Security researchers found Android spyware that targeted Samsung Galaxy phones for almost a year. Researchers at Palo Alto Networks’ Unit 42 said the spyware, which they call “Landfall,” was first detected in July 2024 and relied on exploiting a security flaw in the Galaxy phone software that was unknown to …
Read More »Critical Cisco UCCX flaw allows attackers to execute commands as root
Cisco has issued security updates to fix a critical vulnerability in the Unified Contact Center Express (UCCX) software that could allow attackers to gain root access. The Cisco UCCX platform, described by the company as a “contact center in a box,” is a software solution for managing customer interactions in …
Read More »HackedGPT: 7 New Vulns in GPT-4o and GPT-5 Enables 0-Click Attacks
Tenable researchers found 7 new vulnerabilities in OpenAI’s ChatGPT, putting users at risk of data theft and safety breaches through new attacks on AI systems dubbed HackedGPT. Flaws known as HackedGPT were found during testing of OpenAI’s ChatGPT-4o and some persist in ChatGPT-5. OpenAI has fixed some issues, but others …
Read More »BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh
BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh via CVE: 2025-40778. The high severity flaw can allow remote attackers to inject forged DNS records into resolver caches. BGD e-GOV CIRT published an advisory stating all organizations operating BIND 9 resolvers in Bangladesh (ISPs, data centers, government, enterprises) must upgrade …
Read More »Windows,VMware zero day and Linux flaw exploited: Australia warn unpatched Cisco IOS XE devices
In recent time, Hacker exploited Windows, VMware and Linux flaw. On another side, Australia warn about of BadCandy infections on unpatched Cisco devices. VMware: CISA added a serious security flaw affecting Broadcom VMware Tools and VMware Aria Operations to its Known Exploited Vulnerabilities list after reports of ongoing exploitation. The …
Read More »92% of Exchange servers in Germany unprotected
92% of Microsoft Exchange servers in Germany are outdated and won’t get any more security updates, as warned by the German Federal Office for Information Security (BSI). The BSI in Germany reports about 33,000 on-premise Exchange servers with publicly accessible Outlook Web Access. About 30,360 servers are running Exchange 2019 …
Read More »DomeWatch leak exposed Capitol Hill applicants’ personal data
Thousands of Americans’ personal job-seeking details were publicly exposed because of an unsecured database linked to the House Democrats’ Official Online Resume Bank, DomeWatch.us. The security lapse was brought to light by the research firm Safety Detectives, after an anonymous cybersecurity researcher reported to them about an “unencrypted and non-password-protected …
Read More »New CoPhish attack steals OAuth tokens Exploitng Copilot Studio agents
A phishing technique named CoPhish misuses Microsoft Copilot Studio to deceive users into giving hackers access to their Microsoft Entra ID accounts. Datadog Security Labs identified a method that uses customizable AI agents on legitimate Microsoft domains to disguise OAuth consent attacks, making them seem trustworthy and avoiding user suspicion. …
Read More »Hackers exploited Samsung Galaxy S25 0-day vuln allowing camera access and location tracking
At Pwn2Own Ireland 2025, researchers Ben R. and Georgi G. from Interrupt Labs demonstrated their success in exploiting a zero-day vulnerability in the Samsung Galaxy S25. They gained complete control of the device, allowing them to activate the camera and track the user’s location. The exploit, revealed on the event’s final …
Read More »Oracle released 374 new security patches in its October 2025 Tuesday patch
Oracle’s October 2025 Critical Patch Update fixes 374 vulnerabilities in multiple products, making it one of the largest patches recently, covering databases, middleware, enterprise applications, and communication systems. As always, Oracle recommends that customers apply patches without delay, as many of the fixed vulnerabilities can be exploited remotely, even without …
Read More »
InfoSecBulletin Cybersecurity for mankind