CuraSec

tag: Embedded · 2 items

2026-08-28 · The Hacker News · source ↗ #rce#iot-security#embedded
  • Engineer — Plan: If your environment uses Unitree G1 EDU robots, review network segmentation and disable unnecessary BLE/network services; no KEV listing and near-zero EPSS suggest limited active exploitation pressure, but public PoCs exist so schedule patching.
  • SOC/IR — Skip
  • Leader — Skip
  • Signals: CVE-2026-76639 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub · CVE-2026-76640 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
2026-07-13 · arXiv cs.CR · source ↗ #iot-security#cryptography#embedded
  • Engineer — Learn: Solid research demonstrating that ESP32 WDEV output is pseudorandom when RF is disabled yet passes statistical tests — a reminder that output testing is insufficient for source-state validation. Worth reviewing if your team ships ESP32-based IoT products; no patch or CVE to act on yet.
  • SOC/IR — Skip
  • Leader — Skip