LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
phishing

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,

zeroday.news ·

WhatsApp has reportedly enhanced its account security features by introducing support for multiple passkeys for a single user account. This update aims to provide a more robust, phishing-resistant sign-in method for users across both iOS and Android platforms. The move follows the initial introduction of passkey support for Android devices in October 2023, expanding its utility to a broader user base.

The core mechanism of passkeys relies on public-key cryptography, offering a significant upgrade over traditional password-based authentication. Instead of a secret string of characters, a passkey consists of a cryptographic key pair. One key, the public key, is stored on the service provider's server, while the private key remains securely on the user's device. During authentication, the user's device uses the private key to sign a challenge from the server, which the server then verifies with the stored public key. This process eliminates the need for users to remember complex passwords and, crucially, makes phishing attacks far more difficult to execute successfully.

The ability to link multiple passkeys to a single WhatsApp account directly addresses the common scenario where users operate across different mobile ecosystems. For instance, a user might have an iPhone for personal use and an Android device for work, or simply own multiple devices. By supporting multiple passkeys, WhatsApp allows each device to register its own unique passkey, enabling seamless and secure login from any of the user's registered devices without compromising security. This flexibility enhances user convenience while maintaining a high level of protection against credential theft.

This class of authentication method is inherently resistant to phishing because the private key never leaves the user's device and is not transmitted over the network. Even if a user is tricked into visiting a malicious website, the passkey authentication process will only occur with the legitimate service, as the private key is bound to the correct domain. This contrasts sharply with passwords, which can be entered into fake login pages and subsequently stolen.

For users, adopting passkeys typically involves a one-time registration process on each device they wish to use for authentication. This usually entails confirming their identity through a device-level biometric (like a fingerprint or face scan) or a PIN. Once registered, subsequent logins are simplified, often requiring just a biometric scan. Users are generally advised to enable passkeys wherever supported and to ensure their devices are kept updated with the latest security patches.

The reported adoption of passkeys by over a billion WhatsApp users underscores a significant industry trend towards more secure and user-friendly authentication methods. As cyber threats, particularly phishing, continue to evolve in sophistication, the shift away from passwords towards cryptographic solutions like passkeys represents a critical step in enhancing digital security for a global user base. This development reflects a broader industry push to implement FIDO (Fast IDentity Online) standards, which aim to reduce reliance on passwords and improve the overall security posture of online services.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]

CVE-2026-61979

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.

malware

First Malware Built Specifically for Car Head Units Fuels Botnet

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.

vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

security

The County Prosecutors Who Became ICE Informants

Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.

vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap