Jun 28, 2025 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
- 3 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2025-32897
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
New critical Apache Seata Deserialization (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2025-5304
Ptoffice Pt Project Notebooks Privilege Escalation
- CVSS 9.8
- Internet-facing CMS deployments affected
New critical Ptoffice Pt Project Notebooks Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
High-risk exposure
CVE-2025-53391
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has...
- CVSS 9.3
- Potential privilege escalation to admin/root
New critical-severity CVE in today's window — elevated exposure signal, early in the lifecycle.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_user...
The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inac...
View critical disclosures
cvelogic
Threat Intelligence