Adaderana.Lk WhatsApp Spyware Exploit via Phone Calls Poses Serious Threat
Article Content
- •WhatsApp patched a critical buffer-overflow vulnerability that allowed spyware installation.
- •The exploit could compromise devices without user interaction, increasing the risk for all users.
- •The NSO Group's Pegasus spyware was linked to this attack, targeting high-value individuals.
A vulnerability in WhatsApp allowed attackers to install spyware through phone calls made via the app, even if the call was not answered. This exploit, linked to a buffer-overflow vulnerability, was quickly patched by WhatsApp. The malicious code was reportedly developed by the NSO Group, known for its Pegasus spyware, which can activate device cameras and microphones. The attack primarily targets high-risk individuals such as activists and journalists, but regular users are also at risk due to the widespread nature of the vulnerability. Users are urged to update their WhatsApp applications immediately to mitigate the threat. The incident highlights the ongoing risks associated with messaging apps, which are often targeted for their sensitive data. Buffer-overflow vulnerabilities have been a concern in software development for decades, making this a significant security issue.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Morris Worm and NSO Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…