Cyber Threat Digest – 2025-09-12
🔥 Known Exploited Vulnerabilities (CISA KEV)
1 exploited vulns of note in the last 48 hours.
- CVE-2025-5086 — Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-09-11) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-10193 — DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protections and execute unauthorised tool invocations against locally … HIGH 7.4 — Details
- CVE-2025-10252 — A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. … LOW 2.3 — Details
- CVE-2025-10253 — A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation … MEDIUM 5.1 — Details
- CVE-2025-27466 — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling … CRITICAL 9.8 — Details
- CVE-2025-58142 — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling … CRITICAL 9.8 — Details
- CVE-2025-58143 — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling … CRITICAL 9.8 — Details
📰 Security News
Top headlines from trusted sources.
- Man gets over 4 years in prison for selling unreleased movies
— Fri, 12 Sep 2025 11:36:22 GMT - Samsung patches actively exploited zero-day reported by WhatsApp
— Fri, 12 Sep 2025 09:48:30 GMT - Microsoft fixes Exchange Online outage affecting users worldwide
— Thu, 11 Sep 2025 19:43:00 GMT - U.S. Senator accuses Microsoft of "gross cybersecurity negligence"
— Thu, 11 Sep 2025 19:23:41 GMT - Apple warns customers targeted in recent spyware attacks
— Thu, 11 Sep 2025 19:02:51 GMT - Panama Ministry of Economy discloses breach claimed by INC ransomware
— Thu, 11 Sep 2025 18:26:59 GMT
Comments
Post a Comment