Glassbox dev admits he had some help from Claude to build locally running tool

A new browser fingerprinting tool called Glassbox has been released, designed to show users how easily their browser and device can be uniquely identified online. Developed by security engineer David Dale, Glassbox operates entirely within the user's browser, without transmitting any data to external servers, while simulating various tracking and anti-fraud scripts commonly found on websites.
Glassbox provides detailed raw data about a browser's characteristics, along with an "identifiability" score. This score is an estimate, calculated by summing published per-signal entropy, accounting for browser masks, and capped at approximately 33 bits, which is theoretically sufficient to distinguish one person globally. Dale noted that because the tool runs locally, this score is an estimate rather than a measurement against a live population, unlike other tools such as AmIUnique or the EFF's Cover Your Tracks, which provide real population numbers.
The inspiration for Glassbox came when Dale learned about silent sawtooth waves used by fingerprinting code on Alibaba's AliExpress site to identify browsers through audio analysis. Instead of forking existing open-source tools, Dale decided to build his own, incorporating this technique and others. He stated that AI tools like Claude Code assisted him in refining the concept and making it accessible.
Glassbox probes over 30 different browser data points, including canvas, WebGL, font libraries, WebAssembly (WASM) features, API matrices, and cross-site login states. Initial testing with the tool showed varying identifiability estimates: a daily-use Chrome browser scored 99 percent, while Tor Browser with an active circuit scored 56 percent. Firefox also demonstrated a lower identifiability rating of 89 percent. These estimates suggest that a Chrome session could be unique among 1 in 7.6 billion browsers, while Firefox users might share a fingerprint with 1 in 681 million, and Tor users with 1 in 408 thousand.
Dale emphasized that the most effective strategy for online anonymity is to use a browser that places a user within a large, identical crowd. He cautioned that heavily customized or "hardened" browser setups can paradoxically make a user more identifiable due to their uniqueness. Beyond browser choice, Dale recommends using a VPN or Tor and addressing WebRTC leaks, which can expose a user's true IP address even when using some VPNs, as WebRTC is often enabled by default. Glassbox includes a section with suggestions for improving online anonymity.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed