/

1 de setembro de 2026

How To Keep Text Messages Secure As Fbi Warns Of Chinese Hackers : Npr

Enforce the vendor’s configuration guidance, ensuring that linked-device synchronization messages are permitted only from authenticated endpoints. When a user links their WhatsApp client on a new device, synchronization messages propagate chat histories and media over multiple endpoints. Organizations and individual users are strongly urged to apply vendor-supplied mitigations by September 23, 2025, or to discontinue use until secure patches are available. Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services. After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. The Facebook Messenger bug allowed audio calls to connect before the call was answered, while similar issues were discovered affecting both the JioChat and Mocha messaging services.

Whether the observed behaviors do constitute undisclosed sharing depends on the findings from our privacy disclosure analysis, discussed below (§5.3). As we discuss in Section 5, we found inconsistencies between the observed app behavior and promises made by developers of several apps from our data set (see also Table  1). We disclosed our findings to those developers to ensure these inconsistencies can be addressed promptly (see § 7 for a further discussion). The other end of the web tool is the search command, used by ChatGPT to invoke an internet search whenever a user enters a prompt that requires it. ChatGPT uses a proprietary search engine to find and return results based on up-to-date information that may have been published after the model’s training cutoff date. A user can choose this feature with the dedicated “Web search” button; if the user doesn’t select this feature, a search is conducted at the LLM’s discretion.

vulnerability in messaging

We additionally read each privacy policy to understand whether developers disclosed the sharing of personal information for the purposes of providing push notifications. We found that all 11 apps that shared personal information with Google’s FCM servers stated that personal user data may be shared with service providers (such as FCM) for the purpose of app functionality. Furthermore, three apps (Viber, WeChat and Comera) did not specify which companies serve as their service providers. Out of the remaining 8 apps, only 4 mentioned Google in the context of push notifications and/or FCM. As described previously (§ 2.2), push notification architecture can be separated into the host platform that provides the push API and the transit platform that actually delivers the push notification internally. Several studies looked at the security issues of third-party PNS SDKs while excluding system-level transit platforms, such as FCM from Google.

Cyber Tools

They tend to concentrate the infrastructure in a few of the provider’s data centers, creating single points of failure and prime targets for attackers and legal pressure from foreign governments. Signal’s response underscored the distinction between vulnerabilities in an app’s security infrastructure and external threats like phishing. They argued that conflating these distinct issues misrepresents the security of the app and unfairly casts doubt on its encryption protocols. The company reiterated its commitment to providing secure and private communication, emphasizing that its core technology remains robust and unaffected by the phishing threats mentioned in the Pentagon advisory. Alongside international partners, the NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.

The Atlantic’s editor-in-chief, Jeffrey Goldberg, was inadvertently added to the group and was privy to the highly sensitive discussions. Several days after top national security officials accidentally included a reporter in a Signal chat about bombing Houthi sites in Yemen, a Pentagon-wide advisory warned against using the messaging app, even for unclassified information. We appreciate your time reviewing and reporting rendering errors we may not have found yet. Your efforts will help us improve the HTML versions for all readers, because disability should not be a barrier to accessing research. Individuals may become identified based on the information linked to their device’s push tokens.

By indexing some test websites to Bing, we were able to extract their static tracking links and use them to bypass the url_safe check, allowing our links to be fully rendered. The Bing tracking links cannot be altered, so a single link cannot extract information that we did not know in advance. Our solution was to index a page for every letter in the alphabet and then use those links to exfiltrate information one letter at a time. For example, if we want to exfiltrate the word “Hello”, ChatGPT would render the Bing links for H, E, L, L, and O sequentially in its response. GreyNoise’s tag, which monitors attempts to take advantage of the vulnerability, has detected 11 IP addresses that have attempted the exploit since April.

This systematic approach to identifying vulnerable systems suggests organized cybercriminal campaigns rather than opportunistic attacks. Of these, 1,582 IPs specifically targeted /health endpoints, commonly used by attackers to identify internet-exposed Spring Boot deployments vulnerable to exploitation. Rumors of a Signal zero-day started circulating over the weekend with what appears to be a copy-pasted warning the “generate link preview” feature could be exploited to take full control of devices.

From smishing (SMS phishing) to interception of authentication codes, location tracking, and SMS flooding attacks, the humble text message has become a prime vector for telecom fraud and surveillance. Even in 2025, SMS-based attacks remain one of the easiest ways for adversaries to exploit signaling vulnerabilities in SS7, SIGTRAN, Diameter, and LTE networks. The platform has faced similar challenges before, including the notorious XcodeGhost malware in 2015 that infected WeChat version 6.2.5 alongside 38 other popular iOS applications, affecting hundreds of millions of users. The attack, detailed in recent research by cybersecurity firm DARKNAVY, exploits WeChat’s built-in browser components and URL parsing mechanisms to execute remote code without requiring any user interaction beyond receiving the message. Security experts emphasized that this exploit chain operated as a “zero-click attack”, a class of exploit requiring no user interaction.

  • The combined risk of sensitive information leakage and misrepresentation of privacy promises creates serious ramifications for users of secure messaging platforms.
  • Our primary research question concerns how secure messaging apps’ usage of FCM impacts user privacy.
  • As IM apps integrate more features (payments, mini-programs), their attack surfaces expand, requiring stricter access controls and faster patch cycles.

Despite being more than 30 years old, SMS (Short Message Service) is still one of the most widely used communication tools in the world. Billions of messages are sent every day for personal conversations, business notifications, and authentication codes. We analyzed privacy disclosures for the 11 apps that included personal information in the push notifications sent via Google’s FCM. We determined that 8 apps employed an end-to-end encryption strategy to prevent privacy leakage to Google via FCM. In this strategy, when the user launches the app for the first time, the app provisions a keypair and does a secure key exchange between the user’s device and the app’s server.

Common Types Of Sms-based Attacks

For instance, in the context of a messaging app, a sender device may send a message to the app server (1), which then sends a push notification request to FCM (2). The simplest way to ensure your messages are safe from snooping is to use an end-to-end encrypted app like Signal or WhatsApp, says Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation (EFF). With these apps, “your communications are end-to-end encrypted every single time,” she says. Another area where messaging apps have become a hunting ground for criminals is identity theft and phishing .

The issue “stems from the platform’s continued use of a legacy confirmation in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication,” the research team told Cointelegraph. See how to test new CVEs against your environment, confirm what attackers can actually exploit, and fix the exposures that pose the greatest risk. Ó Cearbhaill described the pair of vulnerabilities as a “zero-click” attack, meaning it does not require any user interaction, such as clicking a link, to compromise their device.

Prompt injection is a known issue with the way that LLMs work, and, unfortunately, it will probably not be fixed systematically in the near future. AI vendors should take care to ensure that all of their safety mechanisms (such as url_safe) are working properly to limit the potential damage caused by prompt injection. Hundreds of millions of users ask LLMs questions that require searching the web, and it seems that LLMs will eventually replace classic search engines.

The application uses cloud-based permission arrays to control JSBridge interface reddit.com/r/OnlineDatingApps/comments/1wbm9iv/youragemeets_dating_site access, providing fine-grained control over webpage capabilities. WeChat has implemented several security mechanisms to address these vulnerabilities, including multi-process sandboxing that isolates rendering processes from the main application. Mini-program ecosystems introduce additional attack surfaces, as third-party developers receive extensive system permissions including file system access, sensor invocation, and API calls. The embedded browser components in these applications often lag behind official releases, potentially exposing users to known vulnerabilities that remain unpatched. The security implications extend far beyond individual applications, affecting the broader instant messaging ecosystem that serves as “digital arteries” for modern society. Researchers demonstrate how attackers can craft malicious files disguised as legitimate content to achieve remote code execution.

The DARKNAVY research team’s comprehensive analysis reveals how malicious actors can exploit client-side attack surfaces in popular messaging platforms like WeChat, potentially compromising billions of users worldwide without requiring any user interaction. As IM apps integrate more features (payments, mini-programs), their attack surfaces expand, requiring stricter access controls and faster patch cycles. For developers, prioritizing security without compromising usability is the ultimate challenge one that will define the next era of digital communication. However, their widespread use makes them prime targets for cyberattacks, with vulnerabilities posing a threat to personal privacy, financial assets, and national security. Recent research highlights critical weaknesses in these platforms, underscoring the delicate balance between functionality and security.

Following the discovery of the FaceTime vulnerability, Project Zero found similar flaws affecting Signal, Google Duo, Facebook Messenger, JioChat, and Mocha. CISA has classified both vulnerabilities as actively exploited threats, though the agency notes that their potential use in ransomware campaigns remains unknown at this time. This flaw affects the platform’s JSP (JavaServer Pages) application architecture, where heap content becomes accessible in a manner equivalent to traditional core dumps. This critical security weakness stems from improper configuration of the Spring Boot Actuator component, which inadvertently exposes a sensitive heap dump endpoint accessible via the /heapdump URI path. Organizations utilizing Spring Boot frameworks, particularly those operating secure messaging environments, must immediately verify whether their /heapdump endpoints are exposed to the internet.

It quickly became clear to us that there is some kind of cache mechanism for such browsing, since when we asked about a URL that was already opened, ChatGPT would respond without browsing again. In addition to its long-term memory feature, ChatGPT considers the current conversation and context when responding. Chainalysis’ latest crime report notes that over $2.17 billion has been stolen so far in 2025, a pace that would take crypto-related thefts to new highs. Notable security attacks over the past months include physical “wrench attacks” on Bitcoin holders and high-profile incidents such as the February hack of crypto exchange Bybit.