One big caveat, though: You need your contact's phone number

Signal has introduced Automatic Key Verification (AKV), a new security feature designed to prevent man-in-the-middle attacks that could compromise encrypted chats. The feature, announced on Tuesday, August 11, 2026, aims to ensure users are communicating with the intended contact by verifying their public encryption keys.
Signal is widely used by individuals who prioritize privacy, such as diplomats, activists, and journalists. Its existing security measures include end-to-end message encryption and "safety numbers," which are cryptographic fingerprints that users can compare to confirm the integrity of their connection. However, a theoretical vulnerability remained where a malicious actor could tamper with Signal's centralized directory of accounts, impersonating a user and redirecting encrypted messages.
AKV addresses this by establishing a new architecture that detects unauthorized changes to public keys. From a user's perspective, activating AKV is straightforward: users can navigate to a contact's profile, access the "View Safety Number" screen, and tap "Verify automatically." A green checkmark will then indicate that the contact's public encryption key aligns with Signal's key transparency system.
Behind the scenes, Signal has developed an open-source key transparency server that functions as a ledger of public keys. Every modification a user makes to their account information, such as changing a phone number or username, creates a new entry in this ledger. An accompanying index allows users to verify information about themselves or their contacts, ensuring it has not been altered by a third party attempting to intercept messages. Signal's system automatically searches this index on behalf of the user to retrieve the most current information.
To further bolster trust, Signal has engaged third-party auditors, Cloudflare and security firm Trail of Bits. Their role is to verify that Signal's key transparency server itself has not been compromised. These auditors check the index for any signs of tampering and, if clear, sign the response to confirm that the keys provided are consistent for both users, thereby mitigating the risk of a man-in-the-middle attack.
The system also incorporates a monitoring component. Users can interact with the ledger in two ways: by looking up another person's address and by looking up their own. The Signal app periodically and automatically checks a user's own ledger entries. Combined with the ability to manually verify a connection's data via the "Verify Automatically" button, this creates a comprehensive detection system. Auditing ensures that both parties are viewing the same data, while monitoring guarantees regular checks for data accuracy.
A key requirement for using AKV to verify another user is having their phone number linked to their Signal account or present in the user's phone address book. Without this, AKV cannot be used for verification. Users who prefer not to involve a third party in their identity verification have the option to disable AKV and can instead rely on traditional safety number or QR code verification methods.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed