Home
» Risk & Exploitation
» Daily threat intelligence
» Jul 8, 2025
Jul 8, 2025 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Microsoft Defender For Endpoint: public exploit or PoC linked (privilege escalation)
Microsoft Internet Explorer — exploitation likelihood rose sharply (EPSS 22% → 35% · rising (+13%)).
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2024-50477
Stacksmarket Stacks Mobile App Builder Auth Bypass
Public exploit or PoC available
Exploit activity linked
Authentication bypass — unauthenticated access risk
Stacksmarket Stacks Mobile App Builder Auth Bypass now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Active exploit activity
CVE-2025-47161
Microsoft Defender For Endpoint privilege escalation
Public exploit or PoC available
Exploit activity linked
Potential privilege escalation to admin/root
Microsoft Defender For Endpoint privilege escalation now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Emerging exploitation risk
CVE-2016-0068
Microsoft Internet Explorer privilege escalation
Exploitation likelihood sharply increased
Potential privilege escalation to admin/root
EPSS 22% → 35% · rising (+13%)
Microsoft Internet Explorer: EPSS 22% → 35% · rising (+13%) — EPSS is climbing faster than peer CVEs in this window, a leading indicator even before KEV or public exploit linkage.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
View KEV additions
Exploit & PoC activity
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allow...
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users t...
Sudo Inclusion of Functionality from Untrusted Control Sphere
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allo...
Discourse is an open source platform for community discussion.
View new exploit links
Exploitation dynamics
Microsoft Internet Explorer privilege escalation
Microsoft Internet Explorer privilege escalation
See EPSS increases
New critical disclosures
Cryptographic issue occurs due to use of insecure connection method while downloading.
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary co...
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal...
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter.
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
Adobe Experience Manager (MS) versions 6.5.23.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could...
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE')...
View critical disclosures
cvelogic
Threat Intelligence