CISA adds two known exploited vulnerabilities to catalog
CISA adds CVE-2025-11371 and CVE-2025-48703 to its catalog citing verified active exploitation vulnerabilities.
Signals are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • November 26, 2025
CISA adds CVE-2025-11371 and CVE-2025-48703 to its catalog citing verified active exploitation vulnerabilities.
Decision Insights Threat Desk • November 26, 2025
CISA published five advisories for Industrial Control Systems outlining security issues and vulnerabilities in products from Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. Users and administrators are advised to review the advisories for technical details and mitigation steps.
Decision Insights Signals • November 26, 2025
MWC25 Doha gathered nearly 9,500 participants worldwide, featuring 5G demos and discussions on connectivity and collaboration.
Decision Insights Signals • November 26, 2025
Finland blocked scam calls via Elisa's method, reducing losses and gaining Europol's recognition and EU award nomination.
Decision Insights Signals • November 26, 2025
Asiacell, Iraq's telecommunications provider, partners with Evam to deploy the evamX platform. This integration enables real-time, AI-driven, personalized marketing across multiple channels, enhancing customer engagement and supporting Iraq's digital transformation efforts.
Decision Insights Signals • November 26, 2025
Asiacell in Iraq has adopted Cisco's AI-powered Provider Connectivity Assurance to enhance network performance and reliability.
Decision Insights Threat Desk • November 26, 2025
Cross-site scripting found in Lectora Desktop 21.0–21.3 and Lectora Online 7.1.6 and older requires patching and republishing.
Decision Insights Threat Desk • November 26, 2025
A supply chain attack on NPM has compromised over 500 packages using credential theft and self-propagating malware.
Decision Insights Threat Desk • November 26, 2025
Draytek Vigor routers with DrayOS firmware have a remote code execution flaw in EasyVPN and LAN interfaces enabling attacker control.
Decision Insights Threat Desk • November 26, 2025
Kiwire Captive Portal vulnerabilities include SQL injection, open redirection, and XSS; vendor released fixes are available.
Decision Insights Threat Desk • November 26, 2025
Clevo's UEFI firmware leaked private Boot Guard keys, risking pre-boot firmware integrity on affected systems.
Decision Insights Threat Desk • November 26, 2025
A vulnerability in browsers allows DNS rebinding and CORS header manipulation to enable unauthorized data access.
Decision Insights Threat Desk • November 26, 2025
Password managers in browser extensions face DOM-based clickjacking risks that may expose stored credentials during autofill.
Decision Insights Threat Desk • November 26, 2025
Email header syntax allows spoofing of trusted senders by bypassing SPF, DKIM, and DMARC checks, affecting multiple providers.
Decision Insights Threat Desk • November 26, 2025
Lite XL text editor versions 2.1.8 and prior contain vulnerabilities allowing arbitrary code execution via Lua project modules and system.exec.
Decision Insights Threat Desk • November 26, 2025
Wolfram Cloud version 14.2 JVM access to shared /tmp/ temporary directories enables privilege escalation and code execution.
Decision Insights Signals • November 26, 2025
Nota AI and Samsung Electronics collaborate to optimize AI models for the Exynos 2500 processor to enhance on-device generative AI.
Decision Insights Signals • November 26, 2025
Nokia signed a 5-year contract extension with Telefónica Germany to modernize and upgrade its nationwide Radio Access Network (RAN) through 2030. The deal features Nokia's Cloud RAN and AI-powered management solutions to support 5G network expansion and digitalization in Germany.
Decision Insights Coverage • November 25, 2025
RedTiger, an open-source red-teaming tool, is circulating with infostealer variants targeting Discord accounts and gaming credentials.
Decision Insights Coverage • November 25, 2025
Netskope offers real-time log streaming to SIEM tools, aiding zero trust security in hybrid, AI-driven environments.
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.