Cyber Threat Digest – 2025-10-14
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
- CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability — Linux Kernel (Added: 2025-10-06) — Details
- CVE-2010-3962 — Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability — Microsoft Internet Explorer (Added: 2025-10-06) — Details
- CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability — Mozilla Multiple Products (Added: 2025-10-06) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-37729 — Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive infor… CRITICAL 9.1 — Details
- CVE-2025-39964 — In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is … — Details
- CVE-2025-39965 — In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f398… — Details
- CVE-2025-43991 — SupportAssist for Home PCs versions 4.8.2 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain an UNIX Symbolic Link (Symlink) following vulnerability. A … MEDIUM 6.3 — Details
- CVE-2025-11695 — When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5 HIGH 8.0 — Details
- CVE-2025-62244 — Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023… MEDIUM 4.8 — Details
📰 Security News
Top headlines from trusted sources.
- Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops
— Tue, 14 Oct 2025 13:22:14 GMT - Chinese hackers abuse geo-mapping tool for year-long persistence
— Tue, 14 Oct 2025 12:28:03 GMT - Microsoft restricts IE mode access in Edge after zero-day attacks
— Mon, 13 Oct 2025 21:51:47 GMT - SimonMed says 1.2 million patients impacted in January data breach
— Mon, 13 Oct 2025 20:12:04 GMT - Massive multi-country botnet targets RDP services in the US
— Mon, 13 Oct 2025 18:05:56 GMT - SonicWall VPN accounts breached using stolen creds in widespread attacks
— Mon, 13 Oct 2025 15:58:45 GMT
Comments
Post a Comment