Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch python python systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
⚠️ Overhyped vulnerability of the week: CVE severity inflation strikes with CVE-2025-13462.
The issue is a TAR parser discrepancy in Python's `tarfile` module, where a specially crafted archive may be interpreted differently than other TAR implementations.
While NVD scored this CVE as Critical (CVSS 9.8), the publicly disclosed impact includes:
❌ No RCE
❌ No arbitrary file write
❌ No "guaranteed" impact of any kind
Furthermore, the CVE received a LOW severity rating in Python's original advisory.
The only realistic security impact is in systems that mix using Python's TAR parser with other TAR parsers, and make security decisions based on this parsing. This may lead to a validation vs. execution mismatch.
We believe that the advisory's low-severity rating is much more fitting in this case.
Post summary
The tweet argues that CVE‑2025‑13462 is a TAR parser discrepancy with no real impact such as RCE or file write, and that its critical CVSS score is inflated; it presents the issue as a debunked, low‑risk vulnerability.
🚨 New HIGH CVE detected in AWS Lambda 🚨
CVE-2025-13462 impacts python in 6 Lambda base images.
Details: https://github.com/aws/aws-lambda-base-images/issues/475
More: https://lambdawatchdog.com/
#AWS#Lambda#CVE#CloudSecurity#Serverless
Post summary
A newly identified high‑severity CVE (CVE‑2025‑13462) affecting Python in six AWS Lambda base images is disclosed with issue links, but no PoC, exploit, patch, or active exploitation details are provided.
🎙️ RadioCSIRT Ep.596 – Édition du vendredi 13 mars 2026
Cinq sujets. Un fil rouge : des Zero-Day activement exploités, des données sensibles exposées et le renforcement des capacités CSIRT en Afrique.
🔴 CISA KEV : trois nouvelles entrées en exploitation active. CVE-2026-3909 (Google Skia – Out-of-Bounds Write), CVE-2026-3910 (Google Chromium V8 – implémentation incorrecte), CVE-2025-68613 (n8n – exécution de code via ressources dynamiques).
🔴 Google Chrome : patch hors cycle en urgence. Deux Zero-Day corrigés, exploitables à distance via simple visite d'une page malveillante. Versions protégées : 146.0.7680.75/76 sur Windows et macOS, 146.0.7680.75 sur Linux.
🔴 CERT-FR : trois avis publiés ce vendredi. CERTFR-2026-AVI-0294 – CVE-2026-26133, atteinte à la confidentialité dans Microsoft Office sur Android, iOS et macOS. CERTFR-2026-AVI-0285 – CVE-2025-13462, vulnérabilité dans CPython, nature non précisée. CERTFR-2026-AVI-0289 – multiples failles dans le noyau Linux d'Ubuntu 22.04 LTS et 24.04 LTS, quatre CVE référencées.
🔴 Quittr : misconfiguration Firebase expose pendant plusieurs mois les données sensibles de plus de 600 000 utilisateurs d'une application de lutte contre la dépendance à la pornographie. Environ 100 000 profils de mineurs concernés. Alerte initiale ignorée depuis septembre 2025.
🔴 FIRST – African Regional Liaison : bilan deux ans. 1 210 professionnels soutenus, 50 initiatives, 33 pays, 70 CSIRTs engagés. Programme Train-the-Trainer actif dans sept pays africains.
🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct :
https://www.radiocsirt.org/podcast/ep-596-votre-actualite-cybersecurite-du-vendredi-13-mars-2026/
📌 On ne réfléchit pas, on patch !
#RadioCSIRT#Cybersécurité#ThreatIntelligence#CTI#CISA#KEV#Chrome#ZeroDay#Skia#V8#Chromium#Quittr#Firebase#DataLeak#DataBreach#MicrosoftOffice#Python#CPython#Ubuntu#Linux#CERTFR#FIRST#AfricaCyber#CSIRT#n8n#CVE#InfoSec#CERT#SOC#CISO#VOC#Patch
Post summary
Podcast covers three CISA KEV vulnerabilities actively exploited, recent out‑of‑cycle patches for Google Chrome, and data exposure incidents, emphasizing the urgency of patching.
CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUT… https://www.cve.org/CVERecord?id=CVE-2025-13462
Post summary
The post presents a brief technical disclosure of CVE‑2025‑13462, detailing an issue in Python’s tarfile module’s normalization process, with no PoC, exploit, or patch mentioned.