Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

Obscura launches VPN using dual-server design to prevent activity logging

Obscura has released a VPN service that splits traffic handling across two servers so no single party ever sees both a user's identity and their decrypted internet activity. The company says this architecture makes logging impossible even under legal compulsion or server compromise, and it uses a QUIC-based stealth protocol intended to disguise VPN traffic as regular HTTP/3 traffic to evade censorship and network filtering.

VPN kill switches explained: how they stop IP leaks when connections drop

A kill switch is a VPN feature that watches the encrypted tunnel between a device and a VPN server, cutting internet access the moment that connection weakens or fails. This stops a device's real IP address or DNS requests from leaking during outages or server switches, restoring access automatically once the secure tunnel resumes. The feature comes in two forms: app-level, which blocks only chosen programs, and system-level, which halts all network traffic on the device.

Japan's Digital Agency confirms VPN breach exposed 246,000 employee records

Japan's Digital Agency disclosed that an attacker exploited a known, medium-severity vulnerability in a VPN device used by its Government Solution Service to access internal systems. The breach, detected after unusual account activity on June 25 and confirmed on July 9, may have exposed roughly 246,000 rows of data including names, emails, phone numbers and some addresses belonging to government staff and affiliated businesses.

Why security experts recommend keeping VPNs running continuously

Cybersecurity guidance highlights that VPNs are most valuable in two situations: connecting to unsecured public Wi-Fi and preventing internet service providers from tracking browsing habits. Encrypting traffic through a VPN tunnel blocks eavesdroppers on shared networks and stops ISPs from logging and selling usage data to third parties, per FTC research cited in the coverage.

Free VPNs Trade Cash Payments for Data and Ad Tradeoffs

Free VPN services aren't simply schemes to sell user data; some reputable providers offer limited free tiers hoping users will upgrade, while others monetize through ads or unclear data practices. A VPN encrypts traffic between your device and its server, hiding your destinations from your ISP, but it doesn't make you anonymous since sites can still track you via accounts and cookies. Choosing a free VPN means evaluating the provider's business model and privacy tradeoffs, not just the lack of a price tag.

Dutch NCSC warns Check Point VPN flaws face imminent exploitation

The Dutch NCSC has issued an alert about two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, warning that attacks exploiting them are likely to begin soon even though no public proof-of-concept exploit exists yet. Check Point released patches for both bugs on September 9, covering Security Gateways and Management Servers across multiple supported and end-of-support versions.

Android NAT-T keepalive API lets apps bypass VPN lockdown mode

Security researchers found that Android's public NAT-T socket-keepalive API allows ordinary apps to send UDP packets directly to a router, bypassing Always-on VPN and 'Block connections without VPN' protections. Tests on a Pixel 8 Pro, Samsung SM-F966B, and Nothing A059, all running Android 16, confirmed that keepalive packets reached the physical gateway outside the VPN tunnel, with one device sustaining a leak for over 24 hours. The root cause traces to changes in Android's startNattKeepaliveWithFd function, where validation checks tying the socket to the caller's VPN policy were added and later removed.

New Android VPN Bypass Lets Apps Leak Real IP via Keep-Alive UDP Packets

Security researchers found a flaw in Android's network stack that lets any app, without special permissions, send UDP packets through the device's Wi-Fi or cellular hardware that bypass VPN tunnels entirely. This occurs even when the 'Block all connections without VPN' setting is enabled, exposing a user's real IP address. The bug was reported through Google's Vulnerability Reward Program but closed without action, while GrapheneOS says it is working on a fix.

Surfshark confirms breach of internal test and proxy servers, no user data affected

Surfshark disclosed that hackers gained access to an internal engineering test server after a misconfiguration left it exposed to the internet, along with a separate proxy server used for content-accessibility optimization. The company says the exposed systems contained build credentials, code history and system binaries, but no user identities, IP addresses, encryption keys or browsing traffic were compromised. Suspicious activity was spotted on August 31, contained by September 2, and remediation finished three days later.

NordVPN launches PriceMice, a Chrome extension to compare hotel prices by country

NordVPN has released PriceMice, a free Chrome extension that uses AI to scan hotel booking prices across different countries and surface the cheapest option, including taxes and fees at checkout. Users can then switch their VPN to the country offering the lowest rate before completing their booking. In one test, the tool found a savings of about $120 on a Tokyo hotel by switching the browsing location from India to Taiwan.

New open-source tool wg-admin adds a web UI to existing WireGuard servers

A developer released wg-admin, a self-hosted web interface designed to manage WireGuard VPN servers that are already configured and running. Rather than generating new configs or replacing wg-quick, it reads existing files in /etc/wireguard, lets admins add, rename, rotate or remove peers, and applies changes using wg syncconf so the tunnel doesn't restart. It also generates client config files and QR codes, shows live handshake and traffic data, and backs up configs before writing changes.

Mullvad to shut down public encrypted DNS servers, endorses Quad9

Mullvad announced it will shut down its public DNS-over-HTTPS servers, which it has operated since 2022, and redirect support to Quad9 instead. The company said running a privacy-focused public DNS service is highly specialized work best left to Quad9's dedicated team, and it will now fund Quad9 rather than duplicate its efforts. Mullvad Browser users on default settings will be automatically switched to Quad9, while manual configurations must be updated before November 2, 2026.

Today's top topics: openai apple anthropic artificial intelligence qualcomm claude opus 5.5 iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →