CVE-2025-43300
published 2025-08-21CVE-2025-43300: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12…
PriorityP192critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-09-11
Exploited in the wild
EPSS
19.97%
97.1th percentile
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.5_and_ipados | — | — |
| apple | ios_16.7.12_and_ipados | — | — |
| apple | ios_18.6.2_and_ipados | — | — |
| apple | ipados | < 15.8.5 | 15.8.5 |
| apple | ipados | — | — |
| apple | ipados | >= 16.0 < 16.7.12 | 16.7.12 |
| apple | ipados | >= 17.0 < 17.7.10 | 17.7.10 |
| apple | ipados | >= 18.0 < 18.6.2 | 18.6.2 |
| apple | iphone_os | < 15.8.5 | 15.8.5 |
| apple | iphone_os | >= 16.0 < 16.7.12 | 16.7.12 |
| apple | iphone_os | >= 17.0 < 18.6.2 | 18.6.2 |
| apple | macos | >= 13.0 < 13.7.8 | 13.7.8 |
| apple | macos | >= 14.0 < 14.7.8 | 14.7.8 |
| apple | macos | >= 15.0 < 15.6.1 | 15.6.1 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| whatsapp_business_for_ios | >= 2.22.25.2 < 2.25.21.78 | 2.25.21.78 | |
| whatsapp_desktop_for_mac | >= 2.22.25.2 < 2.25.21.78 | 2.25.21.78 | |
| whatsapp_for_ios | >= 2.22.25.2 < 2.25.21.73 | 2.25.21.73 | |
| >= 2.22.25.2 < 2.25.21.73 | 2.25.21.73 | ||
| >= 2.22.25.2 < 2.25.21.78 | 2.25.21.78 | ||
| whatsapp_business | >= 2.22.25.2 < 2.25.21.78 | 2.25.21.78 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-43300 is triggered by processing malicious image files (DNG format); inspect inbound DNG files — especially those with a ZIP archive appended — delivered via messaging apps for anomalous structure. ↗
- →CVE-2025-43300 is an out-of-bounds write in Apple's Image I/O framework; monitor for crashes or unexpected memory corruption events in ImageIO-related processes on iOS/iPadOS/macOS when processing image files. ↗
- →The exploit chain (CVE-2025-55177 + CVE-2025-43300) is zero-click and delivered via WhatsApp linked-device synchronization messages; alert on WhatsApp processes initiating unexpected outbound URL fetches on iOS/macOS. ↗
- →LandFall spyware samples were submitted to VirusTotal starting July 23, 2024, with filenames indicating WhatsApp as the delivery channel; hunt for DNG files delivered via WhatsApp with ZIP data appended. ↗
- ·No technical details or proof-of-concept for CVE-2025-43300 have been publicly published; exploitation was observed in the wild but attack mechanics beyond the image-file trigger are not yet disclosed. ↗
- ·The exploit chain targets specific individuals (journalists, lawyers, activists, politicians, senior officials); broad-population detections will have low base-rate signal and should be tuned for high-value targets. ↗
- ·WhatsApp's own advisory notes that even after patching CVE-2025-55177, the device OS may remain compromised; patching WhatsApp alone is insufficient for already-targeted devices. ↗
- ·LandFall attribution is murky — infrastructure overlaps with Stealth Falcon (UAE) and naming conventions overlap with NSO/Variston/Cytrox/Quadream, but no confident attribution to a known group has been made. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43300: iOS 15.8.5 and iPadOS 15.8.5
vendor_apple·2025-09-15·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: iOS 15.8.5 and iPadOS 15.8.5
Apple Security Update: About the security content of iOS 15.8.5 and iPadOS 15.8.5
Product: iOS 15.8.5 and iPadOS
Version: 15.8.5
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2025-43300: iOS 16.7.12 and iPadOS 16.7.12
vendor_apple·2025-09-15·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: iOS 16.7.12 and iPadOS 16.7.12
Apple Security Update: About the security content of iOS 16.7.12 and iPadOS 16.7.12
Product: iOS 16.7.12 and iPadOS
Version: 16.7.12
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
CISA
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
cisa·2025-08-21·CVSS 10.0
CVE-2025-43300 [CRITICAL] CWE-787 Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Vulnerability: Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Affected: Apple iOS, iPadOS, and macOS
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/124925 ; https://support.apple.com/en-us/124926 ; https://support.apple.com/en-us/124927 ; https://support.apple.com/en-us/124928 ; https://support.apple.com/en-us/124929 ; https://nvd.nist.gov/vuln/detail/CVE-2025-43300
Remediation Due Date: 2025-09-11
Apple
CVE-2025-43300: macOS Sequoia 15.6.1
vendor_apple·2025-08-20·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: macOS Sequoia 15.6.1
Apple Security Update: About the security content of macOS Sequoia 15.6.1
Product: macOS Sequoia
Version: 15.6.1
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2025-43300: macOS Ventura 13.7.8
vendor_apple·2025-08-20·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: macOS Ventura 13.7.8
Apple Security Update: About the security content of macOS Ventura 13.7.8
Product: macOS Ventura
Version: 13.7.8
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2025-43300: macOS Sonoma 14.7.8
vendor_apple·2025-08-20·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: macOS Sonoma 14.7.8
Apple Security Update: About the security content of macOS Sonoma 14.7.8
Product: macOS Sonoma
Version: 14.7.8
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2025-43300: iPadOS 17.7.10
vendor_apple·2025-08-20·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: iPadOS 17.7.10
Apple Security Update: About the security content of iPadOS 17.7.10
Product: iPadOS
Version: 17.7.10
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple
CVE-2025-43300: iOS 18.6.2 and iPadOS 18.6.2
vendor_apple·2025-08-20·CVSS 10.0
CVE-2025-43300 [CRITICAL] CVE-2025-43300: iOS 18.6.2 and iPadOS 18.6.2
Apple Security Update: About the security content of iOS 18.6.2 and iPadOS 18.6.2
Product: iOS 18.6.2 and iPadOS
Version: 18.6.2
CVE: CVE-2025-43300
Component: ImageIO
Impact: Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
GHSA
GHSA-f7wf-m2qg-r9rx: Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2
ghsa_unreviewed·2025-08-29·CVSS 10.0
CVE-2025-55177 [CRITICAL] CWE-863 GHSA-f7wf-m2qg-r9rx: Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.
GHSA
GHSA-cpwx-wfp4-x368: An out-of-bounds write issue was addressed with improved bounds checking
ghsa_unreviewed·2025-08-21
CVE-2025-43300 [HIGH] CWE-787 GHSA-cpwx-wfp4-x368: An out-of-bounds write issue was addressed with improved bounds checking
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.8, macOS Ventura 13.7.8, iPadOS 17.7.10, macOS Sequoia 15.6.1, iOS 18.6.2 and iPadOS 18.6.2. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
VulnCheck
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
vulncheck·2025·CVSS 10.0
CVE-2025-43300 [CRITICAL] CWE-787 Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
Affected: Apple iOS, iPadOS, and macOS
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://nvd.nist.gov/vuln/detail/CVE-2025-43300; https://support.apple.com/en-us/124925; https://support.apple.com/en-us/124926; https://support.apple.com/en-us/124927; https://support.apple.com/en-us/124928; https://support.apple.com/en-us/124929; https://www.acn.gov.it/portale/w/aggiornament
No detection rules found.
No public exploits indexed.
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
Threat Intelligence
# Look What You Made Us Patch: 2025 Zero-Days in Review
March 5, 2026
##### Google Threat Intelligence Group
##### Google Threat Intelligence
Visibility and context on the threats that matter most.
Contact Us & Get a Demo
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
### Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first
Mandiant
Look What You Made Us Patch: 2025 Zero-Days in Review
blogs_mandiant·2026-03-05
Look What You Made Us Patch: 2025 Zero-Days in Review
## Look What You Made Us Patch: 2025 Zero-Days in Review
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan
## Executive Summary
Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years, indicating a trend toward stabilization at these levels.
In 2025, we continued to observe the structural shift, first identified in 2024, toward increased enterprise exploitation. Both
Bleepingcomputer
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
blogs_bleepingcomputer·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Lawrence Abrams
CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group.
CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group.
Devices impacted by both flaws include:
iPhone 11 and later
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (8th generation and later)
iPad mini (5th generation and later)
Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7
Bleepingcomputer
New LandFall spyware exploited Samsung zero-day via WhatsApp messages
blogs_bleepingcomputer·2025-11-07·CVSS 8.8
[HIGH] New LandFall spyware exploited Samsung zero-day via WhatsApp messages
## New LandFall spyware exploited Samsung zero-day via WhatsApp messages
## Bill Toulas
According to researchers at Palo Alto Networks’ Unit 42, the LandFall spyware is likely a commercial surveillance framework used in targeted intrusions.
The attacks begin with the delivery of a malformed .DNG raw image format with a .ZIP archive appended towards the end of the file.
Unit 42 researchers retrieved and examined samples that were submitted to the VirusTotal scanning platform starting July 23, 2024, indicating WhatsApp as the delivery channel, based on the filenames used.
From a technical perspective, the DNGs embed two main components: a loader ( b.so ) that can retrieve and load additional modules, and a SELinux policy manipulator ( l.so ), which modifies security settings on the devi
Unit42
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
blogs_unit42·2025-11-07·CVSS 8.8
CVE-2025-21042 [HIGH] LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
## Executive Summary
Unit 42 researchers have uncovered a previously unknown Android spyware family, which we have named LANDFALL. To deliver the spyware, attackers exploited a zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library. The specific flaw LANDFALL exploited, CVE-2025-21042, is not an isolated case but rather part of a broader pattern of similar issues found on multiple mobile platforms.
This vulnerability was actively exploited in the wild before Samsung patched it in April 2025, following reports of in-the-wild attacks. However, the exploit itself — and the commercial-grade spyware used with it — have not yet been publicly reported and analyzed.
LANDFALL was embedded in malicious image files (DNG file format) that appear to have been sent via
Unit42
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
blogs_unit42·2025-11-07·CVSS 8.8
CVE-2025-21042 [HIGH] LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Threat Research Center
Threat Research
Vulnerabilities
## LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Unit 42
Published: November 7, 2025
Threat Research
Vulnerabilities
Android
Apple
CVE-2025-21042
CVE-2025-21043
CVE-2025-43300
CVE-2025-55177
Samsung
## Executive Summary
Unit 42 researchers have uncovered a previously unknown Android spyware family, which we have named LANDFALL. To deliver the spyware, attackers exploited a zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library. The specific flaw LANDFALL exploited, CVE-2025-21042, is not an isolated case but rather part of a broader pattern of similar issues found on multiple mobile platforms.
This vulnerability was actively exploited in the
Bleepingcomputer
Apple backports zero-day patches to older iPhones and iPads
blogs_bleepingcomputer·2025-09-16·CVSS 10.0
[CRITICAL] Apple backports zero-day patches to older iPhones and iPads
## Apple backports zero-day patches to older iPhones and iPads
## Sergiu Gatlan
An out-of-bounds write occurs when attackers supply maliciously crafted input to a program that causes it to write data outside the allocated memory buffer, potentially triggering crashes, corrupting data, or even allowing remote code execution.
Apple has now addressed this zero-day flaw in iOS 15.8.5 / 16.7.12, as well as iPadOS 15.8.5 / 16.7.12, with improved bounds checks.
"Processing a malicious image file may result in memory corruption. An out-of-bounds write issue was addressed with improved bounds checking," the company said in Monday advisories .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
The lis
Bleepingcomputer
Samsung patches actively exploited zero-day reported by WhatsApp
blogs_bleepingcomputer·2025-09-12·CVSS 8.8
CVE-2025-21043 [HIGH] Samsung patches actively exploited zero-day reported by WhatsApp
## Samsung patches actively exploited zero-day reported by WhatsApp
## Sergiu Gatlan
Samsung has patched a remote code execution vulnerability that was exploited in zero-day attacks targeting its Android devices.
Tracked as CVE-2025-21043, this critical security flaw affects Samsung devices running Android 13 or later and was reported by the security teams of Meta and WhatsApp on August 13.
As Samsung explains in a recently updated advisory , this vulnerability was discovered in libimagecodec.quram.so (a closed-source image parsing library developed by Quramsoft that implements support for various image formats) and is caused by an out-of-bounds write weakness that allows attackers to execute malicious code on vulnerable devices remotely .
"Out-of-bounds Write in libimagecodec.quram.s
Bleepingcomputer
Apple warns customers targeted in recent spyware attacks
blogs_bleepingcomputer·2025-09-11·CVSS 10.0
[CRITICAL] Apple warns customers targeted in recent spyware attacks
## Apple warns customers targeted in recent spyware attacks
## Sergiu Gatlan
Apple warned customers last week that their devices were targeted in a new series of spyware attacks, according to the French national Computer Emergency Response Team (CERT-FR).
CERT-FR is operated by ANSSI, the National Cybersecurity Agency, and is responsible for preventing and mitigating cybersecurity-related incidents impacting public and critical organizations.
According to a Thursday advisory, CERT-FR is aware of at least four instances of Apple threat notifications alerting the company's users about mercenary spyware attacks that have occurred since the beginning of the year.
These alerts were sent on March 5, April 29, June 25, and last week, on September 3, to the phone numbers and email addresses a
Krebs
Microsoft Patch Tuesday, September 2025 Edition
blogs_krebs·2025-09-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, September 2025 Edition
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known “zero-day” or actively exploited vulnerabilities in this month’s bundle from Redmond, which nevertheless includes patches for 13 flaws that earned Microsoft’s most-dire “critical” label. Meanwhile, both Apple and Google recently released updates to fix zero-day bugs in their devices.
Microsoft assigns security flaws a “critical” rating when malware or miscreants can exploit them to gain remote access to a Windows system with little or no help from users. Among the more concerning critical bugs quashed this month is CVE-2025-54918 . The problem here resides with Windows NTLM , or NT LAN Manager, a suite of code for managing authentication in a
Krebs
Microsoft Patch Tuesday, September 2025 Edition
blogs_krebs·2025-09-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, September 2025 Edition
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known “zero-day” or actively exploited vulnerabilities in this month’s bundle from Redmond, which nevertheless includes patches for 13 flaws that earned Microsoft’s most-dire “critical” label. Meanwhile, both Apple and Google recently released updates to fix zero-day bugs in their devices.
Microsoft assigns security flaws a “critical” rating when malware or miscreants can exploit them to gain remote access to a Windows system with little or no help from users. Among the more concerning critical bugs quashed this month is CVE-2025-54918. The problem here resides with Windows NTLM, or NT LAN Manager, a suite of code for managing authentication in a Wi
Checkpoint
8th September – Threat Intelligence Report
blogs_checkpoint·2025-09-08
CVE-2025-55177 8th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
A supply chain breach involving Salesloft’s Drift integration to Salesforce exposed sensitive customer data from multiple organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Workiva. The attackers accessed Salesforce CRM systems via compromised OAuth tokens, stealing contact details, account records, s
Checkpoint
1st September – Threat Intelligence Report
blogs_checkpoint·2025-09-01
CVE-2025-55177 1st September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American consumer credit reporting agency TransUnion has suffered a data breach that resulted in the exposure of sensitive personal information for over 4.4 million individuals in the United States. The leaked data includes names, billing addresses, phone numbers, email addresses, dates of birth, unredacted Social Secur
Bleepingcomputer
WhatsApp patches vulnerability exploited in zero-day attacks
blogs_bleepingcomputer·2025-08-29·CVSS 10.0
CVE-2025-55177 [CRITICAL] WhatsApp patches vulnerability exploited in zero-day attacks
## WhatsApp patches vulnerability exploited in zero-day attacks
## Sergiu Gatlan
WhatsApp has patched a security vulnerability in its iOS and macOS messaging clients that was exploited in targeted zero-day attacks.
The company says this zero-click flaw (tracked as CVE-2025-55177) affects WhatsApp for iOS prior to version 2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78.
"Incomplete authorization of linked device synchronization messages in WhatsApp [..] could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target's device," WhatsApp said in a Friday security advisory .
"We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploite
Checkpoint
25th August – Threat Intelligence Report
blogs_checkpoint·2025-08-25
CVE-2025-43300 25th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
US pharmaceutical company Inotiv has experienced a ransomware attack that resulted in the unauthorized access and encryption of certain systems and data. The Qilin ransomware gang claimed responsibility and alleged the theft of approximately 162,000 files totaling 176GB.
Check Point Threat Emulation and Harmony Endpoint pr
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
# September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorization
Recorded Future
September 2025 CVE Landscape
blogs_recorded_future·CVSS 7.2
[HIGH] September 2025 CVE Landscape
## September 2025 CVE Landscape
In September 2025, Recorded Future’s Insikt Group® identified sixteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the eighteen identified in August, with the number of Very Critical vulnerabilities also decreasing (11) month over month.
These vulnerabilities have affected the following vendors: Sudo, Libraesva, Fortra, Cisco, Adminer, Google, Dassault Systèmes, Linux, Android, Sitecore, TP-Link, and Meta Platforms.
September was dominated by flaws in Cisco and TP-Link, which together represented six of the sixteen vulnerabilities. Cisco’s IOS, IOS XE, and Secure Firewall products were affected by flaws, including stack-based and classic buffer overflows (CWE-121, CWE-120) and missing authorizatio
Recorded Future
August 2025 CVE Landscape
blogs_recorded_future·CVSS 8.8
[HIGH] August 2025 CVE Landscape
# August 2025 CVE Landscape
In August 2025, Recorded Future’s Insikt Group® identified eighteen high-impact vulnerabilities that should be prioritized for remediation. This represents a decrease from the 22 identified in July.
However, the number of Very Critical vulnerabilities has remained the same (16) compared to July. These vulnerabilities have affected the following vendors: Trend Micro, WinRAR, N-able, Cisco, Apple, Citrix, FreePBX, Git, Microsoft, D-Link, and Fortinet.
August was dominated by Citrix and D-Link flaws, which represented six of the eighteen vulnerabilities. Threat actors actively exploited Citrix NetScaler ADC, NetScaler Gateway, and Citrix Session Recording products, as well as D-Link DNR-322L and DCS-2530L routers.
Recorded Future Insikt Group’s CVE Findings fro
https://support.apple.com/en-us/124925https://support.apple.com/en-us/124926https://support.apple.com/en-us/124927https://support.apple.com/en-us/124928https://support.apple.com/en-us/124929https://support.apple.com/en-us/125141https://support.apple.com/en-us/125142http://seclists.org/fulldisclosure/2025/Sep/10http://seclists.org/fulldisclosure/2025/Sep/14http://seclists.org/fulldisclosure/2025/Sep/52https://github.com/b1n4r1b01/n-days/blob/main/CVE-2025-43300.mdhttps://github.com/cisagov/vulnrichment/issues/201https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-43300
2025-08-21
Published
2025-08-21
Added to CISA KEV
Exploited in the wild