WhatsApp Messages Exploited in Multi-Stage Malware Attack

A recent security alert reveals that attackers are using WhatsApp messages to deliver malicious Microsoft Installer packages, compromising user systems and data.
Ciberseguridad, vulnerabilidades y privacidad

A recent security alert reveals that attackers are using WhatsApp messages to deliver malicious Microsoft Installer packages, compromising user systems and data.

This week's cybersecurity landscape reveals critical vulnerabilities under active exploitation, alongside notable incidents involving high-profile targets and evolving malware campaigns.

A new malware loader, DeepLoad, utilizes social engineering and advanced evasion techniques to steal browser credentials and maintain persistence on infected systems.

OpenAI has patched a security flaw in ChatGPT that allowed data to be leaked via DNS, raising concerns about data protection.

OpenAI has patched significant vulnerabilities in ChatGPT and Codex that could lead to data exfiltration and GitHub token compromise, according to recent reports.

A public policy expert argues that the FCC's ban on foreign-made routers may compromise security rather than enhance it, framing the policy as industrial protectionism.

A recent email campaign attributed to the Russian threat group TA446 has leveraged the DarkSword exploit kit to target iOS devices, raising concerns about the evolving landscape of mobile security threats.

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability affecting F5 BIG-IP APM to its Known Exploited Vulnerabilities catalog, following evidence of active exploitation.

Citrix NetScaler ADC and Gateway are currently under active reconnaissance due to a critical vulnerability, CVE-2026-3055, which could allow attackers to leak sensitive information.

AFC Ajax has confirmed a data breach that allowed unauthorized access to its internal systems, exposing personal data and enabling ticket manipulation.