Tag: firmware
-
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to silently pair with the earbuds, disrupt legitimate audio sessions, and potentially capture microphone audio. This issue, tracked as VU#859658 by the CERT Coordination Center, affects the Skullcandy Dime 3 earbuds (model S2DCW) running firmware version…
-
Your Storage Was Hardened Once. It Isn’t Anymore.
Configuration drift: the silent creator of security risk in storage and backup systems. Every storage and backup environment drifts. Firmware updates reset settings back to their defaults. Temporary changes made during an outage never get reverted. A vendor account created… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/your-storage-was-hardened-once-it-isnt-anymore/
-
Unibleed: Wenn ein Wurm ganze Armeen humanoider Roboter kapern kann
Ein Forscher hat die Firmware eines Unitree-Roboters auf Schwachstellen untersucht. Schadcode hätte wohl von Roboter zu Roboter springen können. First seen on golem.de Jump to article: www.golem.de/news/unibleed-wenn-ein-wurm-reihenweise-roboter-kompromittieren-kann-2609-212495.html
-
Hackers Exploiting Internet-Exposed OT, Warns UK NCSC
Industrial Operators Face Growing Risk From Directly Connected Control Devices. Britain’s NCSC warned that rising OT attack activity is making internet-exposed industrial systems an increasingly attractive entry point, as weak credentials, aging firmware and overlooked connections give threat actors simpler routes into operational networks. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hackers-exploiting-internet-exposed-ot-warns-uk-ncsc-a-32706
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices.The implants, named SPEAKINGSTONE and DARKLANTERN by the company’s zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233. First seen…
-
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilities could enable attackers to execute arbitrary operating system commands with root privileges. The security advisory, updated on August 24, 2026, pertains to the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices.…
-
Botnetz aus Autos: Fahrzeug-Infotainmentsysteme mit Malware infiziert
Forscher haben eine Android-Malware entdeckt, die über eine Firmware-Updatefunktion in Infotainmentsysteme von Fahrzeugen eingeschleust wurde. First seen on golem.de Jump to article: www.golem.de/news/botnetz-aus-autos-fahrzeug-infotainmentsysteme-mit-malware-infiziert-2608-212212.html
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…
-
D-Link DWR-M961 Router Hit by 15 Command Injection and Buffer Overflow Vulnerabilities
D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1. This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the device’s web management components. These vulnerabilities affect non-US DWR-M961 devices running firmware versions 1.1.2_C1_202602110044 and earlier revisions. D-Link DWR-M961 Router Flaw…
-
Beliebte Klimaanlage: Firmware-Lücke in Midea Portasplit ermöglicht Fernsteuerung
Tags: firmwareDie Midea Portasplit gehört derzeit zu den gefragtesten Klimaanlagen. Doch missgünstige Nachbarn könnten nach Belieben in die Steuerung eingreifen. First seen on golem.de Jump to article: www.golem.de/news/beliebte-klimaanlage-firmware-luecke-in-midea-portasplit-ermoeglicht-fernsteuerung-2608-212073.html
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
20 Flaws in Fertility Tracker Risked Data Loss, Fake Results
Mira Ultra 4 Fixes Vulnerabilities After University Team Hacked Bluetooth, Firmware. Multiple vulnerabilities identified in a popular at-home fertility tracking device could have allowed attackers to impersonate the device, manipulate hormone readings, access sensitive health information and reverse engineer production firmware, said the researchers who made the discovery. First seen on govinfosecurity.com Jump to article:…
-
Zbtlink denies backdoor claims amid firmware download pause
First seen on scworld.com Jump to article: www.scworld.com/brief/zbtlink-denies-backdoor-claims-amid-firmware-download-pause
-
Frontier AI Has a Cybersecurity Expertise Problem
First OpenAI’s model went rogue and broke out of testing containment to hack real systems, then Anthropic, and now Meta AI. Do you see a trend? Here is what it means: Although these frontier AI companies employ some of the world’s brightest engineers, architects, and developers, technical excellence is not the same as deep cybersecurity…
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to…
-
Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability. First seen on therecord.media Jump to article: therecord.media/bitcoin-theft-coldcard-cyberattack
-
COLDCARD-Schwachstelle: Für Bitcoin-Diebstahl von 88 Millionen Dollar verantwortlich?
Eine Schwachstelle in der Firmware der Hardware-Wallet COLDCARD steht mutmaßlich hinter dem Diebstahl von umgerechnet rund 88,6 Millionen US-Dollar in Bitcoin. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/coldcard-bitcoin-diebstahl
-
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a combined 1,082.65 BTC, valued at approximately $70.2 million, in just 41 minutes on July 30, 2026. Galaxy Research stated that its transaction-flow analysis was based on a pattern initially identified…
-
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/
-
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite.A March 2021 firmware integration error routed seed generation to a…
-
New usbliter8 SecureROM Exploit Enables iOS 27 Jailbreak on iPhone 11 Pro
A new developer-focused project, usbliter8-fun, showcases an iOS 27 jailbreak workflow specifically for the iPhone 11 Pro. It combines the usbliter8 SecureROM exploit with a custom firmware restoration process. This proof of concept targets Apple’s A13-based iPhone 11 Pro. It is labeled as experimental, destructive, and unsuitable for use on primary devices. New usbliter8 SecureROM…
-
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388,…
-
Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows
Yubico has released the YubiKey firmware version 5.85.85.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but…
-
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.”An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,” First seen on…
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181

