Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CISA Adds Zero-Day Bug Used in Spyware Attacks to KEV
News

CISA Adds Zero-Day Bug Used in Spyware Attacks to KEV

Team-CWDBy Team-CWDNovember 11, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US federal agencies have been told to patch a zero-day vulnerability used by threat actors since last year to deploy spyware to Samsung devices.

The out-of-bounds write flaw CVE-2025-21042 has a CVSS score of 9.8 and was patched by Samsung in April. However, an analysis by Palo Alto Networks published last week claimed it had been used in a spyware campaign since mid-2024.

During that campaign, commercial-grade spyware known as LandFall was embedded in malicious DNG image files and sent via WhatsApp to targets. Zero-click exploits may have been used to achieve remote code execution without any user interaction, Palo Alto said.

“This method closely resembles an exploit chain involving Apple and WhatsApp that drew attention in August 2025,” it added.

“It also resembles an exploit chain that likely occurred using a similar zero-day vulnerability (CVE-2025-21043) disclosed in September. Our research did not identify any unknown vulnerabilities in WhatsApp.”

Read more on commercial spyware: France Warns Apple Users of New Spyware Campaign

According to Palo Alto’s analysis, LandFall is primarily designed to target victims in the Middle East and enables “comprehensive surveillance, including microphone recording, location tracking and collection of photos, contacts and call logs.”

The report adds: “The campaign shares infrastructure and tradecraft patterns with commercial spyware operations in the Middle East, indicating possible links to private-sector offensive actors (PSOAs).”

At risk are a wide range of Samsung devices, including Galaxy S22, S23, and S24, and Z Fold4 and Z Flip4.

CISA KEV Sets Deadline Date

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-21042 to its Known Exploited Vulnerabilities (KEV) catalog yesterday.

It requires federal agencies to take the following actions by December 1: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Private sector organizations are also encouraged to follow KEV guidance where possible to improve their security posture.

Image credit: viewimage / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability
Next Article New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea
Team-CWD
  • Website

Related Posts

News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Don’t let “back to school” become “back to bullying”

September 11, 2025

Top IRS scams to look out for in 2026

February 10, 2026

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.