Cyber Threat Digest – 2025-09-30
🔥 Known Exploited Vulnerabilities (CISA KEV)
5 exploited vulns of note in the last 48 hours.
- CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
- CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
- CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details
- CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability — Cisco IOS and IOS XE (Added: 2025-09-29) — Details
- CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability — Adminer Adminer (Added: 2025-09-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-57428 — Default credentials in Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and exec… — Details
- CVE-2025-36351 — IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions. MEDIUM 4.3 — Details
- CVE-2025-36352 — IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the… MEDIUM 6.4 — Details
- CVE-2025-55795 — The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated … LOW 3.5 — Details
- CVE-2025-56449 — A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement… — Details
- CVE-2025-57516 — OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or… — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft fixes Windows DRM video playback issues for some users
— Tue, 30 Sep 2025 13:47:45 GMT - CISA warns of critical Linux Sudo flaw exploited in attacks
— Tue, 30 Sep 2025 13:42:53 GMT - Windows 11 KB5065789 update released with 41 changes and fixes
— Tue, 30 Sep 2025 12:50:47 GMT - Broadcom fixes high-severity VMware NSX bugs reported by NSA
— Tue, 30 Sep 2025 12:10:13 GMT - UK convicts "Bitcoin Queen" in world's largest cryptocurrency seizure
— Mon, 29 Sep 2025 22:16:47 GMT - Japan's largest brewer suspends operations due to cyberattack
— Mon, 29 Sep 2025 20:44:50 GMT
Comments
Post a Comment