CISA orders feds to patch Samsung zero-day used in spyware attacks
ID: a10a39d1-5374-5bbc-946e-71a5514b9218
STIX ID: report--a10a39d1-5374-5bbc-946e-71a5514b9218
Feed Name: Bleeping Computer
CISA ordered U.S. federal agencies to urgently patch CVE-2025-21042, an out-of-bounds write in Samsung's libimagecodec.quram.so exploited since at least July 2024 to deliver LandFall spyware via malicious DNG images over WhatsApp; Unit 42 attributes active exploitation against multiple Samsung flagship models, documents the spyware's extensive data-stealing capabilities, notes regional targeting and C2 similarities to previous operations, and reports Samsung released a patch in April while attribution to a specific vendor or threat group remains inconclusive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
