The tech products we absolutely loved this year – and which we’re taking into 2026

From smart plugs to smart glasses, see what we loved (and what surprised us) this year.

Latest news – ​Read More

Libbiosig, Grassroot DiCoM, Smallstep step-ca vulnerabilities

Libbiosig, Grassroot DiCoM, Smallstep step-ca vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Biosig Project Libbiosig, Grassroot DiCoM, and Smallstep step-ca.

The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.    

For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.     

Libbiosig vulnerability

Discovered by Mark Bereza of Cisco Talos.

BioSig is an open source software library for biomedical signal processing. The BioSig Project seeks to encourage research in biomedical signal processing by providing open source software tools.

TALOS-2025-2296 (CVE-2025-66043-CVE-2025-66048) includes several stack-based buffer overflow vulnerabilities in the MFER parsing functionality of the Biosig Project libbiosig 3.9.1. An attacker can supply a specially crafted MFER file to trigger these vulnerabilities, possibly leading to arbitrary code execution.

Grassroot DiCoM vulnerabilities

Discovered by Emmanuel Tacheau of Cisco Talos.

Grassroots DiCoM is a C++ library for DICOM medical files, accessible from Python, C#, Java, and PHP. It supports RAW, JPEG, JPEG 2000, JPEG-LS, RLE and deflated transfer syntax. Talos found three out-of-bounds read vulnerabilities in DiCoM. An attacker can provide a malicious file to trigger these vulnerabilities.

Smallstep step-ca vulnerabilities

Discovered by Stephen Kubik of the Cisco Advanced Security Initiatives Group (ASIG).

Smallstep step-ca is a TLS-secured online Certificate Authority (CA) for X.509 and SSH certificate management. TALOS-2025-2242 (CVE-2025-44005) is an authentication bypass vulnerability in step-ca. An attacker can bypass authorization checks and force a Step-CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.

Cisco Talos Blog – ​Read More

Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users

Researchers said the campaign likely aimed to collect sensitive information from Ukrainian users in support of broader Russian intelligence objectives.

The Record from Recorded Future News – ​Read More

Hopping online at the airport? Cellular may be faster than Wi-Fi – here’s why

Your mobile carrier may offer better access than the airport’s Wi-Fi, according to tests by Ookla. Results vary by airport.

Latest news – ​Read More

FTC orders crypto platform Nomad to distribute $37.5 million after 2022 theft

Under a settlement with the FTC, the Nomad platform will have to redistribute stolen funds that white-hat hackers returned to the company after thieves aggressively exploited a vulnerability in 2022.

The Record from Recorded Future News – ​Read More

Comcast’s new TV plans have no contracts and hidden fees – here’s how they work

The latest Xfinity TV plans keep it simple with one up-front pricing – no equipment rental charges included.

Latest news – ​Read More

Cisco says Chinese hackers are exploiting its customers with a new zero-day

Cisco said it discovered a Chinese hacking campaign targeting its customers by exploiting a zero-day in some of the company’s most popular products.

Security News | TechCrunch – ​Read More

Google’s latest AI tool briefs you on your day like a personal assistant – for free

A new tool called CC tries to help you organize the day ahead by seeing what’s waiting for you in Gmail and Google Calendar.

Latest news – ​Read More

I was skeptical of this minimalist wallet, but this genius feature sold me

The Ridge Wallet lineup just became a lot more customizable.

Latest news – ​Read More

You can try Google’s new Gemini 3 Flash AI model today for free – it’s even in Search’s AI Mode

Designed to balance speed with power, the new model will bring a boost to many of the AI perks that Gemini users have already come to expect, like vibe coding and multimodality.

Latest news – ​Read More