Cyber Threat Digest – 2025-10-17
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11839 — A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing manipulation results in unchecked return value. The a… MEDIUM 4.8 — Details
- CVE-2025-46752 — A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enr… MEDIUM 4.4 — Details
- CVE-2025-53950 — An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 t… MEDIUM 5.5 — Details
- CVE-2025-53951 — An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for Windows 11.5.1 and 11.… MEDIUM 5.3 — Details
- CVE-2025-54658 — An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.… HIGH 7.8 — Details
- CVE-2025-22381 — Aggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password. HIGH 8.2 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft fixes Windows bug breaking localhost HTTP connections
— Fri, 17 Oct 2025 13:58:27 GMT - Over 266,000 F5 BIG-IP instances exposed to remote attacks
— Fri, 17 Oct 2025 12:16:23 GMT - Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections
— Thu, 16 Oct 2025 22:25:46 GMT - Auction giant Sotheby's says data breach exposed financial information
— Thu, 16 Oct 2025 19:24:13 GMT - Have I Been Pwned: Prosper data breach impacts 17.6 million accounts
— Thu, 16 Oct 2025 19:19:49 GMT - Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
— Thu, 16 Oct 2025 18:13:32 GMT
Comments
Post a Comment