:

SURFSHARK VPN CONFIRMS HACKER BREACH OF TEST SERVERS

SECURITY DESK1 MIN READ
THU, SEP 10, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Surfshark disclosed that hackers accessed internal testing and proxy servers following a configuration error that exposed systems to the internet. The VPN provider is investigating the scope of the breach.

Surfshark revealed the security incident after discovering that one of its internal test servers was misconfigured, leaving it publicly accessible. Hackers exploited this vulnerability to gain unauthorized access to testing infrastructure and proxy servers. The company stated it is conducting a full investigation to determine what data, if any, was compromised. Surfshark said it has since secured the affected systems and corrected the configuration error. This marks another significant security incident in the VPN industry, where misconfigurations and breaches have become recurring issues. Users of the service have not been confirmed to be directly affected, but the company has urged customers to review their account security. Surfshark has committed to providing updates as the investigation progresses. The incident underscores ongoing challenges in infrastructure security and the importance of proper access controls for testing environments.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Trezor alerted customers Wednesday that attackers exploited a breach at its third-party email provider to launch phishing campaigns. The cryptocurrency hardware wallet maker urged users to remain vigilant against fraudulent communications.

3H AGOAI Desk

Forgejo, a self-hosted Git service, released version 16.0.4 to address a critical remote code execution vulnerability affecting all versions up to 16.0.3. Users should upgrade immediately.

4H AGOIndustry Desk

Microsoft's September 2026 security patches are disabling Remote Desktop Services across Windows Server 2019, 2022, and 2025, leaving administrators unable to access systems and requiring hard resets in some cases.

4H AGOIndustry Desk

Google has enabled Android users to securely migrate login credentials between password managers. The feature is currently available in a limited number of apps, with broader support expected soon.

5H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.