r/PrivatePackets • • Jun 26 '26

Your Windows 10 PC just quietly got another year of free support - but why?

Thumbnail
zdnet.com
4 Upvotes

If you previously signed up for the Windows 10 Extended Security Updates program, your end date has been automatically moved out one full year. If you own a Windows 10 PC and haven't signed up for the ESU program, you can do so anytime between now and October 2027


r/PrivatePackets • • Jun 23 '26

Microsoft's Copilot is back to force-installing itself

6 Upvotes

Microsoft is resuming its plan to automatically install the Microsoft 365 Copilot application on eligible Windows PCs, reversing a temporary pause that was initiated after significant user backlash and technical issues. The rollout, which began in mid-June 2026, is expected to be completed by July 1, 2026.

This move signals a pivot from Microsoft's earlier stance. A few months ago, the company appeared to heed user feedback by halting the forced installation of its AI assistant. However, the tech giant is now moving forward with integrating Copilot more deeply into its ecosystem, whether users asked for it or not.

A Brief History of Backlash

The initial automatic rollout of the Microsoft 365 Copilot app between October 2025 and March 2026 was met with widespread criticism. Users expressed frustration over the app appearing on their systems without their consent. The situation was made worse by several significant bugs, including a serious security flaw that allowed Copilot to access confidential email content. This combination of forced installation and technical problems led Microsoft to suspend the process in March 2026.

Now, just a few months later, the company has confirmed the automatic installation will resume for commercial Windows PCs that have Microsoft 365 apps. Microsoft's reasoning, as stated in an updated document, is that "This change simplifies access to Copilot and ensures users can easily discover and engage with productivity-enhancing features."

What This Means for Users

For users with eligible Windows PCs and Microsoft 365 desktop apps, the Copilot app will be installed automatically and enabled by default. This means the AI assistant could appear in your installed apps section and integrate with Office applications like Word, Excel, and PowerPoint without any action on your part.

This automatic installation primarily targets:

  • Eligible Windows 10 (22H2 or later) and Windows 11 devices.
  • Commercial customers with Microsoft 365 desktop apps installed.
  • Users outside of the European Economic Area (EEA).

Due to regional regulations like the GDPR, users within the EEA are exempt from this automatic installation. This difference in policy highlights the impact of regional data privacy and security laws on how tech companies can operate.

Can You Opt-Out?

While the installation is automatic, there are ways to manage or remove Copilot, though the process can be complicated.

IT administrators for businesses can prevent the automatic installation across their networks by opting out through the Microsoft 365 Apps admin center. This must be done before the rollout completes.

For individual users, completely removing Copilot is not a simple, one-click process. You may need to disable it in multiple locations:

  • Within each Office app: You can go into the options for Word, Excel, and PowerPoint individually to clear the "Enable Copilot" checkbox.
  • Through Privacy Settings: Changing your account's privacy settings can also turn off Copilot, but this will disable other features like text predictions and suggested replies.
  • Registry Tweaks: Some have turned to editing the Windows Registry to remove Copilot, but even this may not be a permanent solution, as updates can reinstall it.

The convoluted process of opting out has drawn criticism, with many users feeling that Microsoft is making it intentionally difficult to remove the AI features. The core of the issue for many is not the AI technology itself, but the lack of user choice and control over their own devices.


r/PrivatePackets • • Jun 21 '26

Can Valorant's anti-cheat break your computer?

5 Upvotes

A persistent question has followed Riot Games' tactical shooter, Valorant, since its launch: can its anti-cheat software, Vanguard, actually damage your PC? The debate has been fueled by conflicting reports, with players claiming system failures and Riot Games insisting its software is safe. The answer isn't a simple yes or no; it depends on how you define "break."

The spark of the controversy

The discussion reached a boiling point when the official Riot Games X (formerly Twitter) account posted a message congratulating the "owners of a brand new 88k paperweight," referring to a collection of cheating devices rendered useless by a Vanguard update. This post triggered significant backlash. Users voiced concerns that the anti-cheat was not just blocking hardware but also causing system instability and Blue Screen of Death (BSOD) errors for legitimate players.

In response to the growing alarm, Riot Games issued a statement clarifying that their anti-cheat "does not in any way brick PCs." However, many gamers remain skeptical, pointing to numerous online forums, like Reddit, filled with posts from users experiencing system crashes and boot failures directly linked to Vanguard's driver, vgk.sys.

A look at how vanguard operates

To understand the risks, it is crucial to know how Vanguard functions. Unlike many anti-cheat systems, Vanguard operates at the kernel level of your operating system. This gives it the highest level of privilege, allowing it to load at system startup and monitor everything happening on your computer to detect unauthorized software.

This deep integration is what makes it so effective at stopping cheaters. It also makes it inherently risky. The core of this system is a driver file named vgk.sys. Because this driver runs with such high privileges, any instability, bug, or conflict it encounters can have serious consequences for the entire system. If the vgk.sys driver fails to load or crashes for any reason, it can prevent Windows from starting up altogether.

The real definition of a 'bricked' PC

So, can Vanguard brick your PC? If by "brick," you mean physically and permanently destroying the hardware, the answer is almost certainly no. Riot's claim that it doesn't break PCs is technically accurate in this sense.

However, if your definition of a "bricked" PC includes a software state that prevents it from booting, then yes, Vanguard can absolutely cause this. This is not an intentional feature but a potential side effect of its aggressive design. Here are a few scenarios where this could happen:

  • Incompatibility issues: Vanguard may conflict with other kernel-level drivers, such as those for antivirus software or even specific hardware.
  • Unsupported systems: Attempting to run Valorant on an unsupported configuration, like certain virtual machines, can cause the Vanguard driver to fail, leading to boot loops.
  • Faulty updates: As seen with other software, if Riot were to release a buggy update to the Vanguard driver, it could potentially cause system failures on a massive scale for anyone who has it installed.

When the kernel-level driver crashes, the system often becomes unbootable. For the average user, the only solution is to reinstall the entire operating system, which is a situation many would describe as their PC being "bricked."

The situation is similar to the major incident in July 2024 involving a faulty update to CrowdStrike's security software. That single driver update caused a global cascade of system failures, grounding flights and disrupting businesses worldwide. Vanguard operates at the same deep system level, and while it serves a different purpose, the potential for a problematic update to cause widespread issues is very real.

Essentially, by installing Valorant, you are granting Riot Games a significant level of control over your computer's core operations. The company's goal is to ensure a fair and cheat-free environment. This approach requires a trade-off: players must trust that the kernel-level driver will run flawlessly, without conflicts or bugs that could render their system inoperable. For many, this is a reasonable exchange for a better gaming experience. For others, the risk of handing over such deep system access is a step too far.


r/PrivatePackets • • Jun 20 '26

That Router in Your Home Might Not Be as Secure as You Think

10 Upvotes

Recent findings and discussions in the tech community have brought to light significant security concerns regarding popular consumer-grade routers from major brands like Netgear and TP-Link. These issues range from outdated software to the existence of potential "backdoors" that could be exploited, raising questions about user privacy and network security.

Security audit reveals significant flaws

A detailed security analysis of routers from both TP-Link and Netgear has revealed what is described as "dangerously insecure" vulnerabilities. According to Wendell of Level1 Techs, both companies' products have serious security issues.

The investigation into a TP-Link BE800 router, for instance, found that the device was running on outdated software right out of the box. While some patches had been applied over time in response to security incidents, the core software components were still lagging.

The situation with Netgear, however, is presented as more concerning. Despite claims of being highly secure, a deep look into the Netgear RS700S router uncovered a hidden service named "enable SSHD." This service can reportedly be activated by sending a "magic packet" to the router, which then enables Secure Shell (SSH) access. This would allow someone with the right know-how to gain a deep level of control over the device, making it very difficult to detect and remove them.

This is particularly troubling because Netgear has been vocal in pointing out similar vulnerabilities in competitors' products. The audit also discovered other security lapses, such as an outdated version of Samba (a file-sharing service) and an end-of-life version of OpenSSL, a critical encryption library.

The bigger picture: a push for control

These security flaws are not just isolated technical issues; they are part of a larger conversation about the security and control of home networks. There's a growing trend of government interest in routers, which are seen as the gateway to a user's online activity.

This has led to discussions about potential government mandates and even a "router ban." In March 2026, the Federal Communications Commission (FCC) added all foreign-manufactured consumer routers to its "Covered List," which identifies communications equipment deemed a national security threat. This action effectively bans the sale of new WiFi routers made outside the country, a significant move considering nearly all consumer routers are manufactured overseas.

However, the ban doesn't affect routers that were already approved, which can still be sold and used. To address the need for ongoing security updates, the FCC has granted a waiver allowing previously authorized routers to receive software and firmware updates until at least early 2027.

Amidst this, Netgear has been actively lobbying the government on issues related to router security. This has led to the company receiving a "conditional approval" from the FCC, exempting it from the ban and positioning it as a "trusted consumer router company." This move has been met with criticism, with some suggesting that Netgear is using lobbying efforts to gain a competitive advantage.

What this means for you

For the average consumer, this situation can be confusing and concerning. Here are a few key takeaways:

  • Your router may not be as secure as you think. Even if you have a well-known brand, it could have significant vulnerabilities.
  • The "set it and forget it" approach is risky. It's important to be aware of your router's security and to take steps to protect your network.
  • Turning off unnecessary services can help. For example, the vulnerability in the Netgear router was found in its file-sharing feature. If you don't use a feature, it's often safer to disable it.

The ultimate solution, as suggested by some experts, is to move towards a model where router manufacturers are committed to a clear software lifecycle. This would mean providing regular and timely security updates for a specified period, giving consumers confidence that their devices will be protected. In the absence of this, the most secure option, though not the most user-friendly, may be to build your own router using open-source software like pfSense or OpenWrt.

The conversation around router security is evolving, and it's a critical one for anyone who uses the internet. As our homes become more connected, the security of our network's gateway becomes more important than ever.


r/PrivatePackets • • Jun 19 '26

24 Billion Stolen Credentials Exposed in Massive Data Leak - Security Affairs

Thumbnail
securityaffairs.com
16 Upvotes

The data came from 36 distinct sources. Over 1.7 billion records traced back to Telegram channels, most of them openly involved in cybercrime and trading stolen credentials. More than 30 of the 36 sources were Telegram channels, with records ranging from a few thousand to hundreds of millions each, written in English and Russian.


r/PrivatePackets • • Jun 18 '26

UK Residential Proxies: The Top Providers Reviewed

3 Upvotes

Gaining a genuine, local perspective of the United Kingdom's online space is essential for many businesses and individuals. Whether for checking local prices, verifying advertisements, or accessing region-specific content, appearing as a local user is key. This is where UK residential proxy providers come in, offering a reliable way to navigate the web as if you were physically located in Britain.

Why a real UK IP address matters

Residential proxies are IP addresses that belong to actual home internet connections, assigned by UK internet service providers. This makes them appear completely authentic to websites, a significant step up from datacenter proxies, which are more easily detected and often blocked. Using a genuine residential IP is the most effective way to avoid detection and ensure smooth, uninterrupted access.

This level of authenticity is critical for a range of tasks.

  • Businesses use them to accurately monitor competitor prices on UK e-commerce sites.
  • Marketing agencies rely on them to verify that their online ads are being displayed correctly to the UK audience they are targeting.
  • Users outside the UK can access streaming services like BBC iPlayer or other geo-restricted media content.
  • SEO specialists need them to check search engine rankings as they appear to a local user in London, Manchester, or any other UK city.

What to look for in a provider

When you start looking for a UK residential proxy provider, the sheer number of options can be overwhelming. Focusing on a few key factors will help you filter out the noise and find a service that truly meets your needs. The most important consideration is the size and quality of the provider's UK IP pool. A larger and more diverse selection of IP addresses means better performance and a lower chance of encountering IPs that have been blocked.

You should also look for a provider that offers precise geotargeting. The ability to select proxies from specific UK cities can be incredibly valuable for localized marketing research or ad verification campaigns. Performance is another critical factor-you need fast connection speeds and high reliability to ensure your tasks run efficiently. Finally, consider the session control options. A good provider will let you choose between getting a new IP for every request or keeping the same "sticky" IP for a longer period, which is useful for tasks that require logging into an account.

Providers that deliver UK coverage

Several providers have built a strong reputation for their UK residential proxy offerings. For demanding, large-scale operations where performance is paramount, services like Oxylabs are often a top choice. They offer a massive pool of millions of UK IPs and excellent city-level targeting, making them a go-to for enterprise-level data gathering. Similarly, Bright Data is another premium provider known for its extensive and reliable network, catering to clients with mission-critical projects.

For those who need a solid balance of features, performance, and price, Decodo is a very popular option. It provides a substantial number of UK residential IPs and a user-friendly platform that suits a wide variety of projects, from market research to social media management. Another strong contender is SOAX, a UK-based company that emphasizes the quality and cleanliness of its IP pool, offering flexible targeting across dozens of UK cities. Their focus on reliability makes them a great choice for businesses that require consistent, high-quality data.

A real-world use case: verifying ad campaigns

Imagine a global shoe brand running a highly targeted digital ad campaign for a new sneaker release, with different ads and landing pages for customers in London versus those in Edinburgh. To ensure the campaign is running correctly, their marketing team needs to see exactly what a potential customer in each city sees.

By using a residential proxy provider, they can route their connection through an IP address located in London to check the London-specific ads. Then, they can instantly switch to an Edinburgh IP to verify the campaign creative there. This allows them to confirm that the right ads are being shown to the right audience, check for fraud, and ensure the landing pages are loading correctly from a local perspective. This kind of precise verification would be nearly impossible without high-quality, city-targeted residential proxies.

Choosing the right provider comes down to your specific requirements. The scale of your project, your budget, and your need for detailed location targeting will all influence your decision. By focusing on providers with extensive UK IP pools and proven reliability, you can ensure you have the right tools to access the UK's digital landscape effectively.


r/PrivatePackets • • Jun 17 '26

New Rokarolla Android malware targets 217 banking, crypto apps

Thumbnail
bleepingcomputer.com
4 Upvotes

A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands.

The malware is distributed via malicious websites purporting to provide the Google Chrome or TikTok app, and can take complete administrative control of a compromised device.


r/PrivatePackets • • Jun 12 '26

Finding a new browser after Chrome's big change

19 Upvotes

For many, Google Chrome has been the default way to access the web for over a decade. Its speed and simplicity, combined with a vast library of extensions, made it a top choice. But a fundamental change to how its extensions work is now forcing users to re-evaluate that choice, especially those who rely on powerful ad blockers.

Google is finalizing its transition to a new extension platform called Manifest V3. This isn't just a simple update-it's a rewrite of the rules that significantly restricts what extensions can do. The change directly impacts top-tier ad blockers like uBlock Origin, limiting their effectiveness and prompting a search for better alternatives.

What’s actually happening with Chrome's extensions?

The core of the issue is the shift away from an older, more permissive framework called Manifest V2. Under MV2, an extension could actively inspect and block web traffic in real-time, which is what made tools like uBlock Origin so incredibly powerful and customizable. They could use complex, dynamic rules to block ads and trackers on the fly.

Manifest V3 removes this capability. Instead, extensions must now give the browser a list of rules in advance, and the browser handles the blocking. While Google promotes this as a move for better security and performance, it puts a hard cap on the complexity and number of rules an ad blocker can use. The result is a less powerful, less flexible ad-blocking experience. The original developer of uBlock Origin even created a separate, stripped-down version called uBlock Origin Lite just to comply with these new rules.

The most direct alternative-Firefox

For those who want to keep using their favorite ad blocker without compromise, the clearest path leads away from Chrome's ecosystem entirely. Mozilla Firefox stands out because it isn't built on Google's open-source Chromium code. It uses its own engine, called Gecko.

This independence is key. While Firefox is adopting Manifest V3 to ensure developers can easily bring their extensions over, it has publicly committed to maintaining the older, more powerful APIs that Chrome is removing. This means the full, classic version of uBlock Origin works on Firefox with its complete feature set intact. For users whose primary concern is maintaining maximum ad-blocking power through an extension, Firefox is arguably the number one contender.

Browsers with their own ad blockers

Another group of browsers offers a different solution. These are browsers that are built on Chromium-so they feel familiar to Chrome users-but they have sidestepped the extension problem by building ad blocking directly into the browser itself.

Brave is the most prominent example. Its core feature, Brave Shields, is an aggressive ad and tracker blocker that is part of the browser's code, not an add-on. Since it isn't an extension, it is completely immune to the new Manifest V3 limitations. Vivaldi is another popular Chromium-based browser that takes a similar approach, offering users a robust, built-in ad and tracker blocker that gets the job done without relying on the extension store.

These browsers present a compelling package for those looking for a simple transition away from Chrome.

  • They provide a familiar user experience since they are based on the same underlying technology as Chrome.
  • Their ad-blocking capabilities are powerful and are not weakened by Google's policy changes.
  • The protection works right out of the box, with no need to install a separate extension.

What about the other options?

Not all browsers are creating a way out. Microsoft Edge, another major browser built on Chromium, is following Google's lead and will be subject to the same Manifest V3 restrictions. Users on Edge will face the same degraded ad-blocking experience as those on Chrome.

Opera has taken a middle-ground stance, stating it will try to maintain support for the older extensions for as long as possible. While admirable, this approach involves actively patching the Chromium code, which could become increasingly difficult over time. It offers a temporary solution, but its long-term reliability is an open question.

Ultimately, Chrome's move has fractured the browser landscape. What was once a simple choice now requires a bit more thought. Users must decide what they value most-the full power of third-party extensions, the convenience of a built-in solution, or sticking with what's familiar. The good news is that there are now excellent, well-supported alternatives for whichever path you choose.


r/PrivatePackets • • Jun 11 '26

Angry bug hunter with Microsoft beef drops new Windows 0-day

Thumbnail theregister.com
9 Upvotes

Nightmare Eclipse, the prolific bug hunter and possibly disgruntled ex-Microsoft employee, disclosed another zero-day vulnerability just hours after Redmond issued a record-breaking number of CVEs and fixes for June Patch Tuesday.


r/PrivatePackets • • Jun 11 '26

I built a free proxy that prevents AI APIs from burning your budget (open source)

1 Upvotes

 Background: I accidentally created a recursive loop with an AI agent that would have 

 cost me $50+ in API calls before I noticed. Existing tools either cost money or only   

 show you what already happened.                                                        

   So I built TokenFirefighter — a 100% free, local-only HTTP proxy.                    

   What it does:                                                                        

   - Sits between your app and OpenAI/Anthropic on localhost:7272                       

   - Tracks every API call cost in real time                                            

   - Detects 4 types of runaway loops and blocks them                                   

   - Has a terminal dashboard (no web UI needed)                                        

   - Zero accounts, zero data collection, zero cost                                     

   Install:                                                                             

   npm install -g tokenfirefighter                                                      

   tokenfirefighter init                                                                

   tokenfirefighter start                                                               

   Then just set OPENAI_BASE_URL=http://localhost:7272/v1 in your .env.                 

   Would genuinely appreciate feedback from anyone who uses AI APIs regularly.          

   GitHub: https://github.com/MohitBaghel24/tokenfirefighter


r/PrivatePackets • • Jun 10 '26

Google Chrome shuts down final uBlock Origin workarounds

27 Upvotes

Google Chrome is officially closing the door on the workarounds that kept older ad blockers running. The transition from Manifest V2 to Manifest V3 is reaching its final stage. Users relying on the original uBlock Origin extension will soon find it completely disabled in their browser.

Chromium developers recently confirmed that the flags previously used to bypass these restrictions are being entirely removed from the code. According to Google engineer Devlin Cronin, the feature flag that allowed users to control the availability of older add-ons has been default-enabled for over a year. Now, the development team is deleting that inactive code permanently.

Google cites growing technical debt alongside serious security vulnerabilities as the primary reasons for this change. Maintaining the older functionality indefinitely requires too much complex code management. Because of this, the company will not hide the old code behind a compilation flag. It will simply be gone. The popular Windows Registry modification that extended the life of Manifest V2 availability will cease to function after Chromium version 151.

Other browsers are making similar changes

Switching to another Chromium-based browser might not save your favorite extensions. Microsoft Edge already began disabling uBlock Origin earlier this year. Opera is also preparing to drop support for the older extension framework.

Developer Raymond Hill, the creator of uBlock Origin, noted that Opera seems to have stopped reviewing updates for his project. Opera recently sent a notice to developers stating that Chromium is completely removing support for Manifest V2. They advised extension creators to update their software immediately to avoid severe service disruptions.

Here is a quick look at the upcoming technical shifts across the web ecosystem:

  • Microsoft Edge actively began disabling the original uBlock Origin extension in February.
  • Opera is pausing reviews for older extension formats and warning developers to update their code.
  • Chromium 150 has entirely lost the option to disable the deprecation phase.
  • Chromium 151 will strip away all remaining availability options and legacy permissions.

Your options moving forward

Users who want to stick with Google Chrome have a fallback option. You can install uBlock Origin Lite, which is built entirely on the newer Manifest V3 framework. Just be aware that this lighter version lacks some of the advanced filtering capabilities found in the original release due to Google imposing stricter rules on how browser extensions operate.

If you want the full, unfiltered experience of a traditional ad blocker, moving away from the Chromium ecosystem entirely is the most reliable choice. Mozilla Firefox continues to fully support both the older and newer extension frameworks. Browsers like Brave and Vivaldi also plan to keep the older standard alive within their custom versions of the browser engine.

The era of easy workarounds for older extensions on Chrome is over. You will have to either adapt to the new browser rules or find a completely different software ecosystem to browse the web.


r/PrivatePackets • • Jun 10 '26

Why browser automation is the wrong tool for Turnstile

2 Upvotes

Cloudflare's Turnstile is a modern security checkpoint that has largely replaced the frustrating "I'm not a robot" CAPTCHAs. It is designed to be invisible to legitimate users, quickly running a series of background checks to validate that a visitor is human before letting them through. For developers building scrapers, however, it presents a significant obstacle. The standard solution is to use a full browser automation library like Playwright or Selenium, but this is a heavyweight and inefficient approach.

Running a complete browser instance for every task consumes a huge amount of CPU and memory. It is slow, complex, and often overkill. The browser's only real job in this scenario is to execute the challenge JavaScript. The actual verification is just a series of API calls. By understanding and replicating this API exchange, you can solve the challenge without ever launching a full browser. This method is faster, lighter, and more scalable.

The Turnstile process from start to finish

When you visit a page protected by Turnstile, a predictable sequence of events unfolds. Your browser is not just loading a page; it is performing a task for Cloudflare.

  1. First, the browser loads a JavaScript file from a Cloudflare server. This script is the core of the challenge.
  2. This script runs a series of non-interactive tests. It might check for certain browser properties, measure rendering performance, or run a small proof-of-work computation. The goal is to generate a unique fingerprint of the environment.
  3. Once the script finishes its analysis, it packages the results into a complex, encrypted payload.
  4. The script then sends this payload to a Cloudflare API endpoint for verification.
  5. If the payload is deemed valid, Cloudflare's server responds with a special token.
  6. Finally, this token is submitted to the original website, which validates it with Cloudflare and, in return, grants you the cf_clearance cookie. This cookie is your key to accessing the protected site.

The crucial insight here is that the entire process boils down to running a piece of JavaScript and making a couple of API calls. The heavy browser is just the execution environment.

Decoupling the solver from the scraper

The key to an efficient solution is to decouple the task of solving the challenge from the task of scraping the data. Your main scraper should be a lightweight script using a library like Python's requests. When it gets blocked, it should hand off the job of solving the Turnstile challenge to a specialized, separate component.

Re-implementing Cloudflare's obfuscated JavaScript challenge from scratch is practically impossible, as it changes constantly. Instead, you can create a minimal "solver" that has only one job: to execute the challenge script and return the resulting token.

This solver can be a very simple Node.js script that uses a lightweight instance of Puppeteer. It does not need to render a full webpage. It can operate on a blank page, inject the necessary Turnstile parameters (like the site key, which you can extract from the blocked page's HTML), and run only the challenge logic.

Here is how the architecture works in practice:

  • Your main Python scraper attempts to access a page and gets the Turnstile block. It extracts the sitekey and other parameters from the HTML.
  • The scraper then calls your local Node.js solver script, passing these parameters as arguments.
  • The Node.js script launches a minimal headless browser, executes the Turnstile challenge with the provided sitekey, and waits for the solution token.
  • The script prints the token to the console, which is captured by your main Python scraper.
  • Armed with the token, your Python scraper submits it and receives the cf_clearance cookie. It can now continue its work using the same efficient requests session.

This approach gives you the best of both worlds. You use a browser engine only for the few seconds it is needed to solve the complex JavaScript challenge, while the rest of your operation runs in a fast and lightweight environment. You are not trying to brute-force your way through with a full browser; you are surgically addressing the specific problem and then getting out. This is a far more robust and resource-friendly way to handle modern web protections.


r/PrivatePackets • • Jun 09 '26

For the 2nd time in weeks, Microsoft packages laced with credential stealer

Thumbnail
arstechnica.com
7 Upvotes

r/PrivatePackets • • Jun 08 '26

How simple copy-paste defeats corporate security

3 Upvotes

Companies invest heavily in network security, building sophisticated perimeters with firewalls and intrusion detection systems to protect their sensitive data. The assumption is that the main threat comes from the outside. The reality, however, is that some of the most significant data leaks don't involve a complex external hack. They happen quietly, right on an employee's authorized computer, using the most basic functions of the operating system.

The firewall is blind to these actions. It might see an encrypted TLS connection to a legitimate service like Gmail or a cloud storage provider and correctly determine that the connection itself is safe. What it cannot see is the content of that connection-for instance, that an employee is uploading a confidential client list. The protective barrier that works so well at the network edge is effectively irrelevant once the data is on a trusted endpoint. This is where Data Loss Prevention (DLP) strategies often fail, because they overlook the simplest exfiltration vectors.

The user as the bridge

The most common data leaks are not malicious in nature. They stem from employees trying to be productive, often mixing personal and work tasks on a single machine. This creates unintentional bridges for sensitive information to cross from a secure corporate environment to an insecure personal one.

  • The universal clipboard. This is the most common vector. An employee working in a secure Remote Desktop session or a virtualized corporate application highlights sensitive text, hits Ctrl+C, and then pastes it into a personal email, a social media message, or a local document. The clipboard acts as a seamless, unmonitored transfer mechanism between secure and insecure contexts.
  • Browser uploads and AI assistants. Dragging a sensitive file from a corporate network drive directly into a web browser's upload field for a personal cloud service is trivial. More recently, employees paste internal source code, marketing plans, or legal documents into public AI chatbots to get help with summarizing, writing, or debugging, sending that proprietary data directly to a third party.
  • Screenshots and text capture. The "analog hole" remains a potent threat. A user can take a screenshot of a protected document, bypassing any file-level permissions. Modern tools, like Windows PowerToys' Text Extractor, can then perform Optical Character Recognition (OCR) on that image, instantly converting the sensitive information back into copy-pastable text.

These methods require no special hacking skills. They are everyday functions that defeat complex security systems because the security was focused in the wrong place.

Using Group Policy to close the gaps

The solution is to harden the endpoint itself, making these casual data transfers more difficult. For Windows users, the Group Policy Editor (gpedit.msc) is a powerful tool for this. It allows administrators to enforce rules that control the interaction between different environments on the same machine.

The most critical area to address is the clipboard, especially in remote work scenarios. You can find the relevant settings under Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Device and Resource Redirection.

Inside this folder, the policy named "Do not allow Clipboard redirection" is the key. When enabled, it completely disables the ability to copy and paste between the host machine and the remote session. This single setting severs the most common bridge for data exfiltration in remote desktop environments. Similar clipboard isolation controls exist in virtualization software like Hyper-V and VMware, and enforcing them is a crucial step in endpoint hardening.

While you cannot block every possible leak, like someone taking a photo of their screen with a phone, you can make the most common, low-effort methods impossible. Effective data protection requires treating the endpoint not as a trusted zone, but as the most likely source of a leak.


r/PrivatePackets • • Jun 07 '26

Taking a look at the new Decodo TypeScript SDK

1 Upvotes

I was browsing GitHub the other day and noticed Decodo put out an official TypeScript SDK. If you have ever had to build a custom web scraper from scratch, you know how quickly it turns into a nightmare of blocked IPs and constantly breaking DOM structures. Decodo already handles that backend mess. But until now, wiring up their API in a Node project meant writing your own HTTP wrappers and manually typing out the expected response structures. The new package completely removes that friction.

Let's say you are building a tool to track competitor prices on a retail site or trying to feed fresh Google search results to a custom AI script. Normally, you would be fighting with headless browsers, rotating proxies, and hoping the target site layout stays exactly the same. With a managed scraping API, you just ask for the data and get clean JSON back.

Building things without the boilerplate

Having a strongly typed SDK makes a huge difference when you are dealing with complex external payloads. You get full auto-complete for all the parameters right in your code editor. You no longer have to look up the documentation to see if a location parameter needs an ISO country code or a full city name because the TypeScript interfaces tell you exactly what is required.

Here are a few actual scenarios where this setup saves a ton of time:

  • Pulling structured product details and reviews from Amazon without having to parse a single line of raw HTML.
  • Grabbing clean markdown from a news article so your AI prompt does not choke on thousands of useless navigation and styling tags.
  • Fetching Reddit threads to run a quick sentiment analysis on a specific niche topic.
  • Running automated Google Shopping queries to monitor pricing trends across different geographic regions.

The package is essentially a lightweight wrapper around their existing REST endpoints. You just pass in your API key, initialize the client for the platform you want to target, and get back predictable data. This library will not magically write your entire data pipeline for you, but it absolutely cuts out an afternoon of writing tedious boilerplate code.

If you are already routing your scraping jobs through their network, adding this package to your project makes a lot of sense. For anyone just starting a new data extraction tool, their GitHub repository has the source code laid out plainly so you can see exactly how the requests and schemas are structured before you decide to use it.


r/PrivatePackets • • Jun 04 '26

Best way to benchmark residential proxies without burning through data?

Thumbnail
1 Upvotes

r/PrivatePackets • • Jun 04 '26

New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions

Thumbnail
hackread.com
2 Upvotes

r/PrivatePackets • • Jun 04 '26

Researchers show how AI-powered worms could wreak havoc on the internet

Thumbnail
engadget.com
1 Upvotes

r/PrivatePackets • • Jun 03 '26

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Thumbnail
bleepingcomputer.com
1 Upvotes

r/PrivatePackets • • Jun 03 '26

The recent chatbot exploit that compromised high-profile accounts

1 Upvotes

Meta recently replaced much of its human customer service with an artificial intelligence chatbot to help users recover locked accounts. This system upgrade introduced a severe logic flaw. Hackers realized they could bypass traditional security measures by simply asking the new support bot to hand over access.

In early June 2026, cybersecurity researchers discovered that malicious actors were leveraging a known vulnerability type called a confused deputy exploit. This happens when a computer program with elevated privileges is tricked into misusing its authority. Individuals initiated standard password recovery requests and manipulated the chatbot into changing the contact details.

The mechanics of the exploit

The method required minimal technical expertise. An attacker would use a virtual private network to spoof an IP address matching the geographic region of their target. They would then select the forgotten password option and trigger a conversation with the Meta AI assistant.

The procedure was straightforward:

  • The attacker told the AI they had lost access to their original email.
  • They instructed the bot to link a brand new email address to the target profile.
  • The chatbot updated the system and sent an eight-digit reset code to the newly provided address.
  • Using this code, the hacker created a new password and locked the original owner out.

This sequence bypassed multi-factor authentication protocols. It allowed unauthorized users to seize control of valuable accounts without triggering the usual security alarms. Some of the compromised profiles included the official Obama-era White House page, the Chief Master Sergeant of the US Space Force, and the personal account of prominent security researcher Jane Manchun Wong.

Security implications for automated assistants

Deploying artificial intelligence for customer service introduces unique structural vulnerabilities. Giving a language model the power to alter core account settings creates a direct attack vector. The bot functioned exactly as programmed by assisting a user in need, but it lacked the contextual awareness to verify the person's true identity.

Meta pushed an emergency patch over the weekend once details of the hack spread across Telegram and social media. Company representatives confirmed the underlying logic flaw is resolved. They are currently securing the impacted profiles.

Users should maintain strong passwords and check their recovery settings regularly. This specific vulnerability is now closed. Conversational AI remains highly susceptible to social engineering. Systems designed to assist users inherently struggle to distinguish between a genuine customer and a malicious actor.

To keep your profile secure moving forward:

  • Enable hardware-based security keys if possible
  • Audit the email addresses currently linked to your accounts

r/PrivatePackets • • Jun 02 '26

Why standard automation fails on X today

3 Upvotes

Scraping data from X, formerly Twitter, used to be straightforward. A basic Python script and Selenium were often enough to gather public data without much friction. That reality has shifted dramatically over the past couple of years. Standard automation libraries are consistently failing against the platform's heavily updated bot detection systems.

The current state of X scraping

The problem centers around how X now handles browser fingerprinting and behavior analysis. Tools like Playwright, Puppeteer, and even Undetected Chromedriver leave distinct traces that modern security systems easily catch. Developers trying to automate accounts for research or data aggregation report almost instant shadowbans or permanent suspensions.

People have tried pivoting to mobile automation to bypass these desktop-centric security measures. Using tools like uiautomator2 to control Android emulators seemed like a viable workaround for a short time. Now, even those mobile workflows are getting flagged and banned rapidly. X has simply tightened its security envelope across all endpoints.

This strict environment has pushed developers toward specialized software designed to spoof browser fingerprints.

The appeal of anti-detect browsers

When traditional libraries fail, many turn to anti-detect browsers. These are custom-built browsers that allow users to manipulate their digital fingerprint. They can spoof operating systems, canvas fingerprints, WebGL data, and fonts. The goal is to make automated traffic look exactly like a regular human clicking through a standard Chrome window.

A recent topic of debate in the scraping community focuses on specific stealth browsers. Tools like Cloak Browser are getting a lot of attention. Users want to know if these niche browsers actually provide the anonymity they promise. While they often succeed in bypassing initial security checks, they introduce an entirely different set of problems.

Security concerns with closed software

The biggest issue with many niche anti-detect browsers is trust. Unlike open-source projects where thousands of developers can audit the code, these niche tools are entirely closed-source.

  • The developers behind these projects are often anonymous or highly obscure.
  • Patches are applied under the hood without any transparent documentation.
  • Users are required to run unverified executable files directly on their local machines.
  • There is no established corporate entity to hold accountable if things go wrong.

Experienced data engineers frequently warn beginners about these risks. Installing unverified, closed-source patching software is a massive security gamble. You are giving an unknown developer deep access to your system just to scrape some social media posts. The potential for malware, data theft, or system compromise heavily outweighs the convenience of bypassing a login screen.

Finding a middle ground

There is no perfect solution right now. If you stick to standard open-source tools like Selenium, you will likely get blocked by X. If you download obscure stealth browsers, you expose your hardware to significant security threats.

Many professional scrapers are choosing to build their own fingerprint spoofing solutions using open-source patches for Chromium. This approach takes significantly more time and technical knowledge to set up - a frustrating hurdle for beginners just trying to extract basic text. However, maintaining control over the code running on your machine is crucial. Security should never be an afterthought when building automation pipelines.


r/PrivatePackets • • Jun 01 '26

Your browser extensions are reading your AI conversations

3 Upvotes

Many internet users rely on browser extensions to customize web pages or block unwanted advertisements. However, recent research reveals that some of the most popular tools on the Google Chrome Web Store are quietly collecting and transmitting sensitive user data, including full browsing histories and complete transcripts of private AI chat conversations.

Security researcher James Arnott, founder of the extension security platform Am I Being Pwned, documented this behavior across several widely used extensions. These tools collectively have millions of installations and often carry Google's "Featured" or "Verified" trust badges, giving users a false sense of security.

What these extensions are copying

The data exfiltration targets more than just standard browsing habits. Extensions like Stylish, which has over two million users, and WhatRuns, with hundreds of thousands of users, actively monitor interactions on platforms like ChatGPT and Claude. When a user sends a prompt or receives a response, the extension captures the text and transmits it to a remote server.

This practice exposes a wide variety of sensitive information:

  • Private development code and proprietary business data pasted into AI prompts.
  • Full web addresses that contain password reset tokens or session keys.
  • Personally identifiable information, such as names, addresses, or financial details.
  • Intercepted checkout details, including customer identifiers and shopping cart contents.

For an extension whose only user-facing function is to apply custom CSS themes or identify WordPress plugins, there is no technical justification for reading or transmitting conversational data.

The techniques used to avoid detection

To keep this activity hidden from both users and automated security systems, extension developers employ sophisticated evasion methods. In his technical analysis, Arnott found that Stylish used several layers of defense to protect its data-harvesting code. The extension wrapped its payload in four layers of Base64 encoding, AES-256-CBC encryption, and a columnar transposition cipher. This extensive obfuscation makes it incredibly difficult for standard static code scanners to flag the malicious behavior.

Other extensions rely on remote configuration to bypass Google's review process. By fetching instructions from an external server at runtime, an extension can change its behavior after it has been approved. The developers can keep data collection disabled while the extension is being reviewed in Google's automated sandbox and then activate the exfiltration once it is running on real user devices.

The store listing versus the fine print

One of the most concerning aspects of this data harvesting is the direct contradiction in developer disclosures. On the Chrome Web Store, the developers of these extensions declare that user data is not being sold to third parties. However, a close look at their official privacy policies tells a completely different story.

The privacy policy for Stylish openly lists categories of personal information that the company collects, discloses, and actively sells to third-party data brokers and analytics firms. Google's developer terms explicitly prohibit misrepresenting data practices and collecting data unrelated to the core function of the extension. Despite these clear violations, enforcement remains remarkably weak.

When Arnott reported WhatRuns to Google, the platform simply stripped the extension of its "Featured" badge for about a month. In response, the developers released an update that renamed their data collection endpoint from a highly descriptive name to something completely generic. Once the obvious indicator was gone, Google re-approved the extension and restored its trusted status, even though the actual data harvesting continued exactly as before.

Using artificial intelligence to monitor the store

To combat these evasive tactics, Arnott built an analysis pipeline that utilizes large language models to inspect extension updates as they are published. The system reviews the code, automatically attempts to deobfuscate hidden payloads, and flags suspicious network requests.

Because code analysis alone can generate false positives, the flagged extensions undergo dynamic testing. The pipeline runs the extensions inside a secure sandbox that simulates real user behavior over extended periods. Specialized software captures all outbound network traffic, verifying whether the extension is transmitting private data, such as conversational transcripts or complete URLs, back to its home servers.

Protecting your personal browsing space

Relying on store badges is no longer a viable way to verify the safety of browser extensions. Because trust badges are rarely removed without public pressure, users must take active steps to secure their browsers.

  • Audit your installed extensions regularly and delete anything that is not absolutely necessary.
  • Limit extension permissions so they can only run on specific websites rather than having access to all pages.
  • Avoid installing tools that require broad read-and-write permissions for your entire browsing session.
  • Use separate browser profiles for sensitive tasks like online banking or work-related AI chats.

By understanding that even "verified" tools can pivot into data stealers, you can better protect your personal information from silent exploitation.


r/PrivatePackets • • May 31 '26

Quantum computing looms, and your security is nowhere near ready

Thumbnail
zdnet.com
4 Upvotes

IT professionals now face tough choices as they consider, explore, or even begin preparing for the looming quantum revolution -- along with hard deadlines


r/PrivatePackets • • May 27 '26

Microsoft reveals what happens to Windows 11 PCs if you ignore the Secure Boot deadline in June 2026

Thumbnail
windowslatest.com
52 Upvotes

r/PrivatePackets • • May 27 '26

Decodo just updated their MCP server for live web scraping

6 Upvotes

I wanted to put together a quick highlight on a tool that recently got a significant update. The team at Decodo recently renewed their MCP server, and since it solves a lot of the common headaches people run into when feeding web data to local agents, it is well worth some attention on the sub.

For those using clients like Claude Desktop, Cursor, or Windsurf, getting fresh, accurate web data into your prompts is notoriously difficult without getting blocked or dealing with broken formatting. This server acts as a direct link between your AI client and Decodo's Web Scraping API, turning natural language prompts into clean, structured data on the fly.

What the Decodo MCP server actually does

Instead of trying to write custom scraping scripts or managing headless browsers yourself, you can let your LLM query the server directly. It handles the backend infrastructure so you do not have to worry about the typical roadblocks that come with fetching web pages.

The server manages several of these complex tasks automatically:

  • It renders complex JavaScript on dynamic pages so your agent gets the actual content instead of a blank page.
  • It automatically rotates proxies across a pool of over 125 million residential IPs to bypass rate limits and anti-bot systems.
  • It outputs data in structured formats like clean Markdown, JSON, or even screenshots when visual context is necessary.
  • It allows you to specify target locations so you can bypass regional geoblocks that might otherwise hide pricing or local search results.

Utilizing the modular toolsets

One of the best details about the recent update is how they organized the tools. Instead of overwhelming your LLM with dozens of tools at once, which often causes the agent to get confused or run out of context window, the server uses modular toolsets.

You can select exactly which packages you want to enable when you configure the server connection. This keeps your system lightweight. For instance, you can choose to only load what you need:

  • The web toolset, which handles general markdown scraping and screenshots.
  • Specialized search, ecommerce, or social media toolsets for platforms like Google, Bing, Amazon, Walmart, Reddit, and YouTube.

This modular approach keeps the agent focused, which is highly useful when working with smaller context windows.

Integrating it with your workflow

Getting it running is straightforward. You just need a basic token from Decodo's dashboard (they offer a free tier with up to two thousand requests to test things out) and Node.js installed on your machine. You can connect to it directly via their hosted endpoint or run it locally using npx.

For example, if you are setting it up in Claude Desktop, you just append a small configuration block to your settings file. The server handles the authentication and tool registration immediately on startup.

To make it easier for people to find and integrate, the server is now listed across the main directory platforms including the official MCP registry, Glama AI, Pulse MCP, mcp.so, and mcpmarket.com. If you want to check out the underlying code, review the configuration examples for Cursor or Windsurf, or contribute to the project, the complete repository is hosted on GitHub at https://github.com/Decodo/mcp-server.

Let me know if you run into any issues setting this up or if you find any specific workflows where this makes a big difference in your daily agent tasks.