FeeTech's STS3215 servo has factory-default ID=1, making it impossible to distinguish multiple servos on a daisy-chained bus. Engineers discovered a race condition vulnerability that allows selective targeting of individual servos, enabling ID assignment without disconnection. They developed utilities for servo diagnostics, repair, and rapid recalibration during arm assembly.
Google confirmed that a critical modem vulnerability in Pixel phones was exploited in limited, targeted cyberattacks before being patched in the September 2026 Android 17 QPR1 update. The zero-click flaw could allow attackers to bypass Android security protections and access sensitive data without user interaction. Google has not disclosed which Pixel models were affected or the number of users targeted.
A long-time personal website owner reflects on how maintaining a self-hosted site has become increasingly difficult due to security vulnerabilities, AI-driven attacks, and bot scraping, despite initially advocating for personal websites as a technical endeavor worth the effort.
Researchers demonstrate that large language models using the Model Context Protocol for tool-calling are vulnerable to cross-channel fragmentation attacks, where malicious payloads distributed across multiple input channels can bypass single-channel defenses and achieve credential exfiltration at rates up to 100% in frontier models. Existing security tools and prompt-based defenses failed to detect these attacks.
Shodan has indexed over 47,000 exposed Ollama instances without authentication, allowing attackers to run prompts, steal models, and exploit vulnerabilities on systems including cloud GPUs.
A frustrated software engineer critiques the pervasive influence of AI in the industry, arguing that despite massive investment in AI-assisted vulnerability research by major companies, the findings have not meaningfully improved security because the real bottleneck remains patching and deployment, not vulnerability discovery. The post condemns AI companies for ethical failures including IP exploitation, CSAM generation, and military applications while lamenting how AI has degraded communication quality and work satisfaction across tech culture.
Google Pixel phones have been compromised in zero-click attacks, according to security reports. The vulnerability allows attackers to gain access without requiring user interaction. This represents a significant security concern for the Android device line.
Security firm Calif discovered WeWorm, a zero-click worm exploiting a WeChat VoIP vulnerability that could have compromised over a billion accounts across Android and iOS devices without user interaction. Tencent patched the flaw in August after Calif reported it in July, and all users are now safe. Calif's AI system identified and developed the exploit in just nine days.
At GISEC, a major AI and cybersecurity conference, attendees highlighted industry concerns about malicious code in AI assistants and supply chain vulnerabilities. Google Cloud Security and Microsoft presented security approaches involving agent approval systems and scanning, which align with eyebrowcc's artifact inventory and control mechanisms designed to prevent unauthorized agent actions in Web2 and Web3 environments.
Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in Google's September 2026 security update, which addressed over 200 vulnerabilities total.
Google patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem that shows signs of limited targeted exploitation. The vulnerability allows remote privilege escalation without user interaction and can be exploited in zero-click attacks. Google also released patches for 109 other security flaws in September 2026, with CISA adding the modem flaw to its Known Exploited Vulnerabilities catalog.
Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in September 2026 security update and CISA designated it a known exploited vulnerability used in targeted attacks.
Fourteen AI models were tested against a security defense system called Divert in a controlled environment containing a real customer website, two applications with root code execution vulnerabilities, and five deception mazes. All fourteen models were detected and designated as threats by Divert before or concurrent with achieving code execution, demonstrating that the system can identify malicious behavior even when traditional security gaps exist.
ChainGPT discusses how automated triage systems for smart contract auditing create security vulnerabilities, as code flagged as low-risk bypasses human review. The platform offers an auditing service with formal verification to address this gap.
Google patched a zero-day vulnerability in Pixel smartphones' modem software (CVE-2026-58704) that was exploited in targeted attacks. The bug allowed privilege escalation without user interaction, potentially giving attackers access to phone data. Google did not identify the attackers, though surveillance vendors and spyware makers are common exploiters of such vulnerabilities.
PS5 Linux developer TheFloW quit his project after a hypervisor vulnerability he had kept private was independently discovered and reported to Sony by another researcher. Nguyen had planned to preserve the bug until after GTA 6's release to allow users to run Linux on PS5, but the disclosure ended his plans for PS5 Pro support in 2027. The project remains available under GPL 3.0 for other developers to continue.
A sandbox escape vulnerability in Claude Code allowed untrusted repositories to execute commands on macOS outside the sandbox without permission prompts by exploiting git's core.fsmonitor configuration setting. Anthropic patched the issue in version 2.1.247 by blanking the core.fsmonitor value in all harness git commands.
DeepSeek V4.1 Flash achieved perfect results on an AI hacking benchmark, gaining code execution on all 11 vulnerable targets while keeping four fixed targets secure, completing the full attack run for $4.65 by leveraging cached tokens. The model demonstrated strong exploitation abilities across Grafana, Jenkins, and Nextcloud, finding both intended attack paths and alternative routes to achieve code execution.