10.0 RSC flaw actively exploited in the wild by China-based threat groups within hours of public disclosure leads the pack for December's Patch Tuesday.
Open source content analysis toolkit Apache Tika had its core, PDF, and parser modules impacted with a maximum severity vulnerability, tracked as CVE-2025-66516, which could be leveraged in XML external entity attacks, Security Affairs reports.
Attacks involving the critical React2Shell remote code execution vulnerability, tracked as CVE-2025-55182, were noted by Palo Alto Networks Unit 42 researchers to have compromised more than 30 organizations in various industries, reports BleepingComputer.
Interview with Danny Jenkins: How badly configured are your endpoints? Misconfigurations are one of the most overlooked areas in terms of security program quick wins. Everyone freaks out about vulnerabilities, patching, and exploits. Meanwhile, security tools are misconfigured. Thousands of unused software packages increase remediation effort and a...
SecurityWeek reports that mitigations for a high-severity Windows LNK flaw subjected to years-long exploitation have been silently provided by Microsoft as part of last month's security updates.
Numerous WordPress sites with the King Addons for Elementor plugin versions 24.12.92 to 51.1.14 could be compromised in attacks involving a recently addressed critical privilege escalation vulnerability, tracked as CVE-2025-8489, which have been underway since the end of October, Security Affairs reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.