@cR0w@infosec.exchange
Happy Patch Tuesday. Here's your emoji of the day.
Happy Patch Tuesday. Here's your emoji of the day.
SAP published its Patch Tuesday CVEs. I count 16 of them so far.
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2025.htmlsev:LOW: 2
https://www.cve.org/CVERecord?id=CVE-2025-42941
https://www.cve.org/CVERecord?id=CVE-2025-42955sev:MED: 10
https://www.cve.org/CVERecord?id=CVE-2025-42934
https://www.cve.org/CVERecord?id=CVE-2025-42935
https://www.cve.org/CVERecord?id=CVE-2025-42936
https://www.cve.org/CVERecord?id=CVE-2025-42942
https://www.cve.org/CVERecord?id=CVE-2025-42943
https://www.cve.org/CVERecord?id=CVE-2025-42945
https://www.cve.org/CVERecord?id=CVE-2025-42946
https://www.cve.org/CVERecord?id=CVE-2025-42948
https://www.cve.org/CVERecord?id=CVE-2025-42949
https://www.cve.org/CVERecord?id=CVE-2025-42975sev:HIGH: 2
https://www.cve.org/CVERecord?id=CVE-2025-42951
https://www.cve.org/CVERecord?id=CVE-2025-42976sev:CRIT: 2
https://www.cve.org/CVERecord?id=CVE-2025-42950
https://www.cve.org/CVERecord?id=CVE-2025-42957
#patchTuesday
Vim with two nice CVEs. One is a UAF and the other is a double-free.
https://github.com/vim/vim/security/advisories/GHSA-3r4f-mm4w-wgg6
https://github.com/vim/vim/security/advisories/GHSA-5fg8-wvx3-583x
@scottwilson@infosec.exchange They couldn't out crazy real life anymore and gave up.
@scottwilson@infosec.exchange But really, the only thing I've heard was that the guy behind it got arrested for something. No confirmation, no details.
If you run a massive international corporation with lots of money and you need another domain for something, please don't use something like a .xyz or .top or .cloud . It's a poor practice and you are in no place to criticize orgs that rightfully block those shady TLDs.
A sev:CRIT ../ in Xerox in 2025.
https://nvd.nist.gov/vuln/detail/CVE-2025-8356
Go hack more AI shit.
https://github.com/zed-industries/zed/security/advisories/GHSA-x34m-39xw-g2wr
Another space vuln.
https://github.com/nasa/CryptoLib/security/advisories/GHSA-9qph-pxfm-q9g4
Tomorrow is Patch Tuesday. Again. In case you were looking for a reason to call in sick or something.
Are people seriously installing browser plugins to summarize the pages they visit using AI?!