Cyber Threat Digest – 2025-10-19
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-47410 — Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their G… — Details
- CVE-2025-62672 — rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case… MEDIUM 5.3 — Details
- CVE-2025-11938 — A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing manipulation of the argument DB_PASSWORD… MEDIUM 6.3 — Details
- CVE-2025-11939 — A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore… MEDIUM 5.1 — Details
- CVE-2025-11940 — A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of the file assets/setup.nsi of the component Installer. Such m… HIGH 7.3 — Details
📰 Security News
Top headlines from trusted sources.
- OpenAI confirms GPT-6 is not shipping in 2025
— Sat, 18 Oct 2025 21:51:29 GMT - Google ads for fake Homebrew, LogMeIn sites push infostealers
— Sat, 18 Oct 2025 15:02:19 GMT - ConnectWise fixes Automate bug allowing AiTM update attacks
— Fri, 17 Oct 2025 19:29:22 GMT - American Airlines subsidiary Envoy confirms Oracle data theft attack
— Fri, 17 Oct 2025 19:11:52 GMT - Microsoft lifts more safeguard holds blocking Windows 11 updates
— Fri, 17 Oct 2025 17:22:16 GMT - Europol dismantles SIM box operation renting numbers for cybercrime
— Fri, 17 Oct 2025 17:01:51 GMT
Comments
Post a Comment