vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user interaction – visiting a crafted webpage – and doesn't necessitate malware installation or credenti… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach
threat-intel Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws Researchers have identified three security flaws in OpenClaw, an AI assistant, that could allow attackers to steal credentials, escalate privileges, and execute arbitrary code on the host system. These vulnerabilities ca… The Hacker News · Jul 10, 2026 High vulnerabilitysandboxcommand injection
threat-intel US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The United States government is offering a $10 million reward for information leading to the identification of Russian cyber groups involved in targeting Signal and WhatsApp accounts. These groups, UNC5792 and UNC4221, a… The Record · Jun 29, 2026 High USUKRUsocial engineeringencryptionespionage
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
threat-intel NSO Group Hacking WhatsApp Despite Court Order Recent reports indicate that NSO Group, a cybersecurity firm specializing in offensive intelligence, has been found to be utilizing its Pegasus spyware to target WhatsApp users despite a court order restricting its use.… Schneier on Security · Jun 10, 2026 High spywarewhatsappnsogroup