Cyber Threat Digest – 2025-11-02
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability — Broadcom VMware Aria Operations and VMware Tools (Added: 2025-10-30) — Details
- CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability — XWiki Platform (Added: 2025-10-30) — Details
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12599 — Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. CRITICAL 10.0 — Details
- CVE-2025-12600 — Web UI Malfunction when setting unexpected locale via API.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. CRITICAL 10.0 — Details
- CVE-2025-12601 — Denial of Service Due to SlowLoris.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. CRITICAL 10.0 — Details
- CVE-2025-12602 — /etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. LOW 2.3 — Details
- CVE-2025-12603 — /etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. LOW 2.3 — Details
- CVE-2025-12593 — A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the comp… MEDIUM 5.1 — Details
📰 Security News
Top headlines from trusted sources.
- Google confirms AI search will have ads, but they may look different
— Sat, 01 Nov 2025 16:56:00 GMT - Windows 11 Build 26220.7051 released with "Ask Copilot" feature
— Sat, 01 Nov 2025 16:17:22 GMT - China-linked hackers exploited Lanscope flaw as a zero-day in attacks
— Sat, 01 Nov 2025 14:16:26 GMT - Windows 11 tests shared Bluetooth audio support, but only for AI PCs
— Fri, 31 Oct 2025 20:59:02 GMT - 'We got hacked' emails threaten to leak University of Pennsylvania data
— Fri, 31 Oct 2025 18:32:39 GMT - Microsoft Edge gets scareware sensor for faster scam detection
— Fri, 31 Oct 2025 17:15:06 GMT
Comments
Post a Comment