Sponsor of the Day:
Jerkmate
https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.
landfall new commercialgrade android spywareexploit chain targetingsamsung devices
https://projectzero.google/2026/01/pixel-0-click-part-1.html
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby - Project Zero
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One ef...
pixel 9 partexploit chainproject zero01
https://www.helpnetsecurity.com/2022/12/21/cve-2022-41080/
New Microsoft Exchange exploit chain lets ransomware attackers in (CVE-2022-41080) - Help Net...
Dec 22, 2022 - The ProxyNotShell exploit chain used CVE-2022-41040 while this new one uses CVE-2022-41080 to achieve privilege escalation through OWA.
new microsoftexploit chainransomware attackerscve 2022exchange
https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/?pdf=print&lg=en&_wpnonce=522be237ec
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.
landfall new commercialgrade android spywareexploit chain targetingsamsung devices
https://projectzero.google/2026/01/pixel-0-click-part-3.html
A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here? - Project Zero
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our e...
pixel 9 partexploit chainproject zero03
https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/?pdf=download&lg=en&_wpnonce=522be237ec
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices
Commercial-grade LANDFALL spyware exploits CVE-2025-21042 in Samsung Android’s image processing library. The spyware was embedded in malicious DNG files.
landfall new commercialgrade android spywareexploit chain targetingsamsung devices
https://projectzero.google/2026/01/pixel-0-click-part-2.html
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave - Project Zero
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the res...
pixel 9 partexploit chainbig waveproject zero0
https://blockchainmagazine.net/kelp-dao-exploit-mastermind-launders-80-million-through-thorchain-in-sophisticated-cross-chain-operation/
Kelp DAO Exploit Mastermind Launders $80 Million Through THORChain In Sophisticated Cross-Chain...
Apr 22, 2026 - The cybercriminal behind the devastating $290 million Kelp DAO exploit has successfully laundered approximately $80 million worth of stolen Ethereum through
kelp dao exploit80 millioncross chainmastermindlaunders
https://www.infosecurity-magazine.com/news/teampcp-exploit-stolen-supply/
TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets - Infosecurity Magazine
Apr 3, 2026 - TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
supply chaininfosecurity magazineteampcpexploresways
https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/
Nation-State Actors Exploit Notepad++ Supply Chain
Unit 42 reveals new infrastructure associated with the Notepad++ attack. This expands understanding of threat actor operations and malware delivery.
nation stateactors exploitsupply chainnotepad