-
Worth considering: The orbital plane of 3I/ATLAS is unusually precise with the Sun. (3rd Nov 2025)
Worth considering: The orbital plane of 3I/ATLAS is unusually precise with the Sun. Preface: Researchers at the University of California, Riverside conducted an experiment that found that if a terrestrial planet existed between Mars and Jupiter, it could push Earth out of the solar system and destroy life on it. Ref: The full research paper…
-
CVE-2025-58185: improper handling of ASN.1 DER encoding (3rd Nov 2025)
Preface: Is ASN-1 still in use? ASN-1 is used to define a large number of protocols. Its most widespread applications remain in telecommunications, cryptography, and biometrics. ASN.1 is used in protocols like TLS and LDAP/Active Directory because it provides a language and platform independent way to define data structures, making it a standard for interoperability.…
-
About Chrome (V8 Bug 452296415 with CVE-2025-12036): updated to 141.0.7390.122/.123 for Windows and Mac and 141.0.7390.122 for Linux. (31-10-2025)
Preface: Type confusion is a vulnerability where a program accesses a resource using an incompatible type, leading to unexpected behavior or memory corruption. This often occurs when a program misinterprets the type of data being used, potentially leading to the execution of the wrong code or the disclosure of sensitive information. This can happen due…
-
In-depth discussion of the basic knowledge of CAN BUS preventive control (30th Oct 2025)
Preface: Is the CAN bus still in use? While the CAN protocol was originally designed for road vehicles and is still primarily used there, the vehicle bus format has found its way into aircraft, aerospace, and rail systems. Background: CAN bus significantly reduces traditional cable connections by allowing multiple electronic control units (ECUs) to communicate…
-
About Bouncy Castle cryptography – CVE‐2025‐12194: The real fix is reachability fencing, which ensures timely resource disposal regardless of thread type. (28-10-2025)
Published: 2025-10-24 Preface: The Australian government has utilized Bouncy Castle cryptography APIs. Specifically, the Australian Government’s AUSKey project, which was a system for securely accessing government online services, used the Bouncy Castle libraries as its basis for Java cryptography. Bouncy Castle is a widely-used open-source cryptographic API available for Java and C#, developed and maintained…
-
AMD ID: AMD-SB-7055RDSEED Failure on AMD “Zen 5” Processors(27th-10-2025)
Preface: The main consequence of an RDSEED failure on AMD Zen 5 processors is instability, crashes, and potentially corrupted data, as this issue affects the processor’s ability to generate high-quality random numbers for cryptography and other sensitive tasks. This has led to the development of Linux kernel patches to temporarily disable RDSEED on affected Zen…
-
Security Bulletin: NVIDIA ConnectX and BlueField (CVE‑2025-23299) – October 2025 (24th Oct 2025)
Preface: Nvidia BlueField is a line of data processing units (DPUs) designed and produced by Nvidia. Initially developed by Mellanox Technologies. DOCA is a consistent and essential resource across all existing and future generations of BlueField DPU and SuperNIC products. Background: The NVIDIA cloud-native supercomputing platform leverages the NVIDIA BlueField DPU architecture with high-speed, low-latency.…
-
CVE-2025-11678: About warmcat libwebsockets (Industrial network security – Are you worried about?) 23rd Oct 2025
Published: 2025-10-20 Preface: Contribute Automation Expert is a software-centric industrial automation platform that is vendor-agnostic and based on the IEC 61499 standard. It is designed to make industrial automation more agile, efficient, and flexible by decoupling hardware and software, which allows for the use of components from different manufacturers and simplifies the process of updating…
-
AMD response to research about Physical Address Bit Leakage on SEV-SNP Systems (22-10-2025)
Official Revision Date: 20-10-2025 Preface: A 3rd Gen AMD EPYC processor uses an integrated memory controller within its System on a Chip (SoC) to connect to DDR4 DRAM modules, rather than having a separate memory controller component. The memory controller is part of the I/O Die (IOD) which is connected to the Core Complex Dies…
-
AMD response to research about ‘GhostFetch’ (21-10-2025)
Official Revision Date: 17-10-2025 Preface: SEV-SNP is a security technology for confidential computing that encrypts virtual machine memory. SEV-SNP protects memory contents and integrity, and its security model does not depend on the cache indexing method. Background: While SEV-SNP provides strong memory encryption and integrity protections, it does not offer built-in hardware protections specifically for…