SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack
DEC 12, 20256 MIN
SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack
DEC 12, 20256 MIN
Description
<br/>
Using AI Gemma 3 Locally with a Single CPU<br/>
Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise<br/>
<a href="https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556">https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556</a><br/>
Mystery Google Chrome 0-Day Vulnerability<br/>
Google released an update for Google Chrome fixing a vulnerability that is already being exploited, but has not CVE number assigned to it yet<br/>
<a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html</a><br/>
SOAPwn: Pwning NET Framework Applications Through HTTP Client Proxies And WSDL<br/>
Watchtwr identified a common vulnerability in SOAP implementations using .Net<br/>
<a href="https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/">https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/</a><br/>