GhostPairing: WhatsApp Hijacking Threat

Security researchers, first reporting via TechRadar in December 2025, warn WhatsApp's 3 billion users of GhostPairing—a technique tricking victims into linking attackers' browsers to their accounts, enabling full access without breaching passwords or end-to-end encryption.

WhatsApp, Meta's popular messaging app with over 3 billion users, faces ongoing risks from GhostPairing, a sophisticated account takeover method uncovered in December 2025. As detailed in TechRadar's December 21 alert, attackers exploit the device linking process to pair invisibly, bypassing standard security alerts and two-factor authentication to access chats, contacts, and data.

The attack's stealth underscores vulnerabilities in widely used apps. Users should immediately review the Linked Devices section to detect and revoke suspicious pairings, and enable all available privacy and security features. Vigilance remains crucial as threats evolve.

Makala yanayohusiana

IT expert Supangat warns of Lebaran digital scams via WhatsApp and SMS in a press conference illustration.
Picha iliyoundwa na AI

IT expert warns of digital scams ahead of Lebaran

Imeripotiwa na AI Picha iliyoundwa na AI

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

Hackers are targeting WhatsApp users with a new GhostPairing scam that allows full account access without cracking passwords or encryption safeguards. The scam bypasses traditional authentication methods, posing a significant risk to user privacy and security. Users are advised to check the Linked Devices section to detect any compromises.

Imeripotiwa na AI

A new security flaw known as Silent Whisper puts billions of WhatsApp and Signal users at risk. Attackers can monitor activity without detection, leading to battery drain and revelation of daily routines. An expert has created a tool that exploits this vulnerability to spy on users undetected.

Custom-made vishing kits are attacking single sign-on (SSO) accounts across the globe. Major providers including Google, Microsoft, and Okta face threats from these tools. The effectiveness of the kits is driving increased popularity in vishing attacks.

Imeripotiwa na AI

A new Google research report indicates that the cloud security threat landscape is rapidly evolving. Hackers are increasingly targeting third parties and software vulnerabilities to breach systems. The report also notes a decline in cloud misconfigurations.

Cisco Talos has detailed how a Chinese-linked group is exploiting an unpatched zero-day in email security appliances since late November 2025, deploying backdoors and log-wiping tools for persistent access.

Imeripotiwa na AI

WhatsApp may soon add a feature to hide spoilers in group chats, similar to one on Reddit. This would help users avoid plot reveals for popular shows if they are catching up. The development was reported in a TechRadar article published on February 21, 2026.

Jumatano, 11. Mwezi wa tatu 2026, 20:37:58

Meta launches parent-managed WhatsApp accounts for children under 13

Jumatano, 11. Mwezi wa tatu 2026, 02:47:16

Dutch intelligence accuses Russia of hacker attacks on WhatsApp and Signal

Jumamosi, 7. Mwezi wa tatu 2026, 21:02:03

Fake IT support scam infects company devices with Havoc malware

Jumapili, 1. Mwezi wa tatu 2026, 00:38:16

Hacked prayer app sends surrender messages to Iranians amid strikes

Alhamisi, 26. Mwezi wa pili 2026, 18:56:46

Coalition urges Google to reverse Android developer verification policy

Ijumaa, 13. Mwezi wa pili 2026, 14:32:48

Fake Chrome AI extensions targeted over 300,000 users

Jumatatu, 9. Mwezi wa pili 2026, 21:38:38

Photo ID apps leak user data affecting over 150,000

Alhamisi, 15. Mwezi wa kwanza 2026, 04:11:19

Flaw in Google Fast Pair devices allows hackers to eavesdrop

Alhamisi, 1. Mwezi wa kwanza 2026, 11:23:01

Trust Wallet confirms second Shai-Hulud supply-chain attack

Jumatano, 29. Mwezi wa kumi 2025, 11:29:39

Malicious npm packages steal developer credentials on multiple platforms

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa