ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

ICE Reinstates Contract with Paragon

criticalVulnerabilityimportance 60CVE-2025-43200

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43200
Apple iCloud Link media-processing logic flaw exploited in targeted attacks

CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected.

Do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices.

4.21% KEV
  • Apple iOS Versions prior to 15.8.4, 16.7.11, and 18.3.1 (fixed in iOS 15.8.4, 16.7.11, 18.3.1)
  • Apple iPadOS Versions prior to 15.8.4, 16.7.11, 17.7.5, and 18.3.1 (fixed in iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1)
  • Apple macOS Versions prior to Ventura 13.7.4, Sonoma 14.7.4, and Sequoia 15.3.1 (fixed in those releases)
  • +2 more
masshundreds of millions to ~2 billion active Apple devices on affected OS versions
Full article542 words · extracted from infosecurity-magazine.com · click to collapse

The US Immigration and Customs Enforcement (ICE) agency has reinstated a contract with Israeli spyware company Paragon Solutions, now owned by a US private investment firm.

Jack Poulson, an independent journalist and author of the Substack blog All-Source Intelligence, reported that ICE had “lifted the stop work order” on a $2m contract with Paragon on August 30.

The lifting of the order grants the Israeli-founded firm the ability to provide the US agency with ‘Hardware and perpetual license software,’ as shown on the Federal Procurement Data System (FPDS.gov), the US government’s central database for tracking and reporting federal contract actions.

The original $2m contract was signed by Paragon’s US branch based in Chantilly, Virginia, on September 27, 2024.

However, the contract was quickly suspended following a White House review, with a hold being issue on October 8, 2024.

According to Wired, the suspension came after concerns that the contract potentially violated the Biden administration’s March 2023 executive order (EO 14093) limiting US procurement of spyware.

In December 2024, several media outlets reported that AE Industrial Partners, a Florida-based private investment firm, had acquired Paragon Solutions for $500m and intended to merge the Israeli company with REDLattice, a US company part of AE’s portfolio.

Other reports mentioned that REDLattice was the company acquiring Paragon.

According to Poulson, the reinstatement of the contract between ICE and Paragon is expected to show on USASpending.gov by the end of September 2.

Paragon Linked with Spyware Campaigns in Italy

Paragon Solutions was founded in 2019 by Ehud Schneorson, a former commander of Unit 8200, Israel’s signal intelligence agency, with backing from former Israeli Prime Minister Ehud Barak.

In June 2025, Citizen Lab researchers revealed the first forensic evidence that the iPhones of at least two European journalists had been infected with Paragon’s spyware, Graphite.

One of the two targets was Italian journalist Ciro Pellegrino.

“We identify an indicator linking both cases to the same Paragon operator,” Bill Marczak and John Scott-Railton, researchers at the Citizen Lab, confirmed.

Apple later confirmed to the researchers that the zero-click attack deployed in these cases exploited a critical vulnerability (CVSSv3 score of 9.8) in iOS.

The flaw, tracked as CVE-2025-43200, stems from a logic issue when processing a maliciously crafted photo or video shared via an iCloud Link. It was mitigated in the latest iOS version, 18.3.1.

These findings came a few days after the Italian government's parliamentary committee, COPASIR, confirmed in a report that the Italian government had used Paragon's Graphite spyware against two individuals, Luca Casarini and Giuseppe "Beppe" Caccia.

Shortly after the publication of the COPASIR report, the Citizen Lab uncovered that Paragon had offered to help investigate a third victim, Mr. Cancellato, who was also targeted with the same spyware.

However, Italy rejected the offer on June 9, 2025, as reported by Haaretz, with Paragon later claiming it had unilaterally terminated Italy’s contracts.

The Italian Department of Security Intelligence (DIS) defended the rejection, citing national security risks and concerns over damaging its reputation among international intelligence partners, while denying Paragon’s claim of contract termination. Meanwhile, COPASIR clarified that it had declined Paragon’s assistance but instead sought direct access to the company’s databases, also expressing willingness to declassify Paragon’s testimony before the committee.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ice-reinstated-spyware-paragon/