The images in this article were generated with artificial intelligence. How we publish
Meta announced this week that it stopped speech-phishing attempts linked to the Israeli spyware provider NSO Group and that it will submit a contempt motion to a federal court for alleged violations of a court order that prohibits the group from going to WhatsApp and its users. According to the company, the attackers tried to deceive people to click on malicious links that redirected to external sites, a tactic that recalls the "1-click phishing" campaigns previously attributed to NSO and that also involved the creation of accounts and test groups in WhatsApp that Meta eliminated.
It is important to distinguish between the protection provided by end-to-end encryption and the exposure that causes attacks on the user's device. Encryption protects transit content but does not prevent an attacker from compromising a phone by means of a malicious link or invading software like Pegasus. Therefore, although WhatsApp emphasizes that messages and calls remain encrypted by default, the real threat to many victims is the infection of the device, not the interception of transit communication.

The detected maneuver included malicious domains identified by Meta, including fr24cast [.] com, ghazacast [.] com and ikhwancast [.] com, which were used as decoy. Technically, a 1-click phishing attack can work by exploiting vulnerabilities in apps or browsers to run code by just opening a link or a page, which drastically reduces the need for the victim to do more than a simple click. This capacity makes these attacks particularly dangerous for journalists, activists, officials and anyone in high-risk environments.
On the legal and policy level, the case adds another layer of pressure on NSO Group: last year the company was sentenced to pay damages for exploiting WhatsApp servers to deploy spyware against more than 1,400 people, and in 2021 it was included in the list of entities of the US Department of Commerce. United States for activities contrary to national security. Meta's tactic of requesting legal action shows that the large platforms combine technical detection with litigation to stop actors operating at the border between commercial marketing and illegal surveillance.

For users and security officials, practical recommendations remain the same but with a greater emphasis on advanced prevention: maintaining systems and applications always up to date, avoiding opening links received from unverified sources and reporting any suspicious activity to the platform. In addition, WhatsApp offers an option for "Strict account settings"- a hard configuration mode that limits who can see and contact the account - and other protections such as disable previous link views and activating verification in two steps; official information about these measures is available on the WhatsApp security page https: / / www.Whatsapp.com / security.
Those who consider their profile to be a potential target should raise their controls: activate double factor authentication preferably with physical keys, limit the visibility of the profile information, restrict who can add them to groups and consider the advice of mobile device analysis specialists. Organizations and journalists investigating spyware threats can also benefit from public resources and forensic studies on Pegasus and vectors of infection, for example Citizen Lab which document techniques and evidence used by surveillance companies.
Ultimately, this episode stresses that the fight against commercial spyware requires a combined response: continuous improvements in the technical security of platforms, regulatory and judicial updates that criminalize abuse, and stricter digital hygiene practices by users and organizations. Update, restrict and verify remain the basic rules for reducing the area of attack, but in cases of high risk effective protection requires proactive measures and, where appropriate, forensic and legal support.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...