Listen to this Post

A New Security Era Is Taking Shape
Cybersecurity is increasingly becoming a battle fought through everyday applications, trusted accounts, and seemingly ordinary interactions. A messaging app can become a target for account takeover, while a customer relationship management platform can expose personal information without attackers ever touching the most sensitive financial records.
That reality is behind two important cybersecurity developments reported on August 25, 2026. WhatsApp is rolling out a significant set of account-security improvements, including multiple passkeys, stronger two-step verification, and additional information about calls from unknown numbers. At the same time, New Zealand Sotheby’s International Realty is investigating unauthorized access to data stored on a third-party platform.
Together, these stories reveal an important trend: modern security is no longer just about building a stronger wall around a network. It is about protecting identities, reducing the value of stolen credentials, understanding third-party risk, and giving ordinary users enough information to make safer decisions.
WhatsApp Strengthens Account Protection
WhatsApp has announced several new security features designed to make account takeovers harder and suspicious communications easier to identify.
The most significant change is support for multiple passkeys. WhatsApp says more than 1 billion people have already configured a passkey, and users can now add more than one passkey to an account, particularly useful for people who move between Android and iOS devices.
This is an important evolution because passkeys eliminate much of the traditional password problem. Instead of remembering a password or depending on a temporary verification code, users can authenticate through mechanisms already protected by their device, such as a fingerprint, Face ID, or screen-lock credential.
Multiple Passkeys Could Make Recovery Easier
Allowing more than one passkey is more than a convenience feature.
Many people own several devices. A user might have an iPhone as a primary phone, an Android tablet, and another device used for work. A single authentication method can become inconvenient when people change platforms.
Multiple passkeys give users greater flexibility while maintaining a phishing-resistant authentication model.
WhatsApp specifically says users can add multiple passkeys when using both Android and iOS, with the option available under Settings > Account > Passkeys.
The broader security lesson is straightforward: authentication becomes stronger when users do not have to choose between security and convenience.
Passkeys Are Changing the Authentication Battle
Traditional passwords remain one of the weakest links in cybersecurity because they can be guessed, reused, stolen, phished, or exposed through breaches.
Passkeys approach the problem differently.
Rather than asking users to transmit a reusable secret, passkey systems rely on cryptographic credentials associated with the user’s device and protected by local authentication.
This does not make every account attack-proof, but it removes an enormous number of opportunities for attackers.
A criminal can send a convincing phishing page asking for a password. It is much harder to trick someone into remotely providing the cryptographic credential protected by their device.
WhatsApp Replaces the Six-Digit Security PIN
WhatsApp is also strengthening its two-step verification system.
Previously,
This matters because a short numerical PIN has a comparatively small search space.
A longer password dramatically increases the number of possible combinations, especially when users create genuinely unique credentials.
The change is particularly important in scenarios where an attacker has already obtained a user’s one-time login code. WhatsApp describes two-step verification as an additional barrier designed to prevent account takeover even if that one-time code has been compromised.
Security Gets Stronger When the User Gets More Control
One of the most interesting aspects of this update is that WhatsApp is not relying on a single security mechanism.
Instead, the platform is combining multiple layers:
Passkeys protect authentication.
Two-step verification adds another barrier.
Caller context helps users identify suspicious communications.
End-to-end encryption protects personal conversations and calls.
Each layer addresses a different part of the attack surface.
That layered approach is exactly what modern security architecture should look like.
Unknown Callers Will Come With More Context
WhatsApp is also changing how Android users see calls from people who are not in their contacts.
The updated interface can provide additional context, including whether the caller’s number is associated with another country and whether the caller shares groups with the recipient.
At first glance, this may look like a relatively small user-interface improvement.
It is actually a cybersecurity feature.
Why Caller Context Matters
Social engineering attacks often depend on urgency.
An attacker does not necessarily need to break encryption or exploit a software vulnerability. Sometimes all they need is for the victim to answer a call and believe the person on the other end.
A caller from an unfamiliar international number may deserve additional caution.
A caller who suddenly appears in a shared WhatsApp group may deserve a different level of attention.
Giving users more context before they answer creates a small but valuable pause between the arrival of the call and the decision to engage.
That pause can be enough to prevent a successful social-engineering attempt.
The Human Firewall Is Still Important
Technology cannot eliminate human risk.
Attackers continue to exploit curiosity, fear, urgency, authority, and trust.
WhatsApp’s caller-context feature recognizes this reality. Instead of pretending users will never encounter suspicious calls, the platform is giving them more information to make better decisions.
This is an increasingly important cybersecurity philosophy.
The strongest security system is not necessarily the one with the most complicated technology. It is the one that makes secure behavior easier for ordinary people.
A Second Incident Highlights Third-Party Risk
While WhatsApp is strengthening account security, another cybersecurity story involving New Zealand Sotheby’s International Realty demonstrates a completely different problem.
New Zealand
According to reporting from 1News, the affected platform was a customer relationship management system containing contact information used for marketing and operational purposes. Potentially exposed information includes names, addresses, phone numbers, and email addresses.
Sensitive Does Not Always Mean Financial
Sotheby’s stated that email exchanges, property documentation, and other substantive property-related material were not accessed.
The company also said the platform was not used to store information associated with customer financial transactions.
That distinction matters.
A data breach does not have to expose credit-card numbers or bank accounts to create meaningful risk.
Names, phone numbers, email addresses, and physical addresses can become valuable ingredients for phishing, impersonation, fraud, targeted social engineering, and identity-based attacks.
Personal information can become dangerous when combined with information from other databases.
The Third-Party Platform Problem
The
A business may have strong internal security controls while still depending on:
CRM providers.
Cloud hosting platforms.
Email services.
Marketing systems.
Analytics platforms.
Payment processors.
Customer support systems.
Identity providers.
Every external connection creates another potential path into sensitive information.
This is why third-party risk management has become a central part of cybersecurity strategy.
The 1.6 Million Contact Figure Needs Context
The incident has also generated discussion around a reported figure of approximately 1.6 million contacts.
However,
This is an important reminder that breach reporting can become confusing very quickly.
A number circulating online does not automatically represent the number of unique affected individuals.
Security teams need to distinguish between database records, duplicate records, unique people, affected accounts, and confirmed accessed information.
That distinction becomes particularly important when communicating with customers and regulators.
Investigation Is Still Underway
Sotheby’s says it took immediate steps to contain the incident and brought in independent cybersecurity specialists to investigate.
The company also notified New
The forensic investigation remains ongoing.
That means the final understanding of exactly what was accessed may change as investigators examine logs, authentication records, database activity, and third-party platform evidence.
Why These Two Stories Belong Together
At first, WhatsApp’s security update and the Sotheby’s incident appear unrelated.
One is about a messaging platform.
The other concerns a real-estate
But both stories point toward the same cybersecurity principle: identity and data protection must extend beyond the traditional network perimeter.
WhatsApp is attempting to protect the identity of the person logging into an account.
Sotheby’s is dealing with the consequences of unauthorized access to information held by an external platform.
One story focuses on preventing unauthorized access.
The other demonstrates what can happen when unauthorized access occurs.
Cybersecurity Is Becoming an Identity Problem
The security industry has spent decades thinking about firewalls, antivirus software, intrusion detection, and network segmentation.
Those technologies remain important.
But attackers increasingly target identities rather than machines.
They steal credentials.
They manipulate employees.
They exploit password reuse.
They compromise accounts.
They abuse legitimate cloud services.
They target third-party platforms.
This is why passkeys, strong authentication, access controls, and identity monitoring are becoming increasingly important.
What Users Should Do Right Now
WhatsApp users should check whether passkeys are available on their accounts and consider enabling them.
Users who still rely on weak two-step verification credentials should replace predictable PINs or passwords with strong, unique credentials when the new system becomes available to them.
People should also be cautious when receiving unexpected calls, particularly when the caller is unknown or the number appears unusual.
Security warnings should never be treated as background noise.
A suspicious call can be the first step in a much larger social-engineering campaign.
What Businesses Should Learn From the
Organizations should not treat third-party software providers as invisible extensions of their internal infrastructure.
Every external platform should be treated as part of the organization’s effective attack surface.
Security teams should understand what information is stored there, who can access it, how authentication is enforced, how logs are retained, and what happens if the vendor itself is compromised.
The most important question is not simply, “Is our company secure?”
It is also, “Is every company that holds our data secure enough?”
What Undercode Say:
The Authentication Layer Is Moving Forward
WhatsApp’s passkey expansion is part of a much larger migration away from password-centric authentication.
Passwords are fundamentally difficult for humans to manage securely.
Users reuse them.
Users choose predictable passwords.
Users enter them into fake websites.
Users accidentally expose them.
Passkeys attack the problem at its foundation.
They reduce the number of reusable secrets that attackers can steal.
They also make phishing considerably more difficult.
The Real Advantage Is Phishing Resistance
The strongest argument for passkeys is not convenience.
It is resistance to credential theft.
A traditional phishing campaign can convince a victim to type a password into a malicious page.
A properly implemented passkey cannot simply be copied and pasted into an attacker’s website.
That changes the economics of account takeover.
Multiple Devices Create a Practical Security Challenge
Security systems fail when they become too inconvenient.
If users have multiple devices, forcing them to maintain a single authentication path can create unnecessary friction.
Multiple passkeys address this problem.
A user can maintain separate authentication credentials for different devices without abandoning the security advantages of passkey-based authentication.
Stronger 2FA Is Still Valuable
Passkeys should not mean that secondary authentication becomes irrelevant.
Security architecture benefits from defense in depth.
If one layer fails, another should remain standing.
A stronger two-step verification password gives WhatsApp another barrier against account takeover.
Caller Context Attacks Social Engineering
The unknown-caller feature is particularly interesting because it targets psychology rather than software.
Attackers often need victims to participate.
They need a response.
They need trust.
They need urgency.
Caller context introduces friction before that interaction begins.
Small Friction Can Create Big Security Gains
A few seconds of hesitation can stop a scam.
A country indicator can reveal an unexpected international call.
A shared-group indicator can provide useful context.
Neither feature is revolutionary by itself.
Together, they can improve the
Third-Party Risk Is the Other Side of the Story
The Sotheby’s incident demonstrates that security cannot stop at an organization’s own servers.
The moment sensitive information enters an external CRM system, the vendor becomes part of the security equation.
This is increasingly true for almost every modern company.
Data Minimization Matters
Organizations should ask why a third-party platform needs particular information in the first place.
If information does not need to be stored, it does not need to be protected there.
Reducing unnecessary data is one of the simplest ways to reduce breach impact.
Duplicate Records Can Distort Breach Numbers
The dispute over the reported 1.6 million contacts also demonstrates why raw database numbers can be misleading.
One person may appear multiple times.
One contact may exist in multiple records.
A database row is not necessarily a unique victim.
Security reporting needs precision.
Incident Response Must Be Fast
Sotheby’s says it acted quickly to contain the incident.
That is critical.
The longer unauthorized access continues, the greater the opportunity for attackers to move through connected systems or extract additional information.
Logging Becomes Critical
Organizations cannot investigate what they cannot see.
Authentication logs.
API logs.
Database access records.
Administrative activity.
Cloud audit trails.
These records can become essential evidence during a forensic investigation.
Vendor Security Must Be Tested
A security questionnaire alone is not enough.
Organizations should evaluate vendor authentication controls, encryption, incident response procedures, access management, vulnerability management, and logging capabilities.
Zero Trust Is Becoming Practical Reality
The traditional idea of a trusted corporate perimeter is fading.
Users connect from everywhere.
Applications run in clouds.
Data moves between providers.
Employees use multiple devices.
Third parties process sensitive information.
Zero-trust principles are therefore becoming increasingly practical.
Identity Is the New Perimeter
The modern perimeter is increasingly defined by identity.
Who are you?
What device are you using?
What are you authorized to access?
What behavior is normal?
What changed?
Those questions are becoming more important than the physical location of the user.
Security Must Be Designed Around Real People
A complicated security system that nobody uses correctly is not necessarily secure.
WhatsApp’s approach is interesting because it combines stronger cryptography with simpler user decisions.
The best security controls often operate quietly in the background.
Attackers Will Adapt
Every successful defensive improvement eventually changes attacker behavior.
As passkeys become widespread, criminals will increasingly focus on device compromise, social engineering, recovery processes, malicious applications, and session theft.
Security is therefore a continuous process rather than a final destination.
Recovery Accounts Deserve Attention
Account recovery remains one of the most overlooked parts of authentication.
A strong login mechanism can still be undermined by a weak recovery process.
Organizations should therefore protect recovery channels as carefully as primary authentication.
The Biggest Risk May Be Outside the Organization
The
A company can secure its own infrastructure while still being exposed through a supplier.
That means cybersecurity teams need visibility across the entire digital supply chain.
Security Teams Need Better Asset Maps
Organizations should maintain accurate inventories of:
Customer data.
Third-party applications.
API integrations.
Privileged accounts.
Cloud environments.
Authentication providers.
Critical vendors.
Without this visibility, risk assessments become incomplete.
Passkeys Could Reduce Account Takeovers
If passkeys continue gaining adoption, the volume of password-based account attacks could decline.
That does not eliminate cybercrime.
It changes where criminals spend their effort.
The Human Element Will Remain
Technology can make phishing harder.
It cannot eliminate deception.
Users will still receive convincing messages, calls, emails, and fake support requests.
Security awareness therefore remains necessary.
The Strongest Security Model Is Layered
Passkeys.
Strong passwords.
Two-step verification.
Device security.
Caller context.
Monitoring.
Incident response.
Vendor controls.
Each layer contributes something different.
Cybersecurity Is Becoming More Preventive
The industry is gradually moving from detecting attacks after they happen toward preventing entire categories of attacks.
Passkeys are an example.
They do not merely detect phishing.
They make certain forms of credential theft substantially less useful.
Data Breaches Are Becoming More Complex
A breach is rarely a simple question of “what database was hacked?”
Modern investigations must determine:
Who accessed the system?
How did they authenticate?
What records were viewed?
What was downloaded?
Were records duplicated?
Were credentials compromised?
Were other systems affected?
Transparency Builds Trust
Companies facing security incidents need to communicate clearly.
Customers want to know what happened.
They want to know what information was involved.
They want to know what was not affected.
They also need practical advice.
The Security Race Never Ends
Attackers innovate.
Defenders innovate.
Technology changes.
Human behavior changes.
The organizations that remain safest are usually those willing to continuously improve rather than assume yesterday’s controls will protect tomorrow’s systems.
The Bigger Message
WhatsApp’s update shows how security can become easier for consumers.
The
Together, they demonstrate the same fundamental lesson:
Cybersecurity is no longer simply about protecting systems. It is about protecting identities, decisions, relationships, and data wherever they exist.
Deep Analysis: Test Your Security Posture From the Command Line
Check Linux Authentication Activity
On a Linux server, administrators can begin by reviewing recent authentication activity:
last -a
This can help identify unexpected successful logins and unusual access patterns.
Inspect Failed Login Attempts
To examine failed authentication attempts on systems using traditional authentication logs:
sudo grep "Failed password" /var/log/auth.log
Unexpected geographic or temporal patterns can indicate password attacks.
Review Privileged Access
Administrators should regularly examine privileged accounts:
sudo getent group sudo
Unexpected members of privileged groups should immediately trigger investigation.
Check Listening Network Services
A basic local exposure check can be performed with:
sudo ss -tulpn
This displays listening TCP and UDP services and can reveal applications that should not be exposed.
Review Active Connections
Administrators can inspect active network connections using:
sudo ss -tunap
This can help identify unusual outbound or inbound connections.
Examine System Logs
On systems using systemd:
sudo journalctl --since "24 hours ago"
Security teams can narrow this further to authentication-related events.
Search for Suspicious Privilege Changes
A useful investigation step is reviewing logs around changes to users and permissions:
sudo journalctl | grep -Ei "sudo|useradd|usermod|passwd|authentication"
Check Installed Software
Unexpected packages can indicate unauthorized changes:
dpkg -l
On RPM-based systems:
rpm -qa
Review Scheduled Tasks
Attackers sometimes establish persistence through scheduled jobs:
crontab -l sudo ls -la /etc/cron.
Inspect Recently Modified Files
For a basic review of recent filesystem changes:
sudo find /etc -type f -mtime -1 -ls
This is not a complete forensic method, but it can highlight unexpected recent modifications.
Examine SSH Configuration
SSH remains a major attack surface on internet-facing Linux systems:
sudo sshd -T | grep -Ei "passwordauthentication|permitrootlogin|pubkeyauthentication"
Organizations should verify that authentication settings match their security policies.
Audit Cloud and Third-Party Access
Command-line checks are only one part of a modern security program.
Cloud audit logs, SaaS authentication events, API activity, and vendor access logs must also be reviewed.
A secure Linux server cannot compensate for an exposed third-party CRM account.
Security Must Follow the Data
The most important lesson from these incidents is that security teams must follow information wherever it travels.
If customer data moves from a local database to a cloud CRM, security controls must follow it.
If an employee accesses an account from another device, identity controls must follow them.
If a user receives an unexpected WhatsApp call, contextual security information should follow the interaction.
That is the future of cybersecurity.
✅ WhatsApp Security Update Is Confirmed
Meta officially announced stronger two-step verification, multiple passkeys, and additional context for unknown callers on August 25, 2026. Meta also confirmed that more than 1 billion people have configured a WhatsApp passkey.
✅ New Zealand Sotheby’s Incident Is Confirmed
New Zealand
❌ The 1.6 Million Contact Figure Should Not Be Treated as 1.6 Million Unique Victims
The reported 1.6 million figure has been disputed by Sotheby’s, which said its database does not contain anywhere near that number of contacts and that duplicate entries may explain the figure. The investigation is still ongoing.
Prediction
(+1) Passkeys Will Become the Default Authentication Model
As more major platforms adopt passkeys, password-based authentication will gradually become less central to everyday account security.
(+1) Messaging Platforms Will Add More Anti-Scam Context
WhatsApp’s caller-context feature points toward a broader trend in which messaging applications provide users with risk information before they interact with unknown accounts.
(+1) Stronger Authentication Will Reduce Traditional Account Takeovers
Passkeys and stronger secondary authentication should make many credential-phishing attacks less effective, particularly when users keep their devices properly secured.
(+1) Third-Party Risk Management Will Receive More Attention
Incidents involving external SaaS and CRM providers will continue pushing companies toward stronger vendor assessments, tighter access controls, and better monitoring.
(-1) Attackers Will Not Disappear
As passwords become harder to exploit, criminals will likely shift toward social engineering, device compromise, session theft, malicious applications, and attacks against account-recovery mechanisms.
(-1) Data Exposure Will Remain a Major Problem
Even when financial records are not exposed, basic personal information can still fuel highly convincing phishing and impersonation campaigns.
The Bigger Cybersecurity Lesson
The most important message from these two stories is not simply that WhatsApp has added new security features or that Sotheby’s is investigating a third-party incident.
It is that the cybersecurity battlefield is moving closer to everyday life.
Your phone is an authentication device.
Your messaging account is an identity.
Your contact information is valuable intelligence.
A third-party CRM is part of a company’s effective attack surface.
A single unexpected phone call can become a social-engineering opportunity.
Security therefore has to exist at every stage, from the moment a user authenticates to the moment data is stored, processed, transferred, or accessed by a third-party provider.
WhatsApp’s passkeys and stronger verification represent the defensive side of that evolution.
The Sotheby’s incident represents the other side: the uncomfortable reminder that even organizations with security controls can face exposure through systems beyond their direct control.
The future of cybersecurity will belong to organizations and users that understand both sides of the equation.
Stronger authentication protects the door. Better visibility tells you who is approaching it. Strong third-party controls make sure there is not another door hidden somewhere else.
▶️ Related Video (72% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




