Security news aggregator

Latest coverage for Zero-Click

Stay secure with the latest updates on Zero-Click attacks & prevention techniques. Your source for info on seamless yet dangerous cyber threats.

104 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Zero-Click describes a type of cyber attack that requires no interaction from the target user to be executed. Unlike phishing attacks, which typically rely on a user clicking a malicious link or opening an infected attachment, zero-click exploits take advantage of vulnerabilities in software or devices that can be triggered without user action.

In the context of information security, zero-click vulnerabilities are particularly concerning because they can be harder to detect and prevent. Attackers can potentially gain control over devices, access sensitive data, or spread malware without the user's knowledge. These attacks emphasize the need for robust security measures, such as keeping software up to date, using advanced threat detection systems, and implementing strict access controls, to protect against these stealthy and often sophisticated intrusions.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 104 Filtered view

A zero-click attack targeting iPhones on iOS 16 hijacked WhatsApp accounts without linked devices, warnings, or user interaction. There is a particular kind of security incident that is harder to explain than most: your WhatsApp account is sending messages you did not write, asking your contacts for money transfers, and when you check the “Linked […]

Second try's a charm? Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive information on vulnerable systems.…

Could steal sensitive personal and financial data After a whopper of a Patch Tuesday last month, with six Microsoft flaws exploited as zero-days, March didn't exactly roar in like a lion. Just two of the 83 Microsoft CVEs released on Tuesday are listed as publicly known, and none is under active exploitation, which we're sure is a welcome change to sysadmins.…

Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn AI agents can shop for you, program for you, and, if you're feeling bold, chat for you in a messaging app. But beware: attackers can use malicious prompts in chat to trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.…

Most of this week’s threats didn’t rely on new tricks. They relied on familiar systems behaving exactly as designed, just in the wrong hands. Ordinary files, routine services, and trusted workflows were enough to open doors without forcing them

Bank Info Security 5 months, 3 weeks ago

Google Patches AI Flaw That Turned Gemini Into a Spy

Zero-Click Vulnerability Let Attackers Weaponize Enterprise AI AssistantGoogle patched a vulnerability in Gemini Enterprise that allowed attackers to steal corporate data through a shared document, calendar invitation or email without any user action or security alerts. No malware was executed, no credentials were phished and no data left through approved channels.

Cyber Advisory Cites Abuse of Linked Devices to Monitor Sensitive CommunicationsThe U.S cyber defense agency issued an alert outlining how commercial spyware and state-aligned groups are abusing messaging-app features through malicious QR-based linking and zero-click exploitation to monitor U.S. government, military and other high-profile figures.

Attackers sidestep encryption with spoofed apps and zero-click exploits to compromise 'high-value' mobile users CISA has warned that state-backed snoops and cyber-mercenaries are actively abusing commercial spyware to break into Signal and WhatsApp accounts, hijack devices, and quietly rummage through the phones of what the agency calls "high-value" users.…

Loading more headlines...