCy64Akymq1gY/s72-c/mercenary-spyware.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Trezor Says ShipMonk Breach Exposed 13,689 Customers</title><link>https://www.cyberkendra.com/2026/08/trezor-says-shipmonk-breach-exposed.html</link><category>Crypto Currency</category><category>Data Breached</category><category>Security</category><pubDate>Thu, 13 Aug 2026 21:16:20 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-8773066417338039889</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Trezor data breach" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5wDFubQTQQyy1TvYbTCXManUKO85Sgq5ANmUfHPGJps_yG6ZUaJ_zPE12pH-U23JXrNIf8JB7Vo3MVSsfCCbgw0lqXDvUZgaWoshirwt6lY3eVQnx3ePZDzqsj8NJcHC_fipbCXF9B33pmvwsbHSbZYBfPn4IZuDfSm54et9287lOY9CYdY5sX4csfFI/s1600/Trezor-hacked.webp" title="Trezor data breach" /&gt;&lt;/div&gt;&lt;p&gt;Nearly 14,000 people who bought a Trezor hardware wallet this summer now have their names and home addresses sitting in the hands of an unknown attacker — a list that identifies them, by address, as crypto holders.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Trezor &lt;a href="https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident?ABC" rel="nofollow" target="_blank"&gt;disclosed on August 13&lt;/a&gt; that ShipMonk, the third-party fulfilment provider that warehouses and ships its products, reported unauthorised access to systems holding customer order data on Monday, August 10. The investigation is ongoing.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What Data Was Exposed&lt;/h3&gt;&lt;p&gt;11,742 customers had full records exposed: full name, email address, phone number and shipping address. A further 1,947 had partial exposure limited to name, city and email — 13,689 in total. ShipMonk also stores order numbers, which lets an attacker reference a real purchase in a phishing message.&lt;/p&gt;&lt;p&gt;Trezor says its own systems, firmware and devices were untouched. No private keys, wallet backups or funds were involved, and operations continue normally.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Which Orders Are Affected&lt;/h3&gt;&lt;p&gt;Only orders delivered between May 10 and August 8, 2026, to the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. Trezor's 90-day retention rule — which it contractually imposes on fulfilment partners — meant older order data had already been deleted or anonymised, capping the blast radius. Affected customers were emailed directly from help@trezor.io; no email means no exposure.&lt;/p&gt;&lt;p&gt;Trezor's guidance is framed around phishing. The address field carries a heavier risk. When roughly 272,000 Ledger customer records leaked in 2020, victims reported ransom demands and threats of violence, not just fake emails. CertiK verified 52 physical attacks on crypto holders in the first half of 2026, up from 39 a year earlier, with home invasions overtaking kidnapping as the most common method.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This is also the second hardware-wallet vendor compromised through a commerce partner this year — Ledger disclosed a January 2026 incident at provider Global-e that exposed names, postal addresses, phone numbers and order details. The attack surface is the supply chain, not the device.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Five of the seven affected countries fall under GDPR or UK GDPR, which requires regulator notification within 72 hours; Brazil's LGPD imposes similar duties.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What Affected Customers Should Do&lt;/h3&gt;&lt;p&gt;Treat any unsolicited call, letter or email referencing a Trezor order as hostile. Never type a wallet backup into a website. Verify announcements against trezor.io directly. Consider a mail-forwarding address for future hardware deliveries — Trezor's promised Anonymous Delivery option is not live yet, targeting the EU by September 2026 and the US by year-end.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5wDFubQTQQyy1TvYbTCXManUKO85Sgq5ANmUfHPGJps_yG6ZUaJ_zPE12pH-U23JXrNIf8JB7Vo3MVSsfCCbgw0lqXDvUZgaWoshirwt6lY3eVQnx3ePZDzqsj8NJcHC_fipbCXF9B33pmvwsbHSbZYBfPn4IZuDfSm54et9287lOY9CYdY5sX4csfFI/s72-c/Trezor-hacked.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>CVE-2026-63520: SharePoint RCE Patched by Microsoft</title><link>https://www.cyberkendra.com/2026/08/cve-2026-63520-sharepoint-rce-patched.html</link><category>Microsoft</category><category>Security</category><pubDate>Thu, 13 Aug 2026 07:35:54 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4549571314695295522</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="SharePoint RCE vulnerability CVE-2026-63520" border="0" data-original-height="1401" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZv20VJpLN9oF6K0oqYungbMrblWgZA3XFfIvAHMVyf_ihs5WRXFtGejBnKWn7idFRcAMm7Fvn2VCEHwEmdEH-IVK_QWdsFHUDiNcR-9lF6ZuD3yiRfFe7-txLaV0oEb0ctOJm9JHVKKavjMNqaaYoAZXQJjijkLlB8m-CF1YmGYuxa2x9fGyHDZ9FgnI/s1600/sharepoint-rce.webp" title="SharePoint RCE vulnerability CVE-2026-63520" /&gt;&lt;/div&gt;&lt;p&gt;Rapid7 and Microsoft have disclosed &lt;b&gt;CVE-2026-63520&lt;/b&gt;, a remote code execution flaw in Microsoft SharePoint that completes an unauthenticated exploit chain Rapid7 Labs built for Pwn2Own Berlin. Senior Principal Security Researcher Stephen Fewer found it using an AI agent workflow, and Microsoft shipped the fix in its &lt;a href="https://www.cyberkendra.com/2026/08/shieldbreak-poc-bypasses-microsofts.html" target="_blank"&gt;August 11 update cycle&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CVE-2026-63520&lt;/b&gt; carries a CVSSv3.1 score of 8.1 (High) and is classified as CWE-20: Improper Input Validation. The root cause is an unsafe .NET type instantiation issue in &lt;a href="https://learn.microsoft.com/en-us/sharepoint/administration/business-connectivity-services-overview" rel="nofollow" target="_blank"&gt;Business Connectivity Services&lt;/a&gt;. Code runs with the privileges of the Windows service account behind the SharePoint Site instance. It affects all supported SharePoint versions, plus certain builds of Project Server and Office Web Apps Server.&lt;/p&gt;

&lt;h2&gt;How the CVE-2026-63520 Exploit Chain Works&lt;/h2&gt;

&lt;p&gt;On its own, the RCE needs an authenticated session. Paired with &lt;b&gt;CVE-2026-55040&lt;/b&gt; — the JWT token authentication bypass Microsoft patched on July 14 — that requirement disappears. An attacker forges a token, assumes a site user's identity, then crafts a custom .NET gadget chain to run an attacker-controlled OS command.&lt;/p&gt;

&lt;p&gt;Rapid7's agent logged 120 hours of runtime across 24 days, 96 sessions, roughly 80,000 tool calls and 256 human prompts to reach a working chain. It is the same category of pre-auth SharePoint chain as &lt;a href="https://www.cyberkendra.com/2025/07/toolshell-critical-sharepoint-flaw.html" target="_blank"&gt;ToolShell&lt;/a&gt;, which surfaced from Pwn2Own last year.&lt;/p&gt;

&lt;h2&gt;Which SharePoint Builds Are Fixed&lt;/h2&gt;
&lt;div class="table noWrap w100"&gt;
&lt;table border="1"&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Product&lt;/th&gt;
&lt;th&gt;Fixed build&lt;/th&gt;
&lt;th&gt;KB&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SharePoint Server Subscription Edition&lt;/td&gt;
&lt;td&gt;16.0.19725.20522&lt;/td&gt;
&lt;td&gt;KB5002893&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SharePoint Server 2019&lt;/td&gt;
&lt;td&gt;16.0.10417.20198&lt;/td&gt;
&lt;td&gt;KB5002894, KB5002896&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SharePoint Enterprise Server 2016&lt;/td&gt;
&lt;td&gt;16.0.5565.1001&lt;/td&gt;
&lt;td&gt;KB5002905, KB5002906&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;The 30-Day Clock Already Started&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed/" rel="nofollow" target="_blank"&gt;Rapid7&lt;/a&gt; will publish full technical details for CVE-2026-63520 within 30 days — roughly September 10. Treat that as a hard deadline, because the first half of this chain just demonstrated the pattern.&lt;/p&gt;

&lt;p&gt;Rapid7 released its CVE-2026-55040 write-up and PoC on August 11. Threat intelligence firm Defused reported the next day that its honeypots were recording exploitation attempts using that exact PoC. "Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused stated. Shadowserver still tracks more than 8,500 SharePoint servers exposed online, and neither CVE appears in &lt;a href="https://tools.cyberkendra.com/tracker/cisa-kev/" target="_blank"&gt;CISA's Known Exploited Vulnerabilities catalog&lt;/a&gt; at the time of writing — though &lt;a href="https://www.cyberkendra.com/2026/03/hackers-are-actively-exploiting.html" target="_blank"&gt;SharePoint flaws have a history of landing there&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Publication to weaponisation took one day. Administrators have until early September before the RCE half gets the same treatment. Both patches, not one.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZv20VJpLN9oF6K0oqYungbMrblWgZA3XFfIvAHMVyf_ihs5WRXFtGejBnKWn7idFRcAMm7Fvn2VCEHwEmdEH-IVK_QWdsFHUDiNcR-9lF6ZuD3yiRfFe7-txLaV0oEb0ctOJm9JHVKKavjMNqaaYoAZXQJjijkLlB8m-CF1YmGYuxa2x9fGyHDZ9FgnI/s72-c/sharepoint-rce.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms</title><link>https://www.cyberkendra.com/2026/08/litellm-breach-434000-cicd-pipelines-exposed.html</link><category>Data Breached</category><category>Password</category><category>Security</category><pubDate>Thu, 13 Aug 2026 07:10:04 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-8576190895119647439</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="LiteLLM 434,000 CI/CD pipelines" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcRtXAO9zTC6jveE1bv1rw4Cb0rbH2wGI6_kQCFFzY0Hlmer9JlBiD1YRQ-ibIiA2isD4Wy4YmIienFVUTRbbQgkGeHX5GXgoi0p5k8MaR5_JoP7wx2vbqWbhQO0JFQISb5FV00Wmt4rFazZMHk_LLkFIUb7P4PsO4tD3WMX0cYb9B9LNlc-DrcTBsp0I/s1600/LiteLLM-Breach-exposed.webp" title="LiteLLM 434,000 CI/CD pipelines" /&gt;&lt;/div&gt;&lt;p&gt;Two threat intelligence firms have published victim data from the March 2026 LiteLLM supply chain attack, and the scale is far beyond anything known when the malicious packages were pulled. CloudSEK counts more than 2,500 potentially exposed organisations and roughly 434,000 CI/CD pipelines, while Hudson Rock says it independently obtained the attackers' raw exfiltration archive and attributed 118,829 CI runner dumps to 2,488 corporate domains.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;

&lt;p&gt;There is no CVE for this incident because nothing in LiteLLM itself was vulnerable. Attackers linked to the threat group TeamPCP published backdoored LiteLLM 1.82.7 and 1.82.8 to PyPI, where CloudSEK says the packages stayed live for roughly 40 minutes.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Version 1.82.8 shipped a malicious &lt;code&gt;.pth&lt;/code&gt; file — a Python startup hook that runs when the interpreter launches rather than when a library is imported — so the payload is executed on every machine where the package was merely installed, sidestepping the &lt;code&gt;--ignore-scripts&lt;/code&gt; protection teams rely on to make installs safe.&lt;/p&gt;

&lt;h2&gt;How Did TeamPCP Get Into LiteLLM?&lt;/h2&gt;

&lt;p&gt;LiteLLM was never attacked directly. Its CI pipeline installed the Trivy vulnerability scanner unpinned from the system package manager, so when TeamPCP took over Trivy's release process, the poisoned scanner flowed into LiteLLM's build automatically, and that build published the malicious PyPI releases.&lt;/p&gt;

&lt;p&gt;The opening was a single automation token that Trivy's maintainers rotated but did not fully revoke. CloudSEK says that left roughly a 20-day window in which the attacker force-pushed malicious code over the scanner's published version tags, meaning downstream builds pulling those tags received attacker-controlled code that still resolved and still looked legitimate. CloudSEK researchers summarised the cascade as &lt;a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" rel="nofollow" target="_blank"&gt;"one un-revoked token, three tools deep"&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Cyber Kendra &lt;a href="https://www.cyberkendra.com/2026/03/hackers-poisoned-python-package-trusted.html" target="_blank"&gt;covered the original LiteLLM poisoning on March 24&lt;/a&gt;, when Endor Labs first identified the malicious versions. The same campaign has since run through &lt;a href="https://www.cyberkendra.com/2026/04/lapsus-dumps-checkmarx-data-on-dark-web.html" target="_blank"&gt;Checkmarx's KICS images&lt;/a&gt;, the &lt;a href="https://www.cyberkendra.com/2026/04/lightning-pypi-package-compromised-in.html"&gt;Lightning AI PyPI package&lt;/a&gt;, and &lt;a href="https://www.cyberkendra.com/2026/05/tanstack-packages-hit-by-sophisticated.html" target="_blank"&gt;42 TanStack npm packages&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;What Did the Stealer Take?&lt;/h2&gt;

&lt;p&gt;On each compromised runner, the payload — tracked by Google as SANDCLOCK — escalated to root and swept SSH keys, AWS, GCP, and Azure credentials, Kubernetes service account tokens, &lt;code&gt;.env&lt;/code&gt; files, and CI/CD secrets. CloudSEK reports it scraped secret values directly from &lt;code&gt;/proc/&amp;lt;pid&amp;gt;/mem&lt;/code&gt;, including the values GitHub Actions attempts to mask in logs. Cloud keys were read straight from the instance metadata service and Kubernetes tokens from mounted service-account paths, using only the access each runner already carried.&lt;/p&gt;

&lt;p&gt;For AI builds specifically, the stealer took LLM API keys and gateway configuration. Screenshots published by Hudson Rock show OpenAI, Anthropic, Gemini, OpenRouter, Fireworks, Groq, and Cerebras keys captured mid-execution — effectively the credentials to an organisation's entire model stack, plus its billing quota.&lt;/p&gt;

&lt;p&gt;Collected data was encrypted with AES-256 under a hard-coded RSA-4096 key and shipped to a typosquatted domain. Where exfiltration failed, CloudSEK says the malware created a public repository inside the victim's own GitHub account and uploaded the stolen data there as a release asset, which means some organizations spent months publishing their own secrets without knowing it.&lt;/p&gt;

&lt;h2&gt;Do the 434,000 and 2,500 Figures Add Up?&lt;/h2&gt;

&lt;p&gt;The two reports were published a day apart and are being quoted interchangeably, but they do not measure the same things. Laid side by side, the discrepancies matter for anyone trying to size their own exposure.&lt;/p&gt;

&lt;table border="1" cellpadding="6" cellspacing="0" style="border-collapse: collapse; width: 100%;"&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th align="left"&gt;Figure&lt;/th&gt;
&lt;th align="left"&gt;Hudson Rock&lt;/th&gt;
&lt;th align="left"&gt;CloudSEK&lt;/th&gt;
&lt;th align="left"&gt;Ars Technica&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Archive size&lt;/td&gt;
&lt;td&gt;153GB RAR&lt;/td&gt;
&lt;td&gt;Not stated&lt;/td&gt;
&lt;td&gt;195TB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Files in the archive&lt;/td&gt;
&lt;td&gt;433,909&lt;/td&gt;
&lt;td&gt;Not stated&lt;/td&gt;
&lt;td&gt;Not stated&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CI/CD pipelines&lt;/td&gt;
&lt;td&gt;118,829 attributed runner dumps&lt;/td&gt;
&lt;td&gt;~434,000 pipelines&lt;/td&gt;
&lt;td&gt;~434,000 pipelines&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Organisations&lt;/td&gt;
&lt;td&gt;2,488 corporate domains&lt;/td&gt;
&lt;td&gt;2,500+ companies&lt;/td&gt;
&lt;td&gt;2,500+ organisations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exposure window&lt;/td&gt;
&lt;td&gt;Audit from March 24, 2026&lt;/td&gt;
&lt;td&gt;~40 minutes&lt;/td&gt;
&lt;td&gt;40 minutes&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;Two things stand out. First, the headline "434,000 CI/CD pipelines" figure is numerically almost identical to Hudson Rock's count of 433,909 &lt;em&gt;files&lt;/em&gt; in the archive. Hudson Rock's own count of CI runner dumps could be attributed to an organisation of 118,829 — about 27 per cent of that total.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The most likely reading is that the circulating pipeline figure counts records or files rather than distinct pipelines, and that roughly three-quarters of the dumps carried no usable organisational marker. Cyber Kendra has not independently verified either dataset, and neither firm has published a methodology reconciling the two counts.&lt;/p&gt;

&lt;p&gt;Second, the archive size differs by roughly three orders of magnitude between Hudson Rock's own write-up (153GB) and Ars Technica's account of it (195TB). We have not been able to establish which is correct.&lt;/p&gt;

&lt;p&gt;None of this makes the incident smaller. CloudSEK is explicit that its numbers describe reconstructed exposure and should not be read as proof that every listed organization was compromised. But a defender sizing their own blast radius should treat 434,000 as a count of leaked records, not as a count of breached pipelines, until either firm says otherwise.&lt;/p&gt;

&lt;h2&gt;Which Companies Are Affected?&lt;/h2&gt;

&lt;p&gt;CloudSEK's high-confidence list runs to dozens of names across technology, defence, banking, telecoms, manufacturing and logistics. It includes NVIDIA, Amazon Web Services, Samsung Electronics, Cisco Systems, Salesforce, ServiceNow, Siemens AG, S&amp;amp;P Global, Airbus U.S. Space &amp;amp; Defense, John Deere, Regeneron, London Stock Exchange Group, Thomson Reuters, FedEx, Munich Re, MediaTek, Volkswagen, Deloitte, Kroger, Thales, X Corp, Zscaler, Epic Games, Orange, HP, Philips, Vodafone, Carl Zeiss, Deutsche Bahn, NGINX, BT Group, Liebherr, Krungthai Bank and Roku.&lt;/p&gt;

&lt;p&gt;The per-organisation counts are uneven in ways worth reading closely. X Corp shows 3,459 secrets across 1,153 runs. Orange shows 180 secrets but 5,642 runs. Volkswagen shows 2,242 runs and zero secrets. A high run count with no secrets suggests pipelines that executed the package without holding credentials the stealer could reach; a high secret count on a few runs suggests the opposite.&lt;/p&gt;

&lt;p&gt;Attribution is also harder than the domain column implies. Hudson Rock describes one case where the committer email belonged to &lt;code&gt;@siriusxm.com&lt;/code&gt;, but the environment dump's self-hosted GitLab and registry endpoints placed the breach inside AdsWizz, a SiriusXM subsidiary. Routing an alert to the wrong SOC on the strength of an email domain wastes the window that matters.&lt;/p&gt;

&lt;p&gt;Hudson Rock's larger concern is the files with no marker at all. Many pipelines are configured generically, and the firm says those dumps hold &lt;a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" rel="nofollow" target="_blank"&gt;"active database passwords, third-party API keys, and cloud credentials"&lt;/a&gt; with nothing tying them to a company. Absence from both firms' lists is not evidence of safety.&lt;/p&gt;

&lt;h2&gt;Are the Stolen Credentials Still Valid?&lt;/h2&gt;

&lt;p&gt;In at least one case, yes. After the Ars Technica report went live, Kevin Beaumont said a major US technology company told him it had rotated everything and the disclosure was a non-event. Its responsible disclosure policy permitted credential testing, so he tested them. "Almost every one worked," he &lt;a href="https://cyberplace.social/@GossiTheDog/117082983921135330" rel="nofollow" target="_blank"&gt;wrote and filed a report&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;That is the finding defenders should carry out of this story. These credentials date from March. Five months of assumed rotation did not close the exposure at one of the largest technology companies in the United States, which tracks with the FBI's July FLASH advisory (FLASH-20260702-01) warning that affiliated actors are likely to weaponise the harvested credentials long after the original intrusion.&lt;/p&gt;

&lt;h2&gt;What Should You Do If You Ran LiteLLM 1.82.7 or 1.82.8?&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Rotate broadly, not narrowly.&lt;/strong&gt; Rotating the LiteLLM or model-provider key alone is insufficient. Any credential readable by the affected process — in environment variables, process memory, on disk, injected into the job, or retrievable through an instance metadata service — should be treated as exposed until validated. That includes AWS, GCP and Azure IAM keys, Kubernetes service account tokens, and GitHub and GitLab personal access tokens.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Search build history, not just current lockfiles.&lt;/strong&gt; Scheduled jobs, dependency resolvers, ephemeral runners, developer laptops and cached container layers can all hold the artifact long after PyPI removed it. Version 1.82.6 is the last confirmed clean release.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hunt for persistence.&lt;/strong&gt; Check &lt;code&gt;site-packages&lt;/code&gt; for unauthorised &lt;code&gt;.pth&lt;/code&gt; files and look for a systemd unit masquerading as a "System Telemetry Service". CloudSEK is also named &lt;code&gt;tpcp-docs/docs-tpcp&lt;/code&gt; as a repository pattern worth hunting for.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check your own GitHub org for repositories you did not create.&lt;/strong&gt; The exfiltration fallback published stolen data as a release asset in the victim's account.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pull logs from March 24, 2026, onward.&lt;/strong&gt; Review CloudTrail, Kubernetes API audits, source control, package registry and cluster logs for token use from unfamiliar IPs, geographies, runners or user agents.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check the exposure portals.&lt;/strong&gt; Both firms have published domain lookup tools, including CloudSEK's. Note that both are gated behind vendor sign-up flows.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The structural lesson is the one Alon Gal, Hudson Rock's co-founder and CTO, put to Ars Technica: a single upstream breach now reaches thousands of companies at once, and a 40-minute dependency window produced hundreds of thousands of harvested environments. TeamPCP has since &lt;a href="https://www.cyberkendra.com/2026/06/red-hat-cloud-services-npm-packages.html" target="_blank"&gt;open-sourced the Shai-Hulud framework&lt;/a&gt; used across this campaign, which means the next actor to run this playbook will not need to build any of it.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcRtXAO9zTC6jveE1bv1rw4Cb0rbH2wGI6_kQCFFzY0Hlmer9JlBiD1YRQ-ibIiA2isD4Wy4YmIienFVUTRbbQgkGeHX5GXgoi0p5k8MaR5_JoP7wx2vbqWbhQO0JFQISb5FV00Wmt4rFazZMHk_LLkFIUb7P4PsO4tD3WMX0cYb9B9LNlc-DrcTBsp0I/s72-c/LiteLLM-Breach-exposed.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Pirates Bay Proxy List August 2026: Unblock Pirate Bay</title><link>https://www.cyberkendra.com/2022/12/pirate-proxy-list-2023-unblock-pirate.html</link><category>Tips</category><category>Torrents</category><pubDate>Mon, 12 Dec 2022 23:21:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-7709902560608743927</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="The Pirate Bay Proxy or Mirror" border="0" data-original-height="720" data-original-width="1250" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7uZzVIXP-8BBemx38BYX7z1u7QATuG3oRUC8aUhiHWHC8pdH-JZfjNmOcHKfzuaT5ZzUVOgPvOujTyBIQY_DYhauHI1lV7lAuIowp2hIFB8GfHUupUnYluxpBkg2nKG1wgYsZ5iZFbfurlvP18jdrSveJMY0qJCqaadHbgH54C1JbNw8NOAmq9lhae0M/s16000/Pirate%20Bay.webp" title="The Pirate Bay Proxy or Mirror" /&gt;&lt;/div&gt;&lt;p&gt;The Pirate Bay (TPB) is one of the oldest and most popular &lt;b&gt;torrent websites&lt;/b&gt;, allowing users to share and &lt;b&gt;download torrent files&lt;/b&gt; for movies, TV shows, music, games, and software. However, due to legal pressure, many countries have blocked access to the &lt;b&gt;original Pirate Bay&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;Despite these blocks, people still try to access The Pirate Bay using &lt;a href="https://ninjasproxy.com/shared-proxies/" target="_blank"&gt;shared proxy servers&lt;/a&gt;. If you're struggling to access The Pirate Bay due to regional restrictions, this guide will walk you through the best Pirate Bay proxy sites, how they work, and safer alternatives to keep you downloading without hassle.&lt;/p&gt;&lt;p&gt;If you're wondering how to &lt;b&gt;unblock The Pirate Bay&lt;/b&gt;, this guide covers everything you need to know, including:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✅ Pirate Bay proxy list (April 2026)&lt;/li&gt;&lt;li&gt;✅ How proxy sites work&lt;/li&gt;&lt;li&gt;✅ Is torrenting legal?&lt;/li&gt;&lt;li&gt;✅ Why is Pirate Bay blocked?&lt;/li&gt;&lt;li&gt;✅ Best VPNs for Pirate Bay&lt;/li&gt;&lt;li&gt;✅ Tor Browser vs. VPN for torrenting&lt;/li&gt;&lt;li&gt;✅ Safe alternatives to Pirate Bay&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;By the end, you’ll know &lt;b&gt;how to&lt;/b&gt; &lt;b&gt;access The Pirate Bay&lt;/b&gt; safely and legally.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What Is The Pirate Bay?&lt;/h2&gt;&lt;p&gt;The Pirate Bay was launched in 2003 by the founders of the Swedish group advocating for free file sharing. It quickly became the go-to torrent site for millions, despite legal battles and attempts to shut it down.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Why Is Pirate Bay So Popular?&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✔ Huge database of movies, music, games, and software&lt;/li&gt;&lt;li&gt;✔ Magnet links for faster downloads&lt;/li&gt;&lt;li&gt;✔ No registration required&lt;/li&gt;&lt;li&gt;✔ Active community of uploaders&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;However, because it hosts copyrighted content, many ISPs and governments have blocked it.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What Is a Pirate Bay Proxy or Mirror Site?&lt;/h2&gt;&lt;p&gt;A Pirate Bay proxy (or mirror site) acts as a gateway to the original Pirate Bay when the main site is blocked. These proxy servers reroute your connection, making it appear as though you're accessing the site from a different location where restrictions don’t apply.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How Does a Pirate Bay Proxy Work?&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;When you visit a proxy site, your request is sent to an intermediary server.&lt;/li&gt;&lt;li&gt;This server forwards your request to The Pirate Bay and sends the data back to you.&lt;/li&gt;&lt;li&gt;Your real IP address stays hidden, helping you bypass ISP or government blocks.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;This method is one of the easiest ways to unblock The Pirate Bay, but it comes with risks—more on that later.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Why Is Pirate Bay Blocked in Many Countries?&lt;/h3&gt;&lt;p&gt;Governments and copyright agencies have pressured ISPs to block Pirate Bay’s site due to:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Copyright infringement –&lt;/b&gt; Hosting pirated movies, music, and software is illegal.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Legal pressure from Hollywood &amp;amp; record labels – &lt;/b&gt;Companies like Disney and Warner Bros. push for bans.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Anti-piracy laws –&lt;/b&gt; Countries like the US, UK, Australia, and India enforce strict blocking.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Despite blocks, users still access &lt;b&gt;The Pirate Bay using proxy sites&lt;/b&gt;, VPNs, or Tor.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Is Torrenting Legal?&lt;/h3&gt;&lt;p&gt;Torrenting itself is legal, but downloading copyrighted content without permission is illegal in most countries.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Legal Uses of Torrenting:&lt;/h4&gt;&lt;p&gt;✅ Linux distributions (Ubuntu, Fedora, Kali Linux, etc.)&lt;/p&gt;&lt;p&gt;✅ Public domain movies &amp;amp; books&lt;/p&gt;&lt;p&gt;✅ Independent artists sharing free music&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Illegal Uses of Torrenting:&lt;/h4&gt;&lt;p&gt;❌ Downloading the latest Marvel movie&lt;/p&gt;&lt;p&gt;❌ Sharing paid software (Windows, Photoshop)&lt;/p&gt;&lt;p&gt;❌ Distributing copyrighted music albums&lt;/p&gt;&lt;p&gt;Penalties for illegal torrenting:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Fines (up to thousands of dollars)&lt;/li&gt;&lt;li&gt;ISP warnings or throttling&lt;/li&gt;&lt;li&gt;Legal action in severe cases&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How Does a Pirate Bay Proxy Work?&lt;/h3&gt;&lt;p&gt;A &lt;b&gt;Pirate Bay proxy&lt;/b&gt; acts as a middleman between you and the real Pirate Bay site.&lt;/p&gt;&lt;p&gt;Step-by-Step Process:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;1️⃣ You visit a proxy site (e.g., piratebay.proxy)&lt;/li&gt;&lt;li&gt;2️⃣ The proxy fetches data from The Pirate Bay’s servers&lt;/li&gt;&lt;li&gt;3️⃣ It sends the data back to you, bypassing ISP blocks&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Pros of Using Proxies:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✔ Bypasses government/ISP blocks&lt;/li&gt;&lt;li&gt;✔ No software installation needed&lt;/li&gt;&lt;li&gt;✔ Works instantly&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Cons of Using Proxies:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;❌ No encryption (your ISP can still see your activity)&lt;/li&gt;&lt;li&gt;❌ Some proxies contain malware or ads&lt;/li&gt;&lt;li&gt;❌ Unreliable (many proxies shut down quickly)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 id="unblocking_the_pirate_bay_with_pirate_bay_proxy_sites_lists" style="text-align: left;"&gt;Pirate Bay Proxy List (2026) – Working Sites&lt;/h3&gt;&lt;p&gt;Here’s an updated list of working Pirate Bay proxy sites:&lt;/p&gt;&lt;p&gt;
  
  &lt;/p&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Proxy Site&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Status&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Speed&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;piratebay.party&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay10.infoy&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;tpb.party&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay.party&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;piratebay.party&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay.part&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;&#128034; Slow&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay7.com&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay0.org &lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;&#128034; Slow&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;pirateproxylive.org&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;/tr&gt;
        &lt;tr&gt;&lt;td&gt;&lt;strong&gt;thepiratebay.cloud&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;✅ Working&lt;/td&gt;&lt;td&gt;&#128034; Slow&lt;/td&gt;&lt;/tr&gt;
    
    
    &lt;/tbody&gt;&lt;/table&gt;
  
  &lt;p&gt;Note: Proxy sites change frequently—if one doesn’t work, try another.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Is Using a Pirate Bay Proxy Safe?&lt;/h3&gt;&lt;p&gt;Proxies help access Pirate Bay, but they don’t make torrenting safe.&lt;/p&gt;&lt;p&gt;Risks of Using Pirate Bay Proxies:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&#128308; Malware &amp;amp; fake torrents – Some proxies inject ads or distribute infected files.&lt;/li&gt;&lt;li&gt;&#128308; No encryption – Your ISP can still track your downloads.&lt;/li&gt;&lt;li&gt;&#128308; Legal risks – Copyright trolls monitor torrent traffic.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;How to Stay Safe?&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✔ Use a VPN (recommended) – Hides your&amp;nbsp;&lt;a href="https://whoerip.com/?utm_source=cyberkendra&amp;amp;utm_medium=media&amp;amp;utm_campaign=link10" target="_blank"&gt;public IP address&lt;/a&gt; and encrypts traffic.&lt;/li&gt;&lt;li&gt;✔ Check comments &amp;amp; seeders – Avoid torrents with no reviews.&lt;/li&gt;&lt;li&gt;✔ Use antivirus software – Scan downloaded files before opening.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How to Download Torrents Using a Pirate Bay Proxy&lt;/h3&gt;&lt;p&gt;Step 1: Find a Working Proxy&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Use the Pirate Bay proxy list above. If one doesn’t work, try another from the list, as the domain frequently changes.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Step 2: Search for Torrents&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Type the movie/game name in the search bar.&lt;/li&gt;&lt;li&gt;Filter by seeders (high = faster download).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Step 3: Download the Torrent&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Click "Get This Torrent" (magnet link) or download the .torrent file.&lt;/li&gt;&lt;li&gt;Open it in qBittorrent or uTorrent.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Step 4: Stay Anonymous (Use VPN)&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;A VPN like NordVPN or ExpressVPN hides your IP.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Why Use a VPN for Pirate Bay?&lt;/h3&gt;&lt;p&gt;Since proxy sites don’t encrypt traffic, a VPN is the safest way to torrent.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Best VPNs for Pirate Bay (2026)&lt;/h4&gt;&lt;div&gt;

&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;VPN&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Speed&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;No-Logs Policy&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Price&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;NordVPN&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;td&gt;✅ Yes&lt;/td&gt;&lt;td&gt;$3.29/mo&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;ExpressVPN&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;td&gt;✅ Yes&lt;/td&gt;&lt;td&gt;$6.67/mo&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Surfshark&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;⚡ Fast&lt;/td&gt;&lt;td&gt;✅ Yes&lt;/td&gt;&lt;td&gt;$2.49/mo&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;


&lt;/div&gt;&lt;h4 style="text-align: left;"&gt;Why a VPN is Better Than a Proxy:&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✔ Encrypts all traffic (ISP can’t see what you download)&lt;/li&gt;&lt;li&gt;✔ Changes your IP address (hides your real location)&lt;/li&gt;&lt;li&gt;✔ Works with all torrent sites (not just Pirate Bay)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Can You Use Tor Browser to Unblock Pirate Bay?&lt;/h3&gt;&lt;p&gt;Yes, but Tor is slow for torrenting.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Pros of Tor for Pirate Bay:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✔ Extreme anonymity (hard to trace)&lt;/li&gt;&lt;li&gt;✔ Bypasses censorship&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Cons of Tor for Torrenting:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;❌ Very slow downloads (Tor wasn’t made for P2P)&lt;/li&gt;&lt;li&gt;❌ Some exit nodes block torrent traffic&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Best for: Checking Pirate Bay, not downloading large files.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The Pirate Bay Alternatives (2026)&lt;/h3&gt;&lt;p&gt;If proxies aren’t reliable, consider these websites like The Pirate Bay:&lt;/p&gt;&lt;p&gt;

&lt;/p&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Site&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Best For&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Key Feature&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RARBG&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;High-quality torrents&lt;/td&gt;&lt;td&gt;Verified uploads, minimal fake files&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;&lt;a href="https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html" target="_blank"&gt;1337x&lt;/a&gt;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;User-friendly interface&lt;/td&gt;&lt;td&gt;Active community, organised categories&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;&lt;a href="https://www.cyberkendra.com/2022/12/kickass-torrents-proxy-list-2023.html" target="_blank"&gt;KickAss Torrents&lt;/a&gt;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Wide variety of content&lt;/td&gt;&lt;td&gt;Frequently updated domains&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;&lt;a href="https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html" target="_blank"&gt;YTS&lt;/a&gt;&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;HD movies&lt;/td&gt;&lt;td&gt;Small file sizes, high-quality rips&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Torrentz2&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Meta-search engine&lt;/td&gt;&lt;td&gt;Searches multiple torrent sites at once&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;

&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Conclusion: Should You Use Pirate Bay Proxies?&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✅ Yes, if you need quick access, Proxies help bypass blocks.&lt;/li&gt;&lt;li&gt;❌ No, if you want safety, use a VPN instead.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Final Tips:&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&#128313; Always use a VPN for torrenting&lt;/li&gt;&lt;li&gt;&#128313; Avoid downloading copyrighted material illegally&lt;/li&gt;&lt;li&gt;&#128313; Try alternatives like &lt;a href="https://www.cyberkendra.com/2023/10/extratorrents-proxy-list-2024-to.html" target="_blank"&gt;ExtraTorrents&lt;/a&gt; if the Pirate Bay is down&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Now you know how to unblock The Pirate Bay safely. Happy (and legal) downloading! &#128640;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;FAQ Section&lt;/h3&gt;&lt;p&gt;&lt;b&gt;Q: Where are Pirate Bay servers located?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A:&lt;/b&gt; Pirate Bay frequently changes hosting locations (often in countries with lax copyright laws).&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q: Can I create my own proxy site?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A:&lt;/b&gt; Yes, but running a Pirate Bay proxy can lead to legal trouble.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q: Why do some Pirate Bay proxies stop working?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A:&lt;/b&gt; They get taken down due to copyright complaints.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q: Is Pirate Bay shutting down?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A: &lt;/b&gt;No, but it frequently changes domains to avoid blocks.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q: What’s the safest way to use Pirate Bay?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A: &lt;/b&gt;VPN + trusted proxy + antivirus is the best combo.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Q: How do I find a working proxy?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;A:&lt;/b&gt; The list above is updated, but if a proxy fails, search for "&lt;a href="https://www.cyberkendra.com/2024/05/the-pirate-bay-proxy.html.html#unblocking_the_pirate_bay_with_pirate_bay_proxy_sites_lists" target="_blank"&gt;Pirate Bay proxy lists&lt;/a&gt;".&lt;/p&gt;&lt;p&gt;Need more options? Explore &lt;b&gt;alternative torrent sites&lt;/b&gt;&amp;nbsp;like &lt;a href="https://www.cyberkendra.com/2023/10/extratorrents-proxy-list-2024-to.html" target="_blank"&gt;ExtraTorrents&lt;/a&gt; or RARBG &#128204; for a smoother experience. Happy (and safe) downloading! &#128640;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7uZzVIXP-8BBemx38BYX7z1u7QATuG3oRUC8aUhiHWHC8pdH-JZfjNmOcHKfzuaT5ZzUVOgPvOujTyBIQY_DYhauHI1lV7lAuIowp2hIFB8GfHUupUnYluxpBkg2nKG1wgYsZ5iZFbfurlvP18jdrSveJMY0qJCqaadHbgH54C1JbNw8NOAmq9lhae0M/s72-c/Pirate%20Bay.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">10</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>YIFY Proxy List (YTS) August 2026- Working Updated</title><link>https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html</link><category>Tips</category><category>Torrents</category><pubDate>Sun, 29 Jan 2023 09:33:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3633437093078317981</guid><description>&lt;p style="text-align: left;"&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="YIFY Proxy List - WORKING 2026" border="0" data-original-height="630" data-original-width="1120" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBQul6rsvo90MLsKDeABV4CZQwJAmJmCYWtdEbKGeMMm9N3nrXmRr21dwpXP-X2FlNGoYvmY__XL3lRJqfWotT_gh2kReKC57-zaBe90_emrEXaEDSU-vSPgpKFGiUQbWuz8guVKmI-rrNxWHB09-mbeXDziGOthQliTnlrNb3io9gORwJ87hAWukw/s16000/Top-Working-YIFY-Proxy.webp" title="YIFY Proxy List - WORKING 2026" /&gt;&lt;/div&gt;Yify, also known as YTS, was a popular website for &lt;a href="https://www.cyberkendra.com/2023/03/10-best-torrent-search-engine-sites.html" target="_blank"&gt;downloading and streaming movie torrents&lt;/a&gt;. The site was known for its high-quality movie releases and its user-friendly interface, which made it a favorite among many movie enthusiasts. Unfortunately, the original Yify site was shut down in 2015 due to copyright infringement issues.&lt;p&gt;&lt;/p&gt;&lt;p&gt;However, the YTS brand has been taken over by a new group that continues to provide high-quality movie releases on the YTS website. The new YTS site operates similarly to the original, offering a wide selection of movies for download and streaming, along with a user-friendly interface and a clean, easy-to-navigate design.&lt;/p&gt;&lt;p&gt;One of the biggest draws of the new YTS site is its commitment to releasing only high-quality movies. The site only releases movies in 720p and 1080p resolution, ensuring that users can enjoy the best possible viewing experience. Additionally, the site provides a wide range of subtitles in various languages, making it accessible to a global audience.&lt;/p&gt;&lt;p&gt;Another great feature of the new YTS site is its user-friendly interface. The site's simple and clean design makes it easy to find the movies you're looking for, and the site's powerful search function allows you to quickly find the movies you want. Additionally, the site offers a variety of sorting options, including genre, release date, and rating, making it easy to find the perfect movie for any occasion.&lt;/p&gt; &lt;div class="note wr"&gt;
    &lt;strong&gt;Warning!&lt;/strong&gt;
Cyber Kendra does not condone the use of torrents to illegally obtain content. Using the following torrent websites for illegal purposes is done entirely at your own risk.&lt;br /&gt;
Cyber Kendra takes no responsibility for any legal problems you encounter  &lt;/div&gt;&lt;p&gt;It is always important to keep in mind that downloading copyrighted content is illegal in many countries, and it's important to use such sites with caution. It's always recommended to use a VPN service to protect your privacy and to stream content legally instead of downloading copyrighted content.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="YIFY Proxy List" border="0" data-original-height="623" data-original-width="1024" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGIVXe2oMzRzjDVAo65mjza-3tDH7_uaPsEbAnFcw_By31_5RIdTD3OBRwrKqjEMOrjv_RM5Zh0i3Rl0LUGz3C8V_W45vx3DauYxjZXxKogufXTn9JYWHzhJXA686LJzsrWqWoCX220wYI7vJxqaWIqlN8I8AbzABPUc-vwYAUyV-wM1RfyXKhmCYN/s16000/Yify-Proxy.webp" title="YIFY Proxy List" /&gt;&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Live Proxy sites of Yify or&amp;nbsp;YTS Proxy&amp;nbsp;&amp;nbsp;&lt;/h3&gt;&lt;div&gt;&lt;div&gt;Have a look at the &lt;b&gt;best &lt;a href="https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html" target="_blank"&gt;YIFY Proxy list&lt;/a&gt; sites&lt;/b&gt; that can help download YIFY torrents. All the URLs are sourced from different parts of the Internet and are found to be working.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can unblock YIFY domains and mirror sites from anywhere in the world. We check the proxy links every week to ensure they are working properly.&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;yts.gs&lt;/li&gt;&lt;li&gt;yts.torrentworld.pw&lt;/li&gt;&lt;li&gt;ytss.unblocked.lol&lt;/li&gt;&lt;li&gt;yts.mrunlock.xyz&lt;/li&gt;&lt;li&gt;yts.homes&amp;nbsp;&lt;/li&gt;&lt;li&gt;yts.mx &lt;span style="background-color: #f4cccc;"&gt;NEW&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="background-color: white;"&gt;yts.rs&amp;nbsp;&lt;/span&gt;&lt;span style="background-color: #f4cccc;"&gt;NEW&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Yify Proxy: What it is and How to Use it&lt;/h3&gt;&lt;p&gt;Yify is a popular torrent website that is known for its vast collection of movies and TV shows. However, due to copyright infringement issues, the website has been blocked in many countries. This is where the Yify proxy comes in. A Yify proxy is a mirror website that provides access to the original Yify website, allowing users to download movies and TV shows even when the original site is blocked.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Benefits of Using Yify Proxy&lt;/h3&gt;&lt;p&gt;Access to a vast collection of movies and TV shows: Yify Proxy provides access to the original Yify website, which offers a wide selection. This means that users can download their favorite movies and TV shows without any restrictions.&lt;/p&gt;&lt;p&gt;Cost-effective: Yify proxy is a free service, which means that users do not have to pay any subscription fee or monthly charges to access the website.&lt;/p&gt;&lt;p&gt;Anonymous Browsing: Yify proxy allows users to browse the website anonymously, which means that their IP address and other personal information are not tracked. This is especially useful for users who live in countries where the website is blocked.&lt;/p&gt;&lt;p&gt;Easy to use: Yify proxy is very easy to use and requires no technical skills. Users can simply type in the URL of the Yify proxy website and start downloading movies and TV shows.&lt;/p&gt;
  &lt;div class="note wr"&gt;
Cyber Kendra does not condone the use of torrents to illegally obtain content. Using the following torrent websites for illegal purposes is done entirely at your own risk.&lt;br /&gt;Cyber Kendra takes no responsibility for any legal problems you encounter.&lt;/div&gt;
&lt;h3 style="text-align: left;"&gt;Alternatives to Yify Proxy&lt;/h3&gt;&lt;p&gt;&lt;b&gt;KickAss Proxy List: &lt;a href="https://www.cyberkendra.com/2022/12/kickass-torrents-proxy-list-2023.html" target="_blank"&gt;KickAss or KatCr &lt;/a&gt;is a popular torrent website with&lt;/b&gt;&amp;nbsp;a wide variety of content, including movies, TV shows, games, and software. It is also a free service and has a user-friendly interface.&lt;/p&gt;&lt;p&gt;&lt;b&gt;RARBG&lt;/b&gt;: Another popular torrent website with a vast collection of movies and TV shows. It is also a free service and has a user-friendly interface.&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html" target="_blank"&gt;1337x proxy&lt;/a&gt;&lt;/b&gt;: 1337x is a popular torrent website that has a wide variety of content, including movies, TV shows, games, and software. It is also a free service and has a user-friendly interface.&lt;/p&gt;&lt;p&gt;&lt;b&gt;LimeTorrents&lt;/b&gt;: a popular torrent website offering a wide variety of content, including movies, TV shows, games, and software. It is also a free service and has a user-friendly interface.&lt;/p&gt;&lt;p&gt;&lt;b&gt;The Pirate Bay&lt;/b&gt;: &lt;a href="https://www.cyberkendra.com/2022/12/pirate-proxy-list-2023-unblock-pirate.html" target="_blank"&gt;&lt;b&gt;The Pirate Bay&lt;/b&gt;&lt;/a&gt; is one of the oldest and most popular torrent websites. It has a vast collection of movies, TV shows, games, and software. It is also a free service and has a user-friendly interface.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Conclusion&lt;/h3&gt;&lt;p&gt;Yify Proxy is a great way to access the original Yify website and download movies and TV shows. However, users should be aware that &lt;b&gt;downloading copyrighted content without permission is illegal&lt;/b&gt; in many countries. Therefore, it is important to use a VPN to protect your privacy and stay anonymous while browsing Yify proxy or any other torrent website.&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBQul6rsvo90MLsKDeABV4CZQwJAmJmCYWtdEbKGeMMm9N3nrXmRr21dwpXP-X2FlNGoYvmY__XL3lRJqfWotT_gh2kReKC57-zaBe90_emrEXaEDSU-vSPgpKFGiUQbWuz8guVKmI-rrNxWHB09-mbeXDziGOthQliTnlrNb3io9gORwJ87hAWukw/s72-c/Top-Working-YIFY-Proxy.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>ExtraTorrents Proxy List 2026 [August] To Unblock Extra torrent</title><link>https://www.cyberkendra.com/2023/10/extratorrents-proxy-list-2024-to.html</link><category>Torrents</category><pubDate>Thu, 19 Oct 2023 22:36:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-7687163451941064055</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;
  &lt;img alt="ExtraTorrents Proxy List 2026" border="0" data-original-height="1260" data-original-width="2240" height="1260" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmtPcHYoikhY-QIaCAta9wAShqOY_-LlkEZUYZzIO5s2JSh4hDCpJUEkwBHhqqI6b7eX3vRnjmr6-FaWLs_lnDYT2r0OT3-tAQhMGz_UShCMputZVsbSCVBWbq424dhjEoHX-8d9GmKrNQz2C46mt8NprUIWNO7Jp6UIc7ESqQvwnbQA0YMaNDMtTCYA0/w640-h360/ExtraTorrents.webp" title="ExtraTorrents Proxy List 2026" width="2240" /&gt;
&lt;/div&gt;
&lt;p&gt;ExtraTorrents was one of the most popular torrent sites on the web,
providing access to millions of torrent files for movies, TV shows, music,
games, software, and more.&lt;/p&gt;
&lt;p&gt;
  Undoubtedly, it was one of the most popular torrent websites before it was
  shut down in 2017. However, in May 2017,
  &lt;b&gt;&lt;a href="https://www.cyberkendra.com/2017/05/extratorrent-permanently-shut-down.html" target="_blank"&gt;ExtraTorrents went offline permanently&lt;/a&gt;&lt;/b&gt;
  after an alleged domain seizure.
&lt;/p&gt;
&lt;p&gt;
  Millions of users download movies, games, music, software, and more on
  ExtraTorrents each day.
&lt;/p&gt;
&lt;p&gt;
  When ExtraTorrents went offline permanently, many users began searching for
  proxy sites to access the platform again. While ExtraTorrents is gone, proxies offer a workaround to access the site via mirrors and caches.
&lt;/p&gt;
&lt;h2 style="text-align: left;"&gt;
  How Does ExtraTorrent Proxy Work To Unblock ExtraTorrents?
&lt;/h2&gt;
&lt;p&gt;Like other &lt;a href="https://www.cyberkendra.com/2023/03/10-best-torrent-search-engine-sites.html" target="_blank"&gt;torrenting websites&lt;/a&gt; (The Pirate Bay, KickAss Torrents, YIFY, etc.), ExtraTorrents also has its own mirrors or proxies.&lt;/p&gt;
&lt;p&gt;
  An ExtraTorrents proxy site acts as an intermediary between you and
  ExtraTorrents. When you access an ExtraTorrents proxy, the proxy website
  connects to servers and databases where ExtraTorrents data is stored.
&lt;/p&gt;
&lt;p&gt;
  It then fetches the pages, torrent files, and other content you request and
  displays them to you. This allows access to ExtraTorrents even though the
  original site is inaccessible.
&lt;/p&gt;
&lt;p&gt;
  The proxy also masks your IP address, hiding your identity and location. This
  allows access if ExtraTorrents is blocked by your ISP or country. Overall,
  proxies provide a clever workaround to use ExtraTorrents again through cached
  copies.
&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;Benefits of Using an ExtraTorrents Proxy&lt;/h3&gt;
&lt;p&gt;
  There are a few key benefits to accessing ExtraTorrents through a proxy site:
&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;
    &lt;b&gt;Access cached copies of ExtraTorrents content: &lt;/b&gt;Even though
    ExtraTorrents is down, proxy sites can still provide access to cached copies
    of site pages and torrent files. This allows you to browse and download
    content just like when ExtraTorrents was still up.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Bypass ISP blocks: &lt;/b&gt;In some locations, internet service providers
    block access to torrent sites like ExtraTorrents. Proxies can bypass these
    blocks, allowing access from restricted networks.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Enhanced privacy: &lt;/b&gt;Using a proxy hides your IP address and location,
    providing greater anonymity. This prevents sites like ExtraTorrents from
    tracking your downloads.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Circumvent country restrictions: &lt;/b&gt;allows&amp;nbsp;access to ExtraTorrents from
    restricted regions.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Nostalgia - &lt;/b&gt;Long-time users still navigate the familiar ExtraTorrents
    interface through proxies.
  &lt;/li&gt;
&lt;/ul&gt;
&lt;div class="note wr"&gt;
  Cyber Kendra does not condone the use of torrents to illegally obtain content.
  Using the following torrent websites for illegal purposes is done entirely at
  your own risk. Cyber Kendra takes no responsibility for any legal problems you
  encounter
&lt;/div&gt;
&lt;h3 style="text-align: left;"&gt;Risks of ExtraTorrents Proxies&lt;/h3&gt;
&lt;p&gt;
  While proxies provide useful access to blocked sites, there are also some
  risks to consider:
&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;
    &lt;b&gt;No guarantees torrents are safe: &lt;/b&gt;ExtraTorrents proxies lead to cached
    copies of site content. However, there's no guarantee that these torrent
    files are malware-free and safe to download. Be cautious.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Possibility of outdated content:&lt;/b&gt; Proxy sites only have access to
    cached copies of ExtraTorrents. This content may be outdated, with broken
    torrents and missing files. The original ExtraTorrents library can't be
    recreated.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Proxies come and go:&lt;/b&gt; Proxy sites are inherently unstable and can go
    down or change URLs at any time. A proxy that works one day may be
    inaccessible the next.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Legality is questionable: &lt;/b&gt;accessing copyright-infringing torrents via proxies falls into&amp;nbsp;a legal grey area. While proxies themselves aren't
    illegal, they enable piracy, which may carry risks.
  &lt;/li&gt;
&lt;/ul&gt;
&lt;h3 style="text-align: left;"&gt;Latest ExtraTorrents Proxy Sites&lt;/h3&gt;
&lt;p&gt;
  Several ExtraTorrent proxy and mirror sites appeared after the original site
  went down. Here are some of the most popular and reliable options in 2026:
&lt;/p&gt;
  &lt;pre data-lang="ExtraTorrents Working Proxy List 2026"&gt;&lt;code class="your-language-here"&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;a href="http://extratorrent.xyz" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://filesdownloader.com/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://freeanimesonline.com/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 4&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://freeproxy.io/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://sitenable.ch/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 6&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://sitenable.co/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="https://sitenable.pw/o.php?u=https://extratorrent.to/proxy.php" rel="nofollow" target="_blank"&gt;ExtraTorrents Proxy 8&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;h3 style="text-align: left;"&gt;ExtraTorrents Alternatives&lt;/h3&gt;
&lt;p&gt;
  While proxies provide access, no ExtraTorrents mirror is an exact replacement.
  Here are some top alternatives for torrent downloads:
&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ol style="text-align: left;"&gt;
  &lt;li&gt;
    &lt;b&gt;&lt;a href="https://www.cyberkendra.com/2022/12/pirate-proxy-list-2023-unblock-pirate.html" target="_blank"&gt;The Pirate Bay&lt;/a&gt;
      - &lt;/b&gt;One of the most well-known torrent sites globally, with a huge selection.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;RARBG - &lt;/b&gt;Popular site with a clean interface, good for movies and TV.
  &lt;/li&gt;
  &lt;li&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html" target="_blank"&gt;1337X proxy&lt;/a&gt; -&lt;/b&gt; Extensive torrent database for all types of media.&lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;&lt;a href="https://www.cyberkendra.com/2022/12/kickass-torrents-proxy-list-2023.html" target="_blank"&gt;KickAss (KATcr)&lt;/a&gt;
      -&lt;br /&gt;&lt;/b&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;&lt;a href="https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html" target="_blank"&gt;YTS &lt;/a&gt;- &lt;/b&gt;Great source focused on movie torrents in a range of qualities.
  &lt;/li&gt;
  &lt;li&gt;
    &lt;b&gt;Torlock - &lt;/b&gt;A&lt;b&gt;&amp;nbsp;&lt;/b&gt;Torrent index with a strong verified uploader community.
  &lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;
  These alternatives help fill the void left by ExtraTorrents. However, proxies
  remain useful to access ET's extensive library.
&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;VPN To Unblock ExtraTorrents Site&lt;/h3&gt;
&lt;p&gt;
  A VPN, or virtual private network, provides another option to access blocked
  sites like ExtraTorrents. A VPN routes your traffic through an encrypted
  tunnel to a server in another location.
&lt;/p&gt;
&lt;p&gt;This hides your true IP address and spoofs your location. Use a VPN to:&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;Bypass geographic blocks and access ExtraTorrents from anywhere.&lt;/li&gt;
  &lt;li&gt;Encrypt traffic so ISPs can't see your activity.&lt;/li&gt;
  &lt;li&gt;Hide torrenting from your ISP and copyright enforcers.&lt;/li&gt;
  &lt;li&gt;Improve security when downloading files.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Top VPNs like ExpressVPN and NordVPN work seamlessly for torrenting.&lt;/p&gt;
&lt;h3 style="text-align: left;"&gt;How To Download Torrent Files?&lt;/h3&gt;
&lt;p&gt;Here is a quick guide to downloading torrents safely:&lt;/p&gt;
&lt;div class="zerchpro_alert alert_error"&gt;
    Cyber Kendra does not condone the use of torrents to illegally obtain content.
    Using the following torrent websites for illegal purposes is done entirely
    at your own risk. Cyber Kendra takes no responsibility for any legal
    problems you encounter
  &lt;/div&gt;
  &lt;ol&gt;
    &lt;li&gt;
      &lt;p&gt;Choose a trusted proxy or VPN for security.&lt;/p&gt;
    &lt;/li&gt;
    &lt;li&gt;
      &lt;p&gt;
        Find a torrent file for the content you want to download. Note: Stick
        with trusted uploaders.
      &lt;/p&gt;
    &lt;/li&gt;
    &lt;li&gt;
      &lt;p&gt;Download the small .torrent file onto your computer, or you can also get/copy the magnet link of the torrent.&lt;/p&gt;
    &lt;/li&gt;
    &lt;li&gt;
      &lt;p&gt;
        Open the torrent in a BitTorrent client like qBittorrent or
        &lt;a href="https://www.cyberkendra.com/2018/02/critical-remote-code-execution-bug-puts.html" target="_blank"&gt;uTorrent&lt;/a&gt;.
      &lt;/p&gt;
    &lt;/li&gt;
    &lt;li&gt;
      &lt;p&gt;
        Select the location where you want to save the full content files. Let
        the download start!
      &lt;/p&gt;
    &lt;/li&gt;
    &lt;li&gt;
      &lt;p&gt;It is always recommended to do a Virus scan before opening. For
        this, you can use the VirusTotal website, which is very much trusted to
        check the files shared on the internet.
      &lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;


&lt;h3 style="text-align: left;"&gt;Is Torrenting Legal?&lt;/h3&gt;
&lt;p&gt;The legality of torrenting depends on usage:&lt;/p&gt;
&lt;ul style="text-align: left;"&gt;
  &lt;li&gt;
    Downloading copyrighted material is often illegal without permission. This
    includes movies, TV shows, games, music, and software.
  &lt;/li&gt;
  &lt;li&gt;
    Torrenting the public domain and authorised content is perfectly legal. Legally available games, movies, and files can be torrented
    safely.
  &lt;/li&gt;
  &lt;li&gt;
    Many jurisdictions turn a blind eye to individual torrent downloads for
    personal use only. But uploading/sharing may cross the line.
  &lt;/li&gt;
  &lt;li&gt;
    Use common sense and torrent responsibly! A VPN or proxy provides extra
    anonymity for those who sail the high seas.
  &lt;/li&gt;
&lt;/ul&gt;
&lt;h2 style="text-align: left;"&gt;What Happened To ExtraTorrents?&lt;/h2&gt;
&lt;p&gt;
  ExtraTorrents grew into one of the top torrent communities in the 2000s.
  However, in May 2017, the site suddenly went offline.
&lt;/p&gt;
&lt;p&gt;
  Speculation points to legal pressure around copyright. Some reports suggest
  its domain was seized through legal channels.
&lt;/p&gt;
&lt;p&gt;
  Whatever the cause, ExtraTorrents remains inactive with no plans to return.
  The admins did not set up redirects or alternatives before the shutdown.
&lt;/p&gt;
&lt;p&gt;
  While the original community is gone, ExtraTorrent's legacy lives on through
  proxies and replacements. But the loss left a mark on the torrent landscape.
&lt;/p&gt;
&lt;p&gt;
  In summary, while ExtraTorrents is gone, various proxy sites provide
  roundabout access to cached copies in 2023. However, use caution and protect
  yourself when accessing any torrent platform.
&lt;/p&gt;
</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmtPcHYoikhY-QIaCAta9wAShqOY_-LlkEZUYZzIO5s2JSh4hDCpJUEkwBHhqqI6b7eX3vRnjmr6-FaWLs_lnDYT2r0OT3-tAQhMGz_UShCMputZVsbSCVBWbq424dhjEoHX-8d9GmKrNQz2C46mt8NprUIWNO7Jp6UIc7ESqQvwnbQA0YMaNDMtTCYA0/s72-w640-h360-c/ExtraTorrents.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>1337x Proxy List 2026 [August 2026] - Best Alternative and Mirror</title><link>https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html</link><category>Internet</category><category>Torrents</category><pubDate>Sun, 7 Apr 2024 23:21:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-1078991593587710032</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="1337x Proxy List 2026" border="0" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZ-gzFCf5ZYx1Cm8YrIsF7s4rvm-Kho4NTUtW4yXoebz8m98Ac3e-gbafmQ3c46R3gCD5sWCcRznTwzik-ycjezQjFC9CNSptSqHTtvE9vhSJEG188AWnkU5YR0DpD2jZNTnO2n6p6Oesp2K1wPwEEGEoqni8n-XWekKevp932j6UoKCSxAmdbZHjKIaE/s16000/1337x.webp" title="1337x Proxy List 2026" /&gt;&lt;/div&gt;&lt;p&gt;In the ever-evolving world of torrenting, 1337x remains one of the most popular platforms for downloading movies, TV shows, games, and more. However, due to regional restrictions and privacy concerns, many users rely on 1337x proxy sites and mirrors to access this popular torrent platform.&lt;/p&gt;&lt;p&gt;This guide will walk you through everything you need to know about &lt;b&gt;1337x proxies and mirrors&lt;/b&gt;, including how to &lt;b&gt;unblock 1337x proxies&lt;/b&gt;, ensure safe torrenting, and explore the best alternatives.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What Is a 1337x Proxy?&lt;/h2&gt;&lt;p&gt;A 1337x proxy acts as a middleman between your device and the main 1337x torrent sites. When you use a proxy, your internet traffic is routed through another server, hiding your real IP address and location. This helps you:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Bypass ISP blocks (if your ISP blocks access to torrent sites).&lt;/li&gt;&lt;li&gt;Maintain privacy while torrenting files.&lt;/li&gt;&lt;li&gt;Access 1337x unblocked even if the main domain is restricted.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;However, not all proxies are safe—some may be slow, unreliable, or even malicious. Always choose trusted 1337x proxy sites to avoid security risks.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Are 1337x Proxies Legal and Safe?&lt;/h3&gt;&lt;h4 style="text-align: left;"&gt;Legality&lt;/h4&gt;&lt;p&gt;Using a &lt;b&gt;torrent proxy&lt;/b&gt; itself isn’t illegal, but downloading copyrighted content without permission violates laws in many countries. Always check the legal status of files before downloading.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;Safety Concerns&lt;/h4&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Free proxies&lt;/b&gt; may log your data or contain malware.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Reputable proxies&lt;/b&gt; use encryption to protect your activity.&lt;/li&gt;&lt;li&gt;For maximum security, consider a VPN (Virtual Private Network) instead, as it provides stronger encryption and greater anonymity.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Top Working 1337x Proxy Sites (2026)&lt;/h2&gt;&lt;p&gt;Here’s a verified list of 1337x mirrors that are currently active:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;1337x.bz&lt;/li&gt;&lt;li&gt;www.1337x.tw&lt;/li&gt;&lt;li&gt;1337x.proxyninja.org&lt;/li&gt;&lt;li&gt;ww3.13377x.tw&lt;/li&gt;&lt;li&gt;1337x.to&lt;/li&gt;&lt;li&gt;1337x.st&lt;/li&gt;&lt;li&gt;1337x.pro&lt;/li&gt;&lt;li&gt;x1337x.eu&lt;/li&gt;&lt;li&gt;x1337x.ws&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;(Note: Proxy sites can change frequently. Always check for the latest updates.)&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Best Alternatives to 1337x (2026)&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" data-original-height="720" data-original-width="1280" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihBXvkd3A-V-A6O5pnfX2Z5MTHYc8RYZ_31RPlhShv0gyFPLNyvX51oObsUUSovGZJ0O3WREBz7gDgW2aiMD8XTFxDP3nIgTXfKafKPOOzU_yCIdtH2hFGqTp8QSDCXOGN26PFrFyiuoBQW5wKBp3ZTB7VZ9SO2bagHMl5RHFDAsZaspwhAuph0Z6xWcg/s16000/1337x%20Proxy%20List%202024.webp" /&gt;&lt;/div&gt;&lt;p&gt;If &lt;b&gt;1337x torrent sites&lt;/b&gt; are down, try these websites like 1337x:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2022/12/pirate-proxy-list-2023-unblock-pirate.html" target="_blank"&gt;The Pirate Bay Proxy&lt;/a&gt;&lt;/b&gt; – One of the oldest torrent download sites, offering movies, games, and software.&lt;/li&gt;&lt;li&gt;&lt;b&gt;RARBG Proxy&lt;/b&gt; – Known for high-quality movies &amp;amp; TV shows.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html" target="_blank"&gt;YTS Proxy&lt;/a&gt;&lt;/b&gt; – Specialises in HD films with small file sizes.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Zoogle Proxy &lt;/b&gt;– A growing peer-to-peer community with a vast library.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2022/12/kickass-torrents-proxy-list-2023.html" target="_blank"&gt;Kickass Torrents Proxy&lt;/a&gt;&lt;/b&gt; – Despite past legal issues, it remains a popular torrenting method.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How to Use a 1337x Proxy&lt;/h3&gt;&lt;p&gt;Using a &lt;b&gt;1337x mirror site&lt;/b&gt; is simple:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;Find a working proxy (use the list above or search for updated ones).&lt;/li&gt;&lt;li&gt;Enter the URL (e.g., https://1337x.bz) in your browser.&lt;/li&gt;&lt;li&gt;Browse and download torrents as usual.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;For extra security:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Use a VPN to hide your IP.&lt;/li&gt;&lt;li&gt;Avoid clicking on suspicious ads.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How to Unblock 1337x If It’s Restricted&lt;/h3&gt;&lt;p&gt;If your ISP is blocking access to torrent sites, try these methods:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;✅ Use a VPN – Connects you to a server where 1337x is accessible.&lt;/li&gt;&lt;li&gt;✅ Try Different Mirrors – Search for new 1337x proxy sites.&lt;/li&gt;&lt;li&gt;✅ Use Tor Browser – Accesses the site anonymously via the Tor network.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Staying Safe While Torrenting&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Avoid downloading copyrighted material illegally.&lt;/li&gt;&lt;li&gt;Use a VPN for encrypted browsing.&lt;/li&gt;&lt;li&gt;Stick to trusted proxies to prevent malware risks.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Final Thoughts&lt;/h3&gt;&lt;p&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html" target="_blank"&gt;1337x proxies and mirrors&lt;/a&gt;&lt;/b&gt; are useful for bypassing restrictions, but always prioritise safety. Whether you're looking to download free content or explore &lt;b&gt;&lt;a href="https://www.cyberkendra.com/2023/03/10-best-torrent-search-engine-sites.html" target="_blank"&gt;popular torrent sites&lt;/a&gt;&lt;/b&gt;, using a VPN and verified proxies ensures a smooth and secure experience.&lt;/p&gt;&lt;p&gt;Stay updated with the latest &lt;b&gt;1337x unblocked &lt;/b&gt;links, and happy torrenting! &#128640;&lt;/p&gt;&lt;p&gt;Disclaimer: This guide is for educational purposes only. We do not endorse illegal downloading. Always comply with your local laws when using torrent websites.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZ-gzFCf5ZYx1Cm8YrIsF7s4rvm-Kho4NTUtW4yXoebz8m98Ac3e-gbafmQ3c46R3gCD5sWCcRznTwzik-ycjezQjFC9CNSptSqHTtvE9vhSJEG188AWnkU5YR0DpD2jZNTnO2n6p6Oesp2K1wPwEEGEoqni8n-XWekKevp932j6UoKCSxAmdbZHjKIaE/s72-c/1337x.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>TorrentGalaxy Proxy List 2026 : Best Alternative of TorrentGalaxy [August Update]</title><link>https://www.cyberkendra.com/2024/10/torrentgalaxy-proxy-list.html</link><category>Torrents</category><pubDate>Fri, 30 May 2025 22:56:00 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2207211384306934143</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="TorrentGalaxy Proxy list" border="0" data-original-height="630" data-original-width="1200" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp4pnEF33eHEz9GnvFoGi1byFWvyPiOW2Moa7UaFJ3Gjeq6u2FcUsoyFvMt2bNtTmQXfSsHbhtqFQjfpy-ce1id6HOjWH3BQUiZoE0U-1fvDpxND3r5GVhTLXw9jR8yRGltwmId6jDBSiVjwQfoC_NTTr_HM-45v8kj7Fp-FsSAIGjJXPlxXQ36VLPu1s/s16000/torrentgalaxy-proxy.webp" title="TorrentGalaxy Proxy list" /&gt;&lt;/div&gt;&lt;p&gt;Are you looking for the best TorrentGalaxy proxy list, mirror sites, and alternatives, or a new torrent site to download your favourite movies, TV shows, games, or software?&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;So you are in the right place for your needs.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.cyberkendra.com/2024/06/torrentgalaxy-goes-offline-with.html" target="_blank"&gt;TorrentGalaxy mysteriously disappeared&lt;/a&gt; overnight, with just a single line message in June 2024, which left many users puzzled and concerned about its future. Torrent Galaxy often faces downtime or domain changes due to legal pressures, and many users are seeking reliable alternatives.&lt;/p&gt;&lt;p&gt;Here's a detailed guide to help you navigate the best options in 2026, ensuring you find the platform that best matches your torrenting needs.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Why Look for Alternatives?&lt;/h3&gt;&lt;p&gt;Before diving into the alternatives, let's briefly discuss why one might need to look beyond Torrent Galaxy:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Legal Issues: Torrent sites frequently face legal actions, which can lead to site closures or domain shifts.&lt;/li&gt;&lt;li&gt;Site Reliability: Downtime or slow loading times can significantly inconvenience users.&lt;/li&gt;&lt;li&gt;Content Availability: Different sites might offer better access to certain types of content or a more extensive library in specific areas, such as anime or indie games.&lt;/li&gt;&lt;li&gt;User Experience: Not all torrent sites are created equal when it comes to user interface, speed, and community engagement.&lt;/li&gt;&lt;/ul&gt;&lt;div class="note wr"&gt;
  Cyber Kendra does not condone the use of torrents to illegally obtain content.
  Using the following torrent websites for illegal purposes is done entirely at
  your own risk. Cyber Kendra takes no responsibility for any legal problems you
  encounter
&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;TorrentGalaxy Proxy list for 2026&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;https://torrentgalaxy.to&lt;/li&gt;&lt;li&gt;https://torrentgalaxy.hair&lt;/li&gt;&lt;li&gt;https://torrentgalaxy.one&lt;/li&gt;&lt;li&gt;https://torrentgalaxy.skin&lt;/li&gt;&lt;li&gt;https://torrentgalaxy.mx&lt;/li&gt;&lt;li&gt;https://tgx.rs&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;TorrentGalaxy Proxy Onion Domain&lt;/b&gt;&lt;/p&gt;&lt;p&gt;You can use the TorrentGalaxy proxy from the .onion address. Open it in the Tor browser to unblock the TorrentGalaxy torrent site, bypassing the ISP firewall, and, for enhanced privacy and stability, consider using &lt;a href="https://multilogin.com/gateway/residential-proxies/" target="_blank"&gt;residential proxies&lt;/a&gt; alongside Tor.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;galaxy3yrfbwlwo72q3v2wlyjinqr2vejgpkxb22ll5pcpuaxlnqjiid.onion&lt;/li&gt;&lt;li&gt;http://galaxy3k5w5zd77zz2fzrrplj4hkcn6dbauy3nyrxjnhaszgc3xyhrqd.onion (Tor proxy)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Now, let's explore some of the &lt;b&gt;top alternatives to TorrentGalaxy&lt;/b&gt;&amp;nbsp;:&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;1. 1337x&lt;/h4&gt;&lt;p&gt;&lt;a href="https://www.cyberkendra.com/2024/04/1337x-proxy-list-2024-your-guide-to.html" target="_blank"&gt;1337x&lt;/a&gt; has established itself as a robust torrent site with a wide range of content from movies to music, software, and games. Known for its stability, 1337x has avoided many of the pitfalls other sites fall into.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;User-Friendly Interface: Clean and straightforward layout.&lt;/li&gt;&lt;li&gt;Verified Torrents: Many torrents are user-verified, reducing the risk of downloading malicious files.&lt;/li&gt;&lt;li&gt;Active Community: Comment sections often provide useful insights or warnings about torrent quality.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Users:&lt;/b&gt; If you're looking for a site with a broad library and good community feedback, 1337x is ideal. However, always use a VPN for safety, given its notoriety.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;2. YTS&lt;/h4&gt;&lt;p&gt;While YTS primarily focuses on movies, it's renowned for its high-quality video torrents that are small in file size, making it excellent for those with limited bandwidth or storage. Check the &lt;a href="https://www.cyberkendra.com/2023/01/yify-proxy-mirror-site-list-2023.html" target="_blank"&gt;YTS proxy list&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Quality Torrents: High-quality rips with surprisingly small sizes.&lt;/li&gt;&lt;li&gt;Simplistic Design: Makes navigation easy for any user.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Users: &lt;/b&gt;Movie buffs will appreciate YTS's focus and efficiency, though it lacks variety in other content types, such as TV shows or software.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;3. EZTV&lt;/h4&gt;&lt;p&gt;EZTV is your go-to if TV shows are what you’re after. It's been around for a long time, known for its reliability and extensive collection of TV series.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;TV Show Specialisation: Probably the best place for TV content.&lt;/li&gt;&lt;li&gt;Immediate Availability: Episodes often appear shortly after airing.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;For Users: If your torrenting needs are predominantly television-related, EZTV is unparalleled.&amp;nbsp;&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;4. NYAA&lt;/h4&gt;&lt;p&gt;NYAA specialises in East Asian media, particularly anime, manga, and Japanese video games. It's a revival of the original NYAA, which was shut down due to legal issues.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Anime Haven: Extensive collection of anime and manga.&lt;/li&gt;&lt;li&gt;Quality Control: Although not all torrents are verified, the community's feedback system helps sort the good from the bad.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Users: &lt;/b&gt;Anime and manga enthusiasts will find NYAA a treasure trove, but it might not satisfy those looking for Western media.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;5. RARBG&lt;/h4&gt;&lt;p&gt;RARBG has a reputation for high-quality torrents across various categories. It's known for its movie torrents and provides good music, software, and game options.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;High-Quality Torrents: Often provides remuxes or high-bitrate versions of movies.&lt;/li&gt;&lt;li&gt;Community Voting: Allows users to vote on torrent quality.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;For Users: &lt;/b&gt;Ideal for users who prioritise quality over quantity. Its domain has been seized multiple times, so staying updated via social media or forums can help.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;6. Heliosphere&lt;/h4&gt;&lt;p&gt;Mentioned as a favoured alternative in some social media posts, Heliosphere is less well-known but is gaining traction, especially among those seeking a fresh take on torrent communities.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Growing Library: While not as extensive, it's curated well.&lt;/li&gt;&lt;li&gt;User Interface: Modern and easy to navigate.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Users: &lt;/b&gt;This is a good option if you're looking for a site with fewer ads and less legal heat.&lt;/p&gt;&lt;h4 style="text-align: left;"&gt;7. Stremio with Torrentio Add-on&lt;/h4&gt;&lt;p&gt;While not a traditional torrent site, Stremio, with the Torrentio add-on, provides a streaming-like experience from torrents, offering content in a more user-friendly format.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Features:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Integration with Torrent Sources: Pulls from various torrent sites.&lt;/li&gt;&lt;li&gt;Streaming: Watch content without downloading directly from torrent sources.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;For Users:&lt;/b&gt; Perfect for those who prefer streaming over downloading. You still need a VPN for privacy.&lt;/p&gt;&lt;div class="note wr"&gt;
  Cyber Kendra does not condone the use of torrents to illegally obtain content.
  Using the following torrent websites for illegal purposes is done entirely at
  your own risk. Cyber Kendra takes no responsibility for any legal problems you
  encounter
&lt;/div&gt;&lt;h3 style="text-align: left;"&gt;Tips for Safe Torrenting&lt;/h3&gt;&lt;p&gt;&lt;/p&gt;&lt;ol style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Use a VPN:&lt;/b&gt; Always torrent with one to mask your IP address and keep your activities private.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Check Comments: &lt;/b&gt;Review user comments before downloading to gauge torrent reliability.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Antivirus:&lt;/b&gt; Keep your antivirus software up to date to scan torrent files for malware.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Legal Awareness:&lt;/b&gt; Understand the copyright laws in your region. Torrenting copyrighted material without permission is illegal in many countries.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Conclusion&lt;/h3&gt;&lt;p&gt;Finding a good alternative to Torrent Galaxy isn't just about replacing one site with another; it's about choosing a platform that aligns with your specific needs—content focus, user experience, or security features.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Each site listed here offers unique strengths, from YTS's compact movie files to EZTV's extensive TV show archive. When switching, consider what you value most in your torrenting experience and choose accordingly.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Remember, the landscape of torrent sites is ever-changing, so staying informed through tech blogs, forums, and social media can keep you ahead of the curve.&lt;/p&gt;&lt;p&gt;Happy torrenting, and always stay safe online!&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp4pnEF33eHEz9GnvFoGi1byFWvyPiOW2Moa7UaFJ3Gjeq6u2FcUsoyFvMt2bNtTmQXfSsHbhtqFQjfpy-ce1id6HOjWH3BQUiZoE0U-1fvDpxND3r5GVhTLXw9jR8yRGltwmId6jDBSiVjwQfoC_NTTr_HM-45v8kj7Fp-FsSAIGjJXPlxXQ36VLPu1s/s72-c/torrentgalaxy-proxy.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Blogger Malware Lockout: What Happened and What to Do</title><link>https://www.cyberkendra.com/2026/08/bloggers-malware-glitch-dont-touch-your.html</link><category>Blogger</category><category>Google</category><category>Web Hosting</category><pubDate>Wed, 5 Aug 2026 23:42:30 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-7585876853967752208</guid><description>&lt;div class="separator" style="clear: both;"&gt;&lt;img alt="" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2a6i24-77y0zXT6BNOBBmwM76uI64W9ygNyX0BJj1JTQ2-gDmq0FZXWyjygDAox_DbI88qjijtP2GeRLCvSsGEfkwBs2ZDRzk6wMImf6-rQ2Yayj7XOAilnW8ghvTzYxdO0GQqZcU_ZYare9sH8lsssx2vt_u1T-ODG4qEuMRHfOcWW0UhYIJwEbPHYs/s1600/blog-deleted.webp" /&gt;&lt;/div&gt;


&lt;p class="note tp"&gt;&lt;strong&gt;✅ RESOLVED — Updated August 12, 2026&lt;/strong&gt;&lt;br /&gt;
Google has fixed the bug behind the August 4 mass lockout, and Blogger Product Experts have confirmed the root cause is resolved. Most blogs were back within 24 to 48 hours.&lt;br /&gt;
&lt;strong&gt;You can edit your theme again.&lt;/strong&gt; The advice to freeze your template applied during the incident and has now been formally lifted. If your blog is still locked, request a review — blogs that never appealed may not be in the review queue at all.&lt;/p&gt;
 
&lt;p&gt;What follows is the full record: what happened, why restored blogs kept getting locked a second time, and how to make sure a platform-side classifier can never take your archive offline again.&lt;/p&gt;
 
&lt;h2&gt;The resolution: what Google and the Product Experts confirmed&lt;/h2&gt;
 
&lt;p&gt;On August 9, a Blogger Gold Product Expert posted that the issue had been resolved and that confirmation had come from the team responsible, pointing to an official announcement published in the Spanish-language Blogger community. The thread's original poster, a Diamond Product Expert, followed with a summary that is now the marked Recommended Answer:&lt;/p&gt;
 
&lt;blockquote&gt;
&lt;p&gt;The root cause has been resolved. Most blogs were back online within the first 24 to 48 hours. Blogs still locked should click Request review in the dashboard, or wait if they have already done so. Not all reports are false positives, and each case is reviewed individually.&lt;/p&gt;
&lt;cite&gt;— Blogger Diamond Product Expert, August 9, 2026&lt;/cite&gt;
&lt;/blockquote&gt;
 
&lt;p&gt;Three details in that summary matter more than the headline.&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Editing your theme is safe again.&lt;/strong&gt; The same summary states that anyone whose blog was reinstated, or never affected, can return to normal — publishing posts and editing themes included. During the incident the pinned advisory had been amended to tell users to temporarily hold off on theme and layout edits, explicitly on the basis of community reports. That caution is now withdrawn.&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Not every locked blog was a false positive.&lt;/strong&gt; This is the line most coverage has skipped. The Product Expert states plainly that each case is reviewed individually and that not all reports in the thread were misclassifications. A blog still locked after the fix is not automatically owed a restoration.&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;If you never appealed, appeal now.&lt;/strong&gt; A second Diamond Product Expert noted that the official announcement suggests only blogs that requested a review will be reviewed. There is some ambiguity in the wording, and the safe reading is the cautious one: an un-appealed blog may simply be sitting outside the queue.&lt;/p&gt;
 
&lt;p&gt;The support thread has since been soft locked, with only Product Experts and the original poster able to reply. It finished with 531 "I have the same question" votes.&lt;/p&gt;
 
&lt;h2&gt;What happened on August 4&lt;/h2&gt;
 
&lt;p&gt;The finding that mattered most during the incident sat buried 140 comments deep in Google's own support thread: restored blogs were being locked again within minutes, and the common thread in almost every re-lock was a write to the template — not a new post. Here is the full record.&lt;/p&gt;


&lt;h2&gt;The first wave&lt;/h2&gt;

&lt;p&gt;On August 4, 2026, Google's automated systems began locking Blogger blogs en masse, citing the Malware and Similar Malicious Content policy. Owners received an email saying their blog had been removed. The dashboard showed a red padlock and a notice that the blog was removed for violating Blogger's Community Guidelines.&lt;/p&gt;

&lt;p&gt;The first wave hit around 2:15 PM Eastern on August 4. Reports followed in sequence around the world: Brazil at roughly 2:30 PM local, France and Italy through the evening, Korea at about 2:00–2:15 AM KST on August 5, then India, Indonesia, Vietnam and the Gulf through the morning.&lt;/p&gt;

&lt;p&gt;A &lt;strong&gt;Blogger Diamond Product Expert posting as WebLove.PL&lt;/strong&gt; &lt;a href="https://support.google.com/blogger/thread/457259506/august-4-2026-false-positives-for-malware-and-similar-malicious-content-policy" rel="nofollow" target="_blank"&gt;opened a tracking thread&lt;/a&gt; and stated plainly that the volume of identical reports pointed to misclassification by automated systems, adding that false positives happen, but not at this scale. The Blogger engineering team was notified. &lt;/p&gt;&lt;p&gt;That thread went on to draw over 170 replies and more than 500 "I have the same question" votes. For roughly the first day it was the only acknowledgement of any kind — Google published nothing on its blog, its status dashboard or its social channels before issuing a brief statement to BleepingComputer on August 5, confirming a bug had incorrectly flagged Blogger-hosted sites and saying a fix was in progress. No postmortem, affected-blog count, or technical explanation has been published since.&lt;/p&gt;

&lt;h2&gt;The scale is not normal&lt;/h2&gt;

&lt;p&gt;Counting distinct blogs named in the thread and adjacent threads gives a partial list running well past a hundred, across at least sixteen languages — English, Korean, Arabic, Portuguese, Spanish, French, German, Italian, Greek, Indonesian, Thai, Vietnamese, Romanian, Dutch, Polish and Hindi.&lt;/p&gt;

&lt;p&gt;The affected sites have nothing in common except the platform:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;whomyouknow.com&lt;/strong&gt; — 31,200+ posts, offline about 20 hours&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;dynamictutorialsandservices.org&lt;/strong&gt; — an educational site running since 2008, 4,600+ pages&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;raidersofthelostscent.blog&lt;/strong&gt; — vintage perfume archive, active since 2009, 3M+ pageviews&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;tknt-hsu.blogspot.com&lt;/strong&gt; — the official academic blog of the Faculty of Design and Art, Hoa Sen University, Vietnam&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;mediablog.ro&lt;/strong&gt; — a Romanian journalism site of more than 15 years&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;spata-artemis.com&lt;/strong&gt; — a Greek local news archive&lt;/li&gt;
  &lt;li&gt;One Arabic blogger reported four blogs and over 10,000 posts locked at once&lt;/li&gt;
  &lt;li&gt;A Korean blogger reported that six blogs were suspended simultaneously&lt;/li&gt;
  &lt;li&gt;One user reported 20 million lifetime views on a purely educational blog&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Also caught: an 18-year-old Spanish maths blog, a 14-year-old quilting blog, a devotional lyrics site, a dog care blog in Hinglish, a Lombardy events calendar, a baseball news site, and — as one user noted with some irony — an account suspended for "spam" whose only post was pictures of a kitten.&lt;/p&gt;

&lt;p&gt;One report deserves particular weight. A blogger running &lt;strong&gt;three separate blogs on three different Google accounts&lt;/strong&gt; watched all three lock inside a fifteen-minute window. They decompiled and pretty-printed the minified JavaScript in their theme files, checked for redirects and hidden iframes, and ran multi-engine analysis through VirusTotal plus a sandbox behavioural report. Zero detections across every engine. Search Console is clean on all three properties.&lt;/p&gt;

&lt;p&gt;That is about as close to a controlled experiment as a support forum ever produces, and it points squarely at the classifier rather than the content.&lt;/p&gt;

&lt;h2&gt;The re-lock loop: why restored blogs went down again&lt;/h2&gt;

&lt;p&gt;Restorations began around mid-morning UTC on August 5. Emails went out saying the blog had been reviewed and reinstated. Relief lasted, for many people, under an hour.&lt;/p&gt;

&lt;p&gt;What follows is compiled from more than a dozen independent reports in the thread, and it forms a consistent pattern:&lt;/p&gt;

&lt;div class="table noWrap w100"&gt;
&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;&lt;b&gt;What the user did after restoration&lt;/b&gt;&lt;/th&gt;
      &lt;th&gt;&lt;b&gt;Outcome&lt;/b&gt;&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;&lt;td&gt;Edited the template HTML&lt;/td&gt;&lt;td&gt;Locked again&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Uploaded/imported a theme to a new blog&lt;/td&gt;&lt;td&gt;New blog locked within minutes&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Applied a theme change to an unaffected blog&lt;/td&gt;&lt;td&gt;Locked ~10 minutes later&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Removed image gadgets from layout&lt;/td&gt;&lt;td&gt;Locked again&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Inserted ad code into the theme&lt;/td&gt;&lt;td&gt;Locked again ~90 minutes later&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;&lt;strong&gt;Removed&lt;/strong&gt; ad-network scripts from theme HTML&lt;/td&gt;&lt;td&gt;Locked again&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Checked Mediavine settings&lt;/td&gt;&lt;td&gt;Locked ~5 minutes later&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Clicked &lt;code&gt;Stats&lt;/code&gt; in the dashboard&lt;/td&gt;&lt;td&gt;Locked immediately&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Published a new post only&lt;/td&gt;&lt;td&gt;Mostly stayed up&lt;/td&gt;&lt;/tr&gt;
    &lt;tr&gt;&lt;td&gt;Edited and republished existing posts/pages&lt;/td&gt;&lt;td&gt;Stayed up&lt;/td&gt;&lt;/tr&gt;
  &lt;/tbody&gt;
  &lt;/table&gt; &lt;/div&gt;

&lt;p&gt;One blogger stated the distinction outright after testing across several of their own blogs: removal fires after updating the homepage or making template changes, while editing and republishing posts or static pages leaves the blog alone.&lt;/p&gt;

&lt;p&gt;Two independent users confirmed the sharpest version of this. Each created a brand-new blog and imported their content successfully — then applied their theme, and the fresh blog was disabled within minutes. One noted the new blog was fine right up until the theme upload.&lt;/p&gt;&lt;p&gt;The practical implication at the time: whatever misfired on August 4 appeared to re-evaluate a blog whenever the template or layout was written to. That held until Google shipped a fix.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What this meant then — and what applies now&lt;/h3&gt;&lt;p&gt;During the incident, the guidance was to freeze the template completely: no theme edits, no gadget changes, no layout rearranging, no inserting or removing ad code. Reverting a change was itself a template write, and at least one publisher was re-locked doing exactly that.&lt;/p&gt;&lt;p&gt;That guidance is no longer in force. Blogger Product Experts have confirmed normal editing is safe again. The lasting takeaway is narrower but more useful: during any platform-wide enforcement event, stop writing to anything you don't have to write to. Publish nothing, change nothing, export everything. The blast radius of an automated classifier is widest at exactly the moment you are most tempted to fix things yourself.&lt;/p&gt;&lt;p&gt;One piece of housekeeping the Product Experts did recommend once things settled: clear out broken external links, since a link that now resolves to something unsafe is a genuine signal, and delete third-party scripts and gadgets you no longer use. Stale embedded code is both a performance drag and a real risk if the domain it loads from changes hands.&lt;/p&gt;&lt;ol&gt;
&lt;/ol&gt;

&lt;h2&gt;What is &lt;em&gt;not&lt;/em&gt; causing this&lt;/h2&gt;

&lt;p&gt;Several theories circulating in Facebook groups and YouTube videos are contradicted by the thread itself:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;"It's only custom/third-party themes."&lt;/strong&gt; Popular among affected users, and templates from Templateify and other paid vendors do appear frequently. But a Brazilian blogger using a stock Blogger theme with only CSS tweaks for dark mode and rounded image corners was locked too. Custom themes may raise your odds; they are not a requirement.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;"It's AdSense or ad networks."&lt;/strong&gt; Blogs with no ads at all were hit, including a &lt;code&gt;.blogspot.com&lt;/code&gt; subdomain with zero monetisation in the three-account test above.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;"You must have added something."&lt;/strong&gt; Blogs with no changes for months were locked. One had not been touched in over a year.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;"It's a real malware infection."&lt;/strong&gt; Search Console reports "No issues detected" for essentially every affected user who checked. Google Safe Browsing Transparency Report shows clean. VirusTotal shows clean. When Google's own security tooling disagrees with Google's enforcement system, the enforcement system is the outlier.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;The pre-lock signals worth knowing about&lt;/h2&gt;

&lt;p&gt;Several users found anomalies in the hours immediately before their lock. These are individual reports rather than confirmed causes, but the cluster is interesting enough to document:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Bot floods.&lt;/strong&gt; The perfume archive owner found roughly 400 bad bots hitting simultaneously in the minutes before removal, per StatCounter.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Suspicious traffic spikes.&lt;/strong&gt; The Lombardy events blog saw traffic jump from a few hundred daily users to nearly 4,000, heavily from Singapore, Hong Kong and Tokyo, with about five seconds average engagement and an 86.9% homepage bounce rate — textbook automated traffic against a site whose audience is almost entirely Italian.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Crawler 429s.&lt;/strong&gt; At least two users found Meta's Sharing Debugger receiving &lt;code&gt;HTTP 429&lt;/code&gt; (too many requests) from Google and being redirected to Google's &lt;code&gt;/sorry/index&lt;/code&gt; anti-abuse page when trying to scrape their Blogger posts. Both say this began days before the lockdown.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Cloudflare blocking Googlebot.&lt;/strong&gt; One owner discovered Cloudflare's Bot Fight Mode and Block AI Bots were returning &lt;code&gt;403&lt;/code&gt; challenges to Google crawling IPs, and disabled them as a precaution.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Blogger API access.&lt;/strong&gt; Two users had recently created Blogger API credentials for personal scripts. One deleted the credentials as a precaution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you run Cloudflare in front of a custom-domain Blogger blog, checking that Googlebot is not being challenged costs nothing and rules out one variable.&lt;/p&gt;

&lt;h2&gt;The 89-day clock&lt;/h2&gt;

&lt;p&gt;Here is the detail that should set your priorities, and it is printed on the lock screen itself rather than in the email: a removed blog is &lt;strong&gt;permanently deleted within 89 days.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is your real deadline. Not the appeal, not the review — the point at which the content stops existing. Google's own Content Policy states that appeals are typically decided within 10 business days and that, unless noted otherwise, restrictive actions are global and permanent.&lt;/p&gt;

&lt;p&gt;Eighty-nine days sounds generous. It is not, if your appeal sits unanswered for six weeks and you have not exported anything.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Back up first. Appeal second.&lt;/strong&gt; If you only do one thing today, take the Takeout export.&lt;/p&gt;

&lt;h2&gt;Step 1: Request a review (the appeal)&lt;/h2&gt;

&lt;p&gt;There is no separate public appeal form. The appeal lives inside your dashboard.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Sign in at &lt;strong&gt;blogger.com&lt;/strong&gt;.&lt;/li&gt;
  &lt;li&gt;If you have multiple blogs, click the blog name in the left sidebar to open the selector, and pick the one with a &lt;strong&gt;red exclamation mark&lt;/strong&gt; next to its title.&lt;/li&gt;
  &lt;li&gt;Open the &lt;code&gt;Info&lt;/code&gt; tab. Under "Note: this blog has been locked," click &lt;code&gt;REQUEST REVIEW&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;Some users also receive an appeal link directly in the removal email. Either route feeds the same queue.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Official policy: appeals are typically decided within 10 business days, though complex cases take longer. See Google's &lt;a href="https://www.blogger.com/content-policy" rel="nofollow" target="_blank"&gt;blogger policy&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;If the Request Review button is missing or the form won't open&lt;/h3&gt;

&lt;p&gt;Multiple users hit this. Working around it:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Form redirects to your blog instead of opening.&lt;/strong&gt; Sign out of all Google accounts, then sign back into only the account that owns the blog. Multi-account sessions are the usual cause. An incognito window works too.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;No Request Review button under Info.&lt;/strong&gt; Confirm you're on the right blog in the selector, and that you are the blog's Administrator rather than an Author. Authors do not see enforcement controls.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Email says "deleted" rather than "locked."&lt;/strong&gt; These are different enforcement states. Several users with "deleted" emails still had the blog visible in the dashboard and could submit a review — check the dashboard regardless of what the email says.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;The appeal dead-end.&lt;/strong&gt; This one has no clean fix yet. Several users were reinstated, re-locked, and then found the appeal page told them their original appeal was already received and still under review, with no option to file a second one. If you are stuck here, post your case in the Blogger Help Community with your Blog ID so Product Experts can batch-escalate it. It is not satisfying, but it is currently the only channel.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;What to include when you post to the community&lt;/h3&gt;

&lt;p&gt;Product Experts are volunteers, not Google staff, but they can escalate patterns. Give them something they can forward:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Blog URL and &lt;strong&gt;Blog ID&lt;/strong&gt; (from the dashboard URL after &lt;code&gt;blogId=&lt;/code&gt;)&lt;/li&gt;
  &lt;li&gt;Date and time of the lock, with timezone&lt;/li&gt;
  &lt;li&gt;The exact policy quoted in your email&lt;/li&gt;
  &lt;li&gt;Screenshot of Search Console showing &lt;strong&gt;Security Issues: No issues detected&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;Whether you were reinstated and then re-locked, and what you did in between&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last line is the most useful data point you can contribute right now.&lt;/p&gt;

&lt;h2&gt;Step 2: Back up with Google Takeout&lt;/h2&gt;

&lt;p&gt;Blogger's old one-click XML export in Settings is gone. Since July 1, 2025, Takeout is the only way to export posts, pages and comments.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Go to &lt;strong&gt;takeout.google.com&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;Click &lt;code&gt;Deselect all&lt;/code&gt;&lt;/li&gt;
  &lt;li&gt;Scroll to &lt;strong&gt;Blogger&lt;/strong&gt; and tick it&lt;/li&gt;
  &lt;li&gt;Choose &lt;code&gt;Export once&lt;/code&gt;, or schedule exports &lt;strong&gt;every two months for a year&lt;/strong&gt;&lt;/li&gt;
  &lt;li&gt;Pick &lt;code&gt;.zip&lt;/code&gt; and a maximum file size. &lt;strong&gt;2GB is fine for most blogs&lt;/strong&gt; — if your archive is larger, Google splits it across multiple files automatically, so there is no wrong answer here&lt;/li&gt;
  &lt;li&gt;Choose a destination. &lt;strong&gt;Do not use Google Drive as your only copy&lt;/strong&gt; — if your Google account is ever locked, your backup locks with it&lt;/li&gt;
  &lt;li&gt;Wait for the email with the download link. Minutes for small blogs, hours or days for large accounts&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Download within one week.&lt;/strong&gt; Google expires the archive after that&lt;/li&gt;
&lt;/ol&gt;

&lt;h3&gt;Does Takeout work while your blog is locked?&lt;/h3&gt;

&lt;p&gt;Yes. The Blogger Product Expert running the incident thread confirmed that anyone wanting to back up their blog should be able to do so even while it is locked, and linked users straight to the Blogger section of Takeout: takeout.google.com/settings/takeout/custom/blogger&lt;/p&gt;&lt;p&gt;A handful of users during the incident reported that exports were missing their posts, or that their blog was entirely absent from the archive. Given the confirmed guidance, the likely explanation is timing and queue delay rather than the lock state itself. Takeout snapshots on request; large accounts can take hours or days. If your first export looks wrong, request it again rather than concluding your content is gone.&lt;/p&gt;&lt;p&gt;One practical note from the same guidance: if you run many blogs, or one very old and large one, expect to download a substantial number of archive files.&lt;/p&gt;

&lt;h2&gt;Step 3: Understanding &lt;code&gt;feed.atom&lt;/code&gt;&lt;/h2&gt;

&lt;p&gt;Unzip the Takeout archive and open the &lt;code&gt;Blogs&lt;/code&gt; folder. Inside each blog's folder, two files matter:&lt;/p&gt;

&lt;div class="table noWrap w100"&gt;
&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;&lt;b&gt;File&lt;/b&gt;&lt;/th&gt;
      &lt;th&gt;&lt;b&gt;Contains&lt;/b&gt;&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code&gt;feed.atom&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Every post, page and comment, including drafts. The direct replacement for the old Settings XML export.&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;code&gt;theme-layouts.xml&lt;/code&gt;&lt;/td&gt;
      &lt;td&gt;Your theme and most widgets.&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
  &lt;/table&gt; &lt;/div&gt;

&lt;p&gt;Everything else can be deleted.&lt;/p&gt;

&lt;p&gt;What you need to understand about &lt;code&gt;feed.atom&lt;/code&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;It is Atom XML, not Blogger's old export XML.&lt;/strong&gt; Same information, different structure. Since June 2025, Blogger's &lt;code&gt;Settings → Import content&lt;/code&gt; can read it — fixing a long-standing bug where restores silently drop posts and comments.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;It includes draft posts.&lt;/strong&gt; Genuinely useful if you lost drafts, and worth knowing for anyone whose unpublished work is now behind a padlock.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;It contains no images.&lt;/strong&gt; This is the one that catches people. &lt;code&gt;feed.atom&lt;/code&gt; stores the HTML that &lt;em&gt;renders&lt;/em&gt; your images from Google's servers under &lt;code&gt;blogger.googleusercontent.com&lt;/code&gt;. The pictures themselves are not in the file. Takeout does export your image files separately — but only the ones uploaded by the account making the request. On a multi-author blog, your co-authors' images are only in &lt;em&gt;their&lt;/em&gt; Takeout archive.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;It preserves inline formatting only&lt;/strong&gt;, not styling defined by your theme.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;You can read it without Blogger.&lt;/strong&gt; Open it in any text editor. It is dense XML and unpleasant to read, but your writing is in there. Several users pasted theirs into an AI tool to extract clean plain text — a reasonable move if you want a human-readable archive today rather than a restorable one.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That third point is the whole argument for treating &lt;code&gt;feed.atom&lt;/code&gt; as a &lt;em&gt;migration&lt;/em&gt; file rather than a backup. A backup whose images live on servers controlled by the company that just locked you out is not a backup in any meaningful sense.&lt;/p&gt;

&lt;h2&gt;Step 4: If you want to rebuild on Blogger&lt;/h2&gt;

&lt;p&gt;You can import &lt;code&gt;feed.atom&lt;/code&gt; into a fresh blog via &lt;code&gt;Settings → Import content&lt;/code&gt;. Two warnings, both from bloggers who tried it this week:&lt;/p&gt;&lt;p&gt;Do not import your theme. As documented above, this is what re-triggers the lock. Import content, use a stock Blogger theme, and wait.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Test on a dummy blog first.&lt;/b&gt; One reader found the safest route was to create a throwaway Blogger site, apply the theme there, and confirm it survived before touching the live blog. It would have cost five minutes and would have saved several people in the support thread a second lockout. Credit to commenter Lem Revival for posting this while the incident was still live.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Two things that can turn a false positive into a real violation&lt;/h3&gt;&lt;p&gt;Both come directly from the Blogger Product Experts, and neither appears in most coverage of the incident.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Do not create a new blog to repost the same content.&lt;/b&gt; Duplicating your archive onto a fresh blog while the original is under appeal can itself be treated as spam, which would convert a mistaken enforcement into a genuine one. If you are rebuilding, do it because you have given up on the appeal, not alongside it.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Do not remove Blogger from your Google account. &lt;/b&gt;Deleting the Blogger service or your Blogger profile deletes your blogs, and it cannot be undone. This is worth saying plainly because it is exactly the kind of thing a frustrated publisher does at hour eighteen of an outage while trying to "reset" something. There is no undo, no appeal, and no Takeout export after the fact.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Read Google's policy line first.&lt;/strong&gt; Blogger's Content Policy explicitly states that if you have had a blog disabled, you should not create a replacement blog engaging in similar activity. In a genuine false positive, that guidance is arguably unfair — but it is the written policy, and rebuilding while an appeal is pending carries some risk. Weigh it.&lt;/p&gt;

&lt;h3&gt;The custom domain trap&lt;/h3&gt;

&lt;p&gt;If you run a custom domain, this section matters.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It can be reconnected.&lt;/strong&gt; One user confirmed it works: Takeout export, create a new blog, point the same domain at it, and republish gradually. They were about 10 posts into 1,139 and reported it going smoothly, aside from a slider in their paid theme not loading.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;But you pay for it.&lt;/strong&gt; As another user pointed out, search engines treat the reconnected domain as a new site. Crawl history, visit metrics and accumulated authority reset. And cycling a domain between deleted and new Blogger blogs repeatedly risks getting the domain itself flagged.&lt;/p&gt;

&lt;p&gt;So: reconnecting works once, at a real SEO cost. It is a rescue, not a strategy. If you are going to move your domain anyway, moving it somewhere that cannot lock you out is a better use of the same disruption.&lt;/p&gt;

&lt;h2&gt;Step 5: Moving to WordPress&lt;/h2&gt;

&lt;p&gt;Let me be straight about the argument rather than dressing it up.&lt;/p&gt;

&lt;p&gt;Blogger is free, and it has genuinely helped a lot of people for a very long time. Several blogs in that thread have been running since 2007. Nobody should feel foolish for having built there.&lt;/p&gt;

&lt;p&gt;But this week established something concrete: &lt;b&gt;an automated classifier at Google can remove your blog with no warning, no explanation, no human review, a ten-business-day appeal window, and an 89-day deletion clock. &lt;/b&gt;When it misfired at scale, the public accounting amounted to three sentences given to a news outlet — no postmortem, no affected-site count, no explanation of the fault.&amp;nbsp;&lt;/p&gt;&lt;p&gt;People in that thread describe livelihoods stalled, AdSense applications caught mid-review, and 18 years of work sitting behind a padlock they could not open. Several could not access their own dashboard to inspect what had supposedly triggered it.&lt;/p&gt;

&lt;p&gt;That is the actual risk profile. It has nothing to do with whether WordPress is nicer to use.&lt;/p&gt;

&lt;h3&gt;Why now specifically&lt;/h3&gt;

&lt;p&gt;Blogger has received essentially no meaningful development in years, while Google retired the services around it — Album Archive, FeedBurner's core features, and the one-click backup. The direction is maintenance mode. Meanwhile, the practical gap has closed: WordPress 6.9+ on entry-level shared hosting is fast enough to pass Core Web Vitals without a developer, and as AI-driven search reshapes referral traffic, owning your own schema, internal linking, and email list matters more than it did two years ago.&lt;/p&gt;

&lt;p&gt;If you are going to move, moving before your archive grows another two years is cheaper and less painful.&lt;/p&gt;

&lt;h3&gt;The migration path, honestly&lt;/h3&gt;

&lt;p&gt;WordPress's built-in Blogger Importer is &lt;strong&gt;broken&lt;/strong&gt; against the new export format — it was written for the old XML, and Google changed the file. Two free plugins handle &lt;code&gt;feed.atom&lt;/code&gt; directly:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;BtW Importer&lt;/strong&gt; — upload the &lt;code&gt;.atom&lt;/code&gt; file, imports in batches, downloads embedded images into your WordPress media library, rewrites Blogger URLs to local ones, and sets featured images from the first image in each post. Reviewers report ~80 posts per run; click again to resume.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Feed Importer for Blogger&lt;/strong&gt; — same core job, also pulls images off Google's servers and rehosts them locally.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;That image rehosting step is the entire point.&lt;/strong&gt; It is what finally cuts your archive loose from &lt;code&gt;blogger.googleusercontent.com&lt;/code&gt;. Until you do it, every image on your site is a link to a server Google controls.&lt;/p&gt;

&lt;p&gt;One practical note the BtW Importer developer flags: &lt;strong&gt;Nginx-based hosts run these imports noticeably slower than Apache or LiteSpeed.&lt;/strong&gt; For a large Blogger archive, this is the difference between an afternoon and a weekend of timeouts.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not skip redirects.&lt;/strong&gt; Set up &lt;code&gt;301&lt;/code&gt; redirects from your old Blogger URLs to the new permalinks, or you will lose the rankings you spent years building. On a custom domain, this is straightforward. On &lt;code&gt;.blogspot.com&lt;/code&gt; you will lose some link equity — plan for it.&lt;/p&gt;

&lt;h3&gt;Hosting&lt;/h3&gt;

&lt;p&gt;For a migrating Blogger site specifically, &lt;a href="https://www.hostinger.com/in?REFERRALCODE=freeup" rel="sponsored nofollow noopener" target="_blank"&gt;Hostinger&lt;/a&gt; is a sensible landing spot: it runs &lt;strong&gt;LiteSpeed&lt;/strong&gt;, which is the practical difference between a Blogger import that finishes and one that times out halfway through 1,000 posts. You also get free SSL, a free domain on annual plans, one-click WordPress install, and automatic daily backups you actually control.&lt;/p&gt;

&lt;p&gt;Use code &lt;code&gt;&lt;b&gt;freeup&lt;/b&gt;&lt;/code&gt; at checkout for an extra 20% off the current plan price.&lt;/p&gt;

&lt;p&gt;The honest version: no host makes you immune to everything. WordPress has its own exposure — we covered &lt;a href="https://www.cyberkendra.com/2026/07/wp2shell-guide.html" target="_blank"&gt;a critical REST API RCE&lt;/a&gt; in July. The difference is that you can patch your own server; you cannot patch someone else's classifier. What changes is who holds the off switch. On Hostinger, your posts sit in a MySQL database you can export any time, your images sit in a folder you can download, and no classifier can revoke your login at 2 AM.&lt;/p&gt;

&lt;p class="note tp"&gt;&lt;em&gt;Disclosure: Cyber Kendra earns a commission on purchases made through this link, at no additional cost to you. We recommend Hostinger because we use it.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;Current status&lt;/h2&gt;

&lt;p&gt;&lt;b&gt;As of August 12, 2026:&lt;/b&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Resolved. Blogger Product Experts confirmed the root cause was fixed, with confirmation from the team responsible and an official announcement posted in the Spanish-language Blogger community.&lt;/li&gt;&lt;li&gt;Most affected blogs were restored within 24 to 48 hours of the initial lockout.&lt;/li&gt;&lt;li&gt;Normal editing is safe again, including themes and layout code.&lt;/li&gt;&lt;li&gt;Blogs still locked remain under review. Volume is the bottleneck, and blogs that never submitted a review request may not be queued at all.&lt;/li&gt;&lt;li&gt;Not every locked blog was a false positive — each case is reviewed individually.&lt;/li&gt;&lt;li&gt;Google's only public comment remains its three-sentence statement of August 5. No postmortem, no affected-blog count, and no technical explanation of the fault has been published.&lt;/li&gt;&lt;li&gt;The incident thread is now soft-locked, with 531 users reporting the same problem.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your blog is back: export it today, leave your template alone, and treat the restoration as provisional.&lt;/p&gt;

&lt;h2&gt;FAQ&lt;/h2&gt;

&lt;h3&gt;Is it safe to edit my Blogger theme or template now?&lt;/h3&gt;
&lt;p&gt;Yes. Blogger Product Experts confirmed on August 9 that publishers whose blogs were reinstated or were never affected can resume normal activity, including publishing posts and editing themes. The advice to hold off applied only while the faulty classifier was live.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;My blog is still locked. What should I do?&lt;/h3&gt;&lt;p&gt;Check that you actually submitted a Request review from the Info tab of your dashboard. Guidance from the Product Experts suggests that only blogs that requested a review are being reviewed, so an unappealed blog may not be in the queue. If you have already appealed, wait — the backlog is large, and resubmitting resets your place in it.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Why has my blog not been restored when everyone else's has?&lt;/h3&gt;&lt;p&gt;Two possibilities. Either your appeal is still in the backlog, or your blog was not part of the false positive. The Product Experts made it clear that not all reports were misclassifications and that each case is assessed individually. If your blog has broken external links, outdated third-party scripts, or gadgets loading from domains that have changed hands, those are worth auditing on their own merits.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Can I create a new blog and repost my content while I wait?&lt;/h3&gt;&lt;p&gt;No, and this one carries real risk. Duplicating your content onto a new blog while the original is under appeal can be treated as spam, turning a mistaken enforcement into a genuine violation. Wait for the appeal to conclude.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;How long until my blog comes back?&lt;/h3&gt;&lt;p&gt;No guarantee. Observed restorations ran roughly 6 to 20 hours from lock. Official policy allows up to 10 business days.&lt;/p&gt;

&lt;h3&gt;Will I lose my content?&lt;/h3&gt;
&lt;p&gt;Not if you act. Removed blogs are permanently deleted within 89 days. Export before then.&lt;/p&gt;

&lt;h3&gt;Can I check whether my blog really has malware?&lt;/h3&gt;
&lt;p&gt;Yes, and you should, so your appeal is honest. Check Search Console under Security Issues, the Google Safe Browsing Transparency Report, and run your domain through VirusTotal. Essentially, everyone who checked found all three clean.&lt;/p&gt;

&lt;h3&gt;My blog is locked, and I can't reach the dashboard. Can I still export?&lt;/h3&gt;
&lt;p&gt;Try Takeout — it works for some locked blogs and not others. Request it now, and again after restoration.&lt;/p&gt;

&lt;h3&gt;Should I delete my blog and start over?&lt;/h3&gt;
&lt;p&gt;No. Deleting forfeits your appeal and your 89 days.&lt;/p&gt;

&lt;h3&gt;Does this affect AdSense earnings?&lt;/h3&gt;
&lt;p&gt;While the blog is locked, it serves no ads and earns nothing. If you want to quantify what an outage like this costs, our &lt;a href="https://www.cyberkendra.com/p/adsense-earnings-calculator.html" target="_blank"&gt;AdSense earnings calculator&lt;/a&gt; will do the maths. Several users report pending AdSense applications caught mid-review.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;i&gt;Google never published a postmortem. If your blog is still locked, drop your Blog ID and appeal date in the comments — the pattern is still worth tracking.&lt;/i&gt;&lt;/p&gt;


&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "@id": "[POST-URL]#faq",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "How long until my Blogger blog comes back?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "There is no guarantee. Observed restorations during the August 2026 incident ran roughly 6 to 20 hours from the time of the lock. Google's official policy allows appeals to take up to 10 business days."
      }
    },
    {
      "@type": "Question",
      "name": "Will I lose my Blogger content permanently?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Not if you act. The Blogger lock screen states that a removed blog is permanently deleted within 89 days. Export your content through Google Takeout well before that deadline."
      }
    },
    {
      "@type": "Question",
      "name": "How can I check whether my blog really has malware?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Check Google Search Console under Security Issues, review the Google Safe Browsing Transparency Report, and scan your domain through VirusTotal. Essentially every affected user who ran these checks during the August 2026 incident found all three clean."
      }
    },
    {
      "@type": "Question",
      "name": "Can I export my blog with Google Takeout while it is locked?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Sometimes. Reports conflict: several users successfully exported locked blogs, while others found their posts missing from the archive. Request the export immediately, then request it again once your blog is restored, and verify the second archive actually contains your posts."
      }
    },
    {
      "@type": "Question",
      "name": "Should I delete my Blogger blog and start over?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. Deleting the blog forfeits both your pending appeal and the 89-day window before permanent deletion."
      }
    },
    {
      "@type": "Question",
      "name": "Does a Blogger lock affect AdSense earnings?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes. While the blog is locked it serves no ads and earns nothing. Several users also reported pending AdSense applications caught mid-review when their blog was removed."
      }
    },
    {
      "@type": "Question",
      "name": "What is the feed.atom file in a Google Takeout backup?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "feed.atom contains every post, page and comment from your blog, including drafts. It replaced Blogger's old one-click XML export in July 2025. Importantly, it does not contain your images; it stores only the markup that renders them from Google's servers."
      }
    },
    {
      "@type": "Question",
      "name": "Why does my restored Blogger blog keep getting locked again?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Reports from the August 2026 incident consistently link re-locks to template and layout writes rather than post edits. Editing theme HTML, changing gadgets, importing a theme, or inserting and removing ad code all preceded second locks. Editing posts and pages generally did not. Freeze your template until Google confirms a fix."
      }
    }
  ]
}
&lt;/script&gt;


&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "HowTo",
  "@id": "[POST-URL]#howto-backup",
  "name": "How to back up a Blogger blog with Google Takeout",
  "description": "Export all posts, pages and comments from Blogger using Google Takeout, the only supported backup method since July 2025.",
  "totalTime": "PT15M",
  "estimatedCost": {
    "@type": "MonetaryAmount",
    "currency": "USD",
    "value": "0"
  },
  "tool": [
    { "@type": "HowToTool", "name": "Google account with Administrator access to the blog" },
    { "@type": "HowToTool", "name": "Web browser" },
    { "@type": "HowToTool", "name": "File archiver capable of opening .zip files" }
  ],
  "step": [
    {
      "@type": "HowToStep",
      "position": 1,
      "name": "Open Google Takeout",
      "text": "Go to takeout.google.com while signed in to the Google account that administers the blog.",
      "url": "[POST-URL]#step-2-back-up-with-google-takeout"
    },
    {
      "@type": "HowToStep",
      "position": 2,
      "name": "Deselect all services",
      "text": "Click Deselect all so that you export only Blogger data rather than your entire Google account."
    },
    {
      "@type": "HowToStep",
      "position": 3,
      "name": "Select Blogger",
      "text": "Scroll down the service list and tick the Blogger checkbox."
    },
    {
      "@type": "HowToStep",
      "position": 4,
      "name": "Choose export frequency",
      "text": "Choose Export once for an immediate archive, or schedule exports every two months for a year."
    },
    {
      "@type": "HowToStep",
      "position": 5,
      "name": "Set file type and size",
      "text": "Select .zip and a maximum file size. 2GB suits most blogs; larger archives are split across multiple files automatically."
    },
    {
      "@type": "HowToStep",
      "position": 6,
      "name": "Choose a destination outside Google",
      "text": "Avoid using Google Drive as your only destination. If your Google account is ever locked, a backup stored in Drive is locked with it."
    },
    {
      "@type": "HowToStep",
      "position": 7,
      "name": "Download the archive within one week",
      "text": "Google emails a download link when the archive is ready, which can take minutes or days. The link expires after one week, though you can always request another export."
    },
    {
      "@type": "HowToStep",
      "position": 8,
      "name": "Verify the export contains your posts",
      "text": "Unzip the archive, open the Blogs folder, locate your blog, and confirm the feed.atom file is present and contains your post content."
    }
  ]
}
&lt;/script&gt;

&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "HowTo",
  "@id": "[POST-URL]#howto-appeal",
  "name": "How to appeal a removed Blogger blog",
  "description": "Submit a review request for a Blogger blog locked under the Malware and Similar Malicious Content policy.",
  "totalTime": "PT10M",
  "step": [
    {
      "@type": "HowToStep",
      "position": 1,
      "name": "Sign in to Blogger",
      "text": "Sign in at blogger.com using the Google account that administers the affected blog."
    },
    {
      "@type": "HowToStep",
      "position": 2,
      "name": "Select the affected blog",
      "text": "If you have multiple blogs, click the blog name in the left sidebar to open the selector and choose the one marked with a red exclamation mark."
    },
    {
      "@type": "HowToStep",
      "position": 3,
      "name": "Open the Info tab",
      "text": "Open the Info tab and locate the notice reading 'Note: this blog has been locked'."
    },
    {
      "@type": "HowToStep",
      "position": 4,
      "name": "Click Request Review",
      "text": "Click the REQUEST REVIEW button. If the form redirects to your blog instead of opening, sign out of all Google accounts and sign back into only the owning account, or use an incognito window."
    },
    {
      "@type": "HowToStep",
      "position": 5,
      "name": "Gather supporting evidence",
      "text": "Screenshot Google Search Console showing 'No issues detected' under Security Issues, and note your Blog ID from the dashboard URL after blogId=."
    },
    {
      "@type": "HowToStep",
      "position": 6,
      "name": "Post to the Blogger Help Community",
      "text": "Post your blog URL, Blog ID, lock time with timezone, the exact policy quoted, and your Search Console screenshot so Blogger Product Experts can escalate the case."
    },
    {
      "@type": "HowToStep",
      "position": 7,
      "name": "Wait without resubmitting",
      "text": "Appeals are typically decided within 10 business days. Duplicate submissions reset your position in the queue."
    }
  ]
}
&lt;/script&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2a6i24-77y0zXT6BNOBBmwM76uI64W9ygNyX0BJj1JTQ2-gDmq0FZXWyjygDAox_DbI88qjijtP2GeRLCvSsGEfkwBs2ZDRzk6wMImf6-rQ2Yayj7XOAilnW8ghvTzYxdO0GQqZcU_ZYare9sH8lsssx2vt_u1T-ODG4qEuMRHfOcWW0UhYIJwEbPHYs/s72-c/blog-deleted.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">5</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>What AI SOC tools are security teams deploying for Tier 1 work?</title><link>https://www.cyberkendra.com/2026/08/what-ai-soc-tools-are-security-teams.html</link><category>AI</category><category>Tips</category><pubDate>Wed, 12 Aug 2026 21:59:46 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3158665194618529841</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="ai soc platform" border="0" data-original-height="3335" data-original-width="5001" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9uUfZOh_FF95b8gwfjOoS4jyx4GSs0UInyKvQJ0_s3SjI7bk24Z2ezN7cJM7C8c5XQ7XR5T1i1KrSsHE7U9IkHkUrMOxONz0QnVWKE_uyjdE7szFGOwoAr5ycQWzdMwXIbuZKNdvBgzcR3n8j61SnilFMUkdTbFc4JwmNoLrqN9fAVgd_13MJX7D7TCU/s1600/ai-soc.webp" title="ai soc platform" /&gt;&lt;/div&gt;&lt;p&gt;On the 12th of August, 1914, barely a month into the First World War, the German 4th Cavalry Division, rattling their sabers and lances, charged directly into Belgian machine gun fire. It went about as well as you might expect. The new world triumphed over the old.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;We’re currently seeing a similar situation playing out in contemporary SecOps.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Alert volume at AI-scale demands AI-enabled SOCs. Organizations that ignore that fact are already exposed. The organizations that have already recognized it are already reaping the benefits.&lt;/p&gt;&lt;p&gt;This article will explore how AI tools help SOCs keep pace with modern alert volumes by accelerating investigation, how to evaluate AI SOC platforms, and how to ensure AI doesn’t take too much control.&amp;nbsp;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;Why do you need an AI SOC Platform?&lt;/h2&gt;&lt;p&gt;According to &lt;a href="https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai" rel="nofollow" target="_blank"&gt;IBM's Cost of a Data Breach Report 2025&lt;/a&gt;, the global average cost of a breach dropped for the first time in five years, citing faster detection and containment through AI and automation as the reason. In fact, organizations using AI and automation extensively saved an average of $1.9 million per incident compared to those that didn't.&lt;/p&gt;&lt;p&gt;In 2026, however, the global average cost of a breach shot back up to a record $4.99 million. This increase was driven in no small part by a 56% increase in AI-generated attacks, and only 50% of organizations are deploying AI agents in their SOC.&lt;/p&gt;&lt;p&gt;These stats tell us that AI is the differentiator on both sides of the battle. In 2025, average costs fell as defender capabilities outpaced attackers’. By 2026, cybercriminals had turned the tables, using AI better and more widely than their victims.&amp;nbsp;&lt;/p&gt;&lt;p&gt;If you want to stay safe in 2027, it’s clear that an AI SOC platform is the way to go.&amp;nbsp;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What role can AI tools play in modern SOCs?&amp;nbsp;&lt;/h2&gt;&lt;p&gt;In a traditional SOC, analysts receiving an alert would have four tasks to complete. Those four tasks are where an analyst’s time goes, and they are why a queue of thousands of alerts cannot all receive a full review.&amp;nbsp;&lt;/p&gt;&lt;p&gt;An AI SOC platform, however, can handle those tasks before a human sees them:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Matching indicators against threat intelligence: &lt;/b&gt;The AI automatically checks domains, hashes, and IPs against reputation feeds.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Pulling context from every telemetry source: &lt;/b&gt;Instead of an analyst switching between EDR, identity logs, cloud console, and network data, the AI assembles the relevant context into one view.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Correlating signals across systems:&lt;/b&gt; The system reads, for example, a login from a new location, a suspicious EDR event, and unusual cloud activity as a single picture rather than three separate alerts.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Producing a verdict with the reasoning attached: &lt;/b&gt;The output states what happened, why it matters, and what to do next. A human still makes the call, but the AI removes the legwork that once preceded it.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Those first two capabilities are all something a SOAR playbook can do with a fixed decision tree: if A, then B. The third bullet is something only an agentic &lt;a href="https://www.prophetsecurity.ai/blog/how-ai-transforms-tier-1-tier-2-and-tier-3-soc-analysts" target="_blank"&gt;AI SOC platform can do&lt;/a&gt;: leaving the scripted path when the evidence calls for it.&amp;nbsp;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;What is an AI SOC platform?&amp;nbsp;&lt;/h2&gt;&lt;p&gt;Chances are, the previous section piqued your interest. Automating investigation and making analysts’ lives easier is top of mind for most organizations.&amp;nbsp;&lt;/p&gt;&lt;p&gt;But if you search for “AI SOC platform” online, the results can be confusing. That’s because “AI SOC platform” can mean several architecturally distinct things, and most vendor comparisons don't distinguish among them. So, here’s a quick explainer to help you make sense of it all.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;AI-native investigation platform&lt;/h3&gt;&lt;p&gt;In an AI-native investigation platform, AI runs the investigation end-to-end and returns a final verdict; a human then reviews the output. It’s the best solution for organizations looking to fully automate Tier 1 triage across the entire alert volume.&lt;/p&gt;&lt;p&gt;Vendors include:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Prophet Security&lt;/li&gt;&lt;li&gt;Dropzone AI&lt;/li&gt;&lt;li&gt;7ai&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Prophet Security, one of the leading AI SOC platforms and a Rising in Cyber 2026 honoree voted on by more than 150 CISOs and security leaders, is a clear example of the category: an agentic AI SOC platform that investigates alerts like a senior analyst and returns a determination with the queries and evidence attached, running on the SIEM and EDR a team already owns.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Hyperautomation (SOAR + AI layer)&lt;/h3&gt;&lt;p&gt;Hyperautomation just means that predefined playbook logic determines the path, and AI assists with scripted steps. It automates response workflows that are already mapped out.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Architecturally, hyperautomation is an AI layer over playbook logic, which means it inherits the engineering cost of that logic: the hours spent writing, testing, and maintaining the paths. That is a good fit for response workflows that an organization has already mapped, but a poor fit for problems whose paths are not known in advance.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Vendors include:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Torq&lt;/li&gt;&lt;li&gt;D3 Security&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Copilot inside a SIEM or EDR&lt;/p&gt;&lt;p&gt;In this category, a human analyst decides, while AI suggests, summarizes, or takes bounded action inside that one product. It’s primarily used to assist an analyst already working in a parent vendor's console.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Vendors include:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;CrowdStrike Charlotte AI&lt;/li&gt;&lt;li&gt;Microsoft Security Copilot&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;AI-Driven Managed Detection and Response&lt;/h3&gt;&lt;p&gt;All the above categories assume that an organization already has an internal SOC team and is deciding what tool to give them. Managed detection and response tools, however, are for organizations that don’t have an internal team at all.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Confusion is particularly rife here because many managed providers market themselves with the same “AI-native” and “agentic” language as the tools above, even though they technically operate in a different category. One is a tool you operate, the other is a service that an external team operates for you.&amp;nbsp;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;How to evaluate an AI SOC platform?&lt;/h2&gt;&lt;p&gt;You should now understand the differences between “AI SOC platforms.” You also (hopefully) know what type is the best fit for your organization. So, now you need to know how to distinguish between them at the evaluation stage.&amp;nbsp;&lt;/p&gt;&lt;p&gt;A product demonstration alone isn’t going to tell you what you need to know. Asking whether the platform closes alerts on its own, or whether every action requires manual review, does. Asking that direction directly will expose more than a feature list will.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Similarly, Gartner's Hype Cycle for Security Operations, 2026 notes that much of what's sold as an "AI agent" - common on “AI SOC platform” homepages - is an AI assistant, which is limited in autonomy, and tied to one product.&amp;nbsp;&lt;/p&gt;&lt;p&gt;If you’re truly looking for a product that can triage alerts on behalf of analysts, an AI assistant just isn’t going to cut it. Ask vendors whether their system takes the action itself, or whether a human still has to execute it. The former is an agent, the latter is an assistant.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The final thing worth checking before signing anything is whether the "autonomous triage" claim holds for your existing stack or only within the vendor's own SIEM and log pipeline. Some platforms genuinely run on top of what you already have. Others need you to migrate first, and that detail will usually only become apparent after a demo.&amp;nbsp;&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;AI SOC platforms don’t replace human analysts - they just make their lives easier&lt;/h2&gt;&lt;p&gt;One could be forgiven for assuming that AI is coming for analyst jobs. But that’s not the case.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Instead, the industry is moving toward a model where AI handles routine triage, and the analyst's job changes: less time spent working an alert queue, more time on edge cases, tuning detections, and hunting for what the system hasn't caught.&amp;nbsp;&lt;/p&gt;&lt;p&gt;That's a harder (and much more rewarding) job than the one it replaces, not a smaller one. AI is essentially doing the grunt work that analysts would rather avoid.&amp;nbsp;&lt;/p&gt;&lt;p&gt;For a closer look at what separates platforms built for that shift from those that only automate at their edges, GBHackers has put together a practical breakdown of the concrete capabilities to check when evaluating AI SOC platforms.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9uUfZOh_FF95b8gwfjOoS4jyx4GSs0UInyKvQJ0_s3SjI7bk24Z2ezN7cJM7C8c5XQ7XR5T1i1KrSsHE7U9IkHkUrMOxONz0QnVWKE_uyjdE7szFGOwoAr5ycQWzdMwXIbuZKNdvBgzcR3n8j61SnilFMUkdTbFc4JwmNoLrqN9fAVgd_13MJX7D7TCU/s72-c/ai-soc.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>ShieldBreak PoC Bypasses Microsoft's RoguePlanet Defender Fix</title><link>https://www.cyberkendra.com/2026/08/shieldbreak-poc-bypasses-microsofts.html</link><category>Microsoft</category><category>Security</category><category>ZeroDay Bug</category><pubDate>Wed, 12 Aug 2026 08:10:34 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4789275514503869469</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="ShieldBreak Zero-day" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiD4-nd3rviovPn2nWrAxeCxLDDJ5GqqXAT_QQVKqb1uJoPfzbZBEHGbWg14_beVRzerb1VMxornOfMwhMPEu3BzqyOK0FCA63jL3awLidE_RBT3Co_0HvG9T0Hy_SSHhTYa9uzcFefbksuXPmC0bkNQ-0GkXEJgvd3NvWWfoIPQfFOv-GaeA5XzAbNZCE/s1600/ShieldBreak.webp" title="ShieldBreak Zero-day" /&gt;&lt;/div&gt;&lt;p&gt;Security researcher Nightmare Eclipse has released &lt;b&gt;ShieldBreak&lt;/b&gt;, a proof-of-concept exploit that defeats the patch Microsoft shipped five weeks ago for a Windows Defender privilege escalation flaw.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The researcher dropped the PoC code on GitHub and wrote that Microsoft has failed to properly patch the RoguePlanet vulnerability, &lt;b&gt;CVE-2026-50656&lt;/b&gt;.&lt;/p&gt;&lt;p&gt;Two claims make ShieldBreak more dangerous than the exploit it replaces.&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;a href="https://www.cyberkendra.com/2026/06/microsoft-defender-zero-day-poc-gives.html" target="_blank"&gt;RoguePlanet&lt;/a&gt;&lt;/b&gt; was a race condition, and its reliability swung sharply from machine to machine. The researcher described it in June as hit or miss. ShieldBreak is listed with a 100 percent success rate.&lt;/p&gt;&lt;p&gt;The June exploit did not run on Windows Server, because standard users cannot mount ISO images there, though the researcher maintained server builds were vulnerable anyway. ShieldBreak is now listed as tested on Windows Server 2025, alongside Windows 11 25H2 and the Canary channel. Windows 10 stays vulnerable but unsupported by the current code. That pulls domain controllers and session hosts into scope for the first time.&lt;/p&gt;&lt;p&gt;The released code contains &lt;code&gt;Warden.dll&lt;/code&gt;, a &lt;code&gt;Report.wer&lt;/code&gt; Windows Error Reporting artifact, an &lt;code&gt;eicar_com.zip&lt;/code&gt; antivirus test file, and supporting project files. The WER artifact is notable.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Analysts who dissected RoguePlanet in June described an attack chain built on NTFS junctions, opportunistic locks, and the Windows Error Reporting QueueReporting scheduled task, suggesting ShieldBreak reworks the same plumbing rather than opening a new front.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="SheildBreak POC" border="0" data-original-height="1037" data-original-width="1196" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2gq6xnbo8O58R4MFJWWbhGXHG3JkWOvMqfZ11u1ee_EJOUyH76vGW_9qBuEck06T7hFawsy95O86GscSeYkLKSre2-8H9C7jUQ7ii4v2WoRNey2GROAhZYtBFG95nyqTP3Rg8HvVV_VA1NF6wyWnAw4QDeFYQT2yaqRjxPNkuVAfLuzjcqTsk1SmsQqw/s1600/sheildbreak.webp" title="SheildBreak POC" /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;RoguePlanet surfaced on June 10 and targeted the Microsoft Malware Protection Engine, the scanner behind Defender, which runs as SYSTEM. It abused improper link resolution before file access to spawn a SYSTEM shell on fully updated machines. Microsoft &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" rel="nofollow" target="_blank"&gt;rated&lt;/a&gt; it important at CVSS 7.8 and shipped engine build 1.1.26060.3008 on July 9. The Register &lt;a href="https://www.theregister.com/security/2026/07/09/microsoft-closes-book-on-nightmare-eclipses-rogueplanet-zero-day/5269280" rel="nofollow" target="_blank"&gt;reported&lt;/a&gt; that Redmond had closed every public zero-day the researcher disclosed.&lt;/p&gt;&lt;p&gt;It is the second fix in this class to fall. Microsoft hardened Defender's internal file-handling APIs in mid-May, and RoguePlanet was rewritten to defeat that. The release follows Microsoft's August Patch Tuesday, which fixed 421 CVEs on August 11. One of them touched Defender.&lt;/p&gt;&lt;p&gt;Nightmare Eclipse has published working exploits for unpatched Microsoft flaws since April, retaliation for what the researcher says was MSRC revoking their reporting access and refusing to pay bounties.&lt;/p&gt;&lt;p&gt;Previously disclosed flaws in the series include:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;BlueHammer (CVE-2026-33825)&lt;/li&gt;&lt;li&gt;RedSun (CVE-2026-41091)&lt;/li&gt;&lt;li&gt;UnDefend (CVE-2026-45498)&lt;/li&gt;&lt;li&gt;YellowKey (CVE-2026-45585)&lt;/li&gt;&lt;li&gt;GreenPlasma (CVE-2026-45586)&lt;/li&gt;&lt;li&gt;MiniPlasma (CVE-2020-17103)&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/06/microsoft-defender-zero-day-poc-gives.html" target="_blank"&gt;RoguePlanet&lt;/a&gt; (CVE-2026-50656)&lt;/li&gt;&lt;li&gt;&lt;a href="https://www.cyberkendra.com/2026/06/bitlocker-bypass-greatxml-using.html" target="_blank"&gt;GreatXML&lt;/a&gt; (CVE-2026-50661)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;BlueHammer, RedSun, and UnDefend were exploited in real-world intrusions before fixes landed, and all three were added to CISA's Known Exploited Vulnerabilities catalog.&lt;/p&gt;&lt;p&gt;No patch exists for ShieldBreak, and no vendor has reproduced it publicly yet. ThreatLocker found that application allowlisting blocked RoguePlanet by default, the strongest control available for this bug class.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Microsoft had not commented on ShieldBreak at publication.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiD4-nd3rviovPn2nWrAxeCxLDDJ5GqqXAT_QQVKqb1uJoPfzbZBEHGbWg14_beVRzerb1VMxornOfMwhMPEu3BzqyOK0FCA63jL3awLidE_RBT3Co_0HvG9T0Hy_SSHhTYa9uzcFefbksuXPmC0bkNQ-0GkXEJgvd3NvWWfoIPQfFOv-GaeA5XzAbNZCE/s72-c/ShieldBreak.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Anthropic to Watermark All Claude-Generated Text</title><link>https://www.cyberkendra.com/2026/08/anthropic-claude-text-watermarking-eu-ai-act.html</link><category>AI</category><category>Claude</category><pubDate>Tue, 11 Aug 2026 21:52:47 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4837697183870459414</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="anthropic watermark" border="0" data-original-height="1996" data-original-width="3000" height="213" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizOp1j3PbU1tDz9B-47UfMWhxk35-3e-ESEM-oulK_B3UOwwLRw8wO_QE5q5qxrpRx9AwREUa747eEeDT3s71odK5oFkr0jT94NMvQmul9CN_ibfPGJN9aMu2y4k3Tx7WkG-TlyQNTbTnAIg8qzZztSFG2MYEngO_rJnTXzxf0ekRDeoRLQ7wC9eengoI/w320-h213/anthropic-watermark.webp" title="anthropic watermark" width="320" /&gt;&lt;/div&gt;Anthropic has detailed plans to mark content generated by its Claude models, embedding invisible watermarks directly into generated text and attaching cryptographically signed provenance metadata to generated files.&lt;p&gt;&lt;/p&gt;&lt;p&gt;The company set out the approach in a support document confirming it has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, as a provider of both generative AI models and generative AI systems.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The document is framed throughout as a description of how Anthropic is "planning to put those commitments into practice", and the company says it will publish more detailed technical guidance as it becomes available.&lt;/p&gt;&lt;p&gt;Claude models launched in the EU on or after 2 August 2026 will support machine-readable marking at launch, according to the company. Anthropic says it is also working to add marking support to models released before that date, which fall under a transition period allowed by the law.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Two marking mechanisms&lt;/h3&gt;&lt;p&gt;Anthropic is deploying two techniques that address different failure modes.&lt;/p&gt;&lt;p&gt;The first is an embedded text watermark. &lt;a href="https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content" rel="nofollow" target="_blank"&gt;According to the company&lt;/a&gt;, when a supported model generates text, it weaves an imperceptible mark into the text itself, without changing meaning, quality or readability. Because the mark is carried by the text rather than attached to it, Anthropic says it travels through copy-and-paste and may survive some editing.&lt;/p&gt;&lt;p&gt;The second is signed provenance metadata on generated files. For supported formats including SVG, PNG and JPEG, Claude attaches metadata conforming to the Coalition for Content Provenance and Authenticity (C2PA) open standard. Anthropic says a signed label indicates a file was processed by Claude and allows detection of subsequent tampering.&lt;/p&gt;&lt;p&gt;The distinction matters in practice. Metadata is information-rich but fragile — it does not survive screenshots, format conversion or most CDN image pipelines. Watermarks carry far less information but persist through transformations that destroy metadata. Deploying both is what makes the pair complementary rather than redundant: each covers the other's principal failure mode.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Applies worldwide, across every surface&lt;/h3&gt;&lt;p&gt;Although the commitments originate in EU law, Anthropic states that marking will apply to output from supported models wherever Claude is offered, worldwide.&lt;/p&gt;&lt;p&gt;Coverage spans the Claude Platform API, the Claude consumer apps, Claude Code, Claude Cowork and Claude Tag. Embedded watermarks will also apply when supported models are accessed through AWS, Google Cloud and Microsoft Foundry, though Anthropic notes that signed provenance metadata may not be supported on every cloud platform, depending on the features each offers.&lt;/p&gt;&lt;p&gt;Anthropic says watermarking is applied at the model level, meaning it is present regardless of which product or surface the text comes from.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Detection remains unavailable&lt;/h3&gt;&lt;p&gt;The company says it will support users and third parties in detecting Claude's marks, as the Code requires, with details to follow in forthcoming technical documentation.&lt;/p&gt;&lt;p&gt;Until those ships, the text watermark is unverifiable by anyone outside Anthropic. Keyed text watermarking schemes bias token selection during generation according to a secret; confirming the signal requires that secret. Google's SynthID text watermarking runs on Gemini output, but its detector remains restricted to Google and selected enterprise partners, and OpenAI has not deployed a detectable text watermark despite publishing research on the technique.&lt;/p&gt;&lt;p&gt;The practical consequence is a gap between marking and verification. Once marking is live, output will carry a signal that no publisher, platform or academic institution can currently read.&lt;/p&gt;&lt;p&gt;The C2PA file metadata is a different matter — it uses an open standard with public tooling, so anyone can verify it today using the C2PA verification tool, c2patool, or any C2PA-compatible reader.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Anthropic's own caveats&lt;/h3&gt;&lt;p&gt;The support document is unusually direct about what marks do not establish.&lt;/p&gt;&lt;p&gt;A detected mark indicates content may have been processed by Claude, but it is not conclusive. Anthropic notes that people routinely use Claude to proofread, translate, summarise or convert files, so output can carry a mark even when the underlying ideas or text originated elsewhere. Marked content may also be edited, excerpted or combined with other material afterwards.&lt;/p&gt;&lt;p&gt;The reverse holds more strongly. Anthropic lists several conditions under which genuinely AI-generated content will carry no detectable mark: generation by a model predating marking support, heavy editing or paraphrasing, translation, passages too short to carry a reliable signal, metadata stripped through format conversion or re-saving, and platforms or file types where a marking type is not supported.&lt;/p&gt;&lt;p&gt;For anyone building detection into an editorial or compliance workflow, that asymmetry is the operative fact. A mark found is evidence. A mark absent is nothing at all.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What it means for publishers&lt;/h3&gt;&lt;p&gt;Organisations deploying Claude in their own products carry independent obligations. Anthropic says those building with Claude should assess what Article 50 requires of their own products and services, and that it will publish technical guidance to support those obligations.&lt;/p&gt;&lt;p&gt;For publishers, the near-term implication is narrower than it first appears. Text watermarks cannot be checked by anyone yet. File credentials can be, and any newsroom accepting image submissions can start verifying them today — a valid credential identifies the signing tool, the certificate holder, and the exact time of signing, and proves whether the file has changed since.&lt;/p&gt;
&lt;script type="application/ld+json"&gt;
{
  "@context": "https://schema.org",
  "@type": "NewsArticle",
  "headline": "Anthropic to Watermark All Claude-Generated Text",
  "description": "Anthropic will embed invisible watermarks in Claude-generated text and signed C2PA metadata in generated files, under the EU AI Act transparency code commitments.",
  "datePublished": "2026-08-11T00:00:00+05:30",
  "dateModified": "2026-08-11T00:00:00+05:30",
  "author": {
    "@type": "Person",
    "name": "Vivek Kumar",
    "url": "https://www.cyberkendra.com/p/about-us.html"
  },
  "publisher": {
    "@type": "Organization",
    "name": "Cyber Kendra",
    "url": "https://www.cyberkendra.com/",
    "logo": {
      "@type": "ImageObject",
      "url": "https://www.cyberkendra.com/logo.png"
    }
  },
  "mainEntityOfPage": {
    "@type": "WebPage",
    "@id": "https://www.cyberkendra.com/2026/08/anthropic-claude-text-watermarking-eu-ai-act.html"
  },
  "articleSection": "AI Security",
  "keywords": "Anthropic, Claude, AI watermarking, C2PA, EU AI Act, content provenance",
  "citation": {
    "@type": "WebPage",
    "name": "How Claude marks AI-generated content",
    "url": "https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content"
  },
  "about": [
    {
      "@type": "Thing",
      "name": "AI watermarking"
    },
    {
      "@type": "Thing",
      "name": "Content provenance"
    },
    {
      "@type": "Organization",
      "name": "Anthropic"
    }
  ]
}
&lt;/script&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizOp1j3PbU1tDz9B-47UfMWhxk35-3e-ESEM-oulK_B3UOwwLRw8wO_QE5q5qxrpRx9AwREUa747eEeDT3s71odK5oFkr0jT94NMvQmul9CN_ibfPGJN9aMu2y4k3Tx7WkG-TlyQNTbTnAIg8qzZztSFG2MYEngO_rJnTXzxf0ekRDeoRLQ7wC9eengoI/s72-w320-h213-c/anthropic-watermark.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>YouTube Now Wants 8,000 Watch Hours for Monetisation</title><link>https://www.cyberkendra.com/2026/08/youtube-now-wants-8000-watch-hours-for.html</link><category>YouTube</category><pubDate>Tue, 11 Aug 2026 00:40:01 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-7948638461524038061</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="YouTube Earnings" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYvvHt0Zck-43dSiHd-j-yfpNJOLQFim9YCT38rgwktOoERS08gDnLW-YVBDYnfN3YFrlzayCU8T7ti_8euufWjfxL2pbK2FxbXKRln2P5qm8aPlWYyMO8OoHly-gqZUF_EhUfEhUfRTjVAMkCBmB-LMwxkgZRU9JC73gRrjZIEAWKtwGnFYs22_c5pZY/s1600/YouTube-earning.png" title="YouTube Earnings" /&gt;&lt;/div&gt;&lt;p&gt;Most of the attention on YouTube's August 10 announcement went to the double-entry bar for newcomers. The change with longer teeth applies to the three million creators already inside the YouTube Partner Program (YPP).&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;From February 1, 2027, a channel must hold 10 million qualified Shorts views across a rolling 90-day window to draw from the Shorts Creator Pool each month. Fall short, and Short's payouts pause. YouTube says such channels stay in the program and keep earning on long-form video, with Shorts revenue resuming automatically once views recover — missing the mark does not mean removal from YPP, and other earnings are unaffected.&amp;nbsp;&lt;/p&gt;&lt;p&gt;That quietly converts monetization from a milestone you cross once into a test you re-sit every quarter. The shift matters in India, where creators lean on sheer volume because RPM (revenue per thousand views) sits well below Western rates.&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="YouTube Monetization policy" border="0" data-original-height="920" data-original-width="1650" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLLiD-HmZka9MbMLwauo3UioirVxTg71AW0NdveWefagcD6DNtSTzv-zyX5MbpmbNvZMqj5C_iD3U_54J4qVrPjspdZquBWK9KHKaN5oveiRG4AouAdA4M74QfT1bsHE1DUk6aC5klCy3F5wtxhPHrTHG9QMEQDbm8_YWaF7U0UnfnfzrEVUKc-XXnyXc/s1600/ypp.webp" title="YouTube Monetization policy" /&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;New applicants face a steeper climb. They will need &lt;b&gt;1,000 subscribers plus either 8,000 qualified watch hours over 365 days or 20 million Shorts views in 90 days &lt;/b&gt;— double the current 4,000 hours and 10 million views. Fan funding, Shopping and Creator Partnerships stay open at 500 subscribers.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The money side moves too. Premium Lite expands to every country where Premium is sold. Subscription income is pooled — 60% of net revenue for Premium Lite, 30% for Premium — divided by member watch time, then shared 55% for long-form and 45% for Shorts. A separate 45% direct share applies when an advertiser targets five or fewer channels.&amp;nbsp;&lt;/p&gt;&lt;p&gt;YouTube frames the package as "meaningfully rewarding active creators" and expects to pay out more in 2027 than in 2026. Set against the 200 billion Shorts views it serves daily, the subtext is arithmetic: the pool is not growing as fast as the number of hands reaching into it. Promised bonuses for Shopping, brand deals and trend-starting are meant to cover smaller channels, but specifics remain unpublished.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What creators should do now:&lt;/b&gt; review and accept the updated terms in YouTube Studio before January 31, 2027, to keep full monetisation. Channels hovering near the 10 million mark should watch the rolling 90-day count in Analytics rather than monthly totals, and treat long-form uploads as the steadier floor under their earnings.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYvvHt0Zck-43dSiHd-j-yfpNJOLQFim9YCT38rgwktOoERS08gDnLW-YVBDYnfN3YFrlzayCU8T7ti_8euufWjfxL2pbK2FxbXKRln2P5qm8aPlWYyMO8OoHly-gqZUF_EhUfEhUfRTjVAMkCBmB-LMwxkgZRU9JC73gRrjZIEAWKtwGnFYs22_c5pZY/s72-c/YouTube-earning.png" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Microsoft Leaves Windows Passkey Prompt Spoofing Unfixed</title><link>https://www.cyberkendra.com/2026/08/microsoft-leaves-windows-passkey-prompt.html</link><category>Microsoft</category><category>Password</category><category>Security</category><category>Windows</category><pubDate>Tue, 11 Aug 2026 00:09:06 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-4594431908189110990</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Pass-the-Passkey" border="0" data-original-height="1117" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJwQB3rvFyYLUXaWdhI98B4ehdLVKjRURYMWjlu96tMwn-eU6lNOpN31VQdyw7Vd2EwChfmlkL8R99a_4MAYueIbKzH7LKa1wDB8Kv12JY9Fi_pB-pZdaZKqHkUVBp8IUeIME3OU2OR9jxkSbgBJkdpgahKFtmWb4U2zFzx6nyDNnUeQbQB19O2ySkGik/s1600/Pass-the-Passkey.webp" title="Pass-the-Passkey" /&gt;&lt;/div&gt;&lt;p&gt;Three weeks before Microsoft makes passkeys the &lt;a href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement" rel="nofollow" target="_blank"&gt;default sign-in method for Entra ID&lt;/a&gt;, new research shows that the Windows dialog protecting them can be faked well enough to fool the people who build security products for a living — and that Microsoft has decided the underlying weakness isn't worth patching.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The finding comes from SpecterOps principal security researcher Michael Grafnetter, who presented &lt;a href="https://blackhat.com/us-26/briefings/schedule/#pass-the-passkey-family-of-attacks-51821" rel="nofollow" target="_blank"&gt;Pass-the-Passkey Family of Attacks&lt;/a&gt; at Black Hat USA 2026 on August 5 and published a 72-page white paper alongside it.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The research documents three zero-days in Windows 11 and Microsoft Entra ID, more than 20 attack techniques, and a toolkit that SpecterOps has open-sourced so defenders and pentesters can reproduce the attacks.&lt;/p&gt;&lt;p&gt;Two of the three bugs have been fixed. The third has not, and it is arguably the one that matters most going forward.&lt;/p&gt;&lt;h2 style="text-align: left;"&gt;The chain Microsoft closed&lt;/h2&gt;&lt;p&gt;Grafnetter's team found that Windows 11 was writing complete WebAuthn assertions — the signed responses a passkey produces to prove who you are — into the &lt;code&gt;Microsoft-Windows-WebAuthN/Operational&lt;/code&gt; event log in plaintext. Every field an attacker needs was there: challenge, authenticator data, signature, credential ID, and user handle.&lt;/p&gt;&lt;p&gt;Reading that log locally required nothing more than membership in the &lt;b&gt;Users &lt;/b&gt;group. Remotely, membership in &lt;b&gt;Event Log Readers, Remote Desktop Users, Remote Management Users,&lt;/b&gt; or &lt;b&gt;Administrators&lt;/b&gt; was enough.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The logging applies to Windows Hello, YubiKeys, password-manager plugins, and phone-based hybrid flows alike. The only exceptions were private browsing sessions and password managers that autofill passkeys without touching the Windows API.&lt;/p&gt;&lt;p&gt;On its own, a leaked assertion is stale data. The second flaw made it live ammunition: Entra ID was not checking whether a challenge had already been used, was not binding challenges to a session, and was not tracking signature counters — three of the anti-replay checks the WebAuthn Level 3 specification assigns to the relying party. Entra ID's challenges are short-lived signed JWTs valid for five minutes, but the service accepted them for roughly ten.&lt;/p&gt;&lt;p&gt;Put together, a low-privileged user on a shared or managed machine could lift a Global Administrator's assertion out of the event log and replay it, satisfying the phishing-resistant MFA requirement in Conditional Access along the way. In testing against Microsoft 365 E5 tenants with Entra Identity Protection and Defender for Identity enabled, the researchers saw no alerts at all.&lt;/p&gt;&lt;p&gt;Microsoft patched the Windows side on July 14 as &lt;b&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34348" rel="nofollow" target="_blank"&gt;CVE-2026-34348&lt;/a&gt;&lt;/b&gt;, truncating the logged signature to six bytes so the events remain useful for debugging but useless for replay. It classified the issue as information disclosure at CVSS 6.5; SpecterOps had filed it as privilege escalation at 8.6.&lt;/p&gt;&lt;p&gt;The cloud fix arrived quietly in May — Grafnetter says he only noticed it while recording demos for the conference. Notably, that fix covers FIDO2 security keys, not Windows Hello on Entra-registered devices, which still reports a signature counter of zero.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;The one that stayed open&lt;/h3&gt;&lt;p&gt;The unpatched issue is smaller in scope and larger in practical consequence. The Win32 function &lt;code&gt;WebAuthNAuthenticatorGetAssertion&lt;/code&gt;, &lt;a href="https://github.com/microsoft/webauthn/blob/master/webauthn.h" rel="nofollow" target="_blank"&gt;documented in Microsoft's own header&lt;/a&gt;, takes a window handle (&lt;code&gt;hWnd&lt;/code&gt;) that determines which application the credential dialog appears to belong to. Windows does not validate it. Malware can therefore render the "Sign in with a passkey" prompt as a modal child window of Microsoft Edge or Outlook — even when those apps are running under a different user account.&lt;/p&gt;&lt;p&gt;Pair that with a second trick from the paper: the publisher name shown in the prompt comes from the executable's version resource, which the attacker controls. Setting an assembly title of "Microsoft Edge" and an author of "Microsoft Corporation" produces a dialog that reads Requested by Microsoft Edge (Microsoft Corporation) — the exact string a cautious user would look for.&lt;/p&gt;&lt;p&gt;Because malware calling the API directly supplies its own origin, rather than having the browser fill it in from the page, it can request an assertion for any site it likes. Windows blocks two ceremonies at once, so overlaying a rogue prompt on a real one fails — but simply waiting for the legitimate login to finish and then prompting works fine, and a flooding mode re-prompts every couple of seconds until the challenge expires.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The paper is blunt about how effective this is, noting that colleagues admitted to confirming such prompts "reflexively," without checking what they were approving.&lt;/p&gt;&lt;p&gt;Microsoft's Security Response Center reviewed a proof of concept and closed the case on June 4 as low-severity "Defense in Depth." SpecterOps scored it 8.0 High.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;Wider exposure&lt;/h3&gt;&lt;p&gt;The white paper covers a lot more ground than the three CVE-class issues. Windows relays passkey prompts over RDP and Hyper-V enhanced sessions by default via &lt;b&gt;&lt;a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-rdpewa/68f2df2e-7c40-4a93-9bb0-517e4283a991" rel="nofollow" target="_blank"&gt;MS-RDPEWA&lt;/a&gt;&lt;/b&gt;, so malware on a compromised jump host can raise a prompt on the administrator's own desktop.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Administrative passkey registration APIs in Microsoft Graph and Okta can be abused to plant a "shadow passkey" that survives a password reset. And synced passkeys are exportable in cleartext by design: KeePassXC writes .passkey files in the clear, Bitwarden's default JSON export is unencrypted, and the FIDO Alliance's &lt;a href="https://fidoalliance.org/specs/cx/cxf-v1.0-ps-errata-20260309.html" rel="nofollow" target="_blank"&gt;Credential Exchange Format&lt;/a&gt; leaves transport protection to the provider. Any of those files is a working credential to anyone who finds it.&lt;/p&gt;&lt;h3 style="text-align: left;"&gt;What to do now&lt;/h3&gt;&lt;p&gt;Grafnetter is not telling anyone to abandon passkeys. "Passkeys are still a major improvement over passwords, but they are not magic," he told Dark Reading.&lt;/p&gt;&lt;p&gt;For IT administrators, the practical steps are: apply the July 2026 Windows updates; stop treating phishing-resistant MFA in Conditional Access as a sufficient control on its own; issue device-bound passkeys and enforce attestation for privileged accounts instead of synced ones; restrict remote event log access and use privileged access workstations for admin work; and audit passkey registrations through Graph and Okta APIs.&lt;/p&gt;&lt;p&gt;On the detection side, SpecterOps flags several signals worth hunting for: WebAuthn API calls from non-browser processes, unexpected reads of the WebAuthN operational log, enumeration of top-level window handles, and DLL injection into browsers. Any one of them is noisy on its own; correlated, they're a strong indicator.&lt;/p&gt;&lt;p&gt;For developers, the advice is simpler — bind challenges to sessions the way GitHub already does, enforce single-use challenges and signature counters, use a maintained WebAuthn SDK rather than rolling your own, and keep assertions out of your logs.&lt;/p&gt;&lt;p&gt;And for everyone else: if a passkey prompt appears when you weren't signing in to anything, cancel it. Twice, if you have to.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJwQB3rvFyYLUXaWdhI98B4ehdLVKjRURYMWjlu96tMwn-eU6lNOpN31VQdyw7Vd2EwChfmlkL8R99a_4MAYueIbKzH7LKa1wDB8Kv12JY9Fi_pB-pZdaZKqHkUVBp8IUeIME3OU2OR9jxkSbgBJkdpgahKFtmWb4U2zFzx6nyDNnUeQbQB19O2ySkGik/s72-c/Pass-the-Passkey.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Windows 11 Kernel 0day PoC Drops Before Patch Tuesday</title><link>https://www.cyberkendra.com/2026/08/windows-11-kernel-0day-poc-drops-before.html</link><category>Security</category><category>Windows 11</category><category>ZeroDay Bug</category><pubDate>Mon, 10 Aug 2026 23:31:09 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2466426881227181709</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Windows 11 Kernel 0day" border="0" data-original-height="736" data-original-width="1312" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjROOpNmKshLfi8dNuBhndLTYENgYFm5LdW1Gp71t96XBmZdXkAsgriZpRpY47mGMOpAISMomjFjHF10fAm6j2lZTyVp9GxsJy298aQSTlsqgI75F12F4OTvS5Mn-mEz58xfLcBZO2VUFeOUfKwZHZCJ7_l__JwNPrTLUH5mK3tFMgoNGxosN6j3C7io8k/s1600/windows11-0day.webp" title="Windows 11 Kernel 0day" /&gt;&lt;/div&gt;&lt;p&gt;An anonymous researcher has published proof-of-concept (PoC) code for what they describe as an unpatched local privilege-escalation flaw in Windows 11, posting the writeup online just a day before Microsoft's August Patch Tuesday. If the claims hold, a standard user on a fully updated Windows 11 25H2 machine could use the bug to push code toward SYSTEM-level control — the highest privilege on the box.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;The vulnerability, tagged &lt;b&gt;CVE-2026-62737&lt;/b&gt; by its finder, does not yet appear in Microsoft's advisory database or the National Vulnerability Database, and Microsoft has not confirmed it. The researcher says the PoC still fires on the latest Windows build and released a crash dump as evidence, while deliberately withholding the full exploit.&lt;/p&gt;&lt;p&gt;The flaw sits in ExecutionContext.sys, a genuine Microsoft-signed kernel driver that has shipped with Windows since at least 2021 and is documented as the "CPU Scheduler for High Performance I/O." It is a demand-start component that does not run by default.&lt;/p&gt;&lt;p&gt;According to the writeup, a loader/proxy path inside Windows' NDIS networking stack re-exposes this access-controlled device to low-privilege users, sidestepping the permissions (ACL) meant to keep them out. From there, the driver accepts a user-supplied function pointer and passes it to a kernel worker thread, which runs it after only checking that the address falls inside kernel memory.&lt;/p&gt;&lt;p&gt;It never verifies who supplied the pointer or whether it is legitimate enough, the researcher argues, to redirect kernel execution.&lt;/p&gt;&lt;p&gt;The disclosure fits a pattern that has defined 2026: researchers racing to drop kernel PoCs around each Patch Tuesday, which have swelled to record sizes, with Microsoft fixing more than 600 flaws in a single recent month.&amp;nbsp;&lt;/p&gt;&lt;p&gt;This author frames the bug as an AI-assisted find, claiming large language models handled the tedious code-audit work that once took weeks. "After years of relative stability, the Patch Tuesday process has experienced significant turbulence," &lt;a href="https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/" rel="nofollow" target="_blank"&gt;Rapid7's Adam Barnett said&lt;/a&gt; of the 2026 cadence.&lt;/p&gt;&lt;p&gt;On its own, the PoC only forces a blue-screen crash, not a working SYSTEM shell; a full exploit needs a separate kernel-address (KASLR) leak to line up. And while the targeted driver is genuine, the vulnerability itself is not yet confirmed — Microsoft has not acknowledged it, and no other researcher has reproduced the finding.&lt;/p&gt;&lt;p&gt;Defenders should watch tomorrow's Patch Tuesday release for a matching fix and deploy it fast, since privilege-escalation bugs are usually the second stage of a breach rather than the way in. Until Microsoft weighs in, limiting who can run untrusted code on shared and multi-user systems — and watching for unexplained crashes in the affected driver — remains the practical hedge.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjROOpNmKshLfi8dNuBhndLTYENgYFm5LdW1Gp71t96XBmZdXkAsgriZpRpY47mGMOpAISMomjFjHF10fAm6j2lZTyVp9GxsJy298aQSTlsqgI75F12F4OTvS5Mn-mEz58xfLcBZO2VUFeOUfKwZHZCJ7_l__JwNPrTLUH5mK3tFMgoNGxosN6j3C7io8k/s72-c/windows11-0day.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>DeadLock Ransomware Puts Its Negotiation Portal On-Chain</title><link>https://www.cyberkendra.com/2026/08/deadlock-ransomware-puts-its.html</link><category>Ransomware</category><category>Security</category><pubDate>Mon, 10 Aug 2026 22:54:08 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-3941803874053044976</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="DeadLock ransomware" border="0" data-original-height="1068" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMyM9Ynunnyd2W4tR3FFrWSVjnrnAo4vGk4Yg6VOTNJgFZ2CzmyPvBu4pI0dOK6zdh0jSmo2H72wU3MwaJSggAbbie3NlkmZchINE7qVOqLJoL3ay3HBWS3g6IAzi9UfvNDybbMKEhaXxC-TjC6D4GNQF1zpxQoURGPpFIyKkvXvX5esPP0lc8n6_qDCg/s1600/DeadLock%20ransomware.webp" title="DeadLock ransomware" /&gt;&lt;/div&gt;&lt;p&gt;Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Microsoft Threat Intelligence has &lt;a href="https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/" rel="nofollow" target="_blank"&gt;published&lt;/a&gt; a technical breakdown of the Rust-based DeadLock encryptor, and the most consequential finding isn't in the crypto — it's in the ransom note. The file DeadLock drops on desktops and drives roots, &lt;code&gt;RECOVERY_CHAT.&amp;lt;UID&amp;gt;.html&lt;/code&gt;, is a complete single-page web application: encrypted chat, a paginated leak blog, and an S3 file browser, all running in the victim's browser with no conventional backend behind it.&lt;/p&gt;&lt;p&gt;Instead of a hardcoded onion address, the page fires read-only &lt;code&gt;eth_call&lt;/code&gt; requests at six public Polygon RPC endpoints to reach two smart contracts. One stores the URL of the operators' chat proxy; the other holds the leak blog posts.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Knock the proxy offline, and the crew simply updates the on-chain value — every note already sitting on victim machines starts pointing at the replacement. Stolen files are parked in Wasabi buckets, browsable through pre-signed URLs that the note generates on the fly. Microsoft calls the setup "a notable evolution in ransomware infrastructure design."&lt;/p&gt;&lt;p&gt;Victim-operator chat rides the Session network, an onion-routed messenger with no central server. The victim's Session identity is derived by hashing their chosen login and password with SHA-512 — no registration, and no recovery if they forget the combination.&lt;/p&gt;&lt;p&gt;DeadLock surfaced in July 2025 and had listed more than 80 organizations on its leak site by July 2026, over half of them European. Microsoft has watched multiple crews deploy it, including an affiliate of the Lynx and INC operations, against IT, mining, logistics, manufacturing, and hospitality targets across five continents.&lt;/p&gt;&lt;p&gt;A dispatch thread checks system load before releasing each file to a worker and stalls whenever memory use tops 29%, or CPU idle falls below 30%, keeping infected machines responsive and resource graphs unremarkable.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Large files get intermittent 512-byte-block encryption instead of a full pass. Before any of that, it disables Defender, VSS, and backup services, empties the recycle bin across all drives, and clears event logs three different ways — including flipping &lt;code&gt;Enabled&lt;/code&gt; to 0 on every WINEVT channel. Machines set to Russian, Persian, Arabic (Oman or Yemen), or a dozen other CIS-region locales are skipped, and the binary self-deletes.&lt;/p&gt;&lt;p&gt;File encryption pairs Curve25519 with XChaCha20 using per-file ephemeral keys. Microsoft found no practical path to decryption without the operators' private key, so recovery comes down to backups.&lt;/p&gt;&lt;p&gt;Defender flags samples as &lt;code&gt;Ransom:Win32/Deadlock.*&lt;/code&gt;. Microsoft's guidance: enable tamper protection, run EDR in block mode, tighten Controlled Folder Access, and switch on the ASR rules blocking PsExec/WMI process creation and low-prevalence executables. The encryptor's SHA-256 is &lt;code&gt;a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMyM9Ynunnyd2W4tR3FFrWSVjnrnAo4vGk4Yg6VOTNJgFZ2CzmyPvBu4pI0dOK6zdh0jSmo2H72wU3MwaJSggAbbie3NlkmZchINE7qVOqLJoL3ay3HBWS3g6IAzi9UfvNDybbMKEhaXxC-TjC6D4GNQF1zpxQoURGPpFIyKkvXvX5esPP0lc8n6_qDCg/s72-c/DeadLock%20ransomware.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item><item><title>Researchers Buy 'No Reply' Domains and Get Company Data</title><link>https://www.cyberkendra.com/2026/08/researchers-buy-no-reply-domains-and.html</link><category>Cyber Fraud</category><category>Privacy</category><category>Security</category><pubDate>Sat, 8 Aug 2026 23:07:46 +0530</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-3448621598664628523.post-2781529038333203694</guid><description>&lt;p&gt;&lt;/p&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img alt="Corporate secret emails" border="0" data-original-height="900" data-original-width="1600" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnBBhrS7UELGgwMZ6PwFTMYAGRtttS_jk3fg3U19k4l1N1RHILusPcuWJkXGvqZufw9ojy__cxm4TII2Le6pH-7yoJqH81J1uMGyEnEhs6tZHuKrY3z8nMIcvmfrHEGHDl-3f1ZSkhkhqnUtodt0Ybk4_TIR2SLl0gNhqRh9BiynsvvFQvGTQAV3HpvdE/s1600/secret-emails.webp" title="Corporate secret emails" /&gt;&lt;/div&gt;&lt;p&gt;Fifteen dollars is roughly what it costs to start reading email your company thinks nobody receives. Two security researchers who quietly bought placeholder domains — the ones enterprise systems fall back on when an address is retired or an alert needs a fake sender — have collected hundreds of thousands of misdirected corporate messages, and their own scanning suggests hundreds of similar domains are already sitting on live inboxes.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Cory Solovewicz, a security researcher and consultant, laid out the problem at the Defcon security conference this week. He registered noreply.us in 2020, intending to use it as a personal catch-all (an inbox that accepts mail sent to any address on a domain), then noticed that unrelated corporate systems were already mailing it. "I created an accidental honeypot," &lt;a href="https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constantly-this-guy-sees-it-all/" rel="nofollow" target="_blank"&gt;he told WIRED&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The volume since has been extraordinary. His noreply.net domain, bought in 2024, has taken close to 400,000 messages in about 18 months, 28,365 of them carrying attachments.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The mail arrives from more than 14,000 sending addresses across 6,200 root domains, all of it machine-generated: injury reports from a city government, service tickets, school platform signups, and, repeatedly, credentials for test environments.&lt;/p&gt;&lt;p&gt;Mike Sheward, head of security at EV charging company Xeal, ran the same experiment with deleteduser.com. Three organisations emailed it within the first hour. Since then, he has received leave-approval requests, hotel bookings with full guest names, Zoom invites from a UK government agency, and thousands of CCTV stills from an AI vendor monitoring worker safety at Middle East industrial sites — traffic from at least 100 organisations, several of them security vendors themselves.&lt;/p&gt;&lt;p&gt;Rather than deprovisioning an account, many systems simply rewrite the user's address to a placeholder domain the company does not own. Brian Krebs documented the same failure with donotreply.com nearly two decades ago.&lt;/p&gt;&lt;p&gt;The exposure is wider than two inboxes. Solovewicz probed 7,136 candidate placeholder domains and found 328 with catch-all inboxes already configured.&lt;/p&gt;&lt;p&gt;Fixing it is cheap: audit outbound mail for external placeholder domains, switch no-reply senders to a subdomain you control or to .invalid (reserved by RFC 2606 and guaranteed never to resolve), and make account deletion actually delete rather than rename.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnBBhrS7UELGgwMZ6PwFTMYAGRtttS_jk3fg3U19k4l1N1RHILusPcuWJkXGvqZufw9ojy__cxm4TII2Le6pH-7yoJqH81J1uMGyEnEhs6tZHuKrY3z8nMIcvmfrHEGHDl-3f1ZSkhkhqnUtodt0Ybk4_TIR2SLl0gNhqRh9BiynsvvFQvGTQAV3HpvdE/s72-c/secret-emails.webp" width="72"/><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><author>protalweb@gmail.com (Vivek Gurung)</author></item></channel></rss>