← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 12, 2024 · 14:05via API Security News

Issue 254: WhatsApp and IBM WebMethods vulnerabilities, 3rd-party API and LLM risks, API access controls

Brief

This week, we investigate a recent flaw in WhatsApp’s View Once privacy feature and also critical vulnerabilities reported in the IBM WebMethods integration platform. We highlight a NordicAPIs article on the risks from third-party API and LLMs, and an article on solving the challenges of fine-grained access control for APIs.

There’s also an interesting webinar examining how GenAI can increase the attack surface for risky APIs.

Vulnerability: WhatsApp client-side security flaw

A research team at Zengo has discovered a flaw in WhatsApp’s View Once privacy feature. This feature allows a WhatsApp user to send photos, voice messages, or videos that disappear from a chat after the recipient downloads and opens them once. The feature also prevents a recipient from saving, sharing or even screen-capturing a photo or video on their device.

Read more on API Security News