LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
vulnerability

Hackers Stalked Me by Hijacking a Smartwatch for Kids

Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.

zeroday.news ·

Security researchers have uncovered widespread vulnerabilities in children's smartwatches and GPS-enabled car accessories, revealing that tens of millions of devices from numerous brands rely on a small number of insecure backend platforms, primarily based in Shenzhen, China. The flaws allow for surreptitious tracking, eavesdropping, and potential manipulation of these devices.

During a demonstration, researchers Vangelis Stykas and Felipe Solferini successfully tracked and monitored a reporter using a low-cost child's smartwatch. Despite a malfunctioning GPS feature, the device continuously transmitted Wi-Fi network identifiers, enabling precise location tracking. The researchers then remotely activated the watch's camera to capture photos as the reporter entered an elevator and sat at a desk. They also used the microphone to pick up audio, all without any indication on the watch itself that it was being accessed.

The smartwatch used in the demonstration was manufactured by YiQingTeng Electronics and sold under the brand CJC. It operates on the SETracker platform, which Stykas and Solferini identified as one of three major supply chains for GPS-enabled devices. Their analysis of over 70 such gadgets revealed that more than 30 brands of smartwatches and car trackers use the SETracker platform (also associated with Wonlex and Shenzhen 3G Electronics), while another 30-plus brands rely on the NewGPS2012 platform. A third significant platform, SinoTrack, also sells car trackers and smartwatches.

All three platforms were found to have significant security deficiencies. These vulnerabilities, in some cases as simple as a lack of authentication, could allow unauthorized access to devices. Specific risks identified include tracking a child's location, disabling or spoofing location data, intercepting and spoofing text and audio messages, replacing emergency contacts, silent audio eavesdropping, and capturing photos or videos from camera-equipped devices. For car accessories, the researchers noted the potential to track locations or spoof messages that could unlock or disable vehicles, though they did not test these capabilities on actual cars. Server-side vulnerabilities were also discovered, exposing consumer information and potentially allowing for remote code execution. One instance even suggested prior unauthorized access to a system's backend.

The researchers have been attempting to notify the companies behind these platforms for months. A representative for SETracker initially claimed the issues had been resolved but later stated that certain ports on their servers used by a "legacy" version of client systems had been blocked, forcing a "small subset of clients" to upgrade to protect "a small number of devices." SETracker confirmed that "the vulnerability has now been thoroughly remediated." However, SinoTrack and NewGPS2012 did not respond to inquiries, and the researchers indicated that their hacking techniques against those systems still appeared to be effective.

Stykas and Solferini emphasized that the apparent diversity of GPS devices on the market is largely an illusion, as many different consumer brands funnel data to the same vulnerable backend servers. They noted that a vulnerability in one backend can simultaneously affect dozens of consumer brands, making it difficult for consumers to identify which backend their product uses. For example, a "SafeKid" watch in Sweden and a "SaveFamily" watch in Spain might both send a child's location data to the same vulnerable myaqsh.com backend on Alibaba Cloud in mainland China. The researchers plan to present their full findings at the Black Hat cybersecurity conference.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.