GhostPairing: WhatsApp Hijacking Threat

Security researchers, first reporting via TechRadar in December 2025, warn WhatsApp's 3 billion users of GhostPairing—a technique tricking victims into linking attackers' browsers to their accounts, enabling full access without breaching passwords or end-to-end encryption.

WhatsApp, Meta's popular messaging app with over 3 billion users, faces ongoing risks from GhostPairing, a sophisticated account takeover method uncovered in December 2025. As detailed in TechRadar's December 21 alert, attackers exploit the device linking process to pair invisibly, bypassing standard security alerts and two-factor authentication to access chats, contacts, and data.

The attack's stealth underscores vulnerabilities in widely used apps. Users should immediately review the Linked Devices section to detect and revoke suspicious pairings, and enable all available privacy and security features. Vigilance remains crucial as threats evolve.

Related Articles

Illustration of a developer's desk with a computer screen showing malicious npm packages stealing credentials across platforms, highlighting cybersecurity risks.
Image generated by AI

Malicious npm packages steal developer credentials on multiple platforms

Reported by AI Image generated by AI

Ten typosquatted npm packages, uploaded on July 4, 2025, have been found downloading an infostealer that targets sensitive data across Windows, Linux, and macOS systems. These packages, mimicking popular libraries, evaded detection through multiple obfuscation layers and amassed nearly 10,000 downloads. Cybersecurity firm Socket reported the threat, noting the packages remain available in the registry.

Hackers are targeting WhatsApp users with a new GhostPairing scam that allows full account access without cracking passwords or encryption safeguards. The scam bypasses traditional authentication methods, posing a significant risk to user privacy and security. Users are advised to check the Linked Devices section to detect any compromises.

Reported by AI

A new security flaw known as Silent Whisper puts billions of WhatsApp and Signal users at risk. Attackers can monitor activity without detection, leading to battery drain and revelation of daily routines. An expert has created a tool that exploits this vulnerability to spy on users undetected.

Security experts are cautioning PayPal users about a scam where the platform's subscription feature is being exploited to deliver fraudulent purchase confirmation emails. This abuse leverages the legitimate PayPal system to deceive recipients into believing they have made unauthorized transactions. The warning highlights the need for vigilance in verifying email authenticity.

Reported by AI

Hackers have accessed and stolen personal information from millions of Pornhub users, aiming to use the data for extortion schemes. The incident was highlighted in a WIRED security news roundup.

Security firm Varonis has identified a new method for prompt injection attacks targeting Microsoft Copilot, allowing compromise of users with just one click. This vulnerability highlights ongoing risks in AI systems. Details emerged in a recent TechRadar report.

Reported by AI

Cybersecurity experts warn that hackers are leveraging large language models (LLMs) to create sophisticated phishing attacks. These AI tools enable the generation of phishing pages on the spot, potentially making scams more dynamic and harder to detect. The trend highlights evolving threats in digital security.

 

 

 

This website uses cookies

We use cookies for analytics to improve our site. Read our privacy policy for more information.
Decline