logo

CISA orders feds to patch Samsung zero-day used in spyware attacks

ID: a10a39d1-5374-5bbc-946e-71a5514b9218

STIX ID: report--a10a39d1-5374-5bbc-946e-71a5514b9218

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-11-10

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

CISA ordered U.S. federal agencies to urgently patch CVE-2025-21042, an out-of-bounds write in Samsung's libimagecodec.quram.so exploited since at least July 2024 to deliver LandFall spyware via malicious DNG images over WhatsApp; Unit 42 attributes active exploitation against multiple Samsung flagship models, documents the spyware's extensive data-stealing capabilities, notes regional targeting and C2 similarities to previous operations, and reports Samsung released a patch in April while attribution to a specific vendor or threat group remains inconclusive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.