
Critical Vulnerabilities and Exploits: Apple, WinRAR, and More in Weekly Recap
This week's cybersecurity landscape has seen several critical vulnerabilities and exploits come to light. Apple has patched two zero-day vulnerabilities, CVE-2025-21456 and CVE-2025-21457, affecting iOS, iPadOS, and macOS. These vulnerabilities were actively exploited before patches were released, highlighting the importance of timely updates. Additionally, a vulnerability in WinRAR (CVE-2025-38831) allows for arbitrary code execution through malicious archives and has been exploited since August 2025. LastPass has been fined $4.5 million for data breach-related failures from 2022. A remote code execution vulnerability in .NET (CVE-2025-4000) has also been identified. Furthermore, phishing campaigns exploiting OAuth to hijack accounts have been reported. These attacks target smartphone users, browsers, and compression tool users. Given the severity of these vulnerabilities and their active exploitation, it is crucial for organizations and individuals to apply patches promptly and remain vigilant against phishing attempts. The impact on the cybersecurity landscape is significant, as these vulnerabilities affect widely used software and platforms. The LastPass fine underscores the regulatory consequences of inadequate data protection measures. Cybersecurity professionals should prioritize patch management and user education to mitigate these risks.