October 2025 [Game Engine Gremlins, Windows Hello Attacks, and Exchange Exploits]

Episode 24   Published October 14, 2025 19 minute watch

Summary

A code execution flaw in the Unity runtime, CVE-2025-59489, reaches well past gaming, because Unity also runs VR training and field tools used in healthcare and defense. Automox Security Manager Ryan Braunstein and Senior Security Engineer Mat Lee cover three of October 2025's vulnerabilities. They cover the Windows Hello security feature bypass, where an attacker with local admin breaks the biometric template encryption and injects their own face to authenticate as the enrolled user. They close on CVE-2025-59249, a Microsoft Exchange Server elevation-of-privilege flaw, and Braunstein's case for moving off self-hosted Exchange rather than carrying its patching and uptime burden.