An optional new feature uses on-device AI to flag messages that look like scams.

WhatsApp is currently testing a new "Scam Alert" feature designed to help users identify potential scam messages from unknown contacts. This optional beta feature employs an on-device machine-learning model to analyze incoming messages for patterns indicative of fraudulent activity.
The initiative comes as WhatsApp has become a frequent platform for various scams, including impersonation, fake job offers, bogus sales, investment fraud, romance scams, malicious links, and illicit payment requests. These schemes often originate on other social media platforms before moving victims to private WhatsApp chats, where criminals can exert pressure and build false trust.
When enabled, the Scam Alert feature downloads a machine-learning model to the user's device. This model then examines messages from senders not in the user's contact list, looking for linguistic signals and conversational structures previously identified in reported scam conversations. The system is designed to alert users without blocking messages or notifying the sender that their message has been flagged.
If the model identifies a message as a potential scam, a warning banner will appear within the chat. Users then have several options: they can block the sender, report the chat to WhatsApp, continue the conversation if they believe it is legitimate, or mark the chat as trusted, which will remove the warning and prevent future alerts for that specific conversation.
WhatsApp emphasizes that this feature is a defensive layer and will not automatically block any messages. A key limitation is that the alert may not appear for scams originating from compromised contacts, such as account takeover campaigns where messages appear to come from a known individual.
This on-device AI approach allows for the detection of potential scams without requiring WhatsApp to access or read the content of private, encrypted conversations. The feature's optional nature, local classification, and lack of automatic reporting align with privacy considerations for an encrypted messaging service.
The Scam Alert is currently in a limited beta rollout and is being tested with researchers participating in Meta’s bug bounty program before a broader public release. It represents another step in Meta's broader anti-scam efforts across its platforms, including WhatsApp, Facebook, and Messenger.
To enhance personal security on WhatsApp, users are advised to enable two-step verification. They should also exercise caution with unexpected links, especially those requesting account verification or linking, and never scan QR codes or follow device linking instructions unless they initiated the action. Regularly reviewing linked devices in WhatsApp settings and logging out of any unrecognized sessions is also recommended.
When interacting with new contacts, particularly those who attempt to move conversations from other platforms to WhatsApp, users should be wary. Researching the sender's profile and activity can help determine legitimacy. For financial transactions, it is safer to use payment methods offering chargeback protection and to avoid bank transfers, cryptocurrency, gift cards, or "Friends and Family" payment options when dealing with unknown parties. Users should also remember that the presence of an ad on a major platform does not guarantee its legitimacy, as scammers frequently place ads alongside legitimate businesses.



Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

Daybreak program brings subsidized models, training, and support to under-resourced teams

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix