Cyber Threat Digest – 2025-09-05
🔥 Known Exploited Vulnerabilities (CISA KEV)
3 exploited vulns of note in the last 48 hours.
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-57263 — An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php… HIGH 7.2 — Details
- CVE-2024-43184 — IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 is vulnerable to cross-site scripting. This vulnerability allows an un… MEDIUM 6.1 — Details
- CVE-2025-25048 — IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to… MEDIUM 6.5 — Details
- CVE-2025-2667 — IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 could disclose… LOW 2.7 — Details
- CVE-2025-2694 — IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 is vulnerable … MEDIUM 4.8 — Details
- CVE-2025-6785 — Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed CAN messages to control remote start functi… MEDIUM 4.7 — Details
📰 Security News
Top headlines from trusted sources.
- Critical SAP S/4HANA vulnerability now exploited in attacks
— Fri, 05 Sep 2025 13:36:35 GMT - Hackers exploited Sitecore zero-day flaw to deploy backdoors
— Thu, 04 Sep 2025 18:51:42 GMT - Texas sues PowerSchool over breach exposing 62M students, 880k Texans
— Thu, 04 Sep 2025 18:01:31 GMT - Chess.com discloses recent data breach via file transfer app
— Thu, 04 Sep 2025 17:51:37 GMT - New TP-Link zero-day surfaces as CISA warns other flaws are exploited
— Thu, 04 Sep 2025 16:21:19 GMT - France slaps Google with €325M fine for violating cookie regulations
— Thu, 04 Sep 2025 15:58:05 GMT
Comments
Post a Comment