Google is enhancing the security of its Pixel devices by integrating a memory-safe Rust-based DNS parser into the cellular modem firmware. This move aims to mitigate memory-safety vulnerabilities, a significant risk in the complex and remotely attackable modem code. The company hopes this initiative will encourage the wider adoption of memory-safe languages in low-level system programming.

Google is implementing a new security measure for its Pixel smartphones by introducing a DNS parser written in the Rust programming language into the firmware of the cellular modem. This development is part of an ongoing effort to bolster the security posture of the devices, particularly in areas prone to complex vulnerabilities.
The cellular modem, often referred to as the baseband processor, handles all cellular communication for a device. This component is a critical piece of infrastructure, but its firmware is typically written in languages like C, which are susceptible to memory-safety issues. Such issues can lead to exploitable vulnerabilities that attackers could leverage to compromise the device remotely.
By replacing a portion of the modem's code with a parser written in Rust, Google aims to address these memory-safety risks. Rust is designed with memory safety as a core feature, aiming to prevent common programming errors that lead to security flaws, such as buffer overflows and use-after-free bugs, without the need for a garbage collector.
The DNS parser is a component responsible for handling the Domain Name System requests that are essential for cellular connectivity. It translates human-readable domain names into IP addresses that devices use to connect to networks and services. Given its role in network communication, this parser is a potential target for attackers.
Google's initiative to integrate Rust into the baseband firmware signifies a broader strategic goal. The company intends for this project to serve as a catalyst, encouraging other developers and organizations to adopt memory-safe languages for low-level system programming tasks. This shift could lead to more robust and secure software across various critical systems.
The complexity of modem firmware, coupled with its direct exposure to potentially untrusted network inputs, makes it a particularly challenging area for security. Memory-safety vulnerabilities in this context can have severe consequences, potentially allowing attackers to gain control over a device's communication capabilities or even the device itself.
The use of Rust in this sensitive area demonstrates a proactive approach to security by Google. By leveraging a language that inherently mitigates a class of common and dangerous vulnerabilities, the company is building a more resilient foundation for its Pixel devices.
This move aligns with a growing trend in the cybersecurity community to move away from memory-unsafe languages in critical infrastructure. The successful implementation and potential expansion of this Rust-based component could pave the way for similar security enhancements in other hardware and software components.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed