Cyber Threat Digest – 2025-09-07
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
- CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability — Sangoma FreePBX (Added: 2025-08-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-10034 — A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of t… HIGH 7.4 — Details
- CVE-2021-26377 — Insufficient parameter validation while allocating process space in the Trusted OS (TOS) may allow for a malicious userspace process to trigger an integer overflow, leading to a po… MEDIUM 4.1 — Details
- CVE-2021-46750 — Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messages to the graphics mailbox resulting in a… LOW 3.0 — Details
- CVE-2023-20516 — Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentially resulting in loss of confidentiali… LOW 3.3 — Details
- CVE-2023-31306 — Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions result… LOW 3.3 — Details
- CVE-2023-31322 — Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Serviceability trusted application (RAS TA) potentially leading… HIGH 8.7 — Details
📰 Security News
Top headlines from trusted sources.
- VirusTotal finds hidden malware phishing campaign in SVG files
— Sat, 06 Sep 2025 18:58:00 GMT - AI-powered malware hit 2,180 GitHub accounts in "s1ngularity" attack
— Sat, 06 Sep 2025 14:11:21 GMT - Microsoft now enforces MFA on Azure Portal sign-ins for all tenants
— Fri, 05 Sep 2025 19:32:05 GMT - EU fines Google $3.5 billion for anti-competitive ad practices
— Fri, 05 Sep 2025 16:36:03 GMT - Financial services firm Wealthsimple discloses data breach
— Fri, 05 Sep 2025 15:36:48 GMT - Max severity Argo CD API flaw leaks repository credentials
— Fri, 05 Sep 2025 15:30:18 GMT
Comments
Post a Comment