Security News

Terrifying bug in WhatsApp allows hackers to steal files. So get patching all nine of you using it on the desktop
2020-02-05 23:56

A vulnerability in WhatsApp could be exploited to remotely access a victim's files on their computer - if they use the desktop client paired with the iPhone app. The security bug was fixed in January by Facebook in WhatsApp Desktop version 0.3.9309 and later.

WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
2020-02-05 16:50

Security researchers have identified a JavaScript vulnerability in the WhatsApp desktop platform that could allow cybercriminals to spread malware, phishing or ransomware campaigns through notification messages that appear completely normal to unsuspecting users. "Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."

Vulnerability in WhatsApp Desktop Exposed User Files
2020-02-05 15:34

The vulnerability was discovered by PerimeterX security researcher Gal Weizman, who said he found multiple issues in WhatsApp Desktop, starting with an open redirect into persistent XSS and Content Security Policy bypass, and then a "Cross platforms read from the local file system." One of the main issues Weizman identified was that an attacker could modify WhatsApp reply messages to include quotes of messages the recipient never sent.

This WhatsApp Bug Could Have Let Attackers Access Files On Your PCs
2020-02-04 20:22

When combined together, the reported issues could have even enabled hackers to remotely steal files from the Windows or Mac computer of a victim using the WhatsApp desktop app by merely sending a specially crafted message. In a blog post published today, Weizman revealed that WhatsApp Web was vulnerable to a potentially dangerous open-redirect flaw that led to persistent cross-site scripting attacks, which could have been triggered by sending a specially crafted message to the targeted WhatsApp users.

This WhatsApp Bug Could Have Let Attackers Access Files On Your PCs
2020-02-04 12:22

When combined together, the reported issues could have even enabled hackers to remotely steal files from the Windows or Mac computer of a victim using the WhatsApp desktop app by merely sending a specially crafted message. In a blog post published today, Weizman revealed that WhatsApp Web was vulnerable to a potentially dangerous open-redirect flaw that led to persistent cross-site scripting attacks, which could have been triggered by sending a specially crafted message to the targeted WhatsApp users.

Bezos, WhatsApp Cyberattacks Show Growing Mobile Sophistication
2020-01-30 18:03

Beyond these high-profile instances, various journalists and human rights activists have been targeted globally after a WhatsApp zero-day vulnerability was exploited by attackers who were able to inject spyware onto victims' phones. Vanunu, head of products vulnerability research at Check Point research, has seen his share of WhatsApp vulnerabilities - the researcher at Black Hat 2019 demoed several flaws in the messaging platform could be used to manipulate chats, for instance.

Saudi Prince Allegedly Hacked World's Richest Man Jeff Bezos Using WhatsApp
2020-01-22 05:30

The iPhone of Amazon founder Jeff Bezos, the world's richest man, was reportedly hacked in May 2018 after receiving a WhatsApp message from the personal account of Saudi crown prince Mohammed bin Salman, the Guardian newspaper revealed today. The mysterious file was sent when crown prince Salman and Bezos were having a friendly WhatsApp conversation, and it's 'highly probable' that it exploited an undisclosed zero-day vulnerability of WhatsApp messenger to install malware on Bezos's iPhone.

Crown Prince of Saudi Arabia accused of hacking Jeff Bezos' phone with malware-laden WhatsApp message
2020-01-22 00:31

Candid pictures used to threaten Amazon boss Jeff Bezos were exposed not by his current paramour's brother, as some believe, but through a sophisticated hacking operation personally directed by the crown prince of Saudi Arabia, Mohammad bin Salman, The Guardian suggests. The paper today claims to have been told by anonymous sources that Bezos' phone was hacked using a WhatsApp message from the personal account of bin Salman himself.

What's that? Encryption's OK now? UK politicos Brexit from Whatsapp to Signal
2019-12-20 14:00

Take a break from calling for the end of e2e, so they can switch encrypted chat apps It's not just the European Union the UK's ruling party wishes to leave. According to the Guardian, the recently...

Vulnerability in WhatsApp Allows Attackers to Crash Group Chats
2019-12-17 14:40

WhatsApp's end-to-end encryption is only secure if you don't have the encryption keys. But researchers at Check Point Research developed a method of discovering the encryption keys, a produced a...