Meta: NSO Tried Targeting WhatsApp Users Despite Court Order
2026-06-09T08:51:49Z•b409bf4173a7fb81c897ce6dee57c975365af3042ec495e482085680433dd76b
AI securityCISACVE-2024-21182DentaQuestGemini AndroidGitHubHugging FaceLinkedInMetaMicrosoft 365 AndroidNSANSOOAuth token theftOracle WebLogicRCETransformersWhatsAppanthropicdata breachfake recruitersphishingspywaresupply-chain riskzero-day
What happened
A cluster of high-impact security stories: Meta says WhatsApp disrupted new NSO-linked phishing/spyware targeting despite a court order; CISA added Oracle WebLogic CVE-2024-21182 to its KEV as actively exploited; a GitHub one‑click zero‑day exposed developer OAuth tokens; a Hugging Face Transformers flaw could enable RCE via malicious models; and DentaQuest confirmed a breach exposing ~2.6M accounts. Other notable issues include Microsoft 365 Android token debug flaws, malicious WhatsApp/Slack alerts that could manipulate Gemini on Android, Chinese intelligence using fake recruiters on job/LIK
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- techrepublic_security
- Record identifier
- b409bf4173a7fb81c897ce6dee57c975365af3042ec495e482085680433dd76b
- Enrichment time
- 2026-06-09T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.