Sunday , August 2 2026

10 New Vulnerabilities Discovered in MediaTek Chipsets

MediaTek has released its March 2025 Product Security Bulletin, which highlights new security vulnerabilities affecting various chipsets in smartphones, tablets, AIoT devices, smart displays, OTT hardware, computer vision platforms, audio systems, and smart TVs.

The bulletin reports 10 vulnerabilities, three of which are high severity. The high-severity ones could enable attackers to cause denial of service or escalate privileges.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

Three high-severity vulnerabilities have been identified: CVE-2025-20644, CVE-2025-20645, and CVE-2025-20646. Each poses unique risks.

CVE-2025-20644 (Modem – Denial of Service)
Certain versions of Modem software have a syntactic error that can lead to memory corruption and cause remote denial of service (DoS). In severe cases, an attacker could take control of a rogue base station and disconnect a device without the user being aware.

CVE-2025-20645 (KeyInstall – Escalation of Privilege)
Missing bounds checks in KeyInstall can result in out-of-bounds writes. Although an attacker needs System privileges for local privilege escalation, this can lead to unauthorized code execution, compromising core system protections.

CVE-2025-20646 (wlan AP FW – Remote Escalation of Privilege)
A vulnerability in WLAN firmware could allow remote privilege escalation through out-of-bounds writes without any user interaction. This poses a significant risk for Wi-Fi devices in both consumer and enterprise environments.

The bulletin highlights that several popular chipsets, including the MT67xx, MT68xx, and MT69xx series, as well as AIoT solutions, are affected. MediaTek supplied patches to device manufacturers two months before the announcement, allowing them to release over-the-air updates and include fixes in system patches.

Users should promptly update their devices with the latest security updates.

Qualcomm’s March 2025 Security Bulletin Highlights Major Vulns

Check Also

ASUS router

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could …