INTEL_REPORT
Ars Technica — Security · published 5/27/2026, 8:56:03 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Websites have a new way to spy on visitors: Analyzing their SSD activity Telltale SSD activity can be measured in the browser using simple JavaScript. Over the decades, there has been no shortage of sites using clever techniques to covertly track visitors’ browsing histories , device fingerprints , and keystrokes and mouse movements in real time. Even Meta and Yandex were recently caught joining in the privacy-invasive free-for-all . Now sites have a new way to spy on their…
https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity
sha256:1f0752db6cef590252b3aec8714260994893ed6ebe519fa8ed9dde4dd594bb41
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.