WeChat patched zero-click worm flaw after researcher demo
Researchers at Calif found and privately reported a flaw in WeChat that let attackers take over accounts on iOS and Android through an incoming call from a contact. The attack did not require the victim to answer. Calif demonstrated the exploit among test phones and said Tencent has blocked the issue as of late August. There are no reports the flaw was used in real attacks.
- Attack worked on both iOS and Android devices
- Victims targeted via calls from existing contacts
- Exploit gave full account control to attacker
- Tencent mitigation does not require user update
- No evidence of exploitation in the wild
Sources covering this
In this story
More in Cybersecurity
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
Google warns of rising attacks on enterprise AI assets
Google Cloud's security team reports that attackers are increasingly targeting enterprise AI systems, including proprietary models, source code, and cloud resources. Threat actors have shifted from using basic AI prompts to deploying automated, multi-agent AI workflows that can execute breaches rapidly, sometimes in under six hours. The report highlights incidents of mass credential theft and the compromise of cloud infrastructure to run unauthorized AI workloads.
BigBear 2.0 phishing campaign hits Microsoft 365 accounts
Researchers at CloudSEK have identified a phishing-as-a-service campaign called BigBear 2.0 that stole over 5,100 Microsoft 365 credentials from users in at least 40 countries. Attackers obtained session cookies and passwords, allowing them to bypass multifactor authentication in hundreds of cases. IT service providers were among the most targeted organizations, increasing the possibility of broader downstream attacks.
Cloudflare automates post-quantum secure web connections
Cloudflare says it's rolling out Automatic Key Exchange, a system that learns which encryption method each website prefers and uses that from the start. This cuts handshake time for web connections, lowering retries from 52% to 3.7% and shaving over 150 milliseconds off for most people. Hundreds of thousands of sites now have upgraded post-quantum security by default, with no manual setup needed.