WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. The action comes despite a 2025 U.S. court injunction, $167 million fine, and U.S. sanctions against the spyware vendor.

WhatsApp reports that it has identified and blocked spear-phishing operations believed to originate from the NSO Group, following its review of complaints about social engineering tactics.
WhatsApp noted that end-to-end encryption effectively protects users’ messages and calls from Pegasus and other spyware but called users to update their apps and operating systems for optimal protection.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Google has rolled out a selfie video option that lets users recover their Google Accounts by recording head movements for comparison against a stored video. The encrypted feature adds another recovery method while recommending multiple sign-in options and includes safeguards against AI-based impersonation.
The European Commission has fined Alphabet €890 million for two DMA violations: self-preferencing its own services in Google Search and restricting payment steering options in the Play Store. Google must revise its policies within 60 days or face further penalties.
CISA added the actively exploited Microsoft SharePoint deserialization vulnerability CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on 2026-07-22 with a federal due date of 2026-07-25. Agencies and organizations must apply vendor mitigations per BOD 26-04 or discontinue use if patches are unavailable.