“Authentik” — 12 distilled results

Multiple software vulnerabilities disclosed

Six distinct command injection, file inclusion, and authentication bypass vulnerabilities were disclosed between September 24–26, 2026, affecting Frictionless, Cambium, Lantronix, WordPress Visual Composer, Netis routers, and Netlink routers. Each report describes a separate product flaw with no common thread beyond being security exploits.

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.