Tuesday , September 29 2026

Vulnerabilities

Samsung Galaxy Hijacked via 0-Day Exploit Using Single WhatsApp Image

Galaxy

Security researchers found Android spyware that targeted Samsung Galaxy phones for almost a year. Researchers at Palo Alto Networks’ Unit 42 said the spyware, which they call “Landfall,” was first detected in July 2024 and relied on exploiting a security flaw in the Galaxy phone software that was unknown to …

Read More »

Critical Cisco UCCX flaw allows attackers to execute commands as root

UCCX

Cisco has issued security updates to fix a critical vulnerability in the Unified Contact Center Express (UCCX) software that could allow attackers to gain root access. The Cisco UCCX platform, described by the company as a “contact center in a box,” is a software solution for managing customer interactions in …

Read More »

HackedGPT: 7 New Vulns in GPT-4o and GPT-5 Enables 0-Click Attacks

HackedGPT

Tenable researchers found 7 new vulnerabilities in OpenAI’s ChatGPT, putting users at risk of data theft and safety breaches through new attacks on AI systems dubbed HackedGPT. Flaws known as HackedGPT were found during testing of OpenAI’s ChatGPT-4o and some persist in ChatGPT-5. OpenAI has fixed some issues, but others …

Read More »

BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh

Cache poisoning

BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh via CVE: 2025-40778. The high severity flaw can allow remote attackers to inject forged DNS records into resolver caches. BGD e-GOV CIRT published an advisory stating all organizations operating BIND 9 resolvers in Bangladesh (ISPs, data centers, government, enterprises) must upgrade …

Read More »

Windows,VMware zero day and Linux flaw exploited: Australia warn unpatched Cisco IOS XE devices

Linux flaw

In recent time, Hacker exploited Windows, VMware and Linux flaw. On another side, Australia warn about of BadCandy infections on unpatched Cisco devices. VMware:  CISA added a serious security flaw affecting Broadcom VMware Tools and VMware Aria Operations to its Known Exploited Vulnerabilities list after reports of ongoing exploitation. The …

Read More »

DomeWatch leak exposed Capitol Hill applicants’ personal data

DomeWatch

Thousands of Americans’ personal job-seeking details were publicly exposed because of an unsecured database linked to the House Democrats’ Official Online Resume Bank, DomeWatch.us. The security lapse was brought to light by the research firm Safety Detectives, after an anonymous cybersecurity researcher reported to them about an “unencrypted and non-password-protected …

Read More »

New CoPhish attack steals OAuth tokens Exploitng Copilot Studio agents

CoPhish

A phishing technique named CoPhish misuses Microsoft Copilot Studio to deceive users into giving hackers access to their Microsoft Entra ID accounts. Datadog Security Labs identified a method that uses customizable AI agents on legitimate Microsoft domains to disguise OAuth consent attacks, making them seem trustworthy and avoiding user suspicion. …

Read More »

Hackers exploited Samsung Galaxy S25 0-day vuln allowing camera access and location tracking

Samsung Galaxy S25

At Pwn2Own Ireland 2025, researchers Ben R. and Georgi G. from Interrupt Labs demonstrated their success in exploiting a zero-day vulnerability in the Samsung Galaxy S25. They gained complete control of the device, allowing them to activate the camera and track the user’s location. The exploit, revealed on the event’s final …

Read More »

Oracle released 374 new security patches in its October 2025 Tuesday patch

374

Oracle’s October 2025 Critical Patch Update fixes 374 vulnerabilities in multiple products, making it one of the largest patches recently, covering databases, middleware, enterprise applications, and communication systems. As always, Oracle recommends that customers apply patches without delay, as many of the fixed vulnerabilities can be exploited remotely, even without …

Read More »