Cyber Threat Digest – 2025-09-17
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-5086 — Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-09-11) — Details
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2024-12796 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT, Consultancy Coop. Workcube ERP allows Reflected XSS.This i… MEDIUM 5.3 — Details
- CVE-2025-39830 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path In the error path of hws_pool_buddy_init(), t… — Details
- CVE-2025-39831 — In the Linux kernel, the following vulnerability has been resolved: fbnic: Move phylink resume out of service_task and into open/close The fbnic driver was presenting with the fo… — Details
- CVE-2025-39832 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unload event Fix lockdep assertion triggered during sync reset u… — Details
- CVE-2025-39833 — In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci… — Details
- CVE-2025-39834 — In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow When an invalid stc_type is provide… — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service
— Wed, 17 Sep 2025 13:20:05 GMT - BreachForums hacking forum admin resentenced to three years in prison
— Tue, 16 Sep 2025 21:38:22 GMT - Microsoft rolls out Copilot Chat to Microsoft 365 Office apps
— Tue, 16 Sep 2025 18:01:41 GMT - Google nukes 224 Android malware apps behind massive ad fraud campaign
— Tue, 16 Sep 2025 17:20:00 GMT - Self-propagating supply chain attack hits 187 npm packages
— Tue, 16 Sep 2025 16:46:43 GMT - Microsoft: WMIC will be removed after Windows 11 25H2 upgrade
— Tue, 16 Sep 2025 15:58:59 GMT
Comments
Post a Comment