ConciseSignal

WeChat patched zero-click worm flaw after researcher demo

Researchers at Calif found and privately reported a flaw in WeChat that let attackers take over accounts on iOS and Android through an incoming call from a contact. The attack did not require the victim to answer. Calif demonstrated the exploit among test phones and said Tencent has blocked the issue as of late August. There are no reports the flaw was used in real attacks.

Why it mattersWeChat accounts can be used for messaging and payments, making them valuable targets. A flaw that needs no user action could have put a large number of users at risk.

Sources covering this

The Hacker NewsWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls11:54 AMHelp Net Security“Zero-click” WeChat worm could hijack accounts and spread via a single call1:40 PM

In this story

AndroidiPhone
Concise Signal DailyEverything that mattered, every weekday at 7am.

More in Cybersecurity

7 sources · 1d ago

OpenAI pledges $1 billion for AI cyber defense program

OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.

2 sources · 3h ago

Google warns of rising attacks on enterprise AI assets

Google Cloud's security team reports that attackers are increasingly targeting enterprise AI systems, including proprietary models, source code, and cloud resources. Threat actors have shifted from using basic AI prompts to deploying automated, multi-agent AI workflows that can execute breaches rapidly, sometimes in under six hours. The report highlights incidents of mass credential theft and the compromise of cloud infrastructure to run unauthorized AI workloads.

3 sources · 4h ago

BigBear 2.0 phishing campaign hits Microsoft 365 accounts

Researchers at CloudSEK have identified a phishing-as-a-service campaign called BigBear 2.0 that stole over 5,100 Microsoft 365 credentials from users in at least 40 countries. Attackers obtained session cookies and passwords, allowing them to bypass multifactor authentication in hundreds of cases. IT service providers were among the most targeted organizations, increasing the possibility of broader downstream attacks.

1 sources · 2h ago

Cloudflare automates post-quantum secure web connections

Cloudflare says it's rolling out Automatic Key Exchange, a system that learns which encryption method each website prefers and uses that from the start. This cuts handshake time for web connections, lowering retries from 52% to 3.7% and shaving over 150 milliseconds off for most people. Hundreds of thousands of sites now have upgraded post-quantum security by default, with no manual setup needed.