Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation post, november 8, 2025november 10, 2025 Security researchers at Palo Alto Networks Unit 42 have uncovered a sophisticated espionage campaign leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as CVE‑2025‑21042 (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit… Continue Reading
Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access post, oktober 22, 2025 Oracle has disclosed two critical vulnerabilities in its E-Business Suite’s Marketing product that could hand full control to remote attackers. Dubbed CVE-2025-53072 and CVE-2025-62481, these flaws affect the Marketing Administration component and carry a perfect storm CVSS score of 9.8, marking them as among the most severe threats disclosed this… Continue Reading
Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year post, oktober 14, 2025 Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity, per ReliaQuest, is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and… Continue Reading
Critical Zero-Day In Oracle E-Business Suite | Patch Immediately post, oktober 6, 2025oktober 7, 2025 Oracle has released a high-urgency security alert for a newly discovered zero-day vulnerability in its E-Business Suite (EBS), tracked as CVE-2025-61882. This flaw enables unauthenticated, remote execution of arbitrary code, posing a severe risk to any exposed or unpatched installations. Oracle has classified it with a CVSS 3.1 base score… Continue Reading
Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs post, oktober 1, 2025oktober 3, 2025 The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools… Continue Reading
VMware Zero-Day Under Attack By China-Linked Hackers Since October 2024 post, september 30, 2025oktober 3, 2025 Broadcom has published security advisory VMSA-2025-0015, disclosing six vulnerabilities in VMware products — among them four rated High / Important — and urging users to apply patches immediately. One of the more serious flaws is CVE-2025-41244, a local privilege escalation vulnerability (CVSS score 7.8) Continue Reading
Critical SolarWinds Web Help Desk Vulnerability Enables Privilege Escalation post, september 23, 2025september 24, 2025 SolarWinds has issued an urgent security advisory regarding a critical remote code execution (RCE) vulnerability in its Web Help Desk (WHD) platform, warning customers of an actively exploitable flaw that could allow unauthenticated attackers to gain complete control over affected systems. The vulnerability, CVE-2025-26399, has been assigned a CVSS severity… Continue Reading
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs post, september 15, 2025september 18, 2025 The China-aligned threat actor known as Mustang Panda has been observed using an updated version of a backdoor called TONESHELL and a previously undocumented USB worm called SnakeDisk. “The worm only executes on devices with Thailand-based IP addresses and drops the Yokai backdoor,” IBM X-Force researchers Golo Mühr and Joshua Chung said in an analysis published… Continue Reading
Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries post, september 4, 2025september 5, 2025 The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor “is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word,” S2 Grupo’s LAB52 threat intelligence team said…. Continue Reading
Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s Response post, augustus 30, 2025september 4, 2025 Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact… Continue Reading