The Same-Origin Policy (SOP) is a critical browser security mechanism that prevents scripts from one origin from accessing data on another origin. This endpoint can return complete snapshots of heap memory, approximately 150MB in size, potentially containing plaintext usernames, passwords, and other sensitive data. The application uses cloud-based permission arrays to control JSBridge interface access, providing fine-grained control over webpage capabilities.
More recently, security firm Trend Micro uncovered the “Earth Minotaur” threat group using the Moonshine exploit kit to deploy spyware through WeChat, primarily targeting ethnic minority communities. WeChat’s layered defenses, from URL validation to sandboxed browsers, demonstrate a proactive approach to security. To better communicate CVE status, we are updating CVE status labels and descriptions. Additional details on our new process are available on our CVEs and the NVD Process page. Finally, we have updated the NVD Dashboard to accurately report the status of all CVEs and other NVD statistics in real time. A full definition of critical software and a description of our new workflow, including how we will order our processing queue, is available on the NVD website.
The U.S. has been working since late spring to determine the extent of their activities. This month, the Biden administration said at least eight telecommunications infrastructure companies in the U.S., and possibly more, had been broken into by Chinese hackers. “These are for legitimate wiretaps that have been authorized by the courts,” Hong says. But in hackers’ hands, he says, the tools could potentially be used “to surveil communications and metadata for lots of people. And it seems like the hackers’ focus is primarily Washington, D.C.” She recommends getting 2FA messages through an app like Google Authenticator or Authy or by using a physical security key to verify access. The encrypted Signal app is what Defense Secretary Pete Hegseth and other leading national security officials within the administration used to discuss bombing Houthi sites this month.
- One of the issues with the Conversation Injection technique is that the output from SearchGPT appears clearly to the user, which will raise a lot of suspicion.
- Ó Cearbhaill described the pair of vulnerabilities as a “zero-click” attack, meaning it does not require any user interaction, such as clicking a link, to compromise their device.
- Malicious mini-programs can leverage these permissions to conduct sophisticated attacks if proper permission management is lacking.
The debate over the security of Signal and the appropriateness of its use for government communications is likely to continue. However, Signal’s firm denial of any inherent vulnerabilities within its platform and its clarification regarding the nature of the phishing threats underlines the importance of distinguishing between technical flaws and user-related security risks. This incident serves as a reminder of the ever-present threat of phishing attacks and the need for constant vigilance in protecting personal and sensitive information online, regardless of the platform used. It also underscores the ongoing challenge of balancing the need for secure communication with the convenience and accessibility offered by popular messaging apps. According to the Pentagon, security researchers have identified multiple ways in which attackers can compromise Signal communications without breaking its encryption.
Communications leaders must stop thinking of security as someone else’s job and start treating it as a core part of their own. On an individual level, there are several guidelines anyone can follow to reduce their exposure when using messaging apps. The first is to treat phone numbers and codes received via SMS as sensitive credentials that should never be shared , even if the person requesting them appears to be a friend, a technician, or the app itself.
Timeline
The postMessage API was specifically designed as a controlled exception to this policy, allowing developers to explicitly enable safe, cross-origin communication when needed, provided it is used properly. Critical remediation steps include disabling or restricting access to the /heapdump endpoint, limiting exposure of all Actuator endpoints unless explicitly required, and upgrading to supported Spring Boot versions with secure defaults. This systematic approach to identifying vulnerable systems suggests organized cybercriminal campaigns rather than opportunistic attacks. The platform employs strict validation for sensitive operations, restricting debugging functions and enforcing HTTPS-only protocols with domain validation for configuration changes. Scotland bans WhatsApp for official use, leading a movement towards secure, transparent government communication with platforms like Wire.
That’s a serious liability for any organization handling confidential information, be it corporate strategy, crisis communications, or sensitive negotiations. PostMessage vulnerabilities can represent a significant attack surface in modern web applications, yet they often go undetected due to their client-side nature and the manual analysis required to identify them. When exploited, an insecure postMessage handler can lead to DOM-based XSS, information disclosure, authentication bypasses, and other critical flaws that put both the organization and its users at risk. The recent headlines about vulnerabilities in Signal, a messaging app long touted for its end-to-end encryption and privacy-first design, have sent ripples through the cybersecurity and communications worlds. For professionals in communications, marketing, and PR who rely on secure channels to manage sensitive conversations, these revelations are more than just technical footnotes. They raise urgent questions about how secure our “secure” tools really are, and what’s at stake when those tools fall short.
As agencies work to oust the hackers, the FBI called for Americans to embrace tight encryption — an about-face, Galperin says, after years of insisting that law enforcement agencies need a “back door” to access communications. “Encryption is your friend” for texts and phone calls, Jeff Greene, CISA’s executive assistant director for cybersecurity, said on the briefing call. “Even if the adversary is able to intercept the data, if it is encrypted, it will make it impossible, if not really hard, for them to detect it. So our advice is to try to avoid using plain text.” The CISA released a list of best security practices for smartphone users on Thursday, with specific tips for iPhone and Android owners.
In organizations like the Balearic Islands Health Service , instant messaging has become an essential tool for rapid communication between professionals, but that doesn’t mean you can use just any app you have on your personal phone. The choice of tool directly impacts patient data confidentiality and legal compliance. Messaging apps have become the backbone of modern communication — from birthday planning to boardroom discussions, and even customer support. Their convenience makes them indispensable, but it also introduces serious security risks. Although TM SGNL’s use by U.S. agencies came under scrutiny recently, contracts with TeleMessage date back to at least 2023, well before the current administration.
What does this mean for organizations managing sensitive data, and what should leaders in communications and security be doing right now to reduce exposure? It’s a call for a more disciplined, better-informed approach to communications security, one that acknowledges the real-world tactics of threat actors and the operational blind spots that too many organizations still ignore. In an age where these data breaches pose significant risks to organizational integrity and individual privacy, Wire Secure Messenger emerges as a leading solution for safeguarding sensitive communications. Utilizing state-of-the-art end-to-end encryption, Wire ensures that only authorized users can access messages, reducing interception risks. Its open-source architecture fosters transparency and allows security audits, further enhancing trust in its security measures.
The NVD is updating the CVE Detail page to now include the “affected” list (the list of vulnerable product configurations) and the “SSVC” (Stakeholder-Specific Vulnerability Categorization) score. When available, both sets of data will now be shown on the CVE detail page, with the ‘affected’ section above the ‘Change History’ and SSVC data shown within the ‘Metrics’ section. Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services. After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things.
Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Another issue with Conversation Injection is that it only persists for the current conversation. We found that, similarly to Conversation Injection, SearchGPT can actually get ChatGPT to update its memories, allowing us to create an exfiltration that will happen for every single response. This injection creates a persistent threat that will continue to leak user data even between sessions, days, and data changes. The issue “stems from the platform’s continued use of a legacy confirmation in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication,” the research team told Cointelegraph.
The Project Zero researcher also looked at other popular messaging apps such as Telegram and Viber, but she could not find these particular security flaws. She looked at Telegram in August 2020, and Viber was investigated in November last year. Back in November 2018, the very same researcher brought to daylight a similar loophole in WhatsApp – it was affecting not only Android users, but the security flaw was observed on Apple devices too. For communications, marketing, and PR professionals, these technical flaws translate into operational risks. Confidential media strategies, embargoed press releases, and crisis response plans often flow through encrypted messaging apps. But as we’ve seen, the real risk often lies in how these tools are used, not how they’re built.
Tenable Community Support Portal
By integrating advanced security protocols and a commitment to privacy, Wire enables organizations and individuals to communicate with confidence, free from the looming threat of data breaches. Users can link their account to desktop applications, which are often less secure than mobile devices. If an attacker compromises a desktop, they gain access not only to stored messages but to ongoing conversations as well.
It’s one part of a broader security posture that must include device hygiene, access controls, and user awareness. A vulnerability in Google Messages on Wear OS devices allows any installed app to silently send SMS, MMS, or RCS messages on behalf of the user. It’s not about living in fear, but about being aware that, with a few reasonable measures, most disasters can be avoided. Cellcrypt adopts a zero-knowledge architecture with end-to-end encryption and client-side key control .
Finally, it’s important not to forget the role of messaging apps as a distribution channel for malicious files . The breach exploited a critical vulnerability in TM SGNL’s architecture—a lack of proper end-to-end encryption, which allowed attackers to intercept and access stored chat logs, message metadata, and other application heap dumps. As IM apps integrate more features (payments, mini-programs), their attack surfaces expand, requiring stricter access controls and faster patch cycles.
For developers, prioritizing security without compromising usability is the ultimate challenge one that will define the next era of digital communication. However, their widespread use makes them prime targets for cyberattacks, with vulnerabilities posing a threat to personal privacy, financial assets, and national security. Recent research highlights critical weaknesses in these platforms, underscoring the delicate balance between functionality and security.
This represents a significant escalation in instant messaging security threats, particularly affecting the platform’s hundreds of millions of users worldwide. NIST is committed to maintaining the NVD as a critical component of the nation’s cybersecurity infrastructure. By evolving the NVD to meet today’s challenges, we can ensure that the database remains a reliable, sustainable and publicly available source of information about cybersecurity vulnerabilities. We appreciate the continued collaboration of our partnering agencies and the user community as we make these necessary adjustments. This misconfiguration allows unauthorized attackers to access memory dumps containing potentially sensitive information, including authentication credentials, session tokens, and other confidential data stored in the application’s memory space.
Burp Suite DOM Invader is a browser extension built into Burp Suite’s embedded browser that automatically detects DOM-based vulnerabilities, including postMessage bugs. DOM Invader monitors postMessage traffic, identifies message handlers, and can automatically test for XSS by injecting canary values into messages. It highlights potentially dangerous sinks and provides a visual representation of message flows. Automated tooling will hook the message event listener and detect global postMessage calls. This allows you to test for these vulnerabilities at scale, even when you’re dealing with more complex applications or multiple targets. Of these, 1,582 IPs specifically targeted /health endpoints, commonly used by attackers to identify internet-exposed Spring Boot deployments vulnerable to exploitation.
In this article, we explore how to identify and exploit postMessage vulnerabilities in modern web applications, ranging from basic origin validation bypasses to advanced DOM XSS chains that exploit insecure message handlers. Security experts recommend that users maintain updated application versions and exercise caution when opening files from unknown sources, while organizations should implement comprehensive security monitoring for instant messaging platforms. These platforms handle critical activities including social interactions, financial transactions, and business communications for billions of users globally, making successful attacks particularly devastating.
One of the issues with the Conversation Injection technique is that the output from SearchGPT appears clearly to the user, which will raise a lot of suspicion. We discovered a bug with how the ChatGPT website renders markdown that can allow us to hide the malicious content. When rendering code blocks, any data that appears on the same line as the code block opening (past the first word) does not get rendered. This means that unless copied, the response will look completely innocent to the user, despite containing the malicious context, which will be read by ChatGPT.
Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world. Additionally, WeChat’s mini-program architecture separates rendering and logic layers into isolated threads, preventing cross-layer privilege escalation attacks. Malicious mini-programs can leverage these permissions to conduct sophisticated attacks if proper permission management is lacking. Discover in a quick call how Wire enables secure, compliant, and seamless collaboration for your organization, without compromising on usability or control. “The adversaries we face are tenacious and sophisticated, and working together is the best way to ensure eviction,” the senior FBI official said during the news briefing. The agencies also want companies to bolster their security practices and work with the government to make their networks harder to compromise.
That way, whenever a postMessage event is sent or received, the debugger will pause execution, allowing you to inspect the message data, origin, and source. You can examine the call stack to see exactly where the message is being processed and step through the code to identify potential vulnerabilities. A critical security vulnerability in TeleMessageTM SGNL, an enterprise messaging system modeled after Signal, has been actively exploited by cybercriminals seeking to extract sensitive user credentials and personal data. All the rules can be used across dozens of SIEM, EDR, and Data Lake platforms and are aligned with MITRE ATT&CK®. Additionally, each rule is enriched with CTI links, attack timelines, audit configurations, triage recommendations, what is Dateromances and more extensive metadata.
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. The attack becomes particularly dangerous because modern IM clients automatically parse rich media content, making the exploitation completely transparent to victims. Wire joins the Apple Indigo initiative as a strategic partner, advancing secure, resilient communication for defense, government, and high-assurance…
Never share sensitive information (credit card numbers, social security numbers, passwords) through this form. In marketing, product launch plans, advertising budgets, and influencer contracts often contain sensitive financial and strategic information. As technology evolves, vigilance and continuous improvement will remain the foundation of secure digital communication. Ultimately, breaches often stemmed from weak surrounding systems, not the encryption itself.
For government agencies and businesses handling classified or proprietary information, this can be a significant security risk. Cases have been highlighted where foreign intelligence agencies exploited metadata to map communication networks and infer sensitive relationships between individuals, even if the actual messages remained unreadable. What makes this attack particularly dangerous is its exploitation of WeChat’s debugging URL mechanism and built-in browser features. The app includes debugging functionality triggered when users access URLs containing specific parameters, which attackers can abuse to execute high-risk actions like configuration changes without user awareness.
Interestingly, Apple’s optional LockDown Mode disables the iMessage link preview feature in response to malicious targeting by surveillance spyware vendors. Discover why strong encryption matters in the digital age, and how Wire safeguards secure communication across industries amid global backdoor… These incidents show how crucial it is to have strong security measures to protect user data and prevent future breaches. With the rise of remote work,these platforms keep teams connected and productive, regardless of physical distance. These tools facilitate collaboration by enabling employees to share ideas, documents, and feedback seamlessly. As for the risk to everyday consumers, security experts like Hong and Galperin say that with vast amounts of information traveling between our phones, they want to see people get more help in protecting themselves.