OpenAI will provide Ukraine's government with free access to its Daybreak AI cyber defence system, aimed at protecting civilian infrastructure such as hospitals and power plants from cyber-attacks. The deal also gives Ukraine access to OpenAI's GPT 5.6 Sol model, and comes after CERT-UA recorded nearly 6,000 cyber-attacks against the country in 2025.
bbc.co.uk
· 2026-09-23
CERT/CC disclosed that Skullcandy Dime 3 earbuds running firmware 1.0.0.28 accept Bluetooth pairing from nearby devices without any user approval, due to a flaw in the Airoha Bluetooth Audio SDK tracked as CVE-2025-20701. Skullcandy has released firmware 1.0.0.30 to fix the bug, but there is no way for users to update their earbuds manually or through the companion app.
bleepingcomputer.com
· 2026-09-09
Attackers are combining two newly disclosed MikroTik RouterOS vulnerabilities, an SSH authentication bypass (CVE-2026-67276) and a privilege escalation bug (CVE-2026-86060), to seize full control of routers with SSH exposed to the internet. Poland's CERT, which found the flaws with AI assistance, calls the combined exploit 'MikroTrick' and confirms it is being used in real-world attacks. MikroTik patched the issues in RouterOS versions released September 3, alongside a related bandwidth-test flaw that can leak memory or crash devices.
bleepingcomputer.com
· 2026-09-07
Researcher Brian Khan Quintana found that Calix's GS5239XG (GigaSpire 7u10txg) fiber gateway exposes its UPnP control service on the public WAN interface without authentication, tracked as CVE-2026-75501. Anyone online can send a single unauthenticated request to add or remove port-forwarding rules, letting them bypass NAT and firewall protections. Calix did not respond to disclosure attempts, so CERT/CC coordinated a public release of the details.
bleepingcomputer.com
· 2026-08-24