Thursday , July 23 2026
WhatsApp

India asks WhatsApp not to roll out ‘username’ feature over fraud concerns

The Indian government issued a notice WhatsApp planned to roll out its new ‘username’ feature. They are worried about fake accounts and fraud. The company must discuss the issue before moving forward.

This week, WhatsApp said it will let users pick a username and hide their phone numbers when they first contact someone. Users can choose a unique name for their WhatsApp account. Others can use this name to message or call them without seeing their phone number.

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
“PentestCode” AI Agent Automating Penetration Testing with 18 Tools

CVE-2026-60137, CVE-2026-63030
Patch immediately! 2 high severity WordPress flaws found

The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
CVE-2026-60137, CVE-2026-63030  Patch immediately! 2 high severity WordPress flaws found

Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

CVE-2026-53412
Zoom Warns of critical account takeover Flaw via Network Access

Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
CVE-2026-53412  Zoom Warns of critical account takeover Flaw via Network Access

India to built Mythos-like AI model “Sarvam AI” and “BharatGen” assigned

India is speeding up its work to make homegrown AI models for cybersecurity. These models will help protect important digital...
Read More
India to built Mythos-like AI model “Sarvam AI” and “BharatGen” assigned

Cursor, SonicWall, SharePoint 0-day exploited to the wild

A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers...
Read More
Cursor, SonicWall, SharePoint 0-day exploited to the wild

Microsoft Patch Tuesday July-2026 fixes 570 flaws, 3 zero-days

Microsoft's Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June's big update,...
Read More
Microsoft Patch Tuesday July-2026 fixes 570 flaws, 3 zero-days

Senior government officials said the Union Ministry of Home Affairs raised concerns with the Ministry of Electronics and IT. They said the government would undertake a risk assessment of the new feature, and see if it falls foul of the current legal architecture.

The government wants Meta to provide a full explanation of the username feature in three days. They also told the company not to launch the feature until discussions are finished, an official said.

“As we understand now, there is a possibility that bad actors may claim usernames, or close-enough variations related to prominent personalities, institutions, and organizations, and message other users while pretending to be someone they are not. For those who may not be technologically aware to make out the difference, it could be a huge challenge. We have already seen bad actors carry out impersonation-linked scams such as digital arrests through WhatsApp, and this feature could further help them,” a senior government official said, requesting anonymity.

In a statement, WhatsApp said it plans to roll out the features slowly later this year, but clarified it has built safeguards. “To protect against impersonation, we’ve held the highest-profile names — think public figures, government entities, celebrities, verified Meta accounts — so they can only ever be claimed by their legitimate owners and lookalike derivatives of known names are held as well.”

It said the users still require a phone number to use WhatsApp and that it has built multiple layers of defense against scams into usernames. “Other users need to know the exact username to message you, we will limit how many new people an account can contact, block repeated attempts to guess someone’s username key, and have systems to detect and remove activity showing common impersonation and abuse patterns,” the WhatsApp spokesperson said.

Further, it said, when the feature becomes available and someone sends a message for the first time via the username, WhatsApp will show if they are a new account, if they are in contact, if they are in common groups, and if they are based in a different country, so that one can choose whether or not to respond, the spokesperson said.

WhatsApp to allow usernames instead of phone numbers

Check Also

CrowdStrike

CrowdStrike Shows 5 New Prompt Injection Techniques for AI Agents

CrowdStrike has shared five new ways to inject prompts, showing the rising danger to AI …