vulnerability Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth A security researcher discovered two separate root remote code execution (RCE) vulnerabilities in Unitree's G1 and G1 EDU humanoid robots. One vulnerability, accessible via Bluetooth, allows attackers to gain root access without pairing, while the other involves a network-adjacent path. Unitree has addressed the cloud… The Hacker News · 2d ago High CVE-2026-76639CVE-2026-76640roboticsrcebluetooth
threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
vulnerability Bendix EC80 Brake ECU A critical vulnerability exists in Bendix EC80 Brake ECU firmware, potentially allowing an attacker to disable ABS, steering assist, speedometer, and shifting capabilities, or inject malicious CAN bus traffic. Multiple f… CISA Advisories · 5d ago Critical CVE-2026-67560CVE-2026-68967CVE-2026-71396UNCAfirmwarebuffer overflowcan bus
threat-intel Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P Researchers at Hunt.io have uncovered a campaign targeting over 14,500 Dahua IP cameras, leveraging credential attacks and two authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) to gain unauthorize… The Hacker News · Aug 19, 2026 High CVE-2021-33044CVE-2021-33045CVE-2024-39943UKRUcredential attackauthentication bypassp2p
vulnerability Multiples vulnérabilités dans les produits Intel (12 août 2026) Multiple vulnerabilities have been discovered in Intel products, impacting a range of their processors. These vulnerabilities could lead to privilege escalation, data confidentiality breaches, and denial of service attac… CERT-FR · Aug 12, 2026 High intelvulnerabilitysecurity
vulnerability Mira Hormone Monitor, Mira Android App Multiple vulnerabilities in the Mira Hormone Monitor and Mira Android App allow an attacker to access unauthorized health profile information, make changes to health data, cause denial-of-service conditions, and potentia… CISA Advisories · Aug 11, 2026 High CVE-2026-66875CVE-2026-66098CVE-2026-67558bleauthenticationwebview
vulnerability Johnson Controls Inc. TL280 A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly… CISA Advisories · Aug 6, 2026 Critical CVE-2026-27871cwe-327firmwareics
threat-intel Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway A Chinese router vendor, Longchen, initially denied that its firmware contained backdoors, but subsequently paused downloads to address security concerns. This follows reports of potential vulnerabilities and a desire to… The Register · Aug 6, 2026 Medium CHUSsupply-chainrouterbackdoor
vulnerability Vulnérabilité dans Sonicwall SonicOS (06 août 2026) SonicWall has announced a vulnerability in its SonicOS firmware that allows attackers to bypass security policies. This affects a range of firewalls, including models from the Gen6, Gen7, and Gen8 series. The vulnerabili… CERT-FR · Aug 6, 2026 High CVE-2026-0516securityfirmwarepatch
vulnerability Acrisure KARR BT and DR-100 A critical vulnerability has been identified in Acrisure KARR BT and DR-100 automotive anti-theft systems, allowing an attacker within Bluetooth range to potentially control vehicle functions, including door unlocking an… CISA Advisories · Aug 4, 2026 Critical CVE-2026-18411USbluetoothfirmwarecwe-321
threat-intel Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen A popular Bitcoin hardware wallet manufacturer, Coinkite, destroyed its remaining inventory after a firmware vulnerability was exploited, leading to the theft of over $88 million in Bitcoin. The vulnerability, discovered… The Record · Aug 3, 2026 Critical bitcoinhardware walletfirmware
vulnerability Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes A flaw in Coldcard hardware wallets, manufactured by Coinkite, was exploited to steal $70 million in Bitcoin within 41 minutes. The vulnerability stems from a deterministic PRNG used during seed generation, allowing an a… The Hacker News · Aug 1, 2026 Critical hardware walletseed generationbitcoin
vulnerability Toptech Systems RCU II+ and Multiload II+ Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot… CISA Advisories · Jul 30, 2026 High CVE-2026-12562vulnerabilitycontrol systemsauthentication
vulnerability Watchfire Controller Software A critical vulnerability (CVE-2026-5846) exists in Watchfire Controller Software, allowing a malicious user to deliver malicious firmware and gain full control of the device. Multiple versions of the software are affecte… CISA Advisories · Jul 30, 2026 Critical CVE-2026-5846UNDOCAcve-2026-5846industrial control systemsfirmware
vulnerability Long-Lived Vulnerability in Microsoft Secure Boot A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsi… Schneier on Security · Jul 29, 2026 High firmwareshimuefi
threat-intel Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A collaborative research effort between Palo Alto Networks and Siemens has uncovered a critical, chained exploit within the Siemens ROX II operational technology (OT) switches. The vulnerability chain consists of three z… Palo Alto Unit 42 · Jul 17, 2026 Critical CVE-2025-40948CVE-2025-40947CVE-2025-40949otvulnerabilitycommand-injection
threat-intel Siemens SICAM 8 Siemens has released security advisories detailing multiple vulnerabilities in its SICAM 8 industrial control system firmware and related components. These vulnerabilities could allow an attacker to cause denial of servi… CISA Advisories · Jul 16, 2026 High CVE-2026-54798CVE-2026-54799CVE-2026-54800vulnerabilityfirmwareindustrial control systems
vulnerability Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix Several vulnerabilities exist in Rockwell Automation's CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. Successful exploitation could lead to a denial-of-service condition due to an invalid pro… CISA Advisories · Jul 16, 2026 High CVE-2025-12011CVE-2025-12012CVE-2025-11698firmwarecontrol-systemdenial-of-service
threat-intel Forgotten Bootloaders Expose Secure Boot Blind Spot Researchers discovered 11 vulnerable, but still trusted, UEFI shim bootloaders that could have been used to bypass Secure Boot on systems relying on Microsoft's third-party UEFI signing certificate. Despite being outdate… Dark Reading · Jul 15, 2026 High secure bootfirmwareuefi
threat-intel Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Researchers at Binarly discovered six new vulnerabilities in U-Boot, the firmware that starts up many hardware devices, including routers and servers. These flaws could allow attackers to execute malicious code at boot,… The Hacker News · Jul 10, 2026 High CVE-2026-33243firmwarebootloadervulnerability