< ciso
brief />
Tag Banner

All news with #tencent cloud tag

4 articles

WeChat zero-click worm hijacks accounts via calls

๐Ÿ›ก๏ธ A Palo Alto startup, Calif, developed a tool called WeWorm that exploits a remote code execution flaw in WeChat's VoIP stack to compromise Android and iOS devices via incoming calls. Researchers say the zero-click exploit required no user interaction and can hijack accounts to read/send messages and make calls. Tencent patched the vulnerability in Android 8.0.77 and iOS 8.0.76 after being notified, and Calif warns the worm could scale further when combined with other bugs.
read more โ†’

WeChat zero-click worm hijacked accounts via calls

๐Ÿ“ฑ Researchers at security firm Calif created a worm that hijacks WeChat accounts via an incoming call and demonstrated it spreading across three test phones without user interaction. The attacker must already be one of the victim's WeChat contacts, and Calif says Tencent blocked the exploit on its servers after being notified in July. Calif withheld technical details pending a conference presentation and reported using AI to help locate the flaw and build the initial exploit.
read more โ†’

CDN Tsunami: HTTP/3-to-HTTP/1.1 Amplification Risk

๐Ÿ” Researchers disclosed two denial-of-service techniques, collectively dubbed CDN Tsunami, that exploit how major CDNs translate client-facing HTTP/3 into backend HTTP/1.1 requests, amplifying small attacker traffic to large origin load. The study tested Alibaba, Baidu, Cloudflare, CloudFront, Fastly, and Tencent, finding widespread susceptibility to a bandwidth amplification variant and partial susceptibility to a connection-amplification variant. Vendor mitigations are applied at CDN edges, and the work will be presented at a September 2026 symposium.
read more โ†’

VoidLink Linux Malware Targets Multi-Cloud Environments

๐Ÿ” New analysis by Ontinue details VoidLink, a Linux-based command-and-control framework that generates implant binaries for credential theft, data exfiltration and stealthy persistence across cloud and enterprise hosts. The agent fingerprints AWS, GCP, Azure, Alibaba and Tencent environments and adapts its behavior, loading modular plugins for container escape and kernel-level stealth. Researchers identified unusual development artefacts โ€” structured "Phase X:" labels, duplicated numbering, verbose debug logs and embedded documentation โ€” that suggest parts of the implant were written or assisted by a large language model coding agent with limited human review.
read more โ†’