10 Sep Signal Pours Cold Water On Zero-day Exploit Rumors
On an individual level, there are several guidelines anyone can follow to reduce their exposure when using messaging apps. The first is to treat phone numbers and codes received via SMS as sensitive credentials that should never be shared , even if the person requesting them appears to be a friend, a technician, or the app itself. This memory corruption can trigger a Use-After-Free (UAF) vulnerability, causing the imagent process to crash. However, sophisticated attackers could potentially leverage this corruption as a primitive for achieving code execution on targeted devices. Researchers demonstrate how attackers can craft malicious files disguised as legitimate content to achieve remote code execution.
Cyber Security Guide
That incident demonstrated how messaging apps could be compromised at the development level, leading to widespread security breaches. All the rules can be used across dozens of SIEM, EDR, and Data Lake platforms and are aligned with MITRE ATT&CK®. Additionally, each rule is enriched with CTI links, attack timelines, audit configurations, triage recommendations, and more extensive metadata. Reports suggest two separate intrusions occurred within a short timeframe, both believed to have exploited the same underlying weakness. The attacks resulted in the compromise of archived message data, including plaintext messages, metadata, sender/recipient information, group names, and timestamps.
- The good news for people who use Apple phones is that iMessage and FaceTime are also already end-to-end encrypted, says Hong.
- Each platform served a unique audience, but all became prime targets for cybercriminals due to their scale and sensitivity of stored data.
- In early 2019, a bug in group FaceTime calls would have let attackers activate the microphone, and even the camera, of the iPhone they were calling and eavesdrop before the recipient did anything at all.
- This vulnerability was particularly alarming in hands-free scenarios, such as driving, where users depend on voice interaction with Gemini.
Silvanovich has spent years studying “interaction-less” vulnerabilities, hacks that don’t require their targets to click a malicious link, download an attachment, enter a password in the wrong place, or participate in any way. Those attacks have taken on increasing significance as targeted mobile surveillance explodes around the world. It’s a good idea to review the privacy settings of each app to limit who can see your profile picture, description, last seen time, or public profile. The less information that’s publicly available, the harder it will be for an attacker to create a convincing scam or link your number to other leaked data. Using them to process information subject to these regulations is a gamble that, sooner or later, an inspection or incident will reveal the non-compliance. In organizations like the Balearic Islands Health Service , instant messaging has become an essential tool for rapid communication between professionals, but that doesn’t mean you can use just any app you have on your personal phone.
GreyNoise telemetry reveals that 2,009 IP addresses have scanned for Spring Boot Actuator endpoints within the past 90 days. The security firm created a dedicated tracking tag on July 10 to monitor these exploitation attempts. Discover in a quick call how Wire enables secure, compliant, and seamless collaboration for your organization, without compromising on usability or control.
The encryption itself remains intact, but the attacker is now a legitimate participant in the chat. This is the equivalent of someone slipping into a secure boardroom meeting by stealing a badge, no need to crack the safe when the door is open. The encrypted messaging platform Signal has vehemently denied accusations of vulnerabilities within its system, following a Pentagon advisory cautioning against its use.
Cyprus Airways Data Breach: Hackers Claim Access To Real-time Systems And Passenger Records
Panda Security specializes in the development of endpoint security products and is part of the WatchGuard portfolio of IT security solutions. Initially focused on the development of antivirus software, the company has since expanded its line of business to advanced cyber-security services with technology for preventing cyber-crime. Operators can deploy content filtering and AI-driven anomaly detection to flag phishing attempts. However, end-user awareness campaigns remain critical, as smishing often bypasses technical defenses.
The simplest way to ensure your messages are safe from snooping is to use an end-to-end encrypted app like Signal or WhatsApp, says Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation (EFF). With these apps, “your communications are end-to-end encrypted every single time,” she says. Despite being more than 30 years old, SMS (Short Message Service) is still one of the most widely used communication tools in the world.
Billions of messages are sent every day for personal conversations, business notifications, and authentication codes. These platforms handle critical activities including social interactions, financial transactions, and business communications for billions of users globally, making successful attacks particularly devastating. The attack, detailed in recent research by cybersecurity firm DARKNAVY, exploits WeChat’s built-in browser components and URL parsing mechanisms to execute remote code without requiring any user interaction beyond receiving the message. The vulnerability that affected some customers of Metro Bank has to do with the protocol, or set of rules, that telecommunications companies use to pass calls and SMS messages from one phone network to another. The protocol, called Signaling System 7, or SS7, was first developed in 1975, and wasn’t designed for user authentication.
Signal’s security flaw was patched in September 2019, and the rest of the messaging apps were fixed more recently in the second half of 2020. The Project Zero researcher also looked at other popular messaging apps such as Telegram and Viber, but she could not find these particular security flaws. She looked at Telegram in August 2020, and Viber was investigated in November last year. Back in November 2018, https://mantelligence.com/secretmeet-review-how-it-works-in-practice/ the very same researcher brought to daylight a similar loophole in WhatsApp – it was affecting not only Android users, but the security flaw was observed on Apple devices too. For communications, marketing, and PR professionals, these technical flaws translate into operational risks. Confidential media strategies, embargoed press releases, and crisis response plans often flow through encrypted messaging apps.
However, hackers have learned how, using a computer running the Linux operating system and open-source software for writing code that interacts with SS7, to intercept SMS messages intended for others. Armed with a SMS verification code sent out by a bank and the target’s username and password, a hacker could log into a victim’s account in order to transfer money to themselves. Even so, in addition to usernames and passwords, many banks and other companies rely on SMS as an additional layer of security for 2FA. In order to help verify that a user is who they say they are, the company sends a text message with a single-use additional passcode. The user then has to enter the passcode the company sent by SMS, in addition to their usual password, to prove their identity. However, it’s for this reason that it’s become a relatively easy target for people with bad intentions.
The FBI says that the attack was far broader than the CALEA system and that the hackers are still accessing telecom networks. The U.S. has been working since late spring to determine the extent of their activities. This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers. Google Project Zero found a vulnerability in top messaging apps that allowed hackers to listen and watch through their victims’ phones without them knowing. Although messages are encrypted during transmission, many applications encourage backups to third-party services, which don’t always maintain the same level of encryption and can become the weak link. A poorly secured cloud backup can completely negate the benefit of end-to-end encryption.
But in hackers’ hands, he says, the tools could potentially be used “to surveil communications and metadata for lots of people. And it seems like the hackers’ focus is primarily Washington, D.C.” She recommends getting 2FA messages through an app like Google Authenticator or Authy or by using a physical security key to verify access. In full end-to-end encryption, tech companies make a message decipherable only by its sender and receiver — not by anyone else, including the company. Along with a promise of greater security, it makes companies “warrant-proof” from surveillance efforts.
The Facebook Messenger bug could have allowed an attacker to listen in on audio from a target’s device. The Viettel Mocha and JioChat bugs both potentially gave advanced access to audio and video. That code, which many apps (including banking, social media, and SMS-ID authentication systems) use as a second layer of security , is the master key. Sharing it, even “because a friend asked for it,” is tantamount to handing over control of the account on a silver platter.
The breach raises critical questions around supply chain security, government software procurement, and the use of modified encryption technologies that fall short of contemporary cybersecurity standards. Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Now that the WhatsApp Business solution has enabled businesses large and small to interact with their customers right on WhatsApp, the app has become an even more compelling replacement for SMS. But what if users didn’t have to do anything at all to authenticate their mobile devices?
For example, rendering-layer APIs like insertVideoPlayer cannot access high-risk functions such as saveFile, reducing the impact of cross-site scripting (XSS) vulnerabilities, researchers said. WeChat’s debugging mechanism, accessible via URLs like debugxweb.qq.com, poses risks if exploited. Attackers could manipulate parameters to force version rollbacks or configuration changes. Given the breach’s exposure of internal discussions—allegedly including deliberations around airstrikes in Yemen—concerns about both the security and oversight of government communication platforms have grown. On May 19, 2025, DDoSecrets announced that it had published the full 410GB data dump online via its public archive. However, due to the inclusion of personally identifiable information (PII) affecting private individuals unrelated to government activity, full access to the dataset is restricted to vetted journalists and researchers.
The advisory, distributed internally, alleged that Russian hacking groups were exploiting the app’s “linked devices” feature to compromise encrypted conversations. This warning came on the heels of a high-profile incident where top US national security officials inadvertently included a journalist in a Signal group chat discussing a potential military strike against Houthi targets in Yemen. As communication tools become integral to business operations, data breaches involving communication tools can have far-reaching consequences for organizations and individuals. For instance, when email accounts are compromised, sensitive information can be leaked, leading to significant financial losses and reputation damage. Similarly, vulnerabilities in messaging apps can allow unauthorized access to confidential conversations, risking the exposure of trade secrets. In the realm of video conferencing, lapses in security can permit uninvited guests to join meetings, potentially disrupting discussions and leaking sensitive content.
Even in 2025, SMS-based attacks remain one of the easiest ways for adversaries to exploit signaling vulnerabilities in SS7, SIGTRAN, Diameter, and LTE networks. What makes this attack particularly dangerous is its exploitation of WeChat’s debugging URL mechanism and built-in browser features. The app includes debugging functionality triggered when users access URLs containing specific parameters, which attackers can abuse to execute high-risk actions like configuration changes without user awareness.
Sorry, the comment form is closed at this time.