Cyber Threat Digest – 2025-10-31
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability — Broadcom VMware Aria Operations and VMware Tools (Added: 2025-10-30) — Details
- CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability — XWiki Platform (Added: 2025-10-30) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-43939 — Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attac… HIGH 7.8 — Details
- CVE-2025-43940 — Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attac… HIGH 7.8 — Details
- CVE-2025-43941 — Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attac… HIGH 7.2 — Details
- CVE-2025-50736 — An open redirect vulnerability exists in Byaidu PDFMathTranslate v1.9.9 that allows attackers to craft URLs that cause the application to redirect users to arbitrary external websi… — Details
- CVE-2025-50739 — iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization. — Details
- CVE-2025-43027 — A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative access to the Genetec Security C… CRITICAL 9.8 — Details
📰 Security News
Top headlines from trusted sources.
- Alleged Meduza Stealer malware admins arrested after hacking Russian org
— Fri, 31 Oct 2025 13:45:17 GMT - CISA: High-severity Linux flaw now exploited by ransomware gangs
— Fri, 31 Oct 2025 13:05:49 GMT - Google says Search AI Mode will know everything about you
— Fri, 31 Oct 2025 11:55:49 GMT - Windows zero-day actively exploited to spy on European diplomats
— Fri, 31 Oct 2025 11:29:29 GMT - Ukrainian extradited from Ireland on Conti ransomware charges
— Fri, 31 Oct 2025 09:40:17 GMT - OpenAI confirms GPT-5 is now better at handling mental and emotional distress
— Thu, 30 Oct 2025 22:12:28 GMT
Comments
Post a Comment