Signal App Clone Telemessage Vulnerability May Leak Passwords; Hackers Exploiting It

And when even the most trusted platforms show cracks, the consequences stretch far beyond the IT department. For communications, marketing, and PR professionals, these technical flaws translate into operational risks. Confidential media strategies, embargoed press releases, and crisis response plans often flow through encrypted messaging apps. But as we’ve seen, the real risk often lies in how these tools are used, not how they’re built.

Support Contacts

In addition to the general measures described on the DOM-based BestDates – TikTok vulnerabilities page, you should avoid sending web messages that contain data that originated from any untrusted source. When sending cross-origin messages, you should always explicitly specify the target window. Most importantly, make sure to implement robust measures to verify the origin of any incoming messages. Rumors of a Signal zero-day started circulating over the weekend with what appears to be a copy-pasted warning the “generate link preview” feature could be exploited to take full control of devices.

Argentina To Initiate Legal Action Regarding Disinformation Campaign Targeting Lionel Messi And National Team Players

In this post, we’ll explore the major data breaches that affected messaging apps between 2020 and 2024, analyze what went wrong, and extract lessons to build safer communication platforms — without sacrificing convenience. Sometimes ChatGPT will respond with the output of SearchGPT’s browsing results as-is, and sometimes it will take the full output and modify its reply based on the question. As a method of isolation, SearchGPT has no access to the user’s memories or context. Therefore, despite being susceptible to prompt injection in the Browsing Context, the user should, theoretically, be safe, as SearchGPT is doing the browsing. The situation is becoming increasingly alarming as cybercriminals develop more advanced attack methods. Recent data indicates a staggering 150% increase in attack attempts targeting users of these messaging applications over the last quarter alone.

Once a brand is seen as careless with data, regaining public trust is an uphill battle. It’s one part of a broader security posture that must include device hygiene, access controls, and user awareness. Scotland bans WhatsApp for official use, leading a movement towards secure, transparent government communication with platforms like Wire. These incidents show how crucial it is to have strong security measures to protect user data and prevent future breaches.

Find Dom-based Vulnerabilities Using Burp Suite

  • Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls.
  • Dive into live coverage, expert insights, breaking news, exclusive videos, and more – plus, stay updated on the latest in current affairs and entertainment.
  • The NSA, in its guidance, has advised government personnel to avoid using Signal for classified or sensitive conversations.
  • Messaging apps have become the backbone of modern communication — from birthday planning to boardroom discussions, and even customer support.
  • Organizations must rethink their use of third-party apps for sensitive communications.

The FBI says that the attack was far broader than the CALEA system and that the hackers are still accessing telecom networks. The U.S. has been working since late spring to determine the extent of their activities. This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers.

Learn how to secure AI agents with practical controls for access, visibility, secrets, and risk containment. Attackers could have triggered dangerous actions, including controlling smart home devices via Google Home and starting Zoom video calls. Given that Project Zero’s investigation only looked at peer-to-peer calls, an alarming number of vulnerabilities were discovered. Group calling features were not looking into, though Silvanovich said that this is an area that could reveal additional problems. In most cases, the vulnerabilities enabled unauthorized personnel to listen in on a call recipient without requiring any interaction from said recipient. The Signal bug, patched in September 2019, allowed an individual to listen in on the recipient’s surroundings, for example, while a Google Duo flaw caused the leak of video packets from unanswered calls.

“I think it’s really incumbent on software developers and these companies to have much better privacy and security by default,” Hong says. “That way you don’t need a Ph.D. to really understand all the options and to be secure.” “The adversaries we face are tenacious and sophisticated, and working together is the best way to ensure eviction,” the senior FBI official said during the news briefing. The warning from the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) highlighted vulnerabilities in text messaging systems that millions of Americans use every day. Between April 2024 and January 2025, iVerify analyzed crash data from nearly 50,000 devices and found that imagent crashes related to Nickname Updates were extraordinarily rare, comprising less than 0.001% of all crash logs collected. WeChat’s layered defenses, from URL validation to sandboxed browsers, demonstrate a proactive approach to security.

This unprecedented 0-click vulnerability opens a whole new attack vector that could target anyone who relies on AI search for information. AI vendors are relying on metrics like SEO scores, which are not security boundaries, to choose which sources to trust. By hiding the prompt in tailor-made sites, attackers could directly target users based on specific topics or political and social trends. During recent security evaluations, experts uncovered that the built-in data protection mechanisms of these instant messaging services aren’t always performing as intended. A major concern is that even with end-to-end encryption enabled, users might still be susceptible to various forms of cyberattacks, leaving them vulnerable to malicious actors. Alongside international partners, the NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.

Since prompt injection is such a prevalent issue, AI vendors are constantly trying to mitigate the potential impact of these attacks by developing safety features to protect user data. Much of the potential impact of prompt injection stems from having the AI respond with URLs, which could be used to direct the user to a malicious website or exfiltrate information with image markdown rendering. OpenAI has attempted to address this issue with an endpoint named url_safe, which checks most URLs before they are shown to the user and uses proprietary logic to decide whether the URL is safe or not. SafeBreach researchers uncovered a critical vulnerability in Google’s Gemini voice assistant that could have allowed attackers to hijack the AI using indirect prompt injections delivered through ordinary messaging notifications. Its open-source protocol is widely respected, and its encryption model has been adopted by other platforms, including WhatsApp. A recent NPR feature on vulnerabilities within Pentagon communications highlights just how fragile even highly secure systems can be when subjected to targeted attacks.

According to Microsoft, a successful exploit could have a high impact on the confidentiality, integrity, and availability of a user’s data, granting the attacker privileges to read, write, and delete information. The postMessage() method for sending web messages can lead to vulnerabilities if the event listener for receiving messages handles the incoming data in an unsafe way. Discover why strong encryption matters in the digital age, and how Wire safeguards secure communication across industries amid global backdoor… As for the risk to everyday consumers, security experts like Hong and Galperin say that with vast amounts of information traveling between our phones, they want to see people get more help in protecting themselves. As agencies work to oust the hackers, the FBI called for Americans to embrace tight encryption — an about-face, Galperin says, after years of insisting that law enforcement agencies need a “back door” to access communications. In far fewer cases, they said, the actual content of calls and texts was targeted.

While Signal encrypts message content, it still transmits metadata such as who is talking to whom and when. For government agencies and businesses handling classified or proprietary information, this can be a significant security risk. Cases have been highlighted where foreign intelligence agencies exploited metadata to map communication networks and infer sensitive relationships between individuals, even if the actual messages remained unreadable. Enterprise messaging and collaboration tools are central to how work gets done today. In many organizations, message channels and video calls are where the most sensitive business topics are discussed and proprietary data is exchanged.

Left out of the statement is that the protocol the researchers analyzed is old because they disclosed the vulnerabilities to Threema, and Threema updated it. Those working in government should follow government guidance on the use of non-corporate communications channels. The NCSC has previously reported on the targeting of government officials’ accounts by China state-affiliated APT31, Russian Federal Security Service (FSB) actor Star Blizzard and Iran’s Islamic Revolutionary Guard Corps (IRGC).

vulnerability in messaging

The platform has faced similar challenges before, including the notorious XcodeGhost malware in 2015 that infected WeChat version 6.2.5 alongside 38 other popular iOS applications, affecting hundreds of millions of users. There’s almost no precedent for the heads of defense, state, intelligence and national security to be sharing such sensitive military intelligence in a forum that was known to be unsecured. Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. In a web post, Threema officials said the vulnerabilities applied to an old protocol that’s no longer in use.

They argued that conflating these distinct issues misrepresents the security of the app and unfairly casts doubt on its encryption protocols. The company reiterated its commitment to providing secure and private communication, emphasizing that its core technology remains robust and unaffected by the phishing threats mentioned in the Pentagon advisory. While this specific Teams RCE flaw requires a complex attack chain, past vulnerabilities in enterprise messaging apps have shown the potential for widespread impact. Organizations must rethink their use of third-party apps for sensitive communications. The NSA, in its guidance, has advised government personnel to avoid using Signal for classified or sensitive conversations. While that may not be practical for every business, it’s a strong signal (no pun intended) that not all encrypted apps are created equal.

Microsoft disclosed a significant remote code execution (RCE) vulnerability in its Teams collaboration software as part of its August 2025 Patch Tuesday updates. The implications of these vulnerabilities extend far beyond technical inconvenience. They strike at the heart of trust, trust between colleagues, between brands and customers, and between organizations and the public. When sensitive information leaks, the damage isn’t limited to the immediate breach.

An earlier version of this story incorrectly identified the accidental release of classified data over insecure channels as “slippage” when the incident is minor. The correct term is “spillage,” and the term applies regardless of severity.An earlier version also incorrectly said a recent Pentagon memo about Signal went out before the leak to a reporter in a chat about bombing Houthi sites in Yemen. Gain visibility into your internet-connected assets to eliminate blind spots and unknown sources of risk. Streamline security and IT collaboration and shorten the mean time to remediate with automation.

If one team member’s desktop is compromised, the attacker now has access to the entire conversation thread. That includes draft statements, internal assessments, and real-time strategy adjustments. The fallout could be disastrous, not just in terms of the breach itself, but in how it undermines trust with clients, stakeholders, and the public. Have you ever wondered about the messages you send every day, believing they’re secure?

Shopping Cart
Scroll to Top
× How can I help you?