Observed attacks involving the recently disclosed WinRAR path traversal flaw, tracked as CVE-2025-8088, and the older Microsoft Internet Explorer resource management errors issue and Microsoft Excel remote code execution bug, tracked as CVE-2013-3893 and CVE-2007-0671, have prompted their inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, reports Security Affairs.
Updates have been issued by the Matrix Foundation to resolve a pair of high-severity flaws in the Matrix federated communications protocol, according to The Record, a news site by cybersecurity firm Recorded Future.
CyberScoop reports that updates have been issued by Microsoft to resolve 111 security flaws across its different offerings as part of this month's Patch Tuesday.
Ongoing intrusions involving the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, were discovered by the Shadowserver Foundation to potentially compromise 3,312 Citrix NetScaler appliances almost two months following the issuance of patches, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.