LIVE · cybersecurity feed
Live wire
US sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
security

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

Glassbox dev admits he had some help from Claude to build locally running tool

zeroday.news ·

A new browser fingerprinting tool called Glassbox has been released, designed to show users how easily their browser and device can be uniquely identified online. Developed by security engineer David Dale, Glassbox operates entirely within the user's browser, without transmitting any data to external servers, while simulating various tracking and anti-fraud scripts commonly found on websites.

Glassbox provides detailed raw data about a browser's characteristics, along with an "identifiability" score. This score is an estimate, calculated by summing published per-signal entropy, accounting for browser masks, and capped at approximately 33 bits, which is theoretically sufficient to distinguish one person globally. Dale noted that because the tool runs locally, this score is an estimate rather than a measurement against a live population, unlike other tools such as AmIUnique or the EFF's Cover Your Tracks, which provide real population numbers.

The inspiration for Glassbox came when Dale learned about silent sawtooth waves used by fingerprinting code on Alibaba's AliExpress site to identify browsers through audio analysis. Instead of forking existing open-source tools, Dale decided to build his own, incorporating this technique and others. He stated that AI tools like Claude Code assisted him in refining the concept and making it accessible.

Glassbox probes over 30 different browser data points, including canvas, WebGL, font libraries, WebAssembly (WASM) features, API matrices, and cross-site login states. Initial testing with the tool showed varying identifiability estimates: a daily-use Chrome browser scored 99 percent, while Tor Browser with an active circuit scored 56 percent. Firefox also demonstrated a lower identifiability rating of 89 percent. These estimates suggest that a Chrome session could be unique among 1 in 7.6 billion browsers, while Firefox users might share a fingerprint with 1 in 681 million, and Tor users with 1 in 408 thousand.

Dale emphasized that the most effective strategy for online anonymity is to use a browser that places a user within a large, identical crowd. He cautioned that heavily customized or "hardened" browser setups can paradoxically make a user more identifiable due to their uniqueness. Beyond browser choice, Dale recommends using a VPN or Tor and addressing WebRTC leaks, which can expose a user's true IP address even when using some VPNs, as WebRTC is often enabled by default. Glassbox includes a section with suggestions for improving online anonymity.

ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.

security

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'

vulnerability

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]

malware

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.

security

New Zealand to pursue social media ban for children under 16

The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation, digital ID services, formal IDs and existing account information for verification.

vulnerabilitycritical

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]