“Encryption is your friend” for texts and phone calls, Jeff Greene, CISA’s executive assistant director for cybersecurity, said on the briefing call. “Even if the adversary is able to intercept the data, if it is encrypted, it will make it impossible, if not really hard, for them to detect it. So our advice is to try to avoid using plain text.” On the other hand, there are currently no public reports about how the three Ivanti EPM flaws are being weaponized in real-world attacks. The cybersecurity company described them as “credential coercion” bugs that could allow an unauthenticated attacker to compromise the servers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting Advantive VeraCore and Ivanti Endpoint Manager (EPM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.
Instant messaging (IM) applications like WhatsApp, Telegram, WeChat, and QQ have become the “digital arteries” of modern society, facilitating communication for billions of users worldwide. These trends turned messaging apps into critical digital infrastructure, making their protection as vital as corporate networks. Between 2020 and 2024, messaging apps evolved from casual chat tools into essential communication infrastructure. The COVID-19 pandemic accelerated this shift, with billions depending on these apps for work meetings, virtual classes, and even healthcare consultations. Hundreds of thousands of websites may be exposed to account takeover attacks due to a critical-severity vulnerability in the email delivery WordPress plugin Post SMTP, Defiant warns. More than 6,000 Coinbase users had funds stolen from their accounts after hackers used a vulnerability in Coinbase’s SMS-based two-factor authentication system to breach accounts.
In the military, sending classified data over insecure channels is called “spillage”; it can be a career ender for a military officer. Between April 2024 and January 2025, iVerify analyzed crash data from nearly 50,000 devices and found that imagent crashes related to Nickname Updates were extraordinarily rare, comprising less than 0.001% of all crash logs collected. This created a classic race condition where one thread might read Nickname Update details while another thread simultaneously modified the same data container.
When Identity Verification Fails: Lessons From A Real-world Sim Swap And Near Account Takeover
However, their widespread use makes them prime targets for cyberattacks, with vulnerabilities posing a threat to personal privacy, financial assets, and national security. Recent research highlights critical weaknesses in these platforms, underscoring the delicate balance between functionality and security. The core exploit leverages Gemini’s Android Utilities agent, specifically the tool that reads incoming notifications. Because this tool processes untrusted data from third-party apps, an attacker can embed malicious instructions directly inside a crafted message.
The warning from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) highlighted vulnerabilities in text messaging systems that millions of Americans use every day. The vulnerability was reported by Google Threat Analysis Group (GTIG), which typically finds security defects targeted by state-sponsored groups and commercial spyware vendors. Zimbra did not share details on the flaw, which does not appear to have been assigned a CVE identifier yet, but urged all customers using the Classic Web Client to update their deployments as soon as possible. Based on WordPress’s statistics, Post SMTP was downloaded less than 200,000 times over the past seven days, which suggests that roughly 200,000 websites are potentially exposed to takeover because of the bug. “Some customers have already been reimbursed — we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today,” the company promised.
Fbi Issues Alert As Thousands Of Signal Accounts Confirmed Hacked
WeChat’s debugging mechanism, accessible via URLs like debugxweb.qq.com, poses risks if exploited. True digital safety requires not just encryption, but also user awareness, platform transparency, and adaptive regulation. Combining both techniques into an “Ultimate Combo” payload allowed researchers to bypass all of Google’s latest mitigations with high reliability and near-zero user awareness. As for the risk to everyday consumers, security experts like Hong and Galperin say that with vast amounts of information traveling between our phones, they want to see people get more help in protecting themselves. “The adversaries we face are tenacious and sophisticated, and working together is the best way to ensure eviction,” the senior FBI official said during the news briefing. Bad actors such as cybercriminals might have different objectives, Hong says, “but if you just do a few relatively simple things, you can actually protect yourself from the vast majority of those kinds of threats.”
The company has assured its users that it is committed to protecting their data and preventing future breaches. Other vulnerabilities have included bypassing privacy protections and stealing private user information, such as phone numbers and user IDs. Despite these issues, TikTok remains one of the most popular social media platforms globally, with over 1 billion users.
“This can be used for complete site compromise by an attacker triggering a password reset for a site’s administrator user, and then obtaining the password reset email through the log data. Once an attacker has access to this key, they can reset the password for that user and log in to the account,” Defiant notes. Is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers. For now, TikTok users, particularly those with high-profile accounts, are advised to remain vigilant and report any suspicious activity to the platform’s security team.
Google confirmed on November 14, 2025, that updated content classifier improvements successfully mitigated the indirect prompt injection and Delayed Tool Invocation scenarios described in the research. Lastly, scheduled surveillance tactics allow the establishment of recurring tasks that automatically read the user’s recent messages daily, further compromising their privacy and security. With Delayed Tool Invocation re-enabled, researchers demonstrated a range of high-severity exploits. The emergence of smart home technology has facilitated various forms of exploitation, such as remotely controlling connected devices like windows, boilers, and lighting via Google Home.
In light of active exploitation, it’s essential that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by March 31, 2025. “The third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account,” Coinbase said. Individuals are also finding ways to circumvent national firewalls and bans on privacy-preserving applications by using virtual private networks (VPNs) and other tools that mask or obscure IP addresses and geolocation, according to Durov. However, TikTok has not disclosed the exact number of compromised accounts or detailed the specific nature of the vulnerability, citing security concerns. Jason Grosse, a representative of TikTok’s privacy and security team, stated that the company is collaborating with the affected users to mitigate the impact and ensure such incidents do not recur. The company works directly with the affected account owners to restore access and implement additional security measures.
This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers. In full end-to-end encryption, tech companies make Amoredate a message decipherable only by its sender and receiver — not by anyone else, including the company. Along with a promise of greater security, it makes companies “warrant-proof” from surveillance efforts. The CISA released a list of best security practices for smartphone users on Thursday, with specific tips for iPhone and Android owners.
- As for the risk to everyday consumers, security experts like Hong and Galperin say that with vast amounts of information traveling between our phones, they want to see people get more help in protecting themselves.
- Cointelegraph reached out to Signal about the FBI’s data retrieval but did not receive a response by the time of publication.
- Despite Apple’s implementation of BlastDoor sandboxing in iOS 14 to protect against such attacks, determined threat actors continue finding narrow vectors through Apple’s defenses.
- WhatsApp stated that user messages remain protected through default end-to-end encryption and thanked researchers for their collaboration on mitigation testing.
- Researchers exploited weak rate-limiting protections to probe over 100 million phone numbers per hour without encountering blocking or effective rate-limiting measures.
The intrusions took place earlier this year, between March and May, the exchange said in a data breach notification letter it has filed with US state attorney general offices. Cointelegraph reached out to Signal about the FBI’s data retrieval but did not receive a response by the time of publication. The memo continues, “Russian professional hacking groups are employing the ‘linked devices’ features to spy on encrypted conversations.” It notes that Google has identified Russian hacking groups that are “targeting Signal Messenger to spy on persons of interest.” Malicious mini-programs can leverage these permissions to conduct sophisticated attacks if proper permission management is lacking. As technology evolves, vigilance and continuous improvement will remain the foundation of secure digital communication.
The Project Zero researcher also looked at other popular messaging apps such as Telegram and Viber, but she could not find these particular security flaws. Back in November 2018, the very same researcher brought to daylight a similar loophole in WhatsApp – it was affecting not only Android users, but the security flaw was observed on Apple devices too. The DARKNAVY research team’s comprehensive analysis reveals how malicious actors can exploit client-side attack surfaces in popular messaging platforms like WeChat, potentially compromising billions of users worldwide without requiring any user interaction. Security researchers from the University of Vienna have uncovered a critical vulnerability in WhatsApp that allowed them to enumerate phone numbers of 3.5 billion users worldwide, exposing a massive privacy flaw in the world’s most popular messaging platform. Even though all of the vulnerabilities have been patched by the app developers, hackers would still be able to exploit the loophole if the targeted devices are running an older version of the apps.