Threats are potential events, conditions, or actions that can exploit vulnerabilities to harm an enterprise’s systems, data, operations, or individuals, and they serve as a core input for risk assessment, security architecture, regulatory compliance, and incident response planning.
CISA added CVE-2025-58034, a Fortinet FortiWeb OS command code injection vulnerability, to the Known Exploited Vulnerabilities Catalog with a one-week remediation guideline.
CISA added CVE-2025-21042, an out-of-bounds write flaw in Samsung mobile devices, to its Known Exploited Vulnerabilities catalog due to active exploitation.
Cyber threat actors use commercial spyware to target messaging app users in the US, Middle East, and Europe employing phishing and zero-click exploits.