Operators can deploy content filtering and AI-driven anomaly detection to flag phishing attempts. However, end-user awareness campaigns remain critical, as smishing often bypasses technical defenses. WeChat’s Android client uses the XWEB engine, a Chromium-based browser lagging behind official releases (v130 vs. Chrome’s v136).
New Research Reveals Multiple Attack Surfaces In Wechat & Other Instant Messaging Apps
- With a strong background in cybersecurity and a focus on systems like SAP, he has contributed to enhancing organizational resilience.
- Once Gemini reads the poisoned notification, it silently incorporates the attacker’s commands into the conversational context without the user’s knowledge.
- As security expert Luis Corrons pointed out, a careful attacker would perform the scan slowly and across many IP addresses , blending in with normal traffic and evading detection.
- Teaching employees how to spot suspicious links, question unexpected group invites, and verify QR codes can prevent many of these attacks before they start.
- SafeBreach reported these findings to Google’s Vulnerability Reward Program on August 17, 2025.
Once inside, the criminal can impersonate the victim to request money, access previous conversations, or extend the attack to other services linked to the same number. Security experts recommend that users maintain updated application versions and exercise caution when opening files from unknown sources, while organizations should implement comprehensive security monitoring for instant messaging platforms. Although messages are encrypted during transmission, many applications encourage backups to third-party services, which don’t always maintain the same level of encryption and can become the weak link. A poorly secured cloud backup can completely negate the benefit of end-to-end encryption.
The techniques also allow for covert video streaming by remotely activating video conferencing software, posing significant privacy threats. Research led by Or Yair from SafeBreach outlines how this new security flaw expands upon previous findings. Earlier, Google Calendar invitations were weaponized, but the current attack method uses any app capable of sending device notifications as a potential delivery channel. Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe.
S4get (cve-2026- : A Critical Pre-authentication Vulnerability In Sap Netweaver’s Message Server
Sensitive communications linked to senior U.S. government officials have been exposed after pro-transparency collective Distributed Denial of Secrets (DDoSecrets) published a massive archive of breached data from TeleMessage’s secure messaging app, TM SGNL. Messaging apps have become the backbone of modern communication — from birthday planning to boardroom discussions, and even customer support. Their convenience makes them indispensable, but it also introduces serious security risks. Ó Cearbhaill described the pair of vulnerabilities as a “zero-click” attack, meaning it does not require any user interaction, such as clicking a link, to compromise their device. CISA has classified both vulnerabilities as actively exploited threats, though the agency notes that their potential use in ransomware campaigns remains unknown at this time. It’s one part of a broader security posture that must include device hygiene, access controls, and user awareness.
The Message Server accepts the claim and propagates that trust across every application server in the cluster. The attacker then connects to the Gateway from that IP, is admitted as internal, invokes RFC-callable external programs, and obtains remote code execution as adm. Despite being more than 30 years old, SMS (Short Message Service) is still one of the most widely used communication tools in the world. Billions of messages are sent every day for personal conversations, business notifications, and authentication codes.
What made these crashes particularly suspicious was their exclusive appearance on devices belonging to individuals likely to be targeted by advanced persistent threat actors. Given the breach’s exposure of internal discussions—allegedly including deliberations around airstrikes in Yemen—concerns about both the security and oversight of government communication platforms have grown. These trends turned messaging apps into critical digital infrastructure, making their protection as vital as corporate networks. Cybersecurity firm Rapid7 Lovesmoments reviews identified this permission bypass vulnerability across several OnePlus smartphone models, including the OnePlus 8T, OnePlus 10 Pro 5G, and potentially other devices in the ecosystem.
