The images in this article were generated with artificial intelligence. How we publish
Meta has presented a new security option in WhatsApp for people who, for their work or public visibility, can be the target of sophisticated digital espionage attacks. This is a way that restricts several app functions and raises barriers to attack vectors that often take advantage of apparently harmless interactions, such as messages or attachments of unknown senders.
The functionality, baptized as Strict Account Settings, recalls tools already known in other ecosystems, such as the Lockdown Apple Mode or Google Advanced Protection. In essence, Meta proposes to sacrifice some comfort to obtain a much stricter safety profile: when the mode is active, several settings are set in the most conservative option and the application limits the reception of content from people who are not on the contact agenda.

The practical consequences include the restriction of automatic downloads, the reduction of ways in which third parties can initiate communications and, according to the company, the silencing of calls from unrecognized numbers. They are measures aimed at cutting the pass to exploits that spread through multimedia files or links sent by adversaries who try to camouflage themselves as legitimate contacts.
Meta explains that the new alternative can be activated from the app itself: Settings > Privacy > Advanced, and that the implementation will be gradual over the next few weeks. While the firm does not want it to be a solution for all users - it is not necessary for the majority - it does recommend it for journalists, activists, officials or anyone who may be at greater risk for their public profile.
In parallel to this functionality, WhatsApp has announced a relevant technical initiative: the incorporation of programming language Rust in its media exchange infrastructure. The objective is to minimize vulnerabilities linked to memory management, a type of failure often exploited by advanced spyware.
By adopting Rust to develop a multi-platform bookstore called "wamedia," Meta states that it has achieved a safer and more efficient platform for processing photos, videos and other files that users share daily. Rust is known for its model of memory security in compilation time, which drastically reduces classic errors such as buffer overflows or already released memory access, problems that in C and C + + have generated serious historical gaps.
The company describes this initiative as one of the largest implementation of code written in Rust on a global scale within its products, and it is accompanied by a three-pronged approach to address the risks: design to limit the attack surface, strengthening the parts still written in C / C + + with greater security guarantees, and choosing languages with memory security for the new code whenever possible.
In addition to the use of Rust, Meta points out that it has applied techniques such as Control-Flow Integrity (CFI), hardened memory and APIs that handle buffers more safely. They are measures that, combined, form an in-depth defence strategy aimed at reducing the likelihood that an isolated failure will lead to a massive intrusion.
Such technical improvements are not an instant remedy to all threats, but they do mark an important trend in industry: to put memory protection and best security practices as pillars of development in applications that handle large-scale personal data. That an app with more than two billion users invest in these measures is relevant to the entire ecosystem.

If you are concerned about safety for your media or professional exposure, activating these options can be a good first step. However, it should be recalled that basic digital hygiene remains essential: to keep the operating system and apps up to date, to distrust links and files from unknown shipping and to complement protection with practices such as the use of safe passwords and verification in two steps.
For those who want to deepen the official ads, Meta has posted details on her corporate blog on the new strict account mode and Rust's deployment on the multimedia platform. You can see the WhatsApp privacy note on the platform's official blog Here. and technical explanation in the engineering blog of Meta Here.. Meta has also disseminated a statement on the initiative from its corporate site Here..
In short, the combination of more restrictive use adjustments for risk profiles and deep changes in the code base are signs that security on large platforms is evolving. There is no single solution to targeted espionage, but the measures announced by Meta represent concrete steps in the right direction to reduce attack vectors used by sophisticated actors.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...