Cyber Threat Digest – 2025-10-10
🔥 Known Exploited Vulnerabilities (CISA KEV)
1 exploited vulns of note in the last 48 hours.
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2023-37401 — IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted. MEDIUM 5.3 — Details
- CVE-2025-11561 — A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, SSSD does not enable the Kerbero… HIGH 8.8 — Details
- CVE-2025-36171 — IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly validated API input due to excessive resource consumption. MEDIUM 4.9 — Details
- CVE-2025-36225 — IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user due to an observable discrepancy of returned data. MEDIUM 4.3 — Details
- CVE-2025-62228 — Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-i… MEDIUM 5.1 — Details
- CVE-2025-32916 — Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to… LOW 1.0 — Details
📰 Security News
Top headlines from trusted sources.
- FBI takes down BreachForums portal used for Salesforce extortion
— Fri, 10 Oct 2025 08:24:16 GMT - New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube
— Thu, 09 Oct 2025 21:06:31 GMT - Microsoft: Hackers target universities in "payroll pirate" attacks
— Thu, 09 Oct 2025 19:38:00 GMT - Hackers now use Velociraptor DFIR tool in ransomware attacks
— Thu, 09 Oct 2025 19:31:55 GMT - Microsoft Defender mistakenly flags SQL Server as end-of-life
— Thu, 09 Oct 2025 18:09:26 GMT - RondoDox botnet targets 56 n-day flaws in worldwide attacks
— Thu, 09 Oct 2025 17:17:28 GMT
Comments
Post a Comment