Signal has rolled out Automatic Key Verification, a new security feature designed to prevent man-in-the-middle attacks on encrypted messages. The feature strengthens Signal's existing encryption protections.
The new Automatic Key Verification system works by continuously monitoring encryption keys used in Signal conversations. If a key is tampered with or replaced during communication, the feature alerts users to potential interception attempts.
Man-in-the-middle attacks occur when a third party intercepts encrypted communications and substitutes their own encryption keys, allowing them to read messages while remaining undetected. Signal's verification system closes this vulnerability by making key changes immediately visible to both parties.
Users don't need to take action to enable the protection—it operates automatically across all Signal chats. The feature builds on Signal's existing end-to-end encryption, which already prevents unauthorized access to message content.
Signal, the encrypted messaging app backed by the Signal Foundation, continues to emphasize security improvements as messaging apps face increasing scrutiny over data privacy. The update is available to Signal users on all platforms.
Security group Nightmare Eclipse has disclosed a zero-day vulnerability in Microsoft Defender named 'ShieldBreak' that grants SYSTEM-level privileges. The exploit emerged after Microsoft's August 2026 Patch Tuesday updates.
Wesco, a global supply chain and distribution company, acknowledged a cybersecurity incident following claims by ExfilSquad that it stole company data. The investigation is ongoing.
Hackers compromised a heat-and-power facility in Poland that serves approximately 50,000 residents by exploiting a private APN connection to access its operational technology network.
Mozilla has replaced the GPG signing key used for Firefox and Thunderbird releases following an accidental exposure on GitHub. The security update ensures the integrity of future software releases.