On-premises SysAid IT support software instances have been impacted by a trio of XML External Entity injection vulnerabilities, tracked as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777.
Internet exposure of Apache Pinot's primary components facilitated by Kubernetes LoadBalancer services, which remains unknown to the user, has already been exploited by threat actors to access user data.
Google has issued fixes for 47 Android vulnerabilities as part of this month's security update, one of which has already been leveraged by threat actors.