<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update your Whatsapp ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22313#M2769</link>
    <description>&lt;P&gt;Indeed, no user interaction required, other than having your phone on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No details of the prevalence in the wild, but has been tracked in it's attack pattern as deliberate and targeted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's relatively arbitrary to begin with, using an inherent buffer overflow technique within the VoIP stack of the application. The impressive part is the no-touch deployment, and the clean up so the trace is minimal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very similar to the "Pegasus" strain seen at the beginning of the month. Not going to say where that particular piece has come from.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2019 08:23:20 GMT</pubDate>
    <dc:creator>HTCPCP-TEA</dc:creator>
    <dc:date>2019-05-15T08:23:20Z</dc:date>
    <item>
      <title>Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22281#M2761</link>
      <description>&lt;P&gt;Researchers have discovered a way for someone to &lt;A href="https://www.ctvnews.ca/sci-tech/whatsapp-discovers-spyware-that-infected-with-a-call-alone-1.4421075" target="_blank" rel="noopener"&gt;install malware on your phone simply by placing a voice call to your Whatsapp app&lt;/A&gt;.&amp;nbsp; (From the sounds of things, you don't even have to answer.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whatsapp has issued a patch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Various reports are stressing different aspects, but there is some speculation that &lt;A href="https://www.telegraph.co.uk/technology/2019/05/14/whatsapp-flaw-allowed-israeli-hackers-snoop-phones/" target="_blank" rel="noopener"&gt;NSO Group has been actively using the vulnerability to target specific individuals or groups&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 16:48:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22281#M2761</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-05-14T16:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22289#M2762</link>
      <description>&lt;P&gt;And this surprises you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Researchers have discovered a way for someone to &lt;A href="https://www.ctvnews.ca/sci-tech/whatsapp-discovers-spyware-that-infected-with-a-call-alone-1.4421075" target="_blank" rel="noopener"&gt;install malware on your phone simply by placing a voice call to your Whatsapp app&lt;/A&gt;.&amp;nbsp; (From the sounds of things, you don't even have to answer.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whatsapp has issued a patch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Various reports are stressing different aspects, but there is some speculation that &lt;A href="https://www.telegraph.co.uk/technology/2019/05/14/whatsapp-flaw-allowed-israeli-hackers-snoop-phones/" target="_blank" rel="noopener"&gt;NSO Group has been actively using the vulnerability to target specific individuals or groups&lt;/A&gt;.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 17:21:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22289#M2762</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-05-14T17:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22294#M2763</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I was getting messages from friends &lt;A href="https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&amp;amp;objectid=12230963" target="_blank" rel="noopener"&gt;about this&lt;/A&gt; today, but I could find no update since the last one I got a couple of weeks ago, so I suppose that took care of it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;said, we shouldn't be surprised...&amp;nbsp;&amp;nbsp;&lt;img id="manwink" class="emoticon emoticon-manwink" src="https://community.isc2.org/i/smilies/16x16_man-wink.png" alt="Man Wink" title="Man Wink" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 18:19:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22294#M2763</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-05-14T18:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22297#M2764</link>
      <description>&amp;gt; Shannon (Community Champion) posted a new reply in Industry News on 05-14-2019&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; Yes, I was getting messages from friends about this today, but I could find no&lt;BR /&gt;&amp;gt; update since the last one I got a couple of weeks ago, so I suppose that took&lt;BR /&gt;&amp;gt; care of it.&lt;BR /&gt;&lt;BR /&gt;Intriguing. (Particularly since you are in KSA ...)&lt;BR /&gt;&lt;BR /&gt;I'm showing version 2.19.134 (on Android). How does that compare?&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Ignorance is never out of style. It was in fashion yesterday,&lt;BR /&gt;it is the rage today, and it will set the pace tomorrow.&lt;BR /&gt;-- Franklin K. Dane&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 14 May 2019 19:06:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22297#M2764</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-05-14T19:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22299#M2765</link>
      <description>&lt;P&gt;&amp;gt; dcontesti (Community Champion) posted a new reply in Industry News on 05-14-2019&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; And this surprises you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not particularly. This seems to be a "developing" story: it isn't clear whether/how much this is being used "in the wild" (although it's intriguing to think that Shannon could be spying on us all &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According the (various) reports I've read, it's not even too clear who discovered/reported the vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, of course, none of the reports I've read so far have noted that, even if you *do* upgrade, it's not the vulnerability that was being used to spy, but simply as an installation exploit. Which means that, even after upgrading to prevent infection, you still have to find some means of checking if you *have* been infected/compromised ...&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 19:15:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22299#M2765</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-05-14T19:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22301#M2766</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BR /&gt;Intriguing. (Particularly since you are in KSA ...)&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;What's amusing is that WhatsApp calling is blocked by carriers here, at least most of the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;I'm showing version 2.19.134 (on Android). How does that compare?&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, it's the same on mine --- and the latest on Google Play --- so we'll have to keep our fingers crossed...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 19:53:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22301#M2766</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-05-14T19:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22308#M2767</link>
      <description>&lt;P&gt;&lt;A href="https://www.bbc.co.uk/news/technology-48262681" target="_blank"&gt;https://www.bbc.co.uk/news/technology-48262681&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The latest version of WhatsApp on Android is 2.19.134&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The latest version of WhatsApp on iOS is 2.19.51&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 21:34:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22308#M2767</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-05-14T21:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22313#M2769</link>
      <description>&lt;P&gt;Indeed, no user interaction required, other than having your phone on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No details of the prevalence in the wild, but has been tracked in it's attack pattern as deliberate and targeted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's relatively arbitrary to begin with, using an inherent buffer overflow technique within the VoIP stack of the application. The impressive part is the no-touch deployment, and the clean up so the trace is minimal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very similar to the "Pegasus" strain seen at the beginning of the month. Not going to say where that particular piece has come from.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:23:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22313#M2769</guid>
      <dc:creator>HTCPCP-TEA</dc:creator>
      <dc:date>2019-05-15T08:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Update your Whatsapp ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22314#M2770</link>
      <description>&lt;P&gt;Some technical analysis of the issue/fix:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://research.checkpoint.com/the-nso-whatsapp-vulnerability-this-is-how-it-happened/" target="_blank"&gt;https://research.checkpoint.com/the-nso-whatsapp-vulnerability-this-is-how-it-happened/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:32:14 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Update-your-Whatsapp/m-p/22314#M2770</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-05-15T08:32:14Z</dc:date>
    </item>
  </channel>
</rss>

