Mullvad announced it will shut down its public DNS-over-HTTPS servers, which it has operated since 2022, and redirect support to Quad9 instead. The company said running a privacy-focused public DNS service is highly specialized work best left to Quad9's dedicated team, and it will now fund Quad9 rather than duplicate its efforts. Mullvad Browser users on default settings will be automatically switched to Quad9, while manual configurations must be updated before November 2, 2026.
Security researchers at Previdian and Belgium's national cyber center report that hackers are actively probing a critical authentication-bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490. The flaw affects NetScaler devices configured as AAA virtual servers or Gateways, and exploitation attempts began after a working proof-of-concept was posted online. Citrix patched the issue in mid-August but had not confirmed active exploitation as of its most recent advisory.
Senator Ron Wyden sent a letter to NSA Director General Joshua M. Rudd asking the agency to update its public guidance on VPN configurations. He argued that current recommendations don't help Americans facing foreign surveillance—including government staff, contractors, journalists and human rights defenders—choose which VPNs actually protect their communications.
Utah's Department of Commerce has agreed not to enforce SB 73, a law that took effect this week making adult websites liable for users who access them via VPN, while a federal judge weighs a legal challenge. The law treats anyone physically located in Utah as a Utah user regardless of VPN use, and bars sites with significant adult content from encouraging VPN use.
Utah has enacted Senate Bill 73, an age-verification law requiring adult websites to confirm users' ages regardless of whether they use a VPN or proxy to mask their location. The law, which had been delayed by a court injunction after a challenge from Pornhub owner Aylo, imposes fines up to $2,500 per violation and bars sites from telling users how to bypass verification with a VPN.
Proton is experiencing a partial outage that has disrupted access to most of its services, including Mail, VPN, Calendar, and Wallet. The company's website remains operational, but it has acknowledged the issue on its status page and says it is investigating the cause.
Proton's new report examined VPN apps available in the US and found that 64 are linked to Chinese companies, many collecting device IDs, network data, carrier information and even user location. These apps were downloaded more than 13 million times in June alone, and 31 relied on shell companies in places like Singapore, Hong Kong and the UK to obscure ownership. About a quarter of the flagged apps were found actively tracking location data.
Proton confirmed a major outage affecting Proton Mail, VPN, Calendar, Drive, Pass, SimpleLogin, Wallet and its Lumo AI assistant, first detected around 6:09 p.m. ET as Downdetector reports surged. The company said user data remained safe and later reported a fix had been implemented, restoring service for most users while recovery continued for others.
Zimperium researchers found a new version of the ToxicPanda Android malware that requests VPN service permissions to intercept and control device network traffic, allowing it to cut off communication with Google Play and Play Protect. The updated trojan, spread via Amazon AWS-hosted buckets, now supports 167 remote commands and phishing overlays for 349 banking, crypto, and e-wallet apps across 16 countries, plus a separate module that harvests PINs from 140 financial apps.