-
A Tale of Two GPU’s
Story background: Rowhammer Attacks on GPU Memories are Practical (8th Dec 2025) Preface: The story unfolds a hidden tale within two different design purpose GPUs (consumer display card and AI (install ROCm)) and reveals the untold behind-the-scenes story that the two sides concealed from the recent. Background: AMD’s bulletin (Dec 2025) confirms GDDR6-based GPUs are…
-
As a viewer, what will I think about when 3I/ATLAS approaches Regulus in Leo on December 19, 2025? (6th Dec 2025)
Preface: Comet 3I/ATLAS will be near Regulus (the “Heart of the Lion”) in the constellation Leo around its closest approach to Earth on December 19, 2025, appearing just below the bright star in the early pre-dawn, east-northeast sky, though a telescope is needed to see the faint comet itself. About 3I/ATLAS: 3I/ATLAS offers scientists a…
-
CVE-2025-47372: Buffer Copy Without Checking Size of Input in Boot (5th Dec-2025)
Qualcomm – Official announcement: 1st Dec 2025 Quote: I chose a Qualcomm product affected by this vulnerability as an example. The Snapdragon Ride™ Flex SoC, including the SA9000P series, does not run on a single embedded OS, but rather supports mixed-criticality operating systems such as those provided by Qualcomm’s partners or the automaker themselves. Preface:…
-
CVE-2025-47319: Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS (4th Dec 2025)
Published: 12/01/2025 Preface: Qualcomm HLOS (High-Level Operating System) refers to the operating system layer, like Android, that runs on a Qualcomm Snapdragon chipset and is responsible for general device functionality. “TA” (Trusted Application) is a component of the Qualcomm Trusted Execution Environment (QTEE) that runs in a secure environment, separate from the HLOS. Security issues…
-
CVE-2025-66216: About AIS-catcher (3rd Dec 2025)
Preface: AIS-Catcher is a MIT licensed dual band AIS receiver for Linux, Windows and Raspberry Pi. It is compatible with RTL-SDR dongles and the Airspy HF+. AIS stands for Automatic Identification System and is used by marine vessels to broadcast their GPS locations in order to help avoid collisions and aide with rescues. An RTL-SDR…
-
CVE-2025-12183: About official lz4-java library (2nd Dec 2025)
Published: 2025-11-28 Preface: Apache Hadoop and Apache Spark are both prominent and widely used frameworks for big data analytics. They are central to the processing and analysis of large datasets that cannot be handled by traditional data processing tools. Apache Hadoop utilizes the MapReduce programming model as a core component for processing and analyzing large…
-
CVE-2025-33204: About NVIDIA NeMo Framework (1st Dec 2025)
Official Update 11/21/2025 04:36 PM Preface: NeMo Curator is a Python library that includes a suite of modules for data-mining and synthetic data generation. They are scalable and optimized for GPUs, making them ideal for curating natural language data to train or fine-tune LLMs. With NeMo Curator, researchers in Natural Language Processing (NLP) can efficiently…
-
Comets share similar characteristics. What makes Comet 3I/ATLAS special is that the main volatile substance in its coma is carbon dioxide (CO₂)?
Preface: In 14th April,1561, an unidentified flying objects (UFO) above Nuremberg, Germany. Above diagram shown a broadsheet news article printed in April 1561. Is it a coincidence? A pillar shape unknown flying object shown on the picture. As we know, in 1903 the Wright brothers had invented the first successful airplane. Talking about three hundred…
-
CVE-2025-33203 – Design weakness of NVIDIA NeMo Agent Toolkit UI for Web. Another preventive approach. (28th Nov 2025)
Preface: While web vulnerabilities can lead to various cyberattacks, they don’t directly or exclusively cause ransomware attacks. CSRF attacks exploit the trust a website has in a user’s browser to perform unauthorized actions on that website, while ransomware involves malware that encrypts a user’s system and demands payment. Background: The official frontend user interface component…
-
AI developers, please do not underestimate the CVE-2025-33187 (NVIDIA DGX Spark GB10) vulnerability (26th Nov 2025)
Updated 11/21/2025 04:36 PM Preface: NVIDIA DGX Spark will be used by AI developers, researchers, and data scientists who need to prototype and deploy large AI models on their desktop, including those working with agentic AI, LLMs, and robotics. The NVIDIA DGX Secure Root of Trust (SRoT), more commonly referred to as the Hardware Root…