Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
2026-04-11T13:24:15Z•9cca7dd0b5a855167dd4e0c1832654692c6213c307bbc5bbcd0f53d4c7939d64
AI-extensionsAPT28Adobe Reader zero-dayAndroid sandbox bypassCVE-2026-39987Chrome DBSCEngageLab SDKGlassWormIDE compromiseLucidRookMarimoOpen VSXPRISMEXSmart Slider 3 ProUAT-10362Zig dropperbrowser-extensionscobwebsdevice-bound session credentialsgeolocationpenlinkrouter-exploitation (MikroTik/TP-Link)supply-chain-compromisesurveillancewebloc
What happened
A broad set of active threats and vulnerabilities was reported: law‑enforcement and police agencies used an advertising-based global geolocation surveillance system (Webloc) developed by Cobwebs/Penlink; developer tooling and extension supply chains are being abused (GlassWorm using a new Zig dropper in a malicious Open VSX extension, 1,700 malicious packages across npm/PyPI/Go/Rust, and a backdoored Smart Slider 3 Pro update via compromised Nextend servers); and browser/AI extension risk is identified as a major blind spot. Multiple high‑impact vulnerabilities are being actively exploited in‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9cca7dd0b5a855167dd4e0c1832654692c6213c307bbc5bbcd0f53d4c7939d64
- Enrichment time
- 2026-04-11T13:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.