Cyber Threat Digest – 2025-10-30
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2023-7324 — In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible addl_desc_ptr out-of-bounds accesses Sanitize possible addl_desc_ptr out-of-bounds acc… — Details
- CVE-2024-45161 — A CSRF issue was discovered in the administrative web GUI in Blu-Castle BCUM221E 1.0.0P220507. This can be exploited via a URL, an image load, an XMLHttpRequest, etc. and can resul… MEDIUM 4.6 — Details
- CVE-2024-45162 — A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the password field. CRITICAL 9.8 — Details
- CVE-2025-40083 — In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue To prevent a potential crash in agg_dequeue (net/sched/sch_q… — Details
- CVE-2025-40084 — In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before reading handle handle_response() dereferences the payload a… — Details
- CVE-2025-40085 — In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_to_register_card In try_to_register_card(), the return valu… — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft promises more Copilot features in Microsoft 365 companion apps
— Thu, 30 Oct 2025 11:42:03 GMT - Malicious NPM packages fetch infostealer for Windows, Linux, macOS
— Wed, 29 Oct 2025 23:16:10 GMT - WordPress security plugin exposes private data to site subscribers
— Wed, 29 Oct 2025 20:44:00 GMT - Canada says hacktivists breached water and energy facilities
— Wed, 29 Oct 2025 19:03:06 GMT - Microsoft fixes Media Creation Tool broken on some Windows PCs
— Wed, 29 Oct 2025 17:41:28 GMT - Microsoft: DNS outage impacts Azure and Microsoft 365 services
— Wed, 29 Oct 2025 16:49:33 GMT
Comments
Post a Comment