Canadian Centre for Cyber Security

GitHub security advisory (AV25-737)

Multiple versions of GitHub Enterprise Server are affected by a vulnerability identified as CVE-2025-11892. This issue may have been exploited, prompting urgent action to update to the latest patched versions.

Vulnerability in Google Chrome for Desktop Prior to Version 142.0.7444.162

A security vulnerability has been identified in Google Chrome for Desktop. Users running versions prior to 142.0.7444.162/.163 on Windows and 142.0.7444.162 on Mac and Linux are affected.

HPE security advisory (AV25-743)

A high-severity vulnerability, tracked as CVE-2025-61834, has been identified in Adobe Substance3D Stager versions 3.1.5 and earlier. Exploitation requires user interaction, such as opening a specially crafted malicious file.

Multiple Vulnerabilities Identified in Cisco ISE, UCCX, and CUIC Products

Multiple vulnerabilities have been identified in Cisco products, including Cisco Identity Services Engine (ISE), Cisco Unified Contact Center Express (UCCX), and Cisco Unified Intelligence Center (CUIC).

Microsoft Edge security advisory (AV25-720)

A security vulnerability has been identified in Microsoft Edge Stable Channel versions prior to 142.0.3595.53. Microsoft released a security update on October 31, 2025, to address this issue.

Ubiquiti security advisory (AV25-721)

A critical security flaw (CVE-2025-52665) has been identified in Ubiquiti’s UniFi Access Application, affecting versions 3.3.22 through 3.4.31. This vulnerability has been addressed in version 4.0.21.

Splunk security advisory (AV25-710)

Multiple vulnerabilities have been identified in various Splunk AppDynamics agents and the Splunk Operator for Kubernetes Add-on. These vulnerabilities stem from outdated third-party packages.

Drupal security advisory (AV25-709)

A critical access bypass vulnerability has been identified in the Drupal module Simple OAuth (OAuth2) & OpenID Connect, affecting versions 6.0.0 through versions prior to 6.0.7.

Jenkins security advisory (AV25-707)

A recent security advisory has disclosed vulnerabilities in multiple Jenkins plugins. Users and administrators are urged to update the affected plugins to their latest versions to maintain the security and stability of their Jenkins environments.

Docker security advisory (AV25–708)

A path traversal bug was identified in Docker Compose, affecting versions prior to v2.40.2. This issue arises from improper handling of OCI artifact layer annotations, which could potentially allow unauthorized file access.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags