Cyber Threat Digest – 2025-10-25
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2021-43768 — In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mbamservice.exe. MEDIUM 5.3 — Details
- CVE-2025-46183 — The Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a specially crafted .ser file, deserialization may … HIGH 8.2 — Details
- CVE-2025-46185 — An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via the plaintext storage of passwords and usernames. MEDIUM 6.2 — Details
- CVE-2025-46425 — Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with re… MEDIUM 6.5 — Details
- CVE-2025-11145 — Observable Discrepancy, Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in CBK Soft Soft… HIGH 7.5 — Details
- CVE-2025-43994 — Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote… HIGH 8.6 — Details
📰 Security News
Top headlines from trusted sources.
- Hackers launch mass attacks exploiting outdated WordPress plugins
— Fri, 24 Oct 2025 19:28:42 GMT - Critical WSUS flaw in Windows Server now exploited in attacks
— Fri, 24 Oct 2025 16:28:14 GMT - Amazon: This week's AWS outage caused by major DNS failure
— Fri, 24 Oct 2025 15:33:58 GMT - Fake LastPass death claims used to breach password vaults
— Fri, 24 Oct 2025 14:47:48 GMT - How to reduce costs with self-service password resets
— Fri, 24 Oct 2025 14:06:16 GMT - Mozilla: New Firefox extensions must disclose data collection practices
— Fri, 24 Oct 2025 13:17:00 GMT
Comments
Post a Comment