Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.

Security researchers have uncovered widespread vulnerabilities in children's smartwatches and GPS-enabled car accessories, revealing that tens of millions of devices from numerous brands rely on a small number of insecure backend platforms, primarily based in Shenzhen, China. The flaws allow for surreptitious tracking, eavesdropping, and potential manipulation of these devices.
During a demonstration, researchers Vangelis Stykas and Felipe Solferini successfully tracked and monitored a reporter using a low-cost child's smartwatch. Despite a malfunctioning GPS feature, the device continuously transmitted Wi-Fi network identifiers, enabling precise location tracking. The researchers then remotely activated the watch's camera to capture photos as the reporter entered an elevator and sat at a desk. They also used the microphone to pick up audio, all without any indication on the watch itself that it was being accessed.
The smartwatch used in the demonstration was manufactured by YiQingTeng Electronics and sold under the brand CJC. It operates on the SETracker platform, which Stykas and Solferini identified as one of three major supply chains for GPS-enabled devices. Their analysis of over 70 such gadgets revealed that more than 30 brands of smartwatches and car trackers use the SETracker platform (also associated with Wonlex and Shenzhen 3G Electronics), while another 30-plus brands rely on the NewGPS2012 platform. A third significant platform, SinoTrack, also sells car trackers and smartwatches.
All three platforms were found to have significant security deficiencies. These vulnerabilities, in some cases as simple as a lack of authentication, could allow unauthorized access to devices. Specific risks identified include tracking a child's location, disabling or spoofing location data, intercepting and spoofing text and audio messages, replacing emergency contacts, silent audio eavesdropping, and capturing photos or videos from camera-equipped devices. For car accessories, the researchers noted the potential to track locations or spoof messages that could unlock or disable vehicles, though they did not test these capabilities on actual cars. Server-side vulnerabilities were also discovered, exposing consumer information and potentially allowing for remote code execution. One instance even suggested prior unauthorized access to a system's backend.
The researchers have been attempting to notify the companies behind these platforms for months. A representative for SETracker initially claimed the issues had been resolved but later stated that certain ports on their servers used by a "legacy" version of client systems had been blocked, forcing a "small subset of clients" to upgrade to protect "a small number of devices." SETracker confirmed that "the vulnerability has now been thoroughly remediated." However, SinoTrack and NewGPS2012 did not respond to inquiries, and the researchers indicated that their hacking techniques against those systems still appeared to be effective.
Stykas and Solferini emphasized that the apparent diversity of GPS devices on the market is largely an illusion, as many different consumer brands funnel data to the same vulnerable backend servers. They noted that a vulnerability in one backend can simultaneously affect dozens of consumer brands, making it difficult for consumers to identify which backend their product uses. For example, a "SafeKid" watch in Sweden and a "SaveFamily" watch in Spain might both send a child's location data to the same vulnerable myaqsh.com backend on Alibaba Cloud in mainland China. The researchers plan to present their full findings at the Black Hat cybersecurity conference.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.