A security research paper analyzes vulnerabilities in Russia's MAX super-app, demonstrating how malicious super-apps can compromise mini-app security and user privacy through UI capture, storage access, JavaScript injection, and network mediation. The study argues that super-apps like WeChat, MAX, and Bale present inherent architectural risks and calls for OS and app store interventions to address these vulnerabilities.
A social media post criticizes New York Times reporting on Chinese AI vulnerabilities, arguing the framing presents Chinese technological advancement as threatening, regulation as control, and defense measures as escalation. The post contends the article demonstrates American tools and espionage targeting while suggesting China should seek American guidance on AI security.
Researchers at Calif demonstrated WeWorm, the first zero-click worm spreading through WeChat calls on iOS and Android, capable of hijacking accounts and reaching over a billion users. The exploit, developed with AI assistance in about two weeks, requires only calling a victim who need not answer; the vulnerability was reported to Tencent in July and has been mitigated. The demonstration highlights how AI is democratizing sophisticated attack capabilities, making it crucial for collaboration between governments and industry to address mobile messaging vulnerabilities.
Researchers at Calif demonstrated WeWorm, the first zero-click worm spreading through WeChat calls on iOS and Android, which can hijack accounts and propagate across devices without user interaction. The vulnerability was reported to Tencent in July and has been mitigated; the disclosure aims to raise awareness about AI-accelerated exploit development and the need for international collaboration on security.
Researchers at Calif demonstrated WeWorm, the first zero-click worm spreading through WeChat calls on iOS and Android. The exploit allows attackers to hijack accounts and automatically propagate to contacts without user interaction, potentially compromising over a billion devices. The vulnerability was reported to Tencent in July and has been mitigated.