Cyber Threat Digest – 2025-10-29
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12103 — A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any nam… MEDIUM 5.0 — Details
- CVE-2025-12380 — Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have b… — Details
- CVE-2025-12390 — A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak … MEDIUM 6.0 — Details
- CVE-2025-53814 — A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption.… HIGH 7.8 — Details
- CVE-2025-53855 — An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadein file can lead to an out-of-bounds wri… HIGH 7.8 — Details
- CVE-2025-34301 — IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code … MEDIUM 5.1 — Details
📰 Security News
Top headlines from trusted sources.
- Windows 11 KB5067036 update rolls out Administrator Protection feature
— Tue, 28 Oct 2025 23:31:28 GMT - Python rejects $1.5M grant from U.S. govt. fearing ethical compromise
— Tue, 28 Oct 2025 22:16:37 GMT - Advertising giant Dentsu reports data breach at subsidiary Merkle
— Tue, 28 Oct 2025 21:16:26 GMT - Qilin ransomware abuses WSL to run Linux encryptors in Windows
— Tue, 28 Oct 2025 19:11:33 GMT - CISA warns of two more actively exploited Dassault vulnerabilities
— Tue, 28 Oct 2025 18:59:49 GMT - Microsoft: Copilot now lets you build apps, automate workflows
— Tue, 28 Oct 2025 17:59:18 GMT
Comments
Post a Comment