-
CVE-2026-90648: A sandbox escape vulnerability exists in wasm2c of WebAssembly wabt (version 1.0.41 and earlier), which affects a wide range of technical fields.
Source: Mitre, NVD – Published: 2026-09-12 Preface: Automotive & Safety-Critical SystemsIn industries where software must comply with rigid safety certifications (such as ISO 26262 for automotive or DO-178C for aerospace), executing arbitrary code at runtime using a Just-In-Time (JIT) compiler is completely forbidden. The wasm2c Advantage: Since wasm2c acts entirely as an Ahead-Of-Time (AOT) translator…
-
Multi-faceted design defect analysis – CVE-2026-7849 (August 3, 2026)
Preface: “Secure by Design” is a flawless theory when studying standards like IEC 62443 or automotive-specific ISO/SAE 21434, but in reality, original equipment manufacturers (OEMs) always compromise due to Bill of Materials (BOM) and production costs. Background: • The Charging Station Side (EVSE): CVE-2026-7849 is strictly an OS Command Injection vulnerability within the Web management…
-
CVE-2026-54783: SCADA staying alert by CoreWCF design weakness, no special privileges can capture a single signed SOAP envelope and replay arbitrary service operations by acting as the victim principal. (13th Jul 2026)
Preface: The SOAP Header is an optional sub-element in a SOAP message (XML file) used to convey additional non-functional information (such as security authentication, keys, transaction processing, or routing messages) that is not directly related to the business entity. If a SOAP message includes a Header, it must immediately follow the <soap:Envelope> root element and…
-
How can Apple meet requirements for lawful key escrow similar to those in Canada’s C-22 Act? (12th May 2026)
Preface: Can we say that Apple’s iPhone is the most secure smartphone in the world? Yes, the Apple iPhone is widely considered the most secure mainstream smartphone for general users, largely due to its “walled garden” approach. Background: As of May 2026, Canada’s proposed Bill C-22, the Lawful Access Act (2026), is currently being debated…
-
CVE-2025-68620: Signal K Server, no authentication is required, and authentication can be completely bypassed. (5th Jan 2026)
NVD Published Date: 01/01/2026 Preface: Signal K’s popularity in the IoT space, especially in marine tech, is growing due to its open-source nature, enabling advanced, connected, and personalized vessel data systems, integrating with trends like AI, edge computing (via Meshtastic), and edge devices for remote monitoring and control, mirroring the broader IoT boom expected to…
-
The relationship between the solar wind and the Earth (14-06-2025)
Preface: Auroras are a visible manifestation of geomagnetic storms. Geomagnetic storms are disturbances in Earth’s magnetosphere caused by the interaction of charged particles from the sun (the solar wind) with Earth’s magnetic field. Auroras typically appear in high latitudes, including northern North America and parts of Asia. Background: The Sun’s corona and heliosphere, while constantly present, are…
-
CVE-2024-10455 Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block (28 Oct 2024)
Preface: µD3TN is a free space-tested software protocol stack for delay-tolerant networks. It runs on POSIX and Linux operating systems and can easily adapt to a variety of challenging networks. The source code is available under a BSD license. AREAS OF APPLICATION : Car-to-X Communication ,Offshore Communication , Maritime Research , Satellite Communication and Reliable…
-
About CVE-2024-36843: libmodbus v3.1.6 design weakness (3 June 2024)
Preface: Modbus is a communication protocol widely used in the field of industrial automation. It provides a standardized method for devices to communicate with each other over the network, making it an important tool for connecting and controlling various industrial equipment. Background: libmodbus supports the following functions: Vulnerability details: libmodbus v3.1.6 was discovered to contain…
-
Ccache technical matter , whether it will bring your attention? (13th Mar 2023)
Preface: Multiphysics Object-Oriented Simulation Environment (MOOSE) – An open-source, parallel finite element framework. Background: ccache is a compiler cache that speeds up recompilation by caching previous compilations and detecting when the same compilation is being done again. ccache can deliver significant speedups when developing MOOSE-based applications, or working on the framework itself.Multiphysics Object Oriented Simulation…
-
Cyber Défense from narrow to broad (5th Jan 2023)
Preface: Sustainability is a buzzword in the modern world in recent years. It applies to business, culture…even our education. A slogan, keep learning. Maybe it’s the Cantonese mantra, One is never too old to learn. Perhaps it also apply to cyber security protection. Background: In last twenty years, computing technology driven growth of the world.…