Edgar Weippl

19 Followers
30 Following
113 Posts
"WhatsApp gilt als sicherer Messenger – doch Sicherheit endet nicht bei der Verschlüsselung. Neue Forschung zeigt, wie viel sich allein aus der technischen Nutzung und den Profileinstellungen ableiten lässt. " (https://www.futurezone.de/digital-life/apps/article695464/whatsapp-schwachstelle-betrifft-alle-nutzer-diese-einstellung-solltest-du-dringend-pruefen.html und das Paper https://arxiv.org/pdf/2411.11194v4

Obfuscation detection using matrix complexity features of binary grayscale images

Sebastian Raubitzek, Sebastian Schrittwieser, Caroline König, Patrick Felbauer, Kevin Mallinger, Andreas Ekelhart, Edgar Weippl, Computers & Security, https://lnkd.in/gaYgBDWW.
Download at https://lnkd.in/dcfxBSa8

Nice interview with Aljosha on our current WhatsApp paper (University of Vienna and SBA Research): https://netzpolitik.org/2025/interview-zu-whatsapp-von-emojis-zum-mega-datenleck/

The full paper as preprint: https://arxiv.org/abs/2511.20252

Gabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich und Aljosha Judmayer: Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy. In Network and Distributed System Security Symposium (NDSS), 2026.

Lots of additional news outlets picked up our media release about the Whatsapp paper a few days later:
- https://www.pressreader.com/austria/kurier-3402/20251120/281990383806986
- https://www.t-online.de/digital/aktuelles/id_101009188/whatsapp-sicherheitsluecke-daten-von-3-5-milliarden-nutzern-offengelegt.html
- https://www.ad-hoc-news.de/boerse/news/ueberblick/whatsapp-3-5-milliarden-nutzerprofile-lagen-monatelang-offen/68375934
- https://www.ad-hoc-news.de/boerse/news/ueberblick/whatsapp-3-5-milliarden-nutzer-accounts-ausgelesen/68377505
- https://www.ad-hoc-news.de/boerse/news/ueberblick/whatsapp-datenleck-3-5-milliarden-nutzer-betroffen/68376033
- https://maresmedia.se/whatsapp-leak-legt-35-milliarden-profile-offen-was-forscher-ueber-jobs-vorlieben-und-sensible-kontakte-herausfanden/
- https://cybernews.com/de/sicherheit/sicherheitsforscher-extrahieren-100-millionen-whatsapp-nummern/
- https://www.fr.de/verbraucher/forscher-entlarven-fatale-whatsapp-sicherheitsluecke-nummer-und-profilbild-ungeschuetzt-sichtbar-94048307.html
- https://ga.de/news/wirtschaft/regional/sicherheitsluecke-bei-whatsapp-forscher-kommen-an-milliarden-daten_aid-139389671
- https://www.hersfelder-zeitung.de/verbraucher/whatsapp-sicherheitsluecke-betrifft-milliarden-nutzer-telefonnummer-und-profilbild-einsehbar-zr-94048304.html
- https://www.ad-hoc-news.de/boerse/news/ueberblick/whatsapp-3-5-milliarden-konten-durch-sicherheitsluecke-aufgedeckt/68369434
- https://www.wochenblitz.com/forschende-lesen-komplettes-whatsapp-verzeichnis-aus/
- https://www.it-boltwise.de/whatsapp-datenleck-forscher-decken-massive-sicherheitsluecke-auf.html#google_vignette
- https://www.deskmodder.de/blog/2025/11/19/whatsapp-forscher-laden-35-milliarden-profile-groesster-abfluss-der-geschichte/
- https://www.ad-hoc-news.de/boerse/news/ueberblick/whatsapp-3-5-milliarden-nutzerkonten-waren-angreifbar/68372584
...
PressReader.com - Digital Newspaper & Magazine Subscriptions

Digital newsstand featuring 7000+ of the world’s most popular newspapers & magazines. Enjoy unlimited reading on up to 5 devices with 7-day free trial.

Cispa European Cybersecurity & AI Hackathon Championship an der Universität Wien
https://cispa.de/en/cispa-hackathon-championship
"Informatiker*innen der Universität Wien und von SBA Research haben eine große Datenschutzlücke im Contact Discovery Mechanismus von WhatsApp aufgedeckt." https://www.univie.ac.at/aktuelles/detail/forscherinnen-entdecken-grosse-sicherheitsluecke-in-whatsapp

"“Well, scientists now know a lot of phone numbers,” the responsible parties might have thought, “So what?” Repeated warnings submitted ... filed away. Only when the researchers submitted a draft of their paper twice and its uncoordinated publication was imminent did Meta wake up: a surprising amount can be read from the data, and for some users, it can be life-threatening."

Heise: https://www.heise.de/en/news/3-5-Billion-Accounts-Complete-WhatsApp-Directory-Retrieved-and-Evaluated-11083244.html
FutureZone: https://futurezone.at/apps/whatsapp-sicherheitsluecke-alle-nutzer-betroffen-contact-discovery-anfragen/403104148

"Malware that conceals its behaviour through code obfuscation remains a central challenge for automated detection. This work introduced a novel approach for detecting the presence of obfuscation and identifying specific techniques. We transform binary code into grayscale images by mapping its bytes to a pixel intensity and apply singular value decomposition (SVD) to extract 18 matrix-complexity metrics that reflect structural changes introduced by an obfuscation. " (https://doi.org/10.1016/j.cose.2025.104746)
CISPA European AI and Cybersecurity Hackathon Championship. Dec 13+14 @Univie University of Vienna
Critical XSS vuln (CVE-2025-39663, CVSS 9.1) in Checkmk fixed.
Discovered by SBA Research — allowed JS injection & potential RCE in distributed setups.
Admins: update to 2.4.0p14 / 2.3.0p39, disable “Trust this site completely”.
🔗 heise.de/-10964747