Threat Intelligence – CERT Bulletin October 2025

10 Nov, 2025 min read

The October bulletin reviews three major vulnerabilities:

  • Redis – CVE-2025-49844
  • Veeam Backup & Replication – CVE-2025-48983
  • Apache Tomcat – CVE-2025-55754

This bulletin also includes an article with a detailed analysis of the APT group Ghostwriter. It provides the geopolitical and cyber context of Belarus and explains the group’s operations using the Diamond Model. A focus on PicassoLoader, a malware that hides payloads in image files, is also featured.


The bulletin is freely accessible to the entire community.