RobotsOct 1

Image: The Threshold Report/GPT Image 2.5
VicOne demonstrates robot manipulation through visual, audio and control inputs
VicOne LAB R7 redirected a Gemma 4 E4B-powered robot dog with poster text and changed a Nemotron-based hospital robot's behavior with crafted inaudible audio in simulation. At a robotics bug-bounty event, its researchers also injected a ROS 2/DDS message (a message sent through robot-control software) that moved a robot organizers expected to remain still under a safe-control setting. VicOne says protective functions can operate as designed and still make the wrong decision when their inputs are manipulated, so independent safeguards also need adversarial testing (tests that deliberately try to defeat them). The hospital result was simulated, and separately cited research on sound attacks against gyroscopes (motion sensors) involved drones; it did not demonstrate a humanoid falling.
Positive - VicOne's controlled tests exposed ways crafted inputs can override intended robot behavior, giving defenders concrete failures to address.
TextSep 30

Image: The Threshold Report/GPT Image 2.5
Google tracks rising exploitation and code-execution-heavy AI discoveries
Among the flaws Google's Threat Intelligence Group identified as AI-discovered, 50% allowed remote code execution (meaning attackers could run code on affected systems), compared with 26% in the broader dataset; the team tracked more than 1,500 AI-system flaw disclosures from January through August 2026. Observed exploitation averaged 18 vulnerabilities per month in 2026, up from 10.5 in 2025, while exploited zero-days (flaws attacked before fixes were available) rose from eight to eleven per month. GTIG favors prioritizing patches by risk and says the broader increase was concentrated in already-disclosed flaws, without claiming AI caused every additional attack. Attackers exploited the Hacktron AI-discovered BeyondTrust flaw CVE-2026-1731 within four days of public disclosure, followed by five additional clusters of threat activity within seven days.
Negative - Google documented exploitation rising to 18 vulnerabilities a month, showing attackers turning more security flaws into working attacks in the wild.