WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information […]

WhatsApp has announced a significant expansion of its account security features, including stronger two-step verification, enhanced caller context for unknown numbers, and the ability to register multiple passkeys. The company also confirmed that over one billion users now utilize passkeys for account access.
Passkeys offer a more secure login method by allowing users to authenticate with their device's biometric features, such as fingerprint or Face ID, or their screen-lock code, eliminating the need for traditional passwords, PINs, or one-time codes. WhatsApp has now enabled users who operate across both Android and iOS platforms to link multiple passkeys to a single account, streamlining account recovery and reducing reliance on a single device. This move shifts account protection away from user-remembered secrets, making phishing attempts considerably more difficult.
The platform's two-step verification system has also received an upgrade. Previously relying on a six-digit PIN, this additional layer of protection has been enhanced to support a full password. This new password can be longer, incorporate alphanumeric characters, and include special symbols, significantly increasing its strength compared to a short numeric PIN. This change aims to provide a more robust defense against account takeovers, even if an attacker manages to obtain a user's one-time registration code. WhatsApp explicitly encourages users to upgrade from easily guessable PINs like "123456."
In an effort to combat social engineering tactics, WhatsApp on Android will now provide additional context for calls from numbers not saved in a user's contacts. This information may include details such as whether the incoming call originates from a different country or if the caller shares any common groups with the recipient. This feature is designed to give users more information to consider before deciding whether to answer a call, thereby mitigating the pressure often exploited by scammers.
These three security enhancements collectively address different facets of account protection. Passkeys make authentication more resilient to theft, the strengthened two-step verification acts as an additional barrier if a one-time code is compromised, and the caller context provides users with crucial information before engaging in a potentially suspicious interaction. The milestone of one billion passkey users on WhatsApp suggests a growing adoption of phishing-resistant authentication methods on a large scale.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.