Cyber Threat Digest – 2025-09-24
🔥 Known Exploited Vulnerabilities (CISA KEV)
1 exploited vulns of note in the last 48 hours.
- CVE-2025-10585 — Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (Added: 2025-09-23) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2017-20200 — A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The a… MEDIUM 6.3 — Details
- CVE-2025-6921 — The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability ar… MEDIUM 5.3 — Details
- CVE-2025-8354 — A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, ca… HIGH 7.8 — Details
- CVE-2025-9844 — Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6. HIGH 8.8 — Details
- CVE-2025-4760 — An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in th… MEDIUM 4.8 — Details
- CVE-2025-57407 — A stored cross-site scripting (XSS) vulnerability in the Admin Log Viewer of S-Cart <=10.0.3 allows a remote authenticated attacker to inject arbitrary web script or HTML via a … — Details
📰 Security News
Top headlines from trusted sources.
- UK arrests suspect for RTX ransomware attack causing airport disruptions
— Wed, 24 Sep 2025 13:55:48 GMT - PyPI urges users to reset credentials after new phishing attacks
— Wed, 24 Sep 2025 13:15:30 GMT - GitHub notifications abused to impersonate Y Combinator for crypto theft
— Wed, 24 Sep 2025 12:37:31 GMT - Boyd Gaming discloses data breach after suffering a cyberattack
— Tue, 23 Sep 2025 22:25:02 GMT - Libraesva ESG issues emergency fix for bug exploited by state hackers
— Tue, 23 Sep 2025 17:51:19 GMT - WhatsApp adds message translation to iPhone and Android apps
— Tue, 23 Sep 2025 17:11:31 GMT
Comments
Post a Comment