Cyber Threat Digest – 2025-10-24
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-20) — Details
- CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite (Added: 2025-10-20) — Details
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11429 — A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on existing user sessions. Sessions created while "Remember Me"… MEDIUM 5.4 — Details
- CVE-2025-1679 — Cross-site Scripting has been identified in Moxa's Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device's web … MEDIUM 4.8 — Details
- CVE-2025-1680 — An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa's Ethernet switches, which allows attackers with administrative privileges to… NONE 0.0 — Details
- CVE-2025-53701 — Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized pr… MEDIUM 4.8 — Details
- CVE-2025-53702 — Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action… HIGH 7.1 — Details
- CVE-2025-60852 — A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected versions of the framework did not properly sanit… MEDIUM 6.5 — Details
📰 Security News
Top headlines from trusted sources.
- Mozilla: New Firefox extensions must disclose data collection practices
— Fri, 24 Oct 2025 13:17:00 GMT - Windows Server emergency patches fix WSUS bug with PoC exploit
— Fri, 24 Oct 2025 07:27:56 GMT - Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
— Fri, 24 Oct 2025 06:36:55 GMT - Toys "R" Us Canada warns customers' info leaked in data breach
— Thu, 23 Oct 2025 22:25:35 GMT - HP pulls update that broke Microsoft Entra ID auth on some AI PCs
— Thu, 23 Oct 2025 21:50:41 GMT - Meet the new Clippy: Microsoft unveils Copilot's "Mico" avatar
— Thu, 23 Oct 2025 17:28:59 GMT
Comments
Post a Comment