Researchers from the University of Birmingham and Fuzzware discovered that nine out of 26 tested devices, including several Quectel cellular modules and specific OPPO and ASUS phone models, were susceptible to use of the RUN AT command.
VulnCheck CTO Jacob Baines claims that Zbtlink routers are intentionally designed to communicate with command and control servers, a feature he calls a "phone-home trojan horse."
Cyber Insider disclosed that a popular Wansview indoor security camera model, the WVC Q5, was found to be shipping with a web server vulnerable to a flaw first identified over 20 years ago.
In the news this week: InfraTrust and knowing what to patch, Adversary in the middle triggered command injection, Exploitarium again, FreeRDP comes with free vulnerabilities, AI breaking out of sandboxes on its own, Wordpress RCE, DMA dangers, Nightmware eclypse is at it again, Fortisandbox, Turning AI to the dark side, more prompt injection, Secur...
The LG Monitor App Installer, identified by YouTube channel Gamers Nexus, installs automatically when a compatible LG monitor is connected to a Windows PC.
A researcher, known as tokay0, detailed how a flawed policy attached to a certificate on Shark RV2320EDUS robot vacuums enables attackers to execute root commands on other Shark vacuums.