Security News

URL rendering trick enabled WhatsApp, Signal, iMessage phishing
2022-03-25 15:51

A rendering technique affecting the world's leading messaging and email platforms, including Instagram, iMessage, WhatsApp, Signal, and Facebook Messenger, allowed threat actors to create legitimate-looking phishing messages for the past three years. The vulnerabilities are rendering bugs resulting in the apps' interface incorrectly displaying URLs with injected RTLO Unicode control characters, making the user vulnerable to URI spoofing attacks.

Here's How to Find if WhatsApp Web Code on Your Browser Has Been Hacked
2022-03-12 22:09

Meta Platforms' WhatsApp and Cloudflare have banded together for a new initiative called Code Verify to validate the authenticity of the messaging service's web app on desktop computers. Available in the form of a Chrome and Edge browser extension, the open-source add-on is designed to "Automatically verif[y] the authenticity of the WhatsApp Web code being served to your browser," Facebook said in a statement.

WhatsApp emits extension to detect tampering with desktop web apps
2022-03-10 21:04

WhatsApp and Cloudflare have teamed up to provide desktop users of WhatsApp's web client with a browser extension called Code Verify that checks the integrity of the software running in their browser. The Meta-owned biz would like to add more security to its web client, because web security differs from native app security and WhatsApp is seeing more web usage.

RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!
2022-03-01 21:44

WhatsApp and BlueJeans are just two of the world's most popular communication apps that are using an open-source library riddled with newfound security holes. On Monday, devops platform provider JFrog Security disclosed five memory-corruption vulnerabilities in PJSIP, which supplies an API that can be used by IP telephony applications such as voice-over-IP phones and conference apps.

Signal CEO Resigns, WhatsApp Co-Founder Takes Over as Interim CEO
2022-01-13 22:41

Moxie Marlinspike, the founder of the popular encrypted instant messaging service Signal, has announced that he is stepping down as the chief executive of the non-profit in a move that has been underway over the last few months. "In other words, after a decade or more, it's difficult to overstate how important Signal is to me, but I now feel very comfortable replacing myself as CEO based on the team we have, and also believe that it is an important step for expanding on Signal's success," Marlinspike said in a blog post on Monday.

Signal CEO Moxie Marlinspike resigns, leaves WhatsApp co-founder to run things until a successor is named
2022-01-11 01:02

Moxie Marlinspike, the creator of the Signal secure messaging app, on Monday announced his resignation as CEO of the company. Marlinspike said he had always intended to grow Signal to the point that it could go on without his direct involvement but that wasn't possible as recently as four years ago when he was writing most of the code, managing employees, and personally handling support.

Meta Sues Hackers Behind Facebook, WhatsApp and Instagram Phishing Attacks
2021-12-20 23:20

Facebook's parent company Meta Platforms on Monday said it has filed a federal lawsuit in the U.S. state of California against bad actors who operated more than 39,000 phishing websites that impersonated its digital properties to mislead unsuspecting users into divulging their login credentials. The attacks were carried out using a relay service, Ngrok, that redirected internet traffic to the phishing websites in a manner that concealed the true location of the fraudulent infrastructure.

WhatsApp adds default disappearing messages for new chats
2021-12-06 16:17

WhatsApp announced today that it had expanded the privacy control features with the addition of default disappearing messages for all newly initiated chats. Today, with the launch of default disappearing messages, the company also added two new durations that allow setting up messages to disappear after 24 hours or 90 days.

NSO fails once again to claim foreign sovereign immunity in WhatsApp spying lawsuit
2021-11-09 00:53

Spyware maker NSO Group cannot use its government clients to shield itself from litigation, a US appeals court ruled on Monday, a decision that allows WhatsApp's lawsuit against the Israel-based firm to resume. In 2019, Facebook and its WhatsApp subsidiary sued NSO claiming the firm's intrusion software, known as Pegasus, was used to unlawfully compromise the accounts of WhatsApp customers.

Matrix for the masses platform Element One goes live: $5 a month with WhatsApp, Signal, Telegram bridges
2021-10-26 11:41

Element, which makes Matrix-based communications and collaboration tools, has launched a consumer-oriented version of its messaging platform, complete with bridges for WhatsApp, Signal and Telegram. Over the months it has introduced supported bridging tech to allow enterprise users to message users on other platforms such as Slack, Teams and WhatsApp.