Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

Apple Zero-Click Messages Flaw: How Paragon Spyware Targets Journalists

by Jane Doe
June 14, 2025
in Cyber
A A
0
Share on FacebookShare on Twitter

Apple is telling us that a dangerous zero-click security vulnerability in its Messages app, known as CVE-2025-43200, has been aggressively exploited by highly skilled attackers to hack into the accounts of members of civil society, primarily journalists.

This exploitable weakness comprised receiving a next-generation mercenary spyware product, “Graphite,” developed by Israeli company Paragon Solutions, without user interaction.

The weakness was enabled through a “logic issue” in how the Messages app handled a “maliciously crafted photo or video shared via an iCloud Link.” That simply receiving that content on an iPhone could be enough to compromise the device, even if the user didn’t click on the message or otherwise interact with it, making it hard for victims to know they were hacked.

The Citizen Lab, a research center focused on interdisciplinary studies, significantly contributed to the discovery of this exploitation. Their forensic work represented the first public evidence of the Graphite spyware Paragon has managed to get into Apple devices.

Read Also

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

Black Hat SEO Poisoning Search Engine Results For AI

The probe discovered that it had atleast two European journalists — Italian journo Ciro Pellegrino and another yet unnamed influential European journalist — on its hit list. Both were informed by Apple in April 2025 that they may be targets of state-sponsored attacks.

Graphite : Paragon-developed surveillance tool.. which can access messages, emails, camera feeds, microphones, and users location. The journalists received the same exploit using the iMessage account, codenamed “ATTACKER1,” which according to the researchers was a single operator or client of Paragon behind the attacks.

Apple patched the flaw quickly with more rigorous checks in iOS 18.3.1 and and associated releases, which went out on February 10, 2025. The incident highlights the continuing threat of mercenary spyware to civil liberties and press freedom around the world and the race among tech companies to plug digital security holes that can be exploited by surveillance vendors.

The issue has also raised controversy in Italy, where the government’s employment of Paragon to spy on citizens has been the subject of debate.

Jane Doe

You May Also Likes!

Iranian-backed hackers go to work after U.S. strikes
Cyber

Cyber is now the third-largest economy in the world – June 2025 Report

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

DHS warns of heightened cyber threat as US enters Iran conflict

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Leak of data belonging to 7.4 million Paraguayans traced back to infostealers

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Billions of login credentials have been leaked online, Cybernews researchers say

by Jane Doe
June 25, 2025
Iranian-backed hackers go to work after U.S. strikes
Cyber

Global cyber alert: Iranian hackers strike U.S. banks, defence and oil firms

by Jane Doe
June 25, 2025
Load More

Recommended

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

Enhance Your Cybersecurity on World Environment Day with KnowBe4’s Expert Guide

June 5, 2025
New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

New Windows RAT Exploits Corrupted Headers for Stealthy Evasion

May 31, 2025
23andMe Faces £2.31 Million Fine From ICO for Insufficient Data Security

23andMe Faces £2.31 Million Fine From ICO for Insufficient Data Security

June 23, 2025
Hacking AI the Right Way: A Guide to AI Red Teaming

Hacking AI the Right Way: A Guide to AI Red Teaming

May 27, 2025
Iranian-backed hackers go to work after U.S. strikes

Global Connected Car Regulations Analysis Report 2025: Focus on Cybersecurity and Data Privacy

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Black Hat SEO Poisoning Search Engine Results For AI

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

Cyber is now the third-largest economy in the world – June 2025 Report

June 25, 2025
Iranian-backed hackers go to work after U.S. strikes

DHS warns of heightened cyber threat as US enters Iran conflict

June 25, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.