-
CVE‑2025‑23361 and CVE-2025-33178: NVIDIA Nemo Framework contains vulnerabilities (13th Nov 2025)
Preface: The advantages of using Hydra and OmegaConf for configuration management are flexibility, reproducibility, and scalability. Hydra’s ability to override configurations at runtime from the command line and compose them from multiple sources makes it highly flexible. NeMo uses Hydra/OmegaConf for configuration management, which supports interpolation and sometimes dynamic evaluation. Background: NVIDIA NeMo is an…
-
Question: A signal of approximately 1.667 GHz from the interstellar object 3I/ATLAS was detected [specifically at 1.665 GHz and 1.667 GHz]. (12th Nov 2025)
Preface: The space between stars is not a complete vacuum; it is filled with a sparse collection of gas and dust called the interstellar medium, which is primarily composed of hydrogen and helium. Background: When the water ice on a comet is heated by the Sun and vaporizes in the near-vacuum of space, the resulting…
-
CVE-2025-12907: About Devtools in Google Chrome (12th Nov 2025)
Preface: Google Chrome comes with DevTools built directly into the browser by default. These are a comprehensive set of web developer tools that allow users to inspect and debug web pages, analyze network activity, monitor performance, and much more. You can use the snippets option available in the Sources tab in Chrome DevTools. Just type…
-
CVE-2025-12863: About the libxml2 XML parsing library (11th Nov 2025)
Preface: Libxml2, a C library for parsing and manipulating XML documents, can be relevant in machine learning contexts when dealing with data stored or exchanged in XML format. While not a machine learning library itself, libxml2, or its Python binding lxml, serves as a foundational tool for data preparation and feature engineering. Ref: The “difference”…
-
Can we add more imagination to the 3I/ALTAS (the tail contains an iron-nickel alloy) – 10th Nov 2025
Preface: From the current state, if 3I/ATLAS is not a comet, but it did not travel with different dimensions. Therefore, it is possible to use thrusters. Background: The nickel-iron alloys are used in components like reactor vessels and steam generators because they can withstand the extreme temperatures, pressures, and neutron bombardment within a reactor, and…
-
CVE-2025-62161: About Youki, a container runtime written in Rust (10th Nov 2025)
Preface: Amazon, Google, Microsoft, Apple, Cloudflare, Coursera, Discord, Dropbox, and Figma are among the large companies employing Rust for various purposes, including cloud infrastructure, operating system components, web services, and low-level security components. Youki is gaining increasing attention as a container runtime, especially in the Rust ecosystem, but it has not yet achieved the widespread…
-
About CVE-2025-47365: Qualcomm integrated with automotive platform (7th Nov 2025)
Published: 11/03/2025 Preface: GM’s Ultra Cruise system is supposed to be a more capable iteration of its Super Cruise ADAS that was first introduced in 2017. To dig into the weeds a bit, the Ultra Cruise compute, which is about the size of two laptops stacked together, is made up of two Snapdragon SA8540P SoCs…
-
Security Bulletin: About NVIDIA RunAI – CVE-2025-33176 (6th Nov 2025)
Preface: NVIDIA Run:ai is a Kubernetes-native platform for managing and optimizing AI workloads, acquired by NVIDIA in 2024. It provides dynamic orchestration for GPU resources, supporting flexible resource allocation to improve resource utilization and accelerate the AI development lifecycle in hybrid, on-premises, and cloud environments. Prior to its acquisition by NVIDIA in December 2024, Run:ai…
-
CVE-2025-47353: About Automotive Software platform based on QNX (5th Nov 2025)
Preface: An automotive cockpit is the driver’s compartment, integrating all the controls and information displays needed to operate a vehicle, including the steering wheel, dashboard, instruments, and central displays. Background: To install QNX on a Qualcomm SA8775P chip, you will need the specific QNX Board Support Package (BSP) for that platform, as it contains the…
-
TEE.fail: Another perspective on how intercepting DDR5 memory bus can compromise a trusted execution environment. (4th Nov 2025)
Preface: The recent research, released in a paper titled “TEE.fail: Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition”, does not change Intel’s previous out of scope statement for these types of physical attacks. Background: Intel SGX protects memory by creating encrypted “enclaves,” which are isolated, private regions within an application’s address space. These enclaves…