WhatsApp users may need to take extra steps to protect their account information following a potentially concerning discovery. A study by researchers at the University of Vienna revealed the app’s contact-discovery system enabled the collection of extensive WhatsApp user data at an unprecedented scale due to insufficient rate-limiting across global endpoints.
The researchers were able to gather huge amounts of phone numbers, public profile photos, account status text, business tags, and information tied to end-to-end encryption keys.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- The CEVA Logistics data breach is having major knock-on effects across Europe – here’s what we know
August 11, 2026
CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves. CEVA has ...
- Wetherspoons bars smart glasses from filming customers
August 10, 2026
Wetherspoons has stopped short of banning Meta-style smart glasses from its pubs, but told The Register that customers should switch off their cameras and refrain from filming. “Like many hospitality companies, Wetherspoon has CCTV cameras for security reasons, but their use is strictly controlled by data legislation,” a spokesperson said. “Apart from that, the general code that applies in ...
- Intrusion at US healthcare software provider puts 3.8M people’s data at risk
August 7, 2026
A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year. The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. ...
- Swiss government says SharePoint-linked data breach affected hundreds of accounts
August 7, 2026
Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation. In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal ...
- Apple’s Private Relay tool can leak users’ IP addresses
August 6, 2026
WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden. This is according to security researchers Talal Haj Bakry and Tommy Mysk who noted they had found “three WebKit features that bypass the proxy configuration and send traffic directly from the ...
- Over 100,000 UK Police and staff have personal data leaked in attack on national database
August 4, 2026
The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost sensitive data on more than 100,000 criminal justice professionals. In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and ...

