Topic: zero-click exploits

  • Researchers hijack devices via Zoom screen sharing flaw

    Researchers hijack devices via Zoom screen sharing flaw

    Security researchers discovered critical flaws in Zoom's screen-sharing annotation feature, allowing attackers to seize control of any participant's device without user interaction or leaving traces, affecting all supported operating systems. The vulnerabilities were found in under 20 prompts usi...

    Read More »
  • Zoom Screen-Sharing Bug Enabled Full Device Takeover on Calls

    Zoom Screen-Sharing Bug Enabled Full Device Takeover on Calls

    Researchers discovered critical vulnerabilities in Zoom's screen-sharing annotation protocol that could allow silent, zero-interaction takeover of any participant's device during a call, affecting all supported platforms. The flaws were found using publicly accessible AI models in fewer than 20 p...

    Read More »
  • Phone and App Features That Help Block Spyware

    Phone and App Features That Help Block Spyware

    In early 2025, WhatsApp and Apple confirmed that journalists and civil society members were targeted by Paragon Solutions' Graphite spyware using zero-click attacks, highlighting that such espionage is now common. Spyware gives government operators full access to devices,recording calls, stealing...

    Read More »
  • WhatsApp Alerts 200 Users to Fake Spyware App

    WhatsApp Alerts 200 Users to Fake Spyware App

    WhatsApp identified and alerted roughly 200 users, primarily in Italy, who were tricked into installing a malicious counterfeit app containing government spyware developed by the Italian firm SIO. The spyware, called Spyrtacus, embeds itself in fake apps to harvest data and record audio/video, an...

    Read More »
  • Urgent Samsung Patch Stops Spyware Exploit

    Urgent Samsung Patch Stops Spyware Exploit

    Samsung has released a critical security update for a vulnerability (CVE-2025-21042) in its image processing library, which was actively exploited to install the LANDFALL spyware on mobile devices. The spyware uses a zero-click infection method via manipulated image files, allowing it to infect d...

    Read More »
  • CISA Flags Spyware Zero-Day in Urgent Security Alert

    CISA Flags Spyware Zero-Day in Urgent Security Alert

    US authorities issued a critical security alert for a high-risk vulnerability in Samsung mobile devices, exploited since mid-2024 to install spyware via malicious files on WhatsApp. The vulnerability, CVE-2025-21042 with a CVSS score of 9.8, enables attackers to use LandFall spyware for surveilla...

    Read More »
  • Apple Offers $2 Million Bounty for Zero-Click Exploits

    Apple Offers $2 Million Bounty for Zero-Click Exploits

    Apple is dramatically increasing its security bounty rewards, now offering up to $2 million for zero-click exploit chains and potential bonuses that could push payouts over $5 million, targeting vulnerabilities in its latest software and hardware. The program enhancements, including new reward ca...

    Read More »