Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
2026-08-28T13:24:00Z•d9721edea129a7113f525c77a797d87f8f5b734be7734e35f8e4ebe5d9c17882
CVE-2019-1068CVE-2026-19912CVE-2026-19913CVE-2026-65643CVE-2026-74232CVE-2026-74233CVE-2026-75604CVE-2026-76639CVE-2026-76640active-exploitationai-securityaptcisa-kevcpanelcritical-infrastructureiot-securitykalturamalwarenextjspapercutphishingremote-code-executionrobotics-securityroot-accessroutersservicenowsupply-chain-securityvulnerabilitieszero-day
What happened
The Hacker News feed reports multiple major cybersecurity developments, including critical and actively exploited vulnerabilities enabling unauthenticated or root-level remote code execution in Unitree G1 EDU robots, ServiceNow AI Platform, ZBT routers, cPanel/WHM, Next.js, and Kaltura mwEmbed. It also covers an actively exploited PaperCut zero-day, CISA KEV additions, state-sponsored campaigns and malware, phishing-based Microsoft 365 session theft, supply-chain compromises, and emerging AI-agent security risks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d9721edea129a7113f525c77a797d87f8f5b734be7734e35f8e4ebe5d9c17882
- Enrichment time
- 2026-08-28T13:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.