Issue 254: WhatsApp and IBM WebMethods vulnerabilities, 3rd-party API and LLM risks, API access controls
Brief
This week, we investigate a recent flaw in WhatsApp’s View Once privacy feature and also critical vulnerabilities reported in the IBM WebMethods integration platform. We highlight a NordicAPIs article on the risks from third-party API and LLMs, and an article on solving the challenges of fine-grained access control for APIs.
There’s also an interesting webinar examining how GenAI can increase the attack surface for risky APIs.
Vulnerability: WhatsApp client-side security flaw
A research team at Zengo has discovered a flaw in WhatsApp’s View Once privacy feature. This feature allows a WhatsApp user to send photos, voice messages, or videos that disappear from a chat after the recipient downloads and opens them once. The feature also prevents a recipient from saving, sharing or even screen-capturing a photo or video on their device.
