Fixes have been issued by Atlassian to address nearly 30 third-party flaws across its products, including the maximum severity XML external entity injection vulnerability in the open source content analysis toolkit Apache Tika, tracked as CVE-2025-66516, reports SecurityWeek.
The vulnerability, impacting ArrayOS versions 9.4.5.8 and earlier, has been confirmed to be exploited in Japan, where attackers dropped web shells on compromised devices.
Apple announced that it has issued emergency updates to fix the two zero-day vulnerabilities in WebKit that have been exploited in "extremely sophisticated" attacks targeting specific individuals, reports BleepingComputer.
Security Affairs reports that the U.S. Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog to include flaws impacting Google Chromium and Sierra Wireless AirLink ALEOS, which must be remediated by federal civilian executive branch agencies by Jan. 2.