Security Affairs reports that Google has issued a universal Android update addressing the critical Dolby audio decoder vulnerability, tracked as CVE-2025-59457, after initially fixing the issue in Pixel phones last month.
Cyble's analysis indicates that 245 vulnerabilities were added to the CISA KEV catalog in 2025, representing a roughly 20% growth rate and a substantial increase compared to the 185 and 187 vulnerabilities added in 2024 and 2023, respectively.
The goal is not to remove oversight, but to replace brittle manual processes with intelligent automation that operates within clearly defined guardrails.
Singapore's Cyber Security Agency has warned of a maximum-severity arbitrary file upload vulnerability in SmarterTools SmarterMail email software, tracked as CVE-2025-52691, which could be leveraged to facilitate unauthenticated code execution, The Hacker News reports.
Cybernews reports that mounting software complexity, AI usage, supply chain dependencies, and evolving threats were noted by BeyondTrust Chief Security Advisor Morey Haber to fuel the escalation of zero-day exploits in 2025.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.