Author: admin

  • CVE-2025-46647: A vulnerability of plugin openid-connect in Apache APISIX.(3rd July 2025)

    Preface: API Gateway can be helpful for ChatGPT plugin developers to expose, secure, manage, and monitor their API endpoints. This repo demonstrates how to use Apache APISIX API Gateway as a front door for communication between ChatGPT custom plugins and backend APIs. For more details, please refer to the link – https://github.com/Boburmirzo/apisix-chatgpt-gateway-plugin Background: The primary…

  • CVE-2025-0038 exposes a runtime vulnerability due to missing checks in PMU firmware. (2nd July 2025)

    Preface: Users typically build custom PMU firmware tailored to their specific hardware platform and application requirements. PMU firmware can be loaded by either FSBL or CSU BootROM (CBR). Both these flows are supported by AMD. Loading PMU firmware using FSBL has the following benefits: – Possible quick boot time, when PMU firmware is loaded after…

  • CVE-2025-49521: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix Update (1st July 2025)

    Preface: Ansible Automation Platform is a broader enterprise automation platform designed to manage and automate various IT operations, including infrastructure, cloud, networking, and security. While it can be used for automating web server deployments and configurations. Besides, web hosting service providers can and often do use the Ansible Automation Platform for automating various tasks related…

  • CVE-2025-38085: About hugetlb[.]c of Linux kernel. (29-06-2025)

    Preface: Does Big Data use the TLB in the Linux kernel? Yes, big data applications in Linux utilize the Translation Lookaside Buffer (TLB) as a crucial component of memory management. The TLB speeds up address translation by caching recently used virtual-to-physical address mappings. Applications like databases, which often handle large datasets and have specific memory…

  • CVE-2025-23260: About NVIDIA AIStore on Kubernetes (26-06-2025)

    Preface: AI and machine learning workloads rely on optimized object storage to handle the massive, unstructured datasets needed for training and operation. NVIDIA AIStore (AIS) aims to overcome the limitations of traditional filesystems in handling large AI datasets by providing a distributed storage system that can handle the demands of modern AI models. Background: An…

  • CVE-2025-23264 and CVE-2025-23265: About NVIDIA Megatron-LM (25-06-2025)

    Preface: What Does “Linear” Mean in Machine Learning? In the context of machine learning and neural networks: A linear function is one where the relationship between inputs and outputs can be represented as a straight line (in 2D), or more generally, a hyperplane in higher dimensions. Background: NVIDIA Megatron-LM is an open-source framework designed for…

  • AMD Fixed CVE-2024-21969 (23rd June 2025)

    CVE-2024-21969: Whispering Pixels: Exploiting Uninitialized Register Accesses in Modern GPUs. Preface: How to Enable Secure GPU Mode (Register Clearing) Background: The proliferation of graphics processing units (GPUs) has brought unprecedented computing power. Multiple register-based vulnerabilities found across different GPU implementations. So-called whisper pixels. The vulnerability poses unique challenges to an adversary due to opaque scheduling…

  • About Veeam Backup (CVE-2025-23120 and CVE-2025-23121) – 23-06-2025

    CVE-2025-23121 NVD Published Date: 06/18/2025 NVD Last Modified: 06/18/2025 Preface: Veeam introduced a custom serialization formatter to protect against unsafe deserialization vulnerabilities (see below): -They override the default .NET deserialization behavior. -They validate or restrict which types can be deserialized. -This is a security hardening measure to prevent attackers from exploiting deserialization to execute arbitrary…

  • CVE-2025-52556: Insufficient verification of timestamp response signatures. Users should immediately upgrade to rfc3161-client 1.0.3 or later. (23-06-2025)

    Preface: rfc3161-client version 1.0.3 is not designed to be installed on the server side. It’s a Python library, specifically a client-side tool, for interacting with RFC 3161 Time-Stamp Protocol (TSP) servers. It’s used to create timestamp requests and process timestamp responses, which is a client-side function of interacting with a time-stamping authority. Background: The primary…

  • When dreams come true (M78 Nebula) – 20-06-2025

    Preface: When I was a kid watching Japanese science fiction TV series, the M78 Nebula is the location of the Kingdom of Light and the hometown of most Ultraman in the Kingdom of Light world. So believe that M78 Nebula was not real! At that time 70s, the internet technologies of today never been develop!…