<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/mobile-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 18 Sep 2026 22:44:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Mobile Security &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>New Android Feature Flags Missing Security Updates</title>
		<link>https://firsthackersnews.com/android-security-patch-status-apps/</link>
					<comments>https://firsthackersnews.com/android-security-patch-status-apps/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 22:44:11 +0000</pubDate>
				<category><![CDATA[Android malware]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[Google Android]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[Security patches]]></category>
		<category><![CDATA[Security updates]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12420</guid>

					<description><![CDATA[<p>Android has introduced new Security State libraries that allow apps and enterprise security tools to get a clearer</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-security-patch-status-apps/">New Android Feature Flags Missing Security Updates</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Android has introduced new <strong>Security State libraries</strong> that allow apps and enterprise security tools to get a clearer picture of a device’s security status.</p>



<p>Instead of relying only on the traditional Android Security Patch Level date, applications can now check whether important system components, modules, or kernel fixes are missing or available.</p>



<p>The new release includes <strong>AndroidX Security State 1.1.0</strong> and <strong>Security State Provider 1.0.0</strong>. The libraries are aimed at applications where device security is especially important, including banking, healthcare, financial services, enterprise mobility, and Mobile Device Management platforms.</p>



<h2 class="wp-block-heading"><strong>More Detailed Patch Information</strong></h2>



<p>Android devices do not receive every security update through the same channel. Some fixes come from the phone manufacturer, while other components can be updated through Google Play system updates. Linux kernel updates may follow separate Long-Term Support releases.</p>



<p>Because of this, a single patch date does not always provide a complete picture of a phone’s security.</p>



<p>The new Security State libraries can provide information about three different patch levels:</p>



<ul class="wp-block-list">
<li><strong>Device Security Patch Level:</strong> The security level currently installed on the device.</li>



<li><strong>Published Security Patch Level:</strong> The latest security level published through the Android Security Bulletin.</li>



<li><strong>Available Security Patch Level:</strong> A security update that is available for the specific device but has not yet been installed.</li>
</ul>



<p>The checks can cover:</p>



<ul class="wp-block-list">
<li>Android system components</li>



<li>Modular system components</li>



<li>Linux kernel versions</li>
</ul>



<p>This gives applications a more detailed view of which parts of a device are protected and which may still require an update.</p>



<h2 class="wp-block-heading"><strong>Useful for Banking and Enterprise Apps</strong></h2>



<p>The new APIs could allow security-sensitive applications to make decisions based on the actual security state of a device.</p>



<p>For example:</p>



<ul class="wp-block-list">
<li>A banking app could check for important pending security updates before allowing a high-value transaction.</li>



<li>An enterprise app could verify that a managed phone meets the organization&#8217;s security requirements.</li>



<li>A payment application could check whether relevant NFC security fixes have been installed.</li>



<li>An application using Bluetooth could verify whether important Bluetooth-related vulnerabilities have been addressed.</li>
</ul>



<p>Apps could also detect when an update is already available and direct users to Android Settings to install it rather than immediately blocking access.</p>



<p>The libraries can also support vulnerability-specific checks, allowing developers to look at whether fixes for particular security issues have been applied.</p>



<h2 class="wp-block-heading"><strong>Better Visibility for Android Security</strong></h2>



<p>The Security State libraries can use Android security information to provide more accurate assessments of device protection.</p>



<p>Android 17 also adds support for <strong>Supplemental Patches XML</strong>, which allows manufacturers to report security fixes that have been applied before they appear in a complete monthly security patch.</p>



<p>This means an OEM can communicate that a particular vulnerability has already been fixed even when the device has not yet received a newer overall patch-level date.</p>



<p>The Security State Provider also gives update providers a standard way to report available updates to Android applications and management platforms.</p>



<p>Google is working with device manufacturers to bring their update systems into this broader framework.</p>



<p>Overall, the new libraries give developers and enterprise security teams a better way to understand Android patch status. Instead of judging security from a single date, applications can now look more closely at individual components and determine whether important fixes are installed, available, or still missing.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-security-patch-status-apps/">New Android Feature Flags Missing Security Updates</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/android-security-patch-status-apps/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Adds Extra Protection for Private Chats</title>
		<link>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/</link>
					<comments>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 17:54:15 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Chat Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Restricted Chat]]></category>
		<category><![CDATA[whatsapp]]></category>
		<category><![CDATA[WhatsApp linked devices]]></category>
		<category><![CDATA[WhatsApp privacy feature]]></category>
		<category><![CDATA[WhatsApp private chats]]></category>
		<category><![CDATA[WhatsApp Restricted Chat]]></category>
		<category><![CDATA[WhatsApp security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12369</guid>

					<description><![CDATA[<p>WhatsApp is working on a new privacy feature called Restricted Chat that could give users more control over</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-restricted-chat-privacy/">WhatsApp Adds Extra Protection for Private Chats</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp is working on a new privacy feature called <strong>Restricted Chat</strong> that could give users more control over where sensitive conversations are available.</p>



<p>The feature is designed to keep selected chats on the user&#8217;s <strong>main phone</strong> instead of syncing them to WhatsApp Web, desktop apps, or other phones connected to the same account.</p>



<p>Restricted Chat was spotted in <strong>WhatsApp Android beta version 2.26.36.5</strong>, but it is still being developed and has not been released for beta testing yet.</p>



<p>WhatsApp has also not confirmed when the feature will become available to the public.</p>



<h2 class="wp-block-heading"><strong>Restricted Chat Limits Access on Linked Devices</strong></h2>



<p>The new option appears to build on WhatsApp&#8217;s existing <strong>Advanced Chat Privacy</strong> controls. Rather than applying stronger restrictions to an entire account, users would be able to select individual conversations that need additional protection.</p>



<p>Once enabled, a restricted conversation is expected to remain available only on the primary phone.</p>



<p>It would not be synchronized with:</p>



<ul class="wp-block-list">
<li>WhatsApp Web</li>



<li>WhatsApp desktop applications</li>



<li>Secondary phones</li>



<li>Other linked devices</li>
</ul>



<p>This could be useful when users regularly connect their WhatsApp account to computers, tablets, or additional phones.</p>



<p>For example, a confidential conversation could remain on a person&#8217;s main smartphone while normal chats continue to work across their other connected devices.</p>



<p>The approach could also reduce the risk of sensitive messages being exposed through an unattended computer, shared workstation, or unknown linked session.</p>



<h2 class="wp-block-heading"><strong>Useful for Sensitive Conversations</strong></h2>



<p>Restricted Chat could be particularly helpful for people handling confidential information, including:</p>



<ul class="wp-block-list">
<li>Business executives</li>



<li>Journalists</li>



<li>Security and incident response teams</li>



<li>Legal professionals</li>



<li>Activists</li>



<li>Organizations handling sensitive customer or business data</li>
</ul>



<p>The feature is also expected to retain several protections associated with Advanced Chat Privacy. These may include preventing chat exports, stopping media from automatically appearing in the device gallery, and restricting the use of messages with Meta AI.</p>



<p>However, Restricted Chat will <strong>not completely prevent information from being shared</strong>. Someone participating in the conversation could still manually copy information, photograph a screen, or share messages outside WhatsApp.</p>



<p>The feature is therefore better viewed as an additional access-control layer rather than a complete solution against data leaks.</p>



<p>For now, Restricted Chat remains under development on Android. Installing the identified beta version does not activate the feature, and WhatsApp has not provided a confirmed release date.</p>



<p>Until it becomes available, users should regularly review their <strong>Linked Devices</strong> and remove any sessions they do not recognize.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-restricted-chat-privacy/">WhatsApp Adds Extra Protection for Private Chats</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-restricted-chat-privacy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Strengthens Security With WhatsApp passkeys</title>
		<link>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/</link>
					<comments>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:57:05 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[account security]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Passkeys]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Two-Step Verification]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12269</guid>

					<description><![CDATA[<p>WhatsApp is taking a major step toward stronger and simpler account security. More than 1 billion people are</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/">WhatsApp Strengthens Security With WhatsApp passkeys</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp is taking a major step toward stronger and simpler account security. More than <strong>1 billion people are now using WhatsApp passkeys</strong> to protect their WhatsApp accounts, making it one of the biggest passwordless authentication rollouts in the consumer technology space.</p>



<p>Along with this milestone, WhatsApp is introducing stronger two-step verification and additional information for calls from unknown numbers. These updates are designed to make accounts harder to compromise while helping users recognize potential scams.</p>



<p>The integration of WhatsApp passkeys is part of WhatsApp&#8217;s ongoing commitment to enhancing user safety and privacy.</p>



<h2 class="wp-block-heading"><strong>Passkeys Make WhatsApp Accounts Safer</strong></h2>



<p>Passkeys allow users to sign in using security features already available on their devices, such as a <strong>fingerprint, Face ID, or screen lock</strong>. Unlike traditional passwords or SMS codes, passkeys use cryptographic credentials that remain securely associated with the user&#8217;s device.</p>



<p>This makes them much more resistant to phishing, credential theft, and other attacks that depend on tricking users into revealing login information.</p>



<p>WhatsApp has now reached more than 1 billion passkey users and is expanding support for people who use multiple devices or switch between Android and iPhone.</p>



<p>Users can manage their passkeys through <strong>Settings &gt; Account &gt; Passkeys</strong>, where they can add or review their available credentials.</p>



<p>The milestone is significant because messaging accounts contain valuable personal information and are increasingly targeted by attackers looking to steal conversations, impersonate users, or target their contacts.</p>



<h2 class="wp-block-heading"><strong>Stronger Two-Step Verification</strong></h2>



<p>WhatsApp is also giving its two-step verification system a security upgrade. Instead of relying only on the traditional six-digit PIN, users can now create a stronger password.</p>



<p>The new password must be at least <strong>eight characters long</strong>, with at least one letter and one number. Users can also add special characters for additional protection.</p>



<p>A longer password provides a much larger combination of possible values than a short numeric PIN, making simple guessing and automated attacks more difficult.</p>



<p>Users who have been using an easy-to-guess PIN should take this opportunity to switch to a unique and stronger password.</p>



<h2 class="wp-block-heading"><strong>More Context for Unknown Calls</strong></h2>



<p>WhatsApp is also adding another layer of protection against scams by providing more information when users receive calls from unknown numbers on Android.</p>



<p>The incoming call screen can show details such as whether the number is from another country or whether the caller shares a group with the recipient.</p>



<p>This additional context can help users pause before answering a suspicious call or responding to an unexpected request. That is particularly useful because many scams rely on urgency and social engineering rather than technical exploits.</p>



<p>Together, <strong>passkeys, stronger two-step verification, and improved caller information</strong> give WhatsApp users several layers of protection against phishing, account takeovers, and social-engineering attacks.</p>



<p>For users, the message is straightforward: enable passkeys when available, use a strong two-step verification password, and be cautious when dealing with unfamiliar callers or unexpected requests for sensitive information.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/">WhatsApp Strengthens Security With WhatsApp passkeys</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-passkeys-1-billion-users/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Scammers Use WhatsApp to Manipulate Stocks</title>
		<link>https://firsthackersnews.com/whatsapp-stock-scam/</link>
					<comments>https://firsthackersnews.com/whatsapp-stock-scam/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 21 Aug 2026 17:04:46 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12245</guid>

					<description><![CDATA[<p>Scammers are using WhatsApp groups to convince ordinary investors to buy specific stocks. Instead of stealing money directly</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-stock-scam/">Scammers Use WhatsApp to Manipulate Stocks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Scammers are using WhatsApp groups to convince ordinary investors to buy specific stocks. Instead of stealing money directly from a bank or brokerage account, they manipulate victims into making legitimate trades themselves.</p>



<p>The campaigns typically begin with short-lived advertisements featuring fake financial experts or deepfake videos. The ads promise exclusive stock tips and encourage people to join WhatsApp groups.</p>



<p>Once inside, victims are connected with a convincing “analyst” who provides a stock name, buying price and expected target. The advice appears professional, but the real goal is to create artificial demand and push the stock price higher.</p>



<p>Researchers at Group-IB discovered the activity while investigating two organized investment-fraud operations known as GoldBull and CoinLure.</p>



<h2 class="wp-block-heading"><strong>How the Stock Scam Works</strong></h2>



<p>GoldBull uses advertisements designed to look like they come from trusted financial professionals. The ads are often available for only a short time, creating a sense of urgency.</p>



<p>Potential victims are filtered based on their location and redirected into WhatsApp groups. There, the fake analyst encourages members to purchase a genuine small-cap stock using their normal brokerage accounts.</p>



<p>Victims may also be asked to provide proof that they completed the purchase. This helps scammers generate enough buying activity to influence thinly traded stocks.</p>



<p>In one case, investors were told on November 6, 2025, to buy a NASDAQ-listed stock at $24.79, with a target price of $29. The stock eventually reached $27.87 on December 9, giving it a 12.4% gain.</p>



<p>The scammers used the opportunity to sell their own holdings. The promised $29 target was never reached, and by February, the stock had fallen to $14.27—about 42% below the victims’ original purchase price.</p>



<p>The scam therefore works without compromising a brokerage account. <strong>The victims make the trades themselves, while the scammers profit from the resulting price movement.</strong></p>



<h2 class="wp-block-heading"><strong>Fake Investment Platforms Add Another Layer</strong></h2>



<p>The related CoinLure operation takes a different approach by directing victims toward fake investment websites.</p>



<p>Scammers use search-engine pages, social media advertisements and even romance-based manipulation to attract potential victims. The fraudulent platforms are designed to look legitimate, with registration pages, identity checks and even fake trial balances.</p>



<p>After victims deposit money, they may be told they need to pay additional fees before they can withdraw it. Common excuses include taxes, insurance charges, minimum balance requirements, account upgrades and technical problems.</p>



<p>Some victims are later contacted by supposed recovery services that demand another payment to recover their funds.</p>



<p>Investigators found one CoinLure platform connected to 208 domains that shared templates, hosting infrastructure and contact information. This shows how one fraudulent website can be part of a much larger network.</p>



<p>For investors, rushed stock recommendations, guaranteed profits, deepfake financial advertisements and WhatsApp groups asking for proof of purchases should all be treated as major warning signs. Always verify investment advice independently and use official brokerage channels rather than links or instructions provided through suspicious chat groups.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-stock-scam/">Scammers Use WhatsApp to Manipulate Stocks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-stock-scam/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Scam Alert: New Protection Against Hackers</title>
		<link>https://firsthackersnews.com/whatsapp-scam-alert-feature/</link>
					<comments>https://firsthackersnews.com/whatsapp-scam-alert-feature/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 12 Aug 2026 16:54:49 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[AI security]]></category>
		<category><![CDATA[cyber threats]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Messaging Security]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Online scams]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Scam Alert]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[whatsapp]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12190</guid>

					<description><![CDATA[<p>WhatsApp has introduced a new optional feature called Scam Alert to help users identify potentially fraudulent messages while</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>WhatsApp has introduced a new optional feature called <strong>Scam Alert</strong> to help users identify potentially fraudulent messages while keeping its end-to-end encryption intact.</p>



<p>The feature is designed to address the growing use of more convincing scams, including messages created with the help of AI. Instead of sending messages to WhatsApp’s servers for analysis, Scam Alert uses a small machine learning model that runs directly on the user’s device.</p>



<p>Once enabled, the model examines messages from people who are not saved as contacts. It looks for patterns in the conversation and language that may indicate common scam techniques.</p>



<p>The message itself stays on the device during this process. WhatsApp says it does not automatically send messages to Meta, WhatsApp, or another third party for review. Users decide what happens next.</p>



<p>If a message appears suspicious, WhatsApp can display a warning to the recipient. The user can then choose to <strong>block the sender, report the conversation, continue chatting, or mark the conversation as trusted</strong> if they believe the warning is incorrect.</p>



<h3 class="wp-block-heading">Privacy Is a Key Part of Scam Alert</h3>



<p>WhatsApp says the system was designed around three main ideas: <strong>local processing, no automatic reporting, and user control</strong>.</p>



<p>The company still needs some information to understand how well the feature performs. Instead of collecting individual messages, WhatsApp uses a privacy-focused analytics system that gathers limited information such as how many warnings were displayed and what actions users took.</p>



<p>This information is processed using <strong>Trusted Execution Environments (TEEs)</strong> and additional privacy techniques before aggregated statistics are sent to Meta.</p>



<h3 class="wp-block-heading">Protecting the AI Model</h3>



<p>Another concern is making sure attackers cannot secretly deliver a modified version of the scam-detection model to specific users.</p>



<p>WhatsApp says each model version is published with a <strong>SHA-256 hash</strong> in an append-only transparency system before it is deployed. This creates a record that can be used to verify that the model has not been secretly changed.</p>



<p>Model downloads also use an <strong>Oblivious HTTP (OHTTP) relay</strong>, which helps prevent the server from directly linking a model request to a user&#8217;s IP address.</p>



<p>WhatsApp says even the process used to assign users to different model versions for testing happens locally on their devices rather than being controlled by the server.</p>



<h3 class="wp-block-heading">Additional Security Controls</h3>



<p>The company says Scam Alert was designed to protect against several types of threats, including outside attackers, malicious employees, and compromised third-party suppliers.</p>



<p>Its security measures include isolated confidential computing environments, encrypted memory, and additional protections around the systems running the analytics infrastructure.</p>



<p>Users can also check information about the feature through WhatsApp&#8217;s transparency controls. The in-app activity section shows details such as which messages were analyzed and which model version was used.</p>



<h3 class="wp-block-heading">External Researchers Can Test the System</h3>



<p>WhatsApp is also expanding its <strong>Bug Bounty program</strong> to cover parts of the Scam Alert technology, including the machine learning models and analytics infrastructure.</p>



<p>This gives security researchers an opportunity to look for weaknesses and verify whether the system is being used only for its stated purpose of detecting scams.</p>



<h3 class="wp-block-heading">Limited Beta Release</h3>



<p>Scam Alert is initially being introduced through a <strong>limited beta rollout</strong>. WhatsApp says it plans to continue testing the technology with security researchers before making it more widely available.</p>



<p>The company also plans to publish a technical white paper explaining how the system works in greater detail.</p>



<p>The approach reflects a growing focus on building AI-powered security features without giving up user privacy. Instead of sending private conversations to the cloud for analysis, WhatsApp is attempting to combine <strong>on-device AI, confidential computing, and transparency mechanisms</strong> to detect scams while keeping message content protected.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-scam-alert-feature/">WhatsApp Scam Alert: New Protection Against Hackers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-scam-alert-feature/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Android Banking Malware Adopts New Evasion Techniques</title>
		<link>https://firsthackersnews.com/android-banking-malware-evasion-techniques/</link>
					<comments>https://firsthackersnews.com/android-banking-malware-evasion-techniques/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 13:46:00 +0000</pubDate>
				<category><![CDATA[Android banking trojan]]></category>
		<category><![CDATA[Android malware]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Android Banking Malware]]></category>
		<category><![CDATA[android malware]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware Droppers]]></category>
		<category><![CDATA[Mobile Banking Security]]></category>
		<category><![CDATA[mobile malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12169</guid>

					<description><![CDATA[<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Android banking malware continues to evolve as cybercriminals adopt new methods to avoid detection and bypass app store security checks. Instead of distributing banking malware directly, attackers are increasingly using <strong>dropper applications</strong> that deliver the malicious payload only after the app has been installed.</p>



<p>According to recent security research, while the overall number of blocked Android malware attacks declined during the second quarter of 2026, banking malware remains one of the most active mobile threats. Rather than disappearing, attackers are changing how their malware is packaged and deployed.</p>



<h2 class="wp-block-heading"><strong>A Shift Toward Dropper-Based Attacks</strong></h2>



<p>A dropper is an application that appears harmless but is designed to download or activate malware after installation.</p>



<p>This approach allows attackers to hide the real banking Trojan during the initial app review process. Once the application is installed on a victim&#8217;s device, it can retrieve additional malicious components and begin targeting banking credentials.</p>



<p>By separating the delivery mechanism from the actual malware, cybercriminals can update or replace their payloads without creating entirely new malicious applications.</p>



<h2 class="wp-block-heading"><strong>Malicious Apps Disguised as Legitimate Software</strong></h2>



<p>Researchers observed attackers disguising malware as legitimate Android applications, including utility and document reader apps.</p>



<p>In one campaign, a PDF reader displayed what appeared to be a routine software update notification. Instead of installing an update, the application downloaded banking malware onto the victim&#8217;s device.</p>



<p>These fake update prompts make malicious activity appear normal, increasing the likelihood that users will unknowingly install the malware.</p>



<h2 class="wp-block-heading"><strong>Smarter Delivery Techniques</strong></h2>



<p>Modern Android droppers are becoming more selective in how they deliver malware.</p>



<p>Some applications first collect information about where they were downloaded and send that data to a command-and-control (C2) server. The server decides whether to deliver the malicious payload based on the installation source.</p>



<p>This selective delivery helps attackers avoid security researchers, automated analysis tools, and app store review systems while targeting real users.</p>



<h2 class="wp-block-heading"><strong>Banking Malware Continues to Evolve</strong></h2>



<p>Security researchers also observed continued activity from well-known Android banking malware families, including <strong>Mamont</strong> and <strong>Creduz</strong>.</p>



<p>New variants are being released regularly, suggesting that malware operators are continuously testing new delivery techniques, improving evasion methods, and developing updated versions to avoid detection.</p>



<h2 class="wp-block-heading"><strong>Why This Matters</strong></h2>



<p>The growing use of droppers shows that mobile threats are becoming more sophisticated. A reduction in traditional banking Trojan detections does not necessarily indicate a lower risk—it may simply reflect changes in how malware is delivered.</p>



<p>As attackers continue refining their techniques, users and organizations should remain cautious of applications that request unexpected updates or unnecessary permissions.</p>



<h2 class="wp-block-heading"><strong>How to Stay Protected</strong></h2>



<p>To reduce the risk of Android banking malware:</p>



<ul class="wp-block-list">
<li>Install apps only from trusted sources.</li>



<li>Keep Google Play Protect enabled.</li>



<li>Avoid downloading apps from unofficial websites.</li>



<li>Be cautious of unexpected in-app update requests.</li>



<li>Review requested permissions before installing applications.</li>



<li>Keep Android devices and applications updated.</li>



<li>Use a reputable mobile security solution.</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong></h2>



<p>Android banking malware operators are shifting away from traditional delivery methods and increasingly relying on dropper applications to bypass security controls. As these techniques become more advanced, mobile users and organizations should strengthen their security practices, verify application sources, and remain alert to suspicious app behavior to reduce the risk of financial compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/android-banking-malware-evasion-techniques/">Android Banking Malware Adopts New Evasion Techniques</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/android-banking-malware-evasion-techniques/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</title>
		<link>https://firsthackersnews.com/prc-redcap-medical-espionage/</link>
					<comments>https://firsthackersnews.com/prc-redcap-medical-espionage/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 12:38:01 +0000</pubDate>
				<category><![CDATA[AWS]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Vulnerability Reports]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[Cyber Espionage]]></category>
		<category><![CDATA[Healthcare Cybersecurity]]></category>
		<category><![CDATA[INFINITERED Malware]]></category>
		<category><![CDATA[Medical Research Security]]></category>
		<category><![CDATA[PRC Threat Actors]]></category>
		<category><![CDATA[UNC6508]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11842</guid>

					<description><![CDATA[<p>PRC-linked hackers are targeting REDCap servers to conduct cyber espionage against U.S. medical research organizations. The campaign underscores the increasing risks facing healthcare, research, and academic sectors as threat actors seek access to valuable scientific and medical data.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/prc-redcap-medical-espionage/">PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers from Google Threat Intelligence Group (GTIG) uncovered a long-running cyber espionage campaign attributed to <strong>UNC6508</strong>, a PRC-linked threat actor that targeted medical, academic, and military research institutions across North America. The attackers remained undetected for more than a year while collecting sensitive information related to medical research, artificial intelligence, defense intelligence, cyber operations, and military strategy.</p>



<p>The campaign primarily focused on compromising <strong>REDCap (Research Electronic Data Capture)</strong> servers, a widely used platform for managing clinical research databases and surveys. After gaining access, the attackers deployed custom malware called <strong>INFINITERED</strong>, harvested credentials, established persistence, and later abused enterprise email compliance rules to exfiltrate sensitive communications.</p>



<h2 class="wp-block-heading">Campaign Overview</h2>



<p>The operation demonstrates a sophisticated attack chain combining exploitation of public-facing applications, credential theft, malware deployment, persistence mechanisms, and stealthy data exfiltration.</p>



<h3 class="wp-block-heading">Key Objectives</h3>



<ul class="wp-block-list">
<li>Medical research intelligence</li>



<li> Artificial Intelligence research </li>



<li>Defense-related information </li>



<li>Military health research Public health policy data</li>
</ul>



<p>Researchers observed the activity from <strong>September 2023 through November 2025</strong>, indicating a highly patient and well-resourced espionage operation.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="830" src="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-1024x830.png" alt="" class="wp-image-11846" style="aspect-ratio:1.233846489791462;width:606px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-177x142.png 177w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-300x243.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-768x622.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1-1024x830.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_40_14-PM-1.png 1393w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>High-level attack flow used by UNC6508 to compromise research institutions and steal sensitive information.</p>



<h2 class="wp-block-heading">Initial Access Through REDCap Servers</h2>



<h3 class="wp-block-heading">Why REDCap Was Targeted</h3>



<p>REDCap is extensively used across:</p>



<ul class="wp-block-list">
<li>Hospitals </li>



<li>Clinical research organizations </li>



<li>Universities </li>



<li>Government research programs </li>



<li>Military health institutions</li>
</ul>



<p>Because REDCap stores large volumes of research and patient-related information, it provides an attractive entry point for espionage-focused threat actors.</p>



<p>Researchers observed the attackers probing and exploiting vulnerable or legacy REDCap deployments exposed to the internet. Once access was obtained, they began internal reconnaissance and credential discovery activities.</p>



<h2 class="wp-block-heading">Web Shell Deployment and Persistence</h2>



<p>Following successful compromise, UNC6508 deployed a web shell identified as:</p>



<pre class="wp-block-code"><code>help.php</code></pre>



<p>The web shell served multiple purposes:</p>



<ul class="wp-block-list">
<li>Persistent access </li>



<li>File uploads </li>



<li>Command execution </li>



<li>Further malware deployment</li>
</ul>



<p>This allowed the attackers to maintain long-term access even if passwords were changed or some security controls were implemented.</p>



<h2 class="wp-block-heading">INFINITERED Malware Analysis</h2>



<p>Three months after the initial intrusion, researchers observed deployment of a custom malware family called <strong>INFINITERED</strong>. This malware was specifically engineered to operate inside REDCap environments.</p>



<figure class="wp-block-image aligncenter size-large is-resized"><img decoding="async" width="1024" height="819" src="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-1024x819.png" alt="" class="wp-image-11847" style="aspect-ratio:1.2495632366925407;width:599px;height:auto" srcset="https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-177x142.png 177w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-300x240.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-768x615.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM-1024x819.png 1024w, https://firsthackersnews.com/wp-content/uploads/2026/06/ChatGPT-Image-Jun-16-2026-05_41_56-PM.png 1402w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Modular architecture of INFINITERED malware used by UNC6508 to maintain persistence, harvest credentials, and execute commands within compromised REDCap environments.</p>



<h2 class="wp-block-heading">Component 1 – Upgrade Interceptor</h2>



<p>The malware monitors REDCap upgrade activities.</p>



<p>When administrators update REDCap, the malware automatically injects itself into newer versions, ensuring persistence across software upgrades</p>



<h2 class="wp-block-heading">Component 2 – Credential Harvester</h2>



<p>This module captures usernames and passwords entered into REDCap login pages.</p>



<p>Stolen credentials are stored within REDCap database tables and later retrieved by attackers.</p>



<h2 class="wp-block-heading">Component 3 – Command-and-Control Backdoor</h2>



<p>The third module acts as a fully functional backdoor.</p>



<p>Researchers found it could:</p>



<ul class="wp-block-list">
<li>Execute shell commands </li>



<li>Upload files </li>



<li>Download files </li>



<li>Run SQL queries</li>
</ul>



<p>Communication was hidden within HTTP cookie values, helping evade traditional detection mechanisms.</p>



<h2 class="wp-block-heading">Abuse of Google Workspace for Data Exfiltration</h2>



<p>One of the most interesting aspects of the campaign was the attackers&#8217; use of legitimate Google Workspace functionality.</p>



<p>After obtaining administrative access, UNC6508 created a content compliance rule named:</p>



<pre class="wp-block-code"><code>Patroit</code></pre>



<p>The rule automatically monitored emails containing specific keywords and forwarded matching messages to attacker-controlled Gmail accounts.</p>



<h2 class="wp-block-heading">Attack Chain Breakdown</h2>



<ul class="wp-block-list">
<li>External Reconnaissance</li>



<li>Initial Compromise</li>



<li>Persistence</li>



<li>Privilege Escalation</li>



<li>Intelligence Gathering</li>
</ul>



<h2 class="wp-block-heading">Potential Impact on Organizations</h2>



<p>Organizations affected by this campaign could experience:</p>



<h3 class="wp-block-heading">Research Theft</h3>



<p>Loss of valuable intellectual property and scientific research.</p>



<h3 class="wp-block-heading">Strategic Intelligence Exposure</h3>



<p>Disclosure of defense and geopolitical information.</p>



<h3 class="wp-block-heading">Credential Compromise</h3>



<p>Unauthorized access to enterprise systems.</p>



<h3 class="wp-block-heading">Regulatory Risks</h3>



<p>Exposure of regulated healthcare and research data.</p>



<h2 class="wp-block-heading">Alternative Indicators of Compromise (IOCs)</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>IOC Category</th><th>Description</th></tr></thead><tbody><tr><td>Web Shell</td><td>help.php</td></tr><tr><td>Malware Family</td><td>INFINITERED</td></tr><tr><td>Email Rule Name</td><td>Patroit</td></tr><tr><td>Activity</td><td>Unauthorized REDCap upgrades</td></tr><tr><td>Activity</td><td>Suspicious credential harvesting</td></tr><tr><td>Activity</td><td>Unexpected SQL queries</td></tr><tr><td>Activity</td><td>Abnormal Gmail forwarding rules</td></tr><tr><td>Activity</td><td>Unauthorized admin account access</td></tr><tr><td>Activity</td><td>HTTP cookie-based command execution</td></tr><tr><td>Activity</td><td>Unusual database access patterns</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Security Recommendations</h2>



<h3 class="wp-block-heading">Upgrade REDCap Immediately</h3>



<p>Remove legacy versions and apply the latest security updates.</p>



<h3 class="wp-block-heading">Conduct Threat Hunting</h3>



<p>Search for:</p>



<ul class="wp-block-list">
<li>help.php </li>



<li>INFINITERED artifacts </li>



<li>Unauthorized admin activity </li>



<li>Credential harvesting indicators</li>
</ul>



<p>The UNC6508 campaign highlights how modern nation-state threat actors are increasingly targeting research ecosystems to obtain strategic intelligence. By exploiting REDCap servers, deploying INFINITERED malware, and abusing legitimate cloud email features, the attackers maintained access for more than a year while collecting sensitive medical, defense, and technology research data. Organizations operating research platforms should prioritize patching, continuous monitoring, and proactive threat hunting to defend against similar espionage campaigns.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/prc-redcap-medical-espionage/">PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/prc-redcap-medical-espionage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hidden Motorola App Redirects Amazon Traffic</title>
		<link>https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/</link>
					<comments>https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 27 May 2026 17:19:44 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[#Adware]]></category>
		<category><![CDATA[#AffiliateTracking]]></category>
		<category><![CDATA[#Amazon]]></category>
		<category><![CDATA[#Android]]></category>
		<category><![CDATA[#AndroidPrivacy]]></category>
		<category><![CDATA[#AndroidSecurity]]></category>
		<category><![CDATA[#ConsumerPrivacy]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreat]]></category>
		<category><![CDATA[#DataPrivacy]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#MobilePrivacy]]></category>
		<category><![CDATA[#MobileSecurity]]></category>
		<category><![CDATA[#MobileThreats]]></category>
		<category><![CDATA[#Motorola]]></category>
		<category><![CDATA[#privacy]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#SmartphoneSecurity]]></category>
		<category><![CDATA[#TechNews]]></category>
		<category><![CDATA[#Tracking]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11757</guid>

					<description><![CDATA[<p>A hidden application discovered on Motorola smartphones has sparked privacy and security concerns after researchers found it quietly</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/">Hidden Motorola App Redirects Amazon Traffic</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A hidden application discovered on Motorola smartphones has sparked privacy and security concerns after researchers found it quietly rerouting Amazon app launches through affiliate tracking links.</p>



<p>The issue was initially noticed by a Motorola Razr 60 Ultra user who observed unusual behavior when opening the Amazon app. Instead of launching normally, the device briefly opened a web browser before redirecting back to Amazon with a tracking identifier attached.</p>



<p>Further investigation revealed that a preinstalled background application named <code>Smart Feed</code> was responsible for the redirects.</p>



<h2 class="wp-block-heading"><strong>Hidden App Injects Affiliate Tracking Codes</strong></h2>



<p>Researchers found that the hidden app communicates with an external server identified as <code>devicenative[.]com</code>. The server appears to provide affiliate-related settings and redirect instructions used by the application.</p>



<p>When users tap shopping apps from the launcher, the hidden service intercepts the request and inserts affiliate tracking data before sending users to the final destination.</p>



<p>The observed behavior includes:</p>



<ul class="wp-block-list">
<li>Intercepting Amazon app launches</li>



<li>Opening browser-based redirect links</li>



<li>Injecting affiliate tracking parameters</li>



<li>Connecting to remote servers for configuration updates</li>



<li>Running silently in the background</li>
</ul>



<p>Because Android automatically handles supported links inside apps, most users are unlikely to notice the redirection process.</p>



<h2 class="wp-block-heading"><strong>Researchers Warn About Potential Risks</strong></h2>



<p>Security experts noted that the technique shares similarities with behaviors commonly seen in adware and mobile malware.</p>



<p>The concerns go beyond affiliate monetization because the same infrastructure could theoretically be modified to redirect users toward malicious websites, phishing pages, or credential theft portals.</p>



<p>Researchers also highlighted several worrying characteristics:</p>



<ul class="wp-block-list">
<li>Hidden system-level persistence</li>



<li>External server-controlled behavior</li>



<li>Intent interception techniques</li>



<li>Limited user visibility or control</li>



<li>Difficulty removing the application</li>
</ul>



<p>Since the application relies on remote configuration from external servers, its behavior could potentially change without any operating system update.</p>



<p>The issue has currently been confirmed on the Motorola Razr 60 Ultra, although it is still unclear whether other Motorola devices are affected.</p>



<p>While reports suggest a third-party monetization partner may be involved, researchers argue that smartphone manufacturers remain responsible for software bundled with their devices.</p>



<p>Motorola has not publicly commented on the findings at the time of reporting.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/">Hidden Motorola App Redirects Amazon Traffic</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>WhatsApp Chat Data Found Stored Without Encryption</title>
		<link>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/</link>
					<comments>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 25 May 2026 17:41:58 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[#AppleSecurity]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreat]]></category>
		<category><![CDATA[#DataProtection]]></category>
		<category><![CDATA[#Encryption]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#iOSSecurity]]></category>
		<category><![CDATA[#macOSSecurity]]></category>
		<category><![CDATA[#Meta]]></category>
		<category><![CDATA[#MobileSecurity]]></category>
		<category><![CDATA[#privacy]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#WhatsApp]]></category>
		<category><![CDATA[#WhatsAppSecurity]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11745</guid>

					<description><![CDATA[<p>Security researchers have raised concerns about how WhatsApp stores chat data on macOS and iOS devices. According to</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/">WhatsApp Chat Data Found Stored Without Encryption</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Security researchers have raised concerns about how WhatsApp stores chat data on macOS and iOS devices. According to recent findings, message databases may be stored in plaintext inside shared app group containers, potentially exposing sensitive conversations under certain conditions.</p>



<p>Researchers from Mysk reported that WhatsApp uses a shared container linked to Meta applications, identified as <code>group.com.facebook.family</code>. On Apple devices, app group containers allow applications from the same developer to share data and resources.</p>



<p>Because Facebook, Instagram, and WhatsApp belong to the same ecosystem, the shared architecture could introduce privacy and security concerns if exploited alongside operating system vulnerabilities.</p>



<h2 class="wp-block-heading"><strong>Shared Containers Raise Privacy Concerns</strong></h2>



<p>The researchers found that WhatsApp chat databases stored inside these containers are not encrypted at rest. This means the data may remain readable if attackers gain access to the device or exploit weaknesses in the operating system.</p>



<p>According to the report, the following risks were identified:</p>



<ul class="wp-block-list">
<li>Chat histories may be stored in plaintext</li>



<li>Other Meta-owned apps could theoretically access shared data</li>



<li>Users receive no alerts when such access occurs</li>



<li>The issue affects both macOS and iOS environments</li>
</ul>



<p>Researchers also demonstrated that WhatsApp chat histories could be extracted from iPhone backups, where the same unencrypted storage structure was observed.</p>



<p>The findings highlight an important distinction in security design. While WhatsApp uses end-to-end encryption to protect messages during transmission, that protection does not automatically secure data stored locally on the device.</p>



<h2 class="wp-block-heading"><strong>macOS Vulnerability Increases Exposure Risk</strong></h2>



<p>The risk becomes more serious when combined with a recently disclosed macOS vulnerability tracked as CVE-2026-28910. The flaw affected Apple’s Archive Utility tool and reportedly allowed attackers to bypass App Sandbox protections.</p>



<p>By abusing this vulnerability, attackers could potentially:</p>



<ul class="wp-block-list">
<li>Access protected application containers</li>



<li>Extract sensitive information from apps</li>



<li>Bypass Apple’s Transparency, Consent, and Control protections</li>



<li>Access chat histories from applications like WhatsApp</li>
</ul>



<p>Researchers presented a proof-of-concept demonstration showing how the vulnerability could be combined with WhatsApp’s storage behavior to retrieve chat data.</p>



<h2 class="wp-block-heading"><strong>Security Debate Around the Findings</strong></h2>



<p>Not all experts agree on the severity of the issue. WABetaInfo stated that although the databases may not be encrypted locally, Apple’s sandboxing system still provides strong isolation between applications.</p>



<p>From this perspective, attackers would still require elevated system privileges or a separate operating system exploit to access the stored data.</p>



<p>However, researchers at Mysk argue that shared app group permissions between Meta applications reduce isolation boundaries and increase the potential attack surface.</p>



<p>The discussion highlights broader concerns about local data protection in modern mobile ecosystems, especially when multiple applications share common storage environments.</p>



<h2 class="wp-block-heading"><strong>Recommendations for Users</strong></h2>



<p>Security experts recommend several steps to reduce potential exposure risks:</p>



<ul class="wp-block-list">
<li>Enable encrypted Finder or iTunes backups</li>



<li>Keep macOS and iOS updated with the latest security patches</li>



<li>Use strong device passcodes and device encryption</li>



<li>Limit unnecessary applications from the same developer ecosystem</li>



<li>Regularly review application permissions and backup settings</li>
</ul>



<p>At the time of reporting, there were no confirmed cases of widespread exploitation linked to the findings. However, the research highlights the importance of protecting sensitive data not only during transmission but also while stored on devices.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/">WhatsApp Chat Data Found Stored Without Encryption</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Facebook Phishing Campaign Targets Business Accounts</title>
		<link>https://firsthackersnews.com/facebook-phishing-campaign/</link>
					<comments>https://firsthackersnews.com/facebook-phishing-campaign/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Sun, 03 May 2026 20:54:12 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[#AppSheet]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#DataBreach]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#FacebookPhishing]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#MalwareAnalysis]]></category>
		<category><![CDATA[#Netlify]]></category>
		<category><![CDATA[#OnlineSafety]]></category>
		<category><![CDATA[#PhishingAttack]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SocialEngineering]]></category>
		<category><![CDATA[#Telegram]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11680</guid>

					<description><![CDATA[<p>Researchers at Guardio Labs have uncovered a large and highly organized phishing operation known as AccountDumpling, which has</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/facebook-phishing-campaign/">Facebook Phishing Campaign Targets Business Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Researchers at Guardio Labs have uncovered a large and highly organized phishing operation known as <strong>AccountDumpling</strong>, which has already compromised more than 30,000 Facebook accounts worldwide. What makes this campaign stand out is not just its scale, but the way it abuses legitimate platforms to make phishing emails appear completely authentic.</p>



<p>Instead of relying on fake domains or compromised mail servers, attackers use Google AppSheet to send emails through Google’s own infrastructure. These messages are generated as part of automated workflows, meaning they pass authentication checks like SPF, DKIM, and DMARC without raising suspicion. </p>



<p>As a result, security tools and spam filters see them as trusted communications, allowing phishing messages to land directly in inboxes of targeted users—often business account owners managing Facebook pages.</p>



<h2 class="wp-block-heading">Multi-Layered Attack Strategy</h2>



<p>The campaign is not a single phishing page but a structured, multi-stage system designed to increase success rates. Victims are first directed to pages hosted on Netlify, where attackers replicate the Facebook Help Center with high accuracy. These pages are customized per victim using unique subdomains, making them difficult to block using traditional security measures.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="766" src="https://firsthackersnews.com/wp-content/uploads/2026/05/image.png" alt="" class="wp-image-11681" srcset="https://firsthackersnews.com/wp-content/uploads/2026/05/image-300x224.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-768x575.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/05/image.png 1024w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Email phishing (Source: Guard Labs)</figcaption></figure>



<p>From there, users are guided through a series of steps that collect not only login credentials but also deeper identity information such as date of birth and even government-issued ID images. In some cases, the attackers shift tactics by offering fake incentives, like verification badges, hosted on platforms such as Vercel. These pages are designed to look dynamic and legitimate, while quietly bypassing detection systems using techniques like hidden Unicode characters.</p>



<p>The operation becomes more advanced in later stages. Attackers host phishing documents on Google Drive, presenting them as official Meta notifications. These documents, often designed using Canva, contain embedded links that redirect victims into interactive phishing environments. These environments are powered by real-time communication frameworks, allowing attackers to actively engage with victims during the login process.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="809" src="https://firsthackersnews.com/wp-content/uploads/2026/05/image-1.png" alt="" class="wp-image-11682" srcset="https://firsthackersnews.com/wp-content/uploads/2026/05/image-1-300x237.png 300w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-1-768x607.png 768w, https://firsthackersnews.com/wp-content/uploads/2026/05/image-1.png 1024w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Account Dumpling (Source: Guard Labs)</figcaption></figure>



<p>This live interaction is a critical aspect of the campaign. Instead of passively collecting credentials, attackers can request one-time passwords, monitor user actions, and even capture browser sessions as they happen. This significantly increases the likelihood of successful account takeover, even when multi-factor authentication is enabled.</p>



<h2 class="wp-block-heading">Real-Time Data Exfiltration and Attribution</h2>



<p>Once credentials are captured, they are immediately transmitted through a centralized system built around Telegram bots. This allows operators to monitor incoming data in real time and quickly take control of compromised accounts before victims notice suspicious activity.</p>



<p>Analysis of the infrastructure shows a strong operational scale, with thousands of records flowing into attacker-controlled channels. Most victims are concentrated in regions like the United States and Europe, indicating a focus on high-value targets such as businesses and influencers.</p>



<p>Investigators were also able to trace elements of the campaign back to Vietnamese actors. This attribution is supported by metadata found in phishing documents and developer comments embedded within the malicious code, providing insight into the origin of the operation.</p>



<h2 class="wp-block-heading">A Shift Toward Industrialized Phishing</h2>



<p>AccountDumpling reflects a broader shift in cybercrime, where phishing is no longer a simple tactic but part of a larger, industrialized ecosystem. Attackers are combining trusted services, automation, and real-time interaction to create highly effective campaigns that are difficult to detect and disrupt.</p>



<p>Compromised accounts are rarely the end goal. They are often reused for further scams, advertising fraud, or additional phishing attacks, creating a cycle that sustains and expands the operation. This approach shows how modern threat actors are leveraging legitimate platforms at scale, turning them into tools for widespread abuse while staying under the radar.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/facebook-phishing-campaign/">Facebook Phishing Campaign Targets Business Accounts</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/facebook-phishing-campaign/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
