Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16. No Linked Devices, No Warning
2026-05-25T14:51:43Z•4f4d0696584225b48718f2056582039914e8e3d5f877413dd3a92e2cd0ff4465
AnthropicCISACVE-2026-9082ClickFixCobalt StrikeDrupalGhostwriterProject GlasswingSQL injectionStark IndustriesWhatsAppaccount-takeoverdisinformationhosting-takedowniOS 16known-exploited-vulnerabilitymalware-distributionphishingpure-extortionvulnerability-managementzero-click
What happened
Security Affairs roundup covering multiple high-risk incidents: a zero-click WhatsApp account takeover impacting iPhones on iOS 16 (accounts hijacked without linked devices or user interaction); Dutch authorities dismantling a hosting network (Stark Industries) tied to cyberattacks and disinformation; a compromised merchandise site used to distribute malware via a ClickFix-style trick; and the return of Ghostwriter APT using a Ukrainian learning platform to deliver Cobalt Strike. The feed highlights active exploitation of a highly critical Drupal SQL injection (CVE-2026-9082, CVSS 9.8) now onC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 4f4d0696584225b48718f2056582039914e8e3d5f877413dd3a92e2cd0ff4465
- Enrichment time
- 2026-05-25T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.