Security News

Telegram 'Secret Chat' didn't delete self-destructing media files
2021-02-12 19:57

Telegram has fixed a security issue where self-destructing audio and video files were not being deleted from user's macOS devices as expected. Telegram offers a 'Secret Chat' mode that offers increased privacy than the standard chats.

Secret Chat in Telegram Left Self-Destructing Media Files On Devices
2021-02-12 02:18

Popular messaging app Telegram fixed a privacy-defeating bug in its macOS app that made it possible to access self-destructing audio and video messages long after they disappeared from secret chats. Unlike Signal or WhatsApp, conversations on Telegram by default are not end-to-end encrypted, unless users explicitly opt to enable a device-specific feature called "Secret chat," which keeps data encrypted even on Telegram servers.

Bugs in Signal, other video chat apps allowed attackers to listen in on users
2021-01-21 11:28

Bugs in several messaging/video chat mobile apps allowed attackers to spy on targeted users's surroundings. The vulnerabilities - in Signal, Google Duo, Facebook Messenger, JioChat, and Mocha - could be triggered by simply placing a call to the target's device - no other action was needed.

Google Research Pinpoints Security Soft Spot in Multiple Chat Platforms
2021-01-20 15:21

Google Project Zero researcher Natalie Silvanovich outlined what she believes is a common theme when it comes to serious vulnerabilities impacting leading chat platforms. The research, published Tuesday, identifies a common denominator within chat platforms, called "Calling state machine", which acts as a type of dial tone for messenger applications.

Bugs in Signal, Facebook, Google chat apps let attackers spy on users
2021-01-19 16:45

Vulnerabilities found in multiple video conferencing mobile applications allowed attackers to listen to users' surroundings without permission before the person on the other end picked up the calls. The logic bugs were found by Google Project Zero security researcher Natalie Silvanovich in the Signal, Google Duo, Facebook Messenger, JioChat, and Mocha messaging apps and are now all fixed.

FBI Warns of Employee Credential Phishing via Phone, Chat
2021-01-18 19:21

The Federal Bureau of Investigation has issued a Private Industry Notification to warn of attacks targeting enterprises, in which threat actors attempt to obtain employee credentials through vishing or chat rooms. An observed shift in tactics, the FBI says, is the targeting of all employee credentials, not exclusively of those individuals who might have higher access and privileges based on their corporate position.

Signal boost: Secure chat app is wobbly at the moment. Not surprising after gaining 30m+ users in a week, though
2021-01-15 19:30

Signal is experiencing a partial outage as tens of millions of netizens flood the free secure messaging service. Those technical difficulties come as at least 30 million people joined the non-profit end-to-end encrypted communications platform in a matter of days this week.

S3 Ep13: A chat with hacker Keren Elazari [Podcast]
2020-12-31 17:13

Latest episode - listen now!

S3 Ep12: A chat with social engineering hacker Rachel Tobac [Podcast]
2020-12-24 12:25

How do you go from neuroscientist to DEFCON Social Engineering Capture the Flag champ? Find out from hacker and social engineering expert Rachel Tobac! Join us for a fascinating interview with Rachel about her journey, why you should always be "Politely paranoid", and the people who inspired her along the way.

Android chat app with 100 million installs exposes private messages
2020-11-19 10:12

GO SMS Pro, an Android instant messaging application with over 100 million installs, is publicly exposing private multimedia files shared between its users. By abusing a flaw in the app, unauthenticated attackers can gain access to private voice messages, videos, and photos shared by GO SMS Pro users as Trustwave security researchers discovered three months ago.