Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

New 'Landfall' spyware exploited a Samsung 0-day delivered through WhatsApp messages

published on 2025-11-07 22:15:51 UTC by /u/Megabeets
Content:

LANDFALL — a commercial-grade Android spyware exploiting a now-patched Samsung zero-day (CVE-2025-21042) through weaponized DNG images sent via WhatsApp, enabling zero-click compromise of Samsung Galaxy devices.

This isn't an isolated incident. LANDFALL is part of a larger DNG exploitation wave. Within months, attackers weaponized image parsing vulnerabilities across Samsung (CVE-2025-21042, CVE-2025-21043) and Apple (CVE-2025-43300 chained with WhatsApp CVE-2025-55177 for delivery)

It seems like DNG image processing libraries became a new attack vector of choice – suspiciously consistent across campaigns. Samsung had two zero-days in the same library, while a parallel campaign hit iOS - all exploiting the same file format. Should we expect more?

submitted by /u/Megabeets
[link] [comments]
Article: New 'Landfall' spyware exploited a Samsung 0-day delivered through WhatsApp messages - published 1 day ago.

https://www.reddit.com/r/netsec/comments/1or81fv/new_landfall_spyware_exploited_a_samsung_0day/   
Published: 2025 11 07 22:15:51
Received: 2025 11 07 22:31:41
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 4

Custom HTML Block

Click to Open Code Editor