Rewterz

Rewterz Threat Advisory – CVE-2020-6969 – ICS: AutomationDirect C-More Touch Panels

February 6, 2020
Rewterz

Rewterz Threat Advisory – ICS: Medtronic Conexus Radio Frequency Telemetry Protocol

February 7, 2020

Rewterz Threat Advisory – CVE-2019-18426 – WhatsApp Bug Allows Malicious Code-Injection

Severity

High

Analysis summary

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.

rich preview link

Impact

Cross-site scripting

Affected Vendors

WhatsApp

Affected Products

WhatsApp Desktop prior to v0.3.9309 paired with WhatsApp for iPhone versions prior to 2.20.10

Remediation

Update to the latest version.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.