5 Oct
2026
5 Oct
'26
7:36 p.m.
Hello Tor relay operators,
We encourage relay operators running Linux to audit their tor configuration file (torrc) and monitor for unauthorized kernel module loading, tunnelling interfaces or unexplained memory usage. (…) Hello, thanks for monitoring and the warning.
Seems clean here, but is there any pattern in how the actor gains access to the systems? A single campaign usually exploits one vulnerability nowadays. Or does it seem somebody is indeed meticulously work out each node one by one? Cheers, mpan