Cyber Threat Digest – 2025-08-28
π₯ Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler (Added: 2025-08-26) — Details
- CVE-2025-48384 — Git Link Following Vulnerability — Git Git (Added: 2025-08-25) — Details
- CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2024-8069 — Citrix Session Recording Deserialization of Untrusted Data Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability — Apple iOS, iPadOS, and macOS (Added: 2025-08-21) — Details
- CVE-2025-54948 — Trend Micro Apex One OS Command Injection Vulnerability — Trend Micro Apex One (Added: 2025-08-18) — Details
- CVE-2025-8876 — N-able N-Central Command Injection Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
- CVE-2025-8875 — N-able N-Central Insecure Deserialization Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2018-25115 — Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi en… CRITICAL 10.0 — Details
- CVE-2023-7307 — Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the… HIGH 8.7 — Details
- CVE-2023-7308 — SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The aff… HIGH 8.7 — Details
- CVE-2023-7309 — A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting … CRITICAL 10.0 — Details
- CVE-2024-13979 — A SQL injection vulnerability exists in the St. Joe ERP system ("ε£δΉERPη³»η»") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requ… CRITICAL 9.3 — Details
- CVE-2024-13980 — H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling… CRITICAL 10.0 — Details
π° Security News
Top headlines from trusted sources.
- Google shares workarounds for auth failures on ChromeOS devices
— Thu, 28 Aug 2025 18:30:07 GMT - Malware devs abuse Anthropic's Claude AI to build ransomware
— Thu, 28 Aug 2025 17:08:08 GMT - Microsoft Word will save your files to the cloud by default
— Thu, 28 Aug 2025 17:00:28 GMT - Passwordstate dev urges users to patch auth bypass vulnerability
— Thu, 28 Aug 2025 16:16:20 GMT - Police seize VerifTools fake ID marketplace servers, domains
— Thu, 28 Aug 2025 16:00:35 GMT - MATLAB dev says ransomware gang stole data of 10,000 people
— Thu, 28 Aug 2025 15:00:06 GMT
Comments
Post a Comment