Security News

Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle
2020-11-17 23:22

Israeli spyware maker NSO Group has taken a leaf out of Hollywood in an attempt to avoid any legal repercussions from making and selling tools that hack WhatsApp users' phones. When NSO failed to turn up in court in the US state, Facebook claimed victory; and NSO accused it of lying and having failed to serve the legal documents.

Chap beats rap in WhatsApp zap flap: Russian banker walks from insider trading case after deleting software
2020-10-01 06:53

Konstantin Vishnyak, 42, was cleared by Southwark Crown Court in London, England, of destroying documents relevant to a now-discontinued investigation into insider trading. It was reported that Vishnyak, formerly of VTB Capital, deleted the app and messages from his iPhone - one of two handsets he gave to police - not out of fear of an investigation into insider trading, but rather in an effort to conceal his friendship with Andrei Lugovoi, the Russian politician wanted in connection with the polonium poisoning of Alexander Litvinenko in 2006.

Android Spyware Variant Snoops on WhatsApp, Telegram Messages
2020-09-30 19:14

Researchers say they have uncovered a new Android spyware variant with an updated command-and-control communication strategy and extended surveillance capabilities that snoops on social media apps WhatsApp and Telegram. APT-C-23 is known to utilize both Windows and Android components, and has previously targeted victims in the Middle East with apps in order to compromise Android smartphones.

WhatsApp Discloses 6 Bugs via Dedicated Security Site
2020-09-04 13:08

Facebook-owned WhatsApp has fixed six previously undisclosed vulnerabilities in its chat platform, revealing the move on a new dedicated security advisory site aimed at informing its more than 2 million users about bugs and keeping them updated on app security. The site is part of an effort by WhatsApp to be more transparent about platform vulnerabilities to not just users, but also the security community, and patch them in a timely manner.

Charming Kitten Returns with WhatsApp, LinkedIn Effort
2020-08-31 18:46

The Iran-affiliated APT known as Charming Kitten is back with a new approach, impersonating Persian-speaking journalists via WhatsApp and LinkedIn, in order to con victims into opening malicious links. To lend verisimilitude to their impersonations, the cybercriminals also set up fake LinkedIn profiles corresponding to the journalists' names, and have been sending out LinkedIn messages to corner victims as well.

Iranian Hackers Target Academic Researcher via WhatsApp, LinkedIn
2020-08-28 12:16

The hackers used a personalized URL, tailored to the victim's email address, to trick them into accessing the malicious link, and also attempted to send a malicious ZIP file to the victim. "Clearsky alerted 'Deutsche Welle' about the impersonation and the watering hole in their website. A 'Deutsche Welle' representative confirmed that the reporter which Charming Kitten impersonated, did not send any emails to the victim nor any other academic researcher in Israel in the past few weeks," the security firm says.

Facebook’s NSO Group Lawsuit Over WhatsApp Spying Set to Proceed
2020-07-20 17:24

Facebook's lawsuit against NSO Group over alleged spying on WhatsApp users will be allowed to go forward. WhatsApp-owner Facebook is alleging that NSO Group exploited a vulnerability in WhatsApp to deploy its spyware against human rights activists, journalists and political dissidents.

Judge green-lights Facebook, WhatsApp hacking lawsuit against spyware biz NSO, unleashing Zuck's lawyers
2020-07-17 19:27

Facebook won a significant legal victory on Thursday when the judge hearing the lawsuit against Israeli spyware maker NSO Group declined to dismiss the case - and allowed the crucial discovery process to move forward. Last October, Facebook and its WhatsApp subsidiary sued NSO Group, and its Q Cyber Technologies affiliate, in the Northern District of California.

Whatsapp blamed own users for failure to keep phone number repo off Google searches
2020-06-12 21:02

An infosec researcher reckons Whatsapp was a bit too quick off the mark to blame its users when hundreds of thousands of phone numbers, names and profile pictures were found to be easily accessible via Google. Athul Jayaram, a self-described "Full time bug bounty hunter", published a blog post earlier this week highlighting that a large number of Whatsapp users' mobile numbers could easily be found by searching Google for the domain "Wa.me".

WhatsApp Phone Numbers Pop Up in Google Search Results — But is it a Bug?
2020-06-05 16:01

UPDATE. A researcher is warning that a WhatsApp feature called "Click to Chat" puts users' mobile phone numbers at risk - by allowing Google Search to index them for anyone to find. The phone numbers are revealed as part of a URL string and so, this in effect "Leaks" the mobile phone numbers of WhatsApp users in plaintext, according to the researcher's view.