Signal has rolled out additional in-app alerts and verification prompts to help users defend against phishing and social engineering scams. According to the company, these new safeguards are intended to slow users down before responding to suspicious requests, allowing them more time to verify whether a message or action is genuine. The move follows a rise in fraudulent campaigns targeting Signal users through fake support notifications and deceptive account verification requests. Security investigations conducted by organizations such as the FBI and European authorities found that some of these attacks were connected to Russian state-backed hacking groups. The attackers reportedly abused Signal’s Linked Device functionality to gain unauthorized access to user accounts, including private chats and contact information. Victims were manipulated into scanning malicious QR codes or sharing one-time authentication codes under the pretense of securing their accounts. Once attackers obtained these details, they could link their own devices and secretly access user communications. To improve account security, Signal has introduced several new warning indicators and educational messages within the application. Users may now see labels like “Name not verified” or “No groups in common” when contacted by unknown individuals. Additional reminders also inform users that Signal will never ask for registration codes, PINs, or recovery keys. The platform has expanded its in-app safety guidance to help users recognize impersonation attempts and fraudulent support messages. Signal also advises users to stay cautious when interacting with unknown contacts, avoid sharing verification credentials, and routinely check linked devices to detect and remove unauthorized access.
Cybersecurity researchers have uncovered four critical vulnerabilities in OpenClaw that can be chained together to enable data theft, privilege escalation, and long-term persistenc...
OpenAI confirmed that two employee devices were compromised as part of a broader supply chain attack involving malicious packages distributed through the TanStack JavaScript ecosys...
Gunra Ransomware has emerged as a significant cyber threat targeting Windows-based enterprise environments across multiple industries, including manufacturing, pharmaceuticals, and...