LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
security

Signal adds encypted local backup support to iOS, desktop apps

Signal has completed the rollout of its secure backup feature across all supported operating systems, including Android, iOS, Linux, macOS, and Windows, with the release of version 8.30. This update introduces end-to-end encrypted local backups for iOS and desktop applications, while also revamping the Android backup system to utilize a new cross-platform format. The feature, initially…

ZeroDay News ·

Source: BleepingComputer

Signal has completed the rollout of its secure backup feature across all supported operating systems, including Android, iOS, Linux, macOS, and Windows, with the release of version 8.30. This update introduces end-to-end encrypted local backups for iOS and desktop applications, while also revamping the Android backup system to utilize a new cross-platform format. The feature, initially launched on Android nearly a year ago, enables users to create encrypted backups of their chats and restore them on new devices.

The backup system offers two options: Signal-hosted backups and on-device local backups. Signal-hosted backups are limited to 45 days of media and 128 KB per message for free users, with paid plans offering up to 100 GB. Local backups, however, have no size restrictions. Both backup methods are encrypted and require a recovery key for decryption. Signal-hosted backups include an additional supplemental key that rotates daily within a Trusted Execution Environment, enhancing protection and forward secrecy.

According to Signal, a single on-device backup recovery key can decrypt all past backup files it encrypted, regardless of their storage location. The value of this key has been noted by threat actors, who reportedly began targeting it shortly after the feature's initial introduction.

The latest update also introduces several enhancements. When linking a new device from a primary device, the new device will now retrieve older attachments that may be missing from the chat history. Media files are now stored separately from the backup archive, and duplicate files are stored only once, which aims to reduce excessive backing up and syncing. Paying users will also gain an option to purge old media from local storage, retaining only thumbnails, with the ability to automatically retrieve full media from hosted backups.

The backup system is designed to ignore disappearing messages set to vanish within 24 hours, preventing them from being included in either backup method. For users who utilize both hosted and on-device backups, Signal clarifies that hosted backups do not overwrite local backups. During restoration, however, expired disappearing messages from local backups will be skipped.

The iOS client release, version 8.30, also enables direct iPhone-to-iPhone transfers using a local end-to-end encrypted Wi-Fi Aware link, which Signal states improves both speed and reliability. Signal has indicated that this rollout marks the completion of the first phase of its backup project, and engineers will now focus on improving non-backup systems.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.