LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
patch

WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update

When Android users get a call from a non-contact, they will see more information about the caller, including their country. The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on SecurityWeek.

zeroday.news ·

WhatsApp has reportedly rolled out an update that enhances account security through the addition of multiple passkeys and stronger two-step verification (2SV) options. This development aims to provide users with more robust methods for securing their accounts against unauthorized access.

The core of this security update appears to be the integration of multiple passkeys. Passkeys are a modern authentication standard designed to replace passwords, offering a more secure and user-friendly login experience. By allowing users to register multiple passkeys, WhatsApp enables greater flexibility and redundancy in account access. For instance, a user could register passkeys on their primary smartphone, a backup device, and a computer, ensuring they can still access their account even if one device is lost or compromised. This approach leverages public-key cryptography, making passkeys resistant to phishing attacks, which are a common vector for credential theft.

In conjunction with passkeys, the update also reportedly strengthens the existing two-step verification system. While the specific enhancements to 2SV were not detailed, typical improvements in this area often include more secure methods for generating or receiving verification codes, such as through authenticator apps rather than SMS, or more stringent requirements for resetting 2SV. Stronger 2SV mechanisms are critical because they add an additional layer of security beyond the primary authentication method, making it significantly harder for attackers to gain access even if they manage to compromise a user's password or passkey.

The report also mentions a separate feature for Android users, where incoming calls from non-contacts will display additional caller information, specifically their country. While this feature is distinct from the account security enhancements, it contributes to user safety by providing context for unknown callers, potentially helping users identify and avoid spam or fraudulent calls. This information could be particularly useful in mitigating social engineering attempts that often precede account compromise.

For users, the recommended mitigation advice for these types of security features typically involves actively enabling and configuring them. Users should be encouraged to set up passkeys on all their trusted devices and ensure their 2SV is configured using the strongest available method, such as a hardware security key or an authenticator app. Regularly reviewing security settings and being vigilant against phishing attempts are also standard best practices.

This update reflects a broader industry trend towards adopting more secure and user-friendly authentication methods. As cyber threats continue to evolve, platforms like WhatsApp are under increasing pressure to provide robust security features that protect user data and privacy. The move to support multiple passkeys and enhance 2SV aligns with the push for passwordless authentication and multi-factor security, aiming to make accounts more resilient against common attack vectors.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

security

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

ddos

Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack

Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]

security

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

ai

When the Algorithm Fires You: Uber Faces €825M Fine

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.