WhatsApp has introduced a new optional feature called 'Scam Alert' that aims to protect users from potential scams. This feature utilizes a local machine learning model to identify and flag messages that may be from scammers. By alerting users about suspicious messages, WhatsApp hopes to enhance security and reduce the risk of falling victim to fraud. This update comes as online scams continue to rise, making it crucial for messaging platforms to provide users with tools to recognize and avoid such threats. Users can opt in to this feature, which underscores WhatsApp's commitment to improving user safety in its messaging environment.
Articles tagged "Update"
Found 382 articles
Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.
Help Net Security
In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.
Ivanti has released an update to address vulnerabilities in their Endpoint Manager (EPM) that could allow attackers to exploit systems remotely. These flaws could lead to the leaking of credentials for external SQL connections or even crashing the agent service, potentially disrupting operations for affected organizations. Companies using Ivanti EPM need to prioritize applying this update to safeguard against these security risks. The vulnerabilities underline the importance of keeping software up to date to protect sensitive data and maintain system stability.
Zoom has addressed a serious vulnerability in its software that could allow a participant in a video meeting to execute malicious code on another user’s device via the annotation feature. This flaw, known as CVE-2026-53413, is categorized as a zero-click vulnerability, meaning it does not require any interaction from the victim to be exploited. Discovered by A Security, the issue is part of a broader update where Zoom patched a total of four vulnerabilities. The existence of such a flaw raises significant concerns about user safety and privacy during online meetings, as it could potentially lead to unauthorized access to sensitive information. Users are advised to update their Zoom applications to the latest version to protect themselves from possible exploitation.
Zoom has patched a serious vulnerability that could allow a participant in a meeting to execute code on another attendee's machine without any interaction required—hence the term 'zero-click.' This flaw, linked to Zoom's annotation feature, poses a significant risk, particularly as remote work continues to be prevalent. If exploited, it could lead to unauthorized access or control over devices of unsuspecting users. The company has urged users to update to the latest version to ensure their systems are secure. This incident serves as a reminder of the ongoing security challenges faced by popular communication platforms.
The National Institute of Standards and Technology (NIST) is looking to update its National Vulnerability Database in response to the evolving landscape of cyber threats driven by artificial intelligence. As AI technologies become more integrated into security measures, NIST aims to gather public feedback on how to enhance the database to better address these challenges. This initiative is crucial as it will help ensure that security professionals and organizations have access to timely and relevant information about vulnerabilities that AI might exploit. The modernization effort is a proactive step to keep up with the growing complexity of cyber risks that AI presents, ensuring that the database remains a reliable resource for identifying and managing vulnerabilities.
SAP has rolled out 28 new security notes and updated two others to address vulnerabilities in its software. Among these, four notes focus on critical issues related to code injection and memory corruption. These vulnerabilities could allow attackers to execute arbitrary code or crash systems, posing significant risks to organizations using SAP products. Companies relying on SAP software should prioritize applying these patches to protect their systems and sensitive data from potential exploitation. This update underscores the need for ongoing vigilance in maintaining software security.
Help Net Security
A vulnerability in OpenSSH versions prior to 10.5 allowed users to inadvertently expose local-only keys when locking the ssh-agent. In OpenSSH 10.4, locking the agent disabled a security check that determined whether connection requests came from the local machine or a remote, forwarded connection. This flaw meant that if users locked their ssh-agent, it could still respond to requests that shouldn't be permitted. The issue was addressed in the recently released OpenSSH 10.5, which restores the proper functionality of the lock feature. Users relying on ssh-agent for secure connections should update to this version to ensure their private keys remain protected.
SCM feed for Latest
A recent analysis has uncovered 176 vulnerabilities in Samsung's proprietary mobile applications, which are pre-installed and cannot be removed by users. These apps operate outside of Google Play Protect, leaving them exposed to potential security risks. The vulnerabilities could allow attackers to exploit these apps, potentially compromising user data and device security. This is particularly concerning as Samsung devices are widely used around the world. Users of Samsung mobile devices need to stay alert and update their apps as soon as patches are available to mitigate these risks.
The Hacker News
This week saw a range of cybersecurity issues, including the resurgence of old vulnerabilities and concerns over supply chain attacks. Researchers pointed out that common actions like cloning repositories or trusting default settings continue to lead to significant security breaches. One notable incident involved a zero-day vulnerability in Metabase, which could allow unauthorized access to sensitive data. Additionally, there are reports of supply-chain attacks targeting MCP systems, raising concerns about the integrity of software and hardware components. These incidents serve as a reminder for organizations to remain vigilant about their security practices and to frequently update their systems to counteract these evolving threats.
The Hacker News
A group known as Head Mare has been exploiting vulnerabilities in unpatched TrueConf servers to carry out attacks against various Russian companies. These companies operate in sectors like instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a cybersecurity firm, reported detecting these attacks in July 2026. The attackers are reportedly replacing legitimate client installers with malicious software called PhantomCore, which could compromise the security of the affected organizations. This situation raises concerns for companies still using outdated versions of TrueConf, as failure to update could lead to severe security breaches.
Metabase has patched a significant security vulnerability that allowed unauthenticated remote attackers to gain administrative access to its instances. This flaw posed a serious risk, as it enabled attackers to potentially manipulate data and settings without needing any credentials. The issue has been classified as a zero-day exploit, meaning it was actively being exploited in the wild before the patch was released. Users of Metabase should ensure they update to the latest version to protect against this vulnerability. This incident serves as a reminder of the importance of timely software updates and vigilant security practices in safeguarding sensitive data.
Help Net Security
GitHub has expanded its malware detection capabilities to cover eight different ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, in addition to its existing support for npm. This update comes after GitHub's Advisory Database began integrating malware reports from OpenSSF's malicious-packages repository, which has accumulated over 15,000 reports since its launch in 2023. These reports include various types of malicious packages, such as typosquats and dependency confusion. This change is significant as it helps developers and users identify and avoid potentially harmful packages across multiple ecosystems, enhancing overall security in software development. Previously, users were only alerted to npm-related malware, leaving them vulnerable when using packages from other sources.
The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.