Vulnerability-Digest-Apr-2025
Vulnerability-Digest-Apr-2025
April 2025
Sean Carroll William Busler
Lead Technical Product Engineer Technical Product Engineer
Agenda
1 Top Attacks of the Month 3 Software Updates
▪ Ivanti Under Siege with Advanced Malware ▪ Google ▪ Splunk
▪ Oracle Cloud Compromised ▪ Mozilla Firefox ▪ VMware
▪ Veeam
▪ Overview
▪ Apache
▪ Zero-day Vulnerabilities
• Cisco
▪ Critical Vulnerabilities
You’ll get the Feel free to ask Take a short poll You’ll get the
slides via email questions during and survey; we recording within
the ppt via chat appreciate your 24h
or Q&A feedback!
121 11 1
Fixed Vulnerabilities Critical Vulnerabilities Zero-day Vulnerabilities
Fixed
CVE-2025-
Microsoft Office (UAF RCE) 7.8 No Medium
2774/48/45
= Exploited in the wild = Public PoC or suspected = Patch available, no known exploitation