Security News

Cybersecurity news aggregator

INFO Updates SC Media

Signal introduces automatic key verification to combat man-in-the-middle attacks

  • What: Signal introduces Automatic Key Verification to prevent man-in-the-middle attacks
  • Impact: Enhances security for encrypted chats
Read Full Article →

Application security Signal introduces automatic key verification to combat man-in-the-middle attacks August 12, 2026 Share By SC Staff (Adobe Stock) Signal has introduced a new feature called Automatic Key Verification (AKV) to enhance the security of its encrypted chats, aiming to prevent secret interference with user conversations, with further coverage provided by The Register. The new AKV feature is designed to combat man-in-the-middle attacks, where an adversary could intercept messages by corrupting Signal's centralized directory and posing as another user. While messages would remain encrypted, they would be sent to the wrong destination. AKV works by creating a ledger of public keys, with each user interaction generating a new iteration. This ledger is accompanied by an index, allowing users to verify that their contact's public encryption key hasn't been tampered with. Signal has enlisted Cloudflare and Trail of Bits as third-party auditors to verify the integrity of its key transparency server. Users can manually initiate verification by tapping a "Verify automatically" button on a contact's profile, which displays a green checkmark if the encryption key matches Signal's system expectations. However, this feature requires users to have their contact's phone number within Signal or their phone's address book. Users can also disable AKV and rely on traditional safety number or QR code verification if they prefer to avoid third-party involvement. Source: The Register SC Staff Related Application security US cyber officials warn AI is giving attackers an edge SC Staff August 11, 2026 FBI and CISA officials warn AI could accelerate cyberattacks as agencies bolster U.S. defenses. AI/ML ‘GhostJacking’ attack turns error logs into indirect prompt injections Laura French August 11, 2026 Attacks targeting Cloudflare, DataDog and Sentry MCP integrations were demonstrated at DEF CON 34. Application security 176 vulnerabilities discovered in Samsung mobile apps SC Staff August 10, 2026 The vulnerabilities were found in Samsung's proprietary system apps, which cannot be uninstalled by users and operate outside the protection of Google Play Protect. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds

Share this article