The discovery also revealed that around half of the numbers leaked in the massive Facebook scraping of 2021 were still active on WhatsApp, demonstrating that phone numbers, in practice, function as a near-permanent identifier. Thanks to this weakness, researchers demonstrated that it was possible to query more than 100 million phone numbers per hour through WhatsApp’s infrastructure, ultimately enumerating some 3.500 billion active accounts in 245 countries. The system responded to an enormous number of requests from a single source, when the reasonable course of action would have been to reject or limit them. CISA has classified both vulnerabilities as actively exploited threats, though the agency notes that their potential use in ransomware campaigns remains unknown at this time.
This misconfiguration allows unauthorized attackers to access memory dumps containing potentially sensitive information, including authentication credentials, session tokens, and other confidential data stored in the application’s memory space. Threema has introduced mitigations after the researchers privately shared their findings. The updates include a new custom protocol named Ibex, which fixes vulnerabilities 2.1 and 2.2.
However, Google states in their guidelines that “transferring user data to a ‘service provider”’ should not be disclosed as data sharing in the app’s privacy labels (Google 2023d), limiting their scope and potential utility. In this section, we provide an overview of related work on the privacy and security risks of push notifications, mobile app analysis, and analysis of privacy-relevant disclosures. The Pentagon advisory, according to reports, warned against using Signal even for unclassified communications, citing the alleged vulnerability exploited by Russian hackers. However, Signal countered this assertion, explaining that phishing attacks, the actual threat highlighted in the advisory, are not unique to their platform and represent a persistent risk for any popular app or website. They emphasized that these attacks do not exploit flaws in Signal’s underlying encryption technology but instead rely on deceiving users into revealing their credentials or other sensitive information. For communications, marketing, and PR professionals, these technical flaws translate into operational risks.
- Furthermore, none of the data we observed being leaked to FCM was specifically disclosed in those apps’ privacy disclosures.
- As security expert Luis Corrons pointed out, a careful attacker would perform the scan slowly and across many IP addresses , blending in with normal traffic and evading detection.
- In many organizations, message channels and video calls are where the most sensitive business topics are discussed and proprietary data is exchanged.
- Heightened public concerns around the monitoring of online communications have significantly influenced consumer behavior in the past decade.
“Most compromises of systems do not involve taking advantage of vulnerabilities that no one else knows about,” Galperin says, adding that “often, the maker of the product has in fact figured out what the vulnerability is, fixed it and pushed out a patch in the form of a security update.” There’s almost no precedent for the heads of defense, state, intelligence and national security to be sharing such sensitive military intelligence in a forum that was known to be unsecured. WeChat has implemented several security mechanisms to address these vulnerabilities, including multi-process sandboxing that isolates rendering processes from the main application. WeChat’s file processing system, designed to enhance user experience through file previews and content extraction, creates significant security exposure when handling untrusted content. The affected devices belonged to political campaign staff, journalists, tech executives, and government officials in the EU and the US.
In the realm of video conferencing, lapses in security can permit uninvited guests to join meetings, potentially disrupting discussions and leaking sensitive content. As text message users absorb news of an SMS pumping attack that can rack up your phone bill in a matter of minutes, there’s never been a better time to switch to secure messaging apps such as Signal or WhatsApp. According to the Pentagon, security researchers have identified multiple ways in which attackers can compromise Signal communications without breaking its encryption. Russian hacking groups, as reported by the NSA, have used phishing pages and malicious QR codes disguised as legitimate Signal group invite links. These links trick users into adding attacker-controlled devices to their Signal accounts. Once added, the attacker gains real-time access to all future messages in that conversation.
Cyberstrike – Ai-powered Security Platform For Automated Penetration Testing
Is a cloud-based OSPNS that forwards push messages to the appropriate user device using the stored registration token(3), even if the client app is offline or in the background. It also exposes an API to the developer to enable push messaging in their applications. In this post, we’ll explore the major data breaches that affected messaging apps between 2020 and 2024, analyze what went wrong, and extract lessons to build safer communication platforms — without sacrificing convenience. Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.
These incidents show how crucial it is to have strong security measures to protect user data and prevent future breaches. “These are for legitimate wiretaps that have been authorized by the courts,” Hong says. But in hackers’ hands, he says, the tools could potentially be used “to surveil communications and metadata for lots of people. And it seems like the hackers’ focus is primarily Washington, D.C.” She recommends getting 2FA messages through an app like Google Authenticator or Authy or by using a physical security key to verify access. In full end-to-end encryption, tech companies make a message decipherable only by its sender and receiver — not by anyone else, including the company. Along with a promise of greater security, it makes companies “warrant-proof” from surveillance efforts.
For example, an app that provides “end-to-end” encrypted messaging may not actually provide end-to-end encryption if message payloads are not encrypted before being sent to third-party push notification APIs. To make matters worse, misuse of these SDKs may also contribute to the misrepresentation of security and privacy assurances to consumers as articulated in various disclosures, including privacy policies, terms of service, and marketing materials. Many apps beyond secure messaging apps might send private data through push notifications.
Since one of the primary use cases for the Browsing Context is summarizing blogs and articles, our idea was to inject instructions in the comment section. We created our own blogs with dummy content and then left a message for SearchGPT in the comments section. When asked to summarize the contents of the blog, SearchGPT follows the malicious instructions from the comment, compromising the user. (We elaborate on the specific impact to the user in the Full Attack Vector PoCs section below.) The potential reach of this vulnerability is tremendous, since attackers could spray malicious prompts in comment sections on popular blogs and news sites, compromising countless ChatGPT users. We looked specifically at privacy leakage through push notifications that rely on FCM.
And as recent incidents have shown, even the best tools can be compromised if used carelessly. Communications leaders must stop thinking of security as someone else’s job and start treating it as a core part of their own. Signal’s security flaw was patched in September 2019, and the rest of the messaging apps were fixed more recently in the second half of 2020.
The first is to treat phone numbers and codes received via SMS as sensitive credentials that should never be shared , even if the person requesting them appears to be a friend, a technician, or the app itself. That code, which many apps (including banking, social media, and SMS-ID authentication systems) use as a second layer of security , is the master key. Sharing it, even “because a friend asked for it,” is tantamount to handing over control of the account on a silver platter.
1 Mobile Push Notifications
The conversation included names like Vice President JD Vance, Secretary of Defense Pete Hegseth, Director of National Intelligence Tulsi Gabbard, Secretary of State Marco Rubio, and CIA Director John Ratcliffe, among others. The famous phrase “I joined the wrong chat” went from a joke to a global example of the recklessness of discussing military secrets in an encrypted chat without formal controls. If someone leaves a project, their access to group chats must be revoked immediately.
We found that, similarly to Conversation Injection, SearchGPT can actually get ChatGPT to update its memories, allowing us to create an exfiltration that will happen for every single response. This injection creates a persistent threat that will continue to leak user data even between sessions, days, and data changes. If the user asks it to remember something, or if there is some information that the engine deems important even without an explicit request, it can be remembered using memories.
Threema has more than 10 million users, which include the Swiss government, the Swiss army, German Chancellor Olaf Scholz, and other politicians in that country. Threema developers advertise it as a more secure alternative to Meta’s WhatsApp messenger. It’s among the top Android apps for a fee-based category in Switzerland, Germany, Austria, Canada, and Australia. The app uses a custom-designed encryption protocol in contravention of established cryptographic norms. High-risk individuals face a greater likelihood of attacks against their accounts due to a combination of their role and potential access to sensitive information and important people.
The security implications extend far beyond individual applications, affecting the broader instant messaging ecosystem that serves as “digital arteries” for modern society. Researchers demonstrate how attackers can craft malicious files disguised as legitimate content to achieve remote code execution. Despite Apple’s implementation of BlastDoor sandboxing in iOS 14 to protect against such attacks, determined threat actors continue finding narrow vectors through Apple’s defenses. The discovery, made by cybersecurity firm iVerify, reveals how attackers could compromise iPhones without any user interaction by exploiting a flaw in iMessage’s contact profile update feature. Individuals may become https://tracylarson.livepositively.com/technology/youmetalks-review-how-the-platform-performs-on-safety-features-and-usability identified based on the information linked to their device’s push tokens.
One study analyzed 30 different third-party PNS SDKs embedded in 35,173 Android apps and found that 17 SDKs contain vulnerabilities to the confidentiality and integrity of push messages, which an attacker can exploit by running a malicious app on the victim’s device (Chen et al. 2015). Similarly, Lou et al. performed a security and privacy analysis of the twelve most popular PNSs and compared their behavior in 31,049 apps against information practices disclosed in the privacy policies of those PNSs (Lou et al. 2023). They found that out of twelve third-party PNSs, six PNSs collect in-app user behavior and nine collect location information, often without awareness or consent of app users. Google’s FCM developer documentation (Google for Developers 2024) states that “depending on your needs, you may decide to add end-to-end encryption to data messages” and “FCM does not provide an end-to-end solution.” No further guidance is given on what information is appropriate to send. In these cases, app vendors may be held liable for failing to safeguard or minimize the amount of personal information sent via push notification servers and for failing to disclose this practice in their privacy notices. Given the utility of push notifications, companies have started offering push notification services that compete with Google’s FCM.
