Best of 2020: Signal App Crypto Cracked, Claims Cellebrite

The Signal app has been cracked—its encryption is broken. That’s the preposterous claim made by Cellebrite.
The post Best of 2020: Signal App Crypto Cracked, Claims Cellebrite appeared first on Security Boulevard.
Continue reading Best of 2020: Signal App Crypto Cracked, Claims Cellebrite

Signal App, Jenkins Servers, & WordPress – Application Security Weekly #44

Facebook bug exposed private photos of 6.8 million users, thousands of Jenkins servers will let anonymous users become admins, Signal app can’t include a backdoor for the Australian government, WordPress plugs bug that led to Google indexing some… Continue reading Signal App, Jenkins Servers, & WordPress – Application Security Weekly #44

Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

For the second time in less than a week, users of the popular end-to-end encrypted Signal messaging app have to update their desktop applications once again to patch another severe code injection vulnerability.

Discovered Monday by the same team of se… Continue reading Another severe flaw in Signal desktop app lets hackers steal your chats in plaintext

Signal App Delivers Timely Patch for Code Injection Vulnerability that Allows Remote Code Execution

A recent vulnerability in the Signal messaging application that enables encrypted communication between parties, could have enabled attackers to arbitrarily remotely execute code on the victim’s device without any user interaction. Security resea… Continue reading Signal App Delivers Timely Patch for Code Injection Vulnerability that Allows Remote Code Execution

Hackers Reveal How Code Injection Attack Works in Signal Messaging App

After the revelation of the eFail attack details, it’s time to reveal how the recently reported code injection vulnerability in the popular end-to-end encrypted Signal messaging app works.

As we reported last weekend, Signal has patched its messaging … Continue reading Hackers Reveal How Code Injection Attack Works in Signal Messaging App

Self-destructing messages received on ‘Signal for Mac’ can be recovered later

It turns out that macOS client for the popular end-to-end encrypted messaging app Signal fails to properly delete disappearing (self-destructing) messages  from the recipient’s system, leaving the content of your sensitive messages at risk of getting e… Continue reading Self-destructing messages received on ‘Signal for Mac’ can be recovered later

WhatsApp Flaw Could Allow ‘Potential Attackers’ to Spy On Encrypted Group Chats

A more dramatic revelation of 2018—an outsider can secretly eavesdrop on your private end-to-end encrypted group chats on WhatsApp and Signal messaging apps.

Considering protection against three types of attackers—malicious user, network attacker, and… Continue reading WhatsApp Flaw Could Allow ‘Potential Attackers’ to Spy On Encrypted Group Chats

A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits

How much does your privacy cost?

It will soon be sold for half a Million US dollars.

A controversial company specialises in acquiring and reselling zero-day exploits is ready to pay up to US$500,000 for working zero-day vulnerabilities targeting popu… Continue reading A Company Offers $500,000 For Secure Messaging Apps Zero-Day Exploits