-
CVE-2025-48507: About calling processor into Arm Trusted Firmware (26th Nov 2025)
Preface: AMD’s Zynq™ UltraScale+™ RFSoCs are a family of highly integrated adaptive Systems-on-Chip (SoCs) that combine a multi-core Arm® processing system, programmable logic (FPGA fabric), and direct RF-sampling data converters (ADCs and DACs) on a single chip. CVE-2025-48507 Affected Devices: Kria™ SOM, Zynq™ UltraScale+™ MPSoCs and Zynq™ UltraScale+™ RFSoCs. Background: The crypto operations in Arm®…
-
CVE-2025-65947: The thread_amount function calls, risk level change according to definitions. (25th Nov 2025)
Published: 2025-11-21 Preface: The “mach kernel” in iOS refers to the **Mach kernel component of the XNU hybrid kernel, which is the core of Apple’s iOS operating system. XNU is a hybrid kernel that merges the Mach microkernel with components from the BSD Unix system to create a single, cohesive kernel that runs iOS and…
-
CVE-2025-29934 – A vulnerability exists in the TLB entries of certain AMD CPUs. (20th Nov 2025)
Official announcement: November 11, 2025 Preface: AMD EPYC processors support an Input-Output Memory Management Unit (IOMMU), a hardware component essential for managing memory access for peripheral devices. IOMMU technology on EPYC platforms is a critical component for virtualization, device passthrough (PCIe passthrough), and system security. Background: SEV-SNP mitigates many TLB (Translation Lookaside Buffer) attacks by…
-
Cyber security focus for NVIDIA Isaac-GR00T – About CVE-2025-33183 and CVE-2025-33184 (24th Nov 2025)
Updated 11/19/2025 09:03 AM Preface: NVIDIA Isaac is an AI robot development platform consisting of NVIDIA-accelerated libraries, application frameworks, and AI models that accelerate the development of AI robots such as autonomous mobile robots (AMRs), arms and manipulators, and humanoids. NVIDIA Isaac GR00T N1 is the world’s first open foundation model for generalized humanoid robot…
-
CVE-2025-13223: About Chrome – Officially recommendation, patch immediately (20th Nov 2025)
-
In-depth analysis of the Android 0-Click vulnerability – CVE-2025-48593. The issue has been resolved. (20th Nov 2025)
Published: 2025-11-17 Preface: An HFP (Hands-Free Profile) device is a Bluetooth device that supports the Hands-Free Profile, which allows for hands-free calling and control of a mobile phone, such as a car’s infotainment system or a wireless headset. It enables features like answering, making, and ending calls, as well as voice dialing and call waiting,…
-
CVE-2025-52538: About AMD Xilinx Run Time (XRT) 19th Nov 2025
Last updated: November 11, 2025 Preface: AMD Xilinx refers to the former independent company Xilinx, which was acquired by Advanced Micro Devices (AMD) in February 2022. Xilinx’s current and past product lines include: Field-Programmable Gate Arrays (FPGAs), System-on-Chip (SoC) Devices, Adaptive Compute Acceleration Platforms (ACAPs), Data Center Accelerator Cards & System-on-Modules (SoMs). Xilinx provides countless…
-
CVE-2025-42890 – Design flaws of SQL Anywhere Monitor (18th Nov 2025)
NVD Last Modified: 11/12/2025 Preface: The original graphical interface for the SQL Anywhere Monitor relied on Adobe Flash, which reached its end-of-life in December 2020. Consequently, the GUI interface is no longer provided in modern versions, and users must use non-GUI methods. SAP recommends using SAP SQL Anywhere Cockpit or SAP Solution Manager as modern,…
-
CVE-2025-33185: About NVIDIA AIStore (17th Nov 2025)
Official Updated 10th Nov 2025 05:39 AM Preface: The core design objective of NVIDIA AIStore (AIS) is to provide a high-performance, linearly scalable, and flexible storage solution specifically optimized for large-scale AI/ML and data analytics workloads. NVIDIA AIStore (AIS) provides secure access via a standalone Authentication Server (AuthN) that uses OAuth 2.0 compliant JSON Web…
-
CVE-2025-33202: About NVIDIA Triton Inference Server (14th Nov 2025)
Official Updated 11/10/2025 05:39 AM Preface: Clients can communicate with Triton using either an HTTP/REST protocol, a GRPC protocol, or by an in-process C API or its C++ wrapper. Triton supports HTTP/REST and gRPC, both of which involve complex header parsing. In the context of the Open Inference Protocol (OIP), also known as KServe V2…