Cyber Threat Digest – 2025-10-27
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-20) — Details
- CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12275 — Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. CRITICAL 10.0 — Details
- CVE-2025-12278 — Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. MEDIUM 6.9 — Details
- CVE-2025-12284 — Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. MEDIUM 6.9 — Details
- CVE-2025-12285 — Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. CRITICAL 10.0 — Details
- CVE-2025-10497 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticate… HIGH 7.5 — Details
- CVE-2025-11447 — GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated… HIGH 7.5 — Details
📰 Security News
Top headlines from trusted sources.
- CISA orders feds to patch Windows Server WSUS flaw used in attacks
— Mon, 27 Oct 2025 13:27:35 GMT - Hackers steal Discord accounts with RedTiger-based infostealer
— Sun, 26 Oct 2025 14:26:36 GMT - New CoPhish attack steals OAuth tokens via Copilot Studio agents
— Sat, 25 Oct 2025 16:16:00 GMT - Hackers launch mass attacks exploiting outdated WordPress plugins
— Fri, 24 Oct 2025 19:28:42 GMT - Critical WSUS flaw in Windows Server now exploited in attacks
— Fri, 24 Oct 2025 16:28:14 GMT - Amazon: This week's AWS outage caused by major DNS failure
— Fri, 24 Oct 2025 15:33:58 GMT
Comments
Post a Comment