news.mlab.sh
50 results
vulnerability

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

A security researcher discovered two separate root remote code execution (RCE) vulnerabilities in Unitree's G1 and G1 EDU humanoid robots. One vulnerability, accessible via Bluetooth, allows attackers to gain root access without pairing, while the other involves a network-adjacent path. Unitree has addressed the cloud…

The Hacker News · 2d ago High
vulnerability

Johnson Controls Inc. TL280

A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly…

CISA Advisories · Aug 6, 2026 Critical
vulnerability

Acrisure KARR BT and DR-100

A critical vulnerability has been identified in Acrisure KARR BT and DR-100 automotive anti-theft systems, allowing an attacker within Bluetooth range to potentially control vehicle functions, including door unlocking an…

CISA Advisories · Aug 4, 2026 Critical
vulnerability

Long-Lived Vulnerability in Microsoft Secure Boot

A fundamental flaw in Microsoft's Secure Boot, a long-standing security feature designed to protect devices from firmware attacks, has been discovered and has existed for nearly 14 years. Researchers found that old, unsi…

Schneier on Security · Jul 29, 2026 High