
Unibleed Vulnerabilities in Humanoid Robots, Team PCP Arrests, and Meta Settlement
Hacker Oliver Laflamme released a write-up on August 27th detailing two CVEs affecting humanoid robots: CVE 2026-76639 and CVE 2026-76640, collectively called Unibleed. Both vulnerabilities enable remote code execution—the first exploits the robot's AI chatbot to write arbitrary files and access an unauthenticated connection bridge, while the second uses Bluetooth Low Energy to obtain AES keys that can be decrypted using any free Unitree cloud account without ownership verification. When combined, these CVEs create worm functionality that can spread to any robot within Bluetooth range. Unitree patched the cloud ownership issue and paid a $5,000 bounty, though confirmation of which firmware fixes the Bluetooth vulnerability remains unclear. Two members of Team PCP, a group linked to software supply chain attacks beginning in late 2025, were arrested through OSINT investigation that traced a unique cat image from a Steam account to a Team PCP Telegram account. The arrests resulted from collaboration between Australian Federal Police, FBI, and Western Australian Police Force, with the accused facing 14 offenses and up to 20 years in prison if convicted. Meta reached a settlement with California's Attorney General over a lawsuit alleging harmful features targeting teens, agreeing to pay up to $17 billion over 10 years with at least $1.5 billion to California, and implementing restrictions including time limits for users under 18 and default nighttime usage blocks.