Skip to content

2025

On the Malicious NuGet Packages Containing Logic Bombs

Siemens is aware of the following nine malicious NuGet packages reported recently by Socket researchers. 

  • MyDbRepository (Last updated on May 13, 2023), 
  • MCDbRepository (Last updated on June 5, 2024), 
  • Sharp7Extend (Last updated on August 14, 2024), 
  • SqlDbRepository (Last updated on October 24, 2024), 
  • SqlRepository (Last updated on October 25, 2024), 
  • SqlUnicornCoreTest (Last updated on October 26, 2024), 
  • SqlUnicornCore (Last updated on October 26, 2024), 
  • SqlUnicorn.Core (Last updated on October 27, 2024), and 
  • SqlLiteRepository (Last updated on October 28, 2024)

Introduction of "Known Not Affected Products" in Siemens Security Advisories

Last year's improvements in Siemens Security Advisories, where we introduced the ability to describe a product-specific impact to a vulnerability, raised the next logical and expected question: "...but what if a product is not impacted at all by that vulnerability?"

Starting with Advisory Day in June 2025 we're excited to introduce the support of "Known not affected products" in both human-readable HTML advisories, and machine-readable CSAF documents.