LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
security

WhatsApp account takeover scam asks you to “vote for my friend”

Scammers are trying to take over WhatsApp accounts by sending messages asking people to vote for a friend in a fake online contest.

zeroday.news · 3h ago

A new scam is circulating on WhatsApp, designed to take over user accounts by exploiting the platform's legitimate "Linked devices" feature. The attack typically begins with a message from a compromised contact, asking the recipient to vote for a friend or relative in an online contest, such as a ballet performance or a dog competition.

The initial message, often casual or urgent in tone, includes a link that appears to lead to a voting page. However, clicking this link redirects the user to a page that mimics WhatsApp's interface, sometimes involving the wa.me domain. This page then prompts the user to complete a verification, connection, or continuation step.

The scam's objective is to trick users into authorizing a new linked session, effectively granting the attacker full access to their WhatsApp account. This process often resembles the steps for setting up WhatsApp Web or linking a new device. Instead of stealing a password, the attackers leverage the user's unwitting consent to link their own device to the victim's account.

In some variations, the message or landing page instructs victims to open WhatsApp, navigate to "Connected Devices," and then enter a code provided by the scammer. This method also achieves the same outcome: linking the attacker's device to the victim's account.

Once an attacker successfully links their device, they gain significant control. They can read all messages, send messages as the victim, and access ongoing conversations in near real-time. This access allows them to perpetuate the scam by sending similar messages to the victim's contacts, request money or sensitive information from friends and family, and harvest personal data from chat histories.

A key aspect of this scam is its stealth. Since it doesn't involve a traditional login or password theft, there are no typical indicators like password reset emails or failed login alerts. The attacker's device simply appears as another linked session within the victim's account. Unless users actively check their linked devices, the compromise can remain undetected for an extended period.

Users are advised to exercise caution with unexpected "vote" or "support" requests, even if they originate from known contacts. It is crucial to avoid clicking unexpected links, especially those that immediately request verification or account linking. Users should never follow instructions to link devices or scan QR codes unless they have initiated the action themselves.

To protect against such attacks, WhatsApp users should regularly review their linked devices in the app's settings and log out of any unrecognized sessions. Enabling two-step verification adds an extra layer of security. If a message seems suspicious, it is recommended to verify its authenticity with the sender through an alternative communication channel before taking any action.

Examples of domains associated with this scam, though typically short-lived, include ngdance[.]fun/vote, fokindenfo1[.]lol/home/voteeeg3, stardancer[.]fun/home/voteCZ03, thebestscollato[.]top/home/scolatica, vatiter[.]click/home/voteerok, and megadencer[.]top/home/eng10. If an account is suspected of being compromised, users should immediately log out of all linked devices and inform their contacts to prevent further spread of the scam.

ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

EU begins enforcing AI Act, putting AI models under the microscope

Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requiring certain AI systems to tell users when they’re interacting with AI and when content has been generated or altered by it. Under these rules, chatbots have to id

malware

Digital executive protection is a strategic imperative for CEOs

In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email with no multifactor authentication, and traders acted on it before the news went public. He also covers a home network left open after an AV te

security

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

breach

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]

ai

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop.

security

“Adult TikTok” searches lead to scams

That "free" adult TikTok site could leave you with spam, unwanted apps, or fake verification fees.