Aggregator
Faster Not Bigger: New R1T2 LLM Combines DeepSeek Versions
9 months 2 weeks ago
German Consultancy's Latest LLM Aims to Reduce Costs, Preserve Reasoning Skills
Say hello to DeepSeek-TNG R1T2 Chimera, a large language model built by German firm TNG Consulting, using three different DeepSeek LLMs. The goal of R1T2 is to provide a faster LLM with more predictable performance that maintains full reasoning accuracy.
Say hello to DeepSeek-TNG R1T2 Chimera, a large language model built by German firm TNG Consulting, using three different DeepSeek LLMs. The goal of R1T2 is to provide a faster LLM with more predictable performance that maintains full reasoning accuracy.
Editors' Panel: Pro-Iran Hackers Threaten to Leak Trump Data
9 months 2 weeks ago
Also: Medicare Data Breach; Gartner Security & Risk Management Summit Takeaways
In this week's update, ISMG editors discussed Iran-linked hackers claiming to steal emails from Trump's inner circle, how to refine application development in the age of AI, and a U.S. Medicare data breach amplifying concerns over the safety, security and privacy of federal health systems.
In this week's update, ISMG editors discussed Iran-linked hackers claiming to steal emails from Trump's inner circle, how to refine application development in the age of AI, and a U.S. Medicare data breach amplifying concerns over the safety, security and privacy of federal health systems.
EU Pledges 'No Pause' Over Enforcement of Bloc's AI Act
9 months 2 weeks ago
Rejects Business and AI Leaders' Call for Two-Year Enforcement Moratorium
Expect to see no pause in the EU's enforcement of new rules governing artificial intelligence, a spokesperson for the European Commission said amid intensifying calls for officials to "stop the clock" over implementing the bloc's AI Act, in the name of innovation and competition.
Expect to see no pause in the EU's enforcement of new rules governing artificial intelligence, a spokesperson for the European Commission said amid intensifying calls for officials to "stop the clock" over implementing the bloc's AI Act, in the name of innovation and competition.
CVE-2023-0645 | libjxl 0.8.1 Exif out-of-bounds (Nessus ID 241348)
9 months 2 weeks ago
A vulnerability has been found in libjxl 0.8.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Exif Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2023-0645. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-35790 | libjxl 0.8.2 dec_patch_dictionary.cc integer underflow (Nessus ID 241348)
9 months 2 weeks ago
A vulnerability has been found in libjxl 0.8.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file dec_patch_dictionary.cc. The manipulation leads to integer underflow.
This vulnerability is known as CVE-2023-35790. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6221 | corydolphin flask-cors up to 4.0.1 Configuration Options access control (Nessus ID 241350)
9 months 2 weeks ago
A vulnerability was found in corydolphin flask-cors up to 4.0.1 and classified as critical. Affected by this issue is some unknown functionality of the component Configuration Options Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-6221. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2022-2735 | PCS Unix Socket default permission (Nessus ID 241351)
9 months 2 weeks ago
A vulnerability was found in PCS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Unix Socket Handler. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2022-2735. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-6378 | QOS logback 1.4.11 Logback Receiver denial of service (Nessus ID 241352)
9 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in QOS logback 1.4.11. This issue affects some unknown processing of the component Logback Receiver. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2023-6378. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
无影 TscanPlus 兑奖无法添加好友?
9 months 2 weeks ago
添加好友兑奖 TscanPlus
Впервые в истории корабль использовал звёзды как GPS в глубоком космосе
9 months 2 weeks ago
Первый в истории опыт звёздной навигации прошёл успешно на краю Солнечной системы.
CVE-2025-7074 | vercel hyper up to 3.4.1 rimraf-standalone.js expand/braceExpand/ignoreMap redos (Issue 8098 / EUVD-2025-20103)
9 months 2 weeks ago
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2025-7074. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-53482 | IPInfo Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki cross site scripting (EUVD-2025-20083)
9 months 2 weeks ago
A vulnerability was found in IPInfo Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-53482. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52497 | mbed TLS up to 3.6.3 PEM mbedtls_pem_read_buffer off-by-one (EUVD-2025-20082)
9 months 2 weeks ago
A vulnerability was found in mbed TLS up to 3.6.3. It has been declared as problematic. Affected by this vulnerability is the function mbedtls_pem_read_buffer of the component PEM Handler. The manipulation leads to off-by-one.
This vulnerability is known as CVE-2025-52497. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52496 | mbed TLS up to 3.6.3 AESNI Detection compiler optimization removal or modification of security-critical code (EUVD-2025-20081)
9 months 2 weeks ago
A vulnerability was found in mbed TLS up to 3.6.3. It has been classified as problematic. Affected is an unknown function of the component AESNI Detection. The manipulation leads to compiler optimization removal or modification of security-critical code.
This vulnerability is traded as CVE-2025-52496. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49600 | mbed TLS up to 3.6.3 mbedtls_lms_verify missing cryptographic step (EUVD-2025-20080)
9 months 2 weeks ago
A vulnerability was found in mbed TLS up to 3.6.3 and classified as problematic. This issue affects the function mbedtls_lms_verify. The manipulation leads to missing cryptographic step.
The identification of this vulnerability is CVE-2025-49600. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53481 | IPInfo Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki resource consumption (EUVD-2025-20084)
9 months 2 weeks ago
A vulnerability has been found in IPInfo Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki and classified as problematic. This vulnerability affects unknown code. The manipulation leads to resource consumption.
This vulnerability was named CVE-2025-53481. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49601 | mbed TLS up to 3.6.3 mbedtls_lms_import_public_key out-of-bounds (EUVD-2025-20079)
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in mbed TLS up to 3.6.3. This affects the function mbedtls_lms_import_public_key. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-49601. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #602353: vercel hyper >=18.2.79 Inefficient Regular Expression Complexity [Accepted]
9 months 2 weeks ago
Submit #602353 / VDB-314973
DayShift
The 47-Day SSL Certificate Era: What It Means for Site Owners and IT Teams
9 months 2 weeks ago
The move to 47-day SSL certificates is a major step toward a more secure, automated internet. While it introduces new challenges, especially for organizations relying on manual processes, it ultimately pushes the ecosystem toward greater resilience and trust.
The post The 47-Day SSL Certificate Era: What It Means for Site Owners and IT Teams appeared first on Security Boulevard.
Grant Shapiro