Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Operation Endgame 3.0 Dismantles Three Major Malware Networks

November 13, 2025

Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed

November 13, 2025

“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

November 13, 2025
Facebook X (Twitter) Instagram
Friday, November 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CISA Adds Zero-Day Bug Used in Spyware Attacks to KEV
News

CISA Adds Zero-Day Bug Used in Spyware Attacks to KEV

Team-CWDBy Team-CWDNovember 11, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US federal agencies have been told to patch a zero-day vulnerability used by threat actors since last year to deploy spyware to Samsung devices.

The out-of-bounds write flaw CVE-2025-21042 has a CVSS score of 9.8 and was patched by Samsung in April. However, an analysis by Palo Alto Networks published last week claimed it had been used in a spyware campaign since mid-2024.

During that campaign, commercial-grade spyware known as LandFall was embedded in malicious DNG image files and sent via WhatsApp to targets. Zero-click exploits may have been used to achieve remote code execution without any user interaction, Palo Alto said.

“This method closely resembles an exploit chain involving Apple and WhatsApp that drew attention in August 2025,” it added.

“It also resembles an exploit chain that likely occurred using a similar zero-day vulnerability (CVE-2025-21043) disclosed in September. Our research did not identify any unknown vulnerabilities in WhatsApp.”

Read more on commercial spyware: France Warns Apple Users of New Spyware Campaign

According to Palo Alto’s analysis, LandFall is primarily designed to target victims in the Middle East and enables “comprehensive surveillance, including microphone recording, location tracking and collection of photos, contacts and call logs.”

The report adds: “The campaign shares infrastructure and tradecraft patterns with commercial spyware operations in the Middle East, indicating possible links to private-sector offensive actors (PSOAs).”

At risk are a wide range of Samsung devices, including Galaxy S22, S23, and S24, and Z Fold4 and Z Flip4.

CISA KEV Sets Deadline Date

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-21042 to its Known Exploited Vulnerabilities (KEV) catalog yesterday.

It requires federal agencies to take the following actions by December 1: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Private sector organizations are also encouraged to follow KEV guidance where possible to improve their security posture.

Image credit: viewimage / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability
Next Article New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
Team-CWD
  • Website

Related Posts

News

Operation Endgame 3.0 Dismantles Three Major Malware Networks

November 13, 2025
News

Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed

November 13, 2025
News

“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

November 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest News

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views

The risks of unsupported IoT tech

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views
Our Picks

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

It’s all fun and games until someone gets hacked

September 26, 2025

Why you should never pay to get paid

September 15, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2025 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.