Researchers detailed a “commercial‑grade” spyware campaign that exploited CVE-2025-21042, an out‑of‑bounds write in Samsung Galaxy devices, to deliver LANDFALL via specially crafted images sent over WhatsApp. The now‑patched flaw enabled remote code execution, allowing attackers to exfiltrate data, record calls, access photos and logs, and track locations in targeted Middle East operations. Organizations with Samsung fleets should fast‑track patching and review MDM policies for rapid OS and firmware updates.
Source: The Hacker News
US Congressional Budget Office confirms breach, adds new security controls
The Congressional Budget Office said it was hacked and has implemented additional monitoring and new security controls to protect systems going forward. While details remain limited, the incident underscores the continuing exposure of sensitive US government data when patching or monitoring lapses occur.
Source: SecurityWeek
Washington Post confirms data breach tied to Oracle EBS zero‑day campaign
The Washington Post disclosed a breach linked to a wider hacking spree that leveraged Oracle software vulnerabilities, a campaign associated with the Clop/FIN11 group’s extortion tactics. With Oracle EBS used broadly across enterprises, experts warn more victim disclosures are likely as attackers apply pressure.
Source: TechCrunch
ClickFix social engineering evolves with “how‑to” videos and e‑commerce‑style pressure
Attackers have upgraded ClickFix pages with embedded tutorial videos, countdown timers, and fake social proof designed to walk users through disabling protections and executing malware. The technique lowers the bar for successful infections across platforms, reinforcing the need for user awareness, DNS/URL filtering, and hardening of execution policies.
Source: Help Net Security
Cisco patches critical UCCX bug enabling root command execution (CVE‑2025‑20354)
Cisco issued fixes for a critical vulnerability in Unified Contact Center Express that allowed attackers to execute commands with root privileges (CVSS 9.8). Contact center environments often sit at the core of customer operations; rapid patching and configuration reviews are strongly advised.
Source: Security Affairs
Microsoft Teams flaws enabled message manipulation and executive impersonation
Check Point Research uncovered multiple vulnerabilities in Teams that allowed message edits without labels, spoofed notifications, altered display names in chats, and caller ID manipulation—raising BEC and social‑engineering risks across more than 320 million users. Microsoft has pushed fixes, but enterprises should validate client updates and reinforce verification workflows for sensitive requests.
Source: TechTarget SearchSecurity
Malicious NuGet packages hid “logic bombs” set to detonate years later
Security researchers exposed nine NuGet packages uploaded in 2023–2024 that embed time‑delayed payloads capable of sabotaging databases and corrupting industrial control systems as late as 2027. The discovery highlights the long‑tail risk of software supply‑chain attacks and the need for package provenance checks, allow‑listing, and continuous dependency monitoring.
Source: The Hacker News
You May Also Be Interested In... - Chrome 142 Update Patches High-Severity Flaws - Data Exposure Vulnerability Found in Deep Learning Tool Keras - Destructive Russian Cyberattacks on Ukraine Expand to Grain Sector