惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Security Affairs

The Hidden Ransomware Economy Running on Exposed Databases Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack Nimbus Manticore Expanded Attacks With AI-Assisted Malware and Fake Zoom Installers Lazarus APT unveils fileless remote access Trojan designed to evade detection Third-Party Cyberattack Impacts Patient Information at The Oncology Institute Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites 340 Million OnlyFans Profiles Allegedly Rebuilt from Leaks Dutch authorities dismantle hosting network allegedly used for cyberattacks and disinformation FBI director Kash Patel’s brand website taken offline after malware reports SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98 Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION Anthropic’s Project Glasswing: 10,000+ Vulnerabilities Found in One Month, and the Patching Problem Has Never Been More Obvious U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack Why pure extortion is replacing traditional ransomware Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets Authorities arrest 23-year-old accused of running the Kimwolf botnet U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalog One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure U.S. CISA adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog Global law enforcement operation takes First VPN offline Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix Cisco fixed maximum severity flaw CVE-2026-20223 in Secure Workload Discord adds end-to-end encryption to voice and video calls by default PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch Microsoft issues YellowKey mitigation, no patch yet Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free A malicious VS code extension just breached GitHub ‘s internal repositories DirtyDecrypt: PoC Released for yet another Linux flaw Alleged Huawei zero-day blamed for the 2025 Luxembourg telecom crash Drupal is rolling out an emergency security update on May 20. You cannot miss it Microsoft dismantled malware-signing network Fox Tempest Poland shifts away from Signal following cyberattacks on officials’ accounts Massive MENA cybercrime Operation Ramz disrupts infrastructure and arrests 201 suspects Shai-Hulud worm copycats emerge after source code leak Grafana confirms GitHub token breach cybercrime group claims the attack ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed Public Amazon bucket leaks sensitive guest data from Japanese hotel platform Tabiq Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fix Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97 Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog Russian APT Turla builds long-term access tool with Kazuar Botnet evolution OpenAI hit by supply chain attack linked to malicious TanStack packages Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day Ghostwriter group resumes attacks on Ukrainian Government targets Researchers uncover YellowKey and GreenPlasma Windows Zero-Days Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall U.S. CISA adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog Linux Kernel bug Fragnesia allows local root access attacks Broadcom releases VMware Fusion security update for root access bug NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to light FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign Nitrogen Ransomware claims massive data theft from Foxconn Microsoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarming OpenLoop Health confirms January 2026 Data breach affecting 716,000 Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations Instructure settles with hackers following massive student data theft Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator Hackers accessed BWH Hotels reservation system for months The world’s most “Dangerous” AI, Anthropic’s Mythos, found only one flaw in curl Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor WannaCry, the ransomware attack that changed the history of cybersecurity Android banking Trojan TrickMo evolves using TON network for C2 Identity security firm SailPoint discloses GitHub repository breach Google warns artificial intelligence is accelerating cyberattacks and zero-day exploits Crimenetwork returns after takedown, dismantled again by German authorities U.S. CISA adds a flaw in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog Instagram removed end-to-end encryption for DMs. What should users do? New cPanel vulnerabilities could allow file access and remote code execution Official JDownloader site served malware to Windows and Linux users between May 6 and May 7 SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 96 Security Affairs newsletter Round 576 by Pierluigi Paganini – INTERNATIONAL EDITION Quasar Linux RAT (QLNX): A Fileless Linux Implant Built for Stealth and Persistence Braintrust security incident raises concerns over AI supply chain risks RansomHouse says it breached Trellix and exposes internal systems Cyberattacks on Poland’s Water Plants: A Blueprint for Hybrid Warfare Zara Data Breach: 197,000 Customers Exposed in Third-Party Security Incident Dirty Frag: A new Linux privilege escalation vulnerability is already in the wild AI, Cyberwarfare, and Autonomous Weapons: Inside America’s New Military Strategy Nation-state actors exploit Palo Alto PAN-OS zero-day for weeks U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog Cisco patches high-severity flaws enabling SSRF, code execution attacks From Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacks U.S. CISA adds a flaw in Palo Alto Networks PAN-OS to its Known Exploited Vulnerabilities catalog Taiwan High-Speed Rail Emergency Braking Hack: How a Student Stopped the Trains and Exposed a Major Security Gap After 17 years, Gavril Sandu extradited to U.S. for hacking scheme Iranian cyber espionage disguised as a Chaos Ransomware attack Apache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCE Palo Alto Networks PAN-OS flaw exploited for remote code execution Malicious PyTorch Lightning update hits AI supply chain security U.S. court sentences Karakurt ransomware negotiator to 8.5 years Vimeo confirms breach via third-party vendor impacts 119K users Critical Android vulnerability CVE-2026-0073 fixed by Google
Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
Pierluigi Pa · 2026-05-25 · via Security Affairs

A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction.

There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked Devices” section in the app, it shows nothing. No unauthorized sessions, no suspicious logins, no QR codes scanned by mistake. Just your phone, your account, and someone else apparently using it at the same time.

That is exactly what happened to multiple iPhone users in Italy over the past few weeks, and the forensic investigation that followed has uncovered what appears to be an active zero-click exploitation campaign targeting a specific combination of iOS version and WhatsApp client.

The cases were brought to the attention of the Italian digital forensics firm Forenser by users who had all experienced the same bizarre pattern: messages sent from their WhatsApp number to recent contacts requesting wire transfers, with no memory of having sent them and no trace of any linked device in the app’s settings. The firm’s analysis, published this week, reveals a technically sophisticated attack that exploits known vulnerabilities in iOS 16 to gain unauthorized access to WhatsApp sessions without requiring any user interaction.

What the victims saw

The common thread across all reported cases was striking in its consistency. Every affected user was running an iPhone, models ranging from iPhone 8 through iPhone 14, including X, XR, XS, 11, SE, 12, and 13 variants, with some version of iOS 16 installed. The attackers gained access to recent chat conversations and sent messages requesting money transfers, but appeared unable to see older or archived chats. Most importantly, none of the victims recalled doing anything that would have authorized a new device: no QR codes scanned, no verification codes shared, no pairing process completed.

That ruled out the standard “ghost pairing” social engineering technique where an attacker tricks a victim into scanning a malicious QR code. What remained was something more concerning: a zero-click compromise requiring no action from the victim at all.

The first technical clue came from forensic analysis of iOS unified logs and sysdiagnose data from a compromised device. As Forenser described it.

“Analyzing the logs from one of the forensic copies and the related sysdiagnose, it was possible to notice an anomaly in the logs generated by WhatsApp: a continuous sequence of ‘resync’ events, as if the application were continuously renegotiating the session with WhatsApp servers.” reads the analysis published by Forenser.”These are events not very common and present in unusual quantity, unless someone else is attempting in parallel to keep their own session active on the same account.”

That pattern, continuous session resynchronization, is the signature of two endpoints competing to maintain control over the same WhatsApp account. The legitimate phone and the attacker’s client were repeatedly re-authenticating with WhatsApp’s servers in a cycle, with neither side fully displacing the other. This explained why messages were being sent without the victim’s knowledge while the “Linked Devices” section remained empty: the attacker’s session was not registered as a linked device in the traditional sense.

The researchers pointed out that every single case involved iOS 16. That specificity led Forenser’s team to investigate known vulnerabilities in that version of Apple’s operating system, and they found a plausible culprit: CVE-2025-43300, potentially in combination with CVE-2025-55177.

The CVE-2025-43300 vulnerability is an out-of-bounds write issue that resides in the ImageIO framework. An attacker could exploit it to cause memory corruption when processing a malicious image. Apple addressed the flaw in August 2025, after it discovered it was actively exploited as a zero-day in attacks targeting iOS, iPadOS, and macOS.

CVE-2025-55177 is a WhatsApp-specific flaw on iOS and macOS that allowed parsing of content from arbitrary URLs via improperly authorized linked-device sync messages. According to the CVE description, iOS versions below 16.7.12 are vulnerable; versions matching those found on all the compromised devices analyzed by Forenser.

Supporting this theory, the unified logs from affected devices contained multiple errors generated by the image processing library, occurring at times consistent with when the WhatsApp account compromise took place.

Forenser’s team reproduced part of the attack scenario in a controlled lab environment using a test device running a vulnerable iOS version. The reproduction confirmed that an attacker who successfully exploits the vulnerability can extract cryptographic material needed for the WhatsApp session handshake directly from the compromised device. That material can then be used to instantiate a new WhatsApp client elsewhere, attached to the victim’s account, without triggering any visible notification on the victim’s phone or in the WhatsApp app itself.

“Starting from the compromised device, it is possible to exfiltrate the cryptographic material useful for the session initiation handshake, necessary to instantiate a new WhatsApp client elsewhere, but hooked to the victim’s account.” continues the report. “It is precisely in this phase that the continuous sequence of ‘resync’ in the logs is generated (found similarly in our lab tests): the legitimate phone and the attacker’s client contend for the session, cyclically re-authenticating on WhatsApp servers.”

This model matches exactly what was observed in the real-world cases: an account sending messages to recent contacts despite a complete absence of linked devices visible in the app settings.

Since this appears to be a zero-click attack, traditional user hygiene measures like “don’t click suspicious links” do not apply. The most effective mitigation is straightforward: update iOS to the latest available version. CVE-2025-43300 has been patched in releases beyond iOS 16, and every compromised device analyzed by Forenser was running an unpatched iOS 16 build.

For users who suspect their account is already compromised, Forenser’s observations suggest a few practical steps. Locking chats using WhatsApp’s built-in chat lock feature (which hides conversations behind a PIN or biometric authentication) appears to prevent attackers from reading or writing to those chats. Updating the WhatsApp app itself, or reinstalling it on a new device and completing a fresh authentication, seems effective at evicting the attacker’s session. And since all observed cases involved iOS 16, upgrading the operating system should remove the underlying conditions the attack relies on.

One important note for anyone receiving suspicious money requests via WhatsApp: do not reply in the same chat to verify whether the request is legitimate. The attacker may see your response before the legitimate account owner does. Call the person directly instead.

This incident is a reminder that zero-click exploits, once the domain of state-sponsored actors with significant resources, are increasingly appearing in financially motivated cybercrime. The combination of known CVEs, widely available technical documentation, and a large population of devices running unpatched iOS 16 creates conditions where sophisticated attacks become operationally feasible for a broader range of threat actors.

Forenser’s team is continuing to collect forensic images and analyze the attack model in greater detail. In the meantime, the operational recommendation is clear: if you are running iOS 16 on an iPhone, update to the latest patch immediately. The gap between vulnerability disclosure and active exploitation continues to shrink, and in this case, the exploitation window is already open.

In December, attackers were spotted exploiting WhatsApp’s device-linking feature to hijack accounts using pairing codes in a campaign dubbed GhostPairing, without requiring authentication.

Gen Digital first observed the GhostPairing campaign in Czechia, but the attacks spread globally via compromised accounts.

The attack chain begins with victims receiving a message, such as “Hey, I just found your photo!”, from a trusted contact. The message contains a link with a Facebook-style preview.

The links used in the attack led to fake Facebook lookalike domains, not real Facebook sites, using photo-related names and misleading login paths.

The link leads to a fake Facebook viewer that prompts users to “verify” to see the content. By following a short, seemingly harmless sequence of steps, victims unknowingly grant attackers full access to their WhatsApp accounts, without any password theft or SIM swap.

Clicking the WhatsApp link takes victims to a minimal fake Facebook page designed to build trust and prompt verification.

The page acts as a control layer, abusing WhatsApp Web rather than Facebook. Victims are shown either a QR code or, more often, a numeric code to enter in WhatsApp.

Attackers trick victims into entering the code to link a new device, a warning many users overlook.

By completing this step, users unknowingly link the attacker’s browser as a trusted device, giving full access to messages, photos, and account activity.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, WhatsApp)