Cyber Threat Digest – 2025-10-15
🔥 Known Exploited Vulnerabilities (CISA KEV)
5 exploited vulns of note in the last 48 hours.
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-22831 — APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l… MEDIUM 5.8 — Details
- CVE-2025-22832 — APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data corruption and l… MEDIUM 5.8 — Details
- CVE-2025-22833 — APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of this vulnerability m… MEDIUM 4.6 — Details
- CVE-2025-33044 — APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local means. Successful exploitati… MEDIUM 5.8 — Details
- CVE-2025-47856 — Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 an… HIGH 7.2 — Details
- CVE-2024-44088 — Malicious script injection ('Cross-site Scripting') vulnerability in Apache Geode web-api (REST). This vulnerability allows an attacker that tricks a logged-in user into clicking a… MEDIUM 6.1 — Details
📰 Security News
Top headlines from trusted sources.
- F5 says hackers stole undisclosed BIG-IP flaws, source code
— Wed, 15 Oct 2025 13:32:07 GMT - Malicious crypto-stealing VSCode extensions resurface on OpenVSX
— Tue, 14 Oct 2025 21:35:12 GMT - Final Windows 10 Patch Tuesday update rolls out as support ends
— Tue, 14 Oct 2025 19:07:49 GMT - New Android Pixnapping attack steals MFA codes pixel-by-pixel
— Tue, 14 Oct 2025 18:46:47 GMT - Microsoft: Exchange 2016 and 2019 have reached end of support
— Tue, 14 Oct 2025 18:26:16 GMT - Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
— Tue, 14 Oct 2025 18:02:50 GMT
Comments
Post a Comment