1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack https://www. esecurityplanet.com/threats/ne ws-android-apps-hardcoded-secrets-credential-scanning/
8M Android APKs Scanned for Hardcoded Secrets in Automated Attack https://www.
8M Android APKs Scanned for Hardcoded Secrets in Automated Attack https://www.
CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog on July 29, citing active exploitation. The high-severity flaw in Cisco Secure Firewall Management Center allows unauthenticated remote login via hardcoded credentials embedded in the web interface, affecting versions 7.0 through 10.0.
Between August 6 and August 20, 2026, multiple critical security flaws were disclosed: the Clop extortion group exploited CVE-2026-12569 in PTC Windchill to steal engineering data; Microsoft patched CVE-2026-24301 affecting Copilot Personal; and a high-severity vulnerability (CVE-2026-0075) in Android's ContactsProvider was made public, affecting Android versions 14–16.
Between August 25–27, 2026, five major software projects released patches for critical remote code execution and authentication vulnerabilities affecting GitPython, JSONata, Zscaler, LazyOwn, Veeam, and Apache Tomcat. Each vulnerability allowed attackers to execute arbitrary code or bypass authentication controls.
21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.
OpenAI led an open letter signed by more than 100 organizations, including Anthropic, Microsoft, Google, Amazon, and others, on August 27–29, 2026, calling for coordinated defense against rising AI-enabled cyberattacks. Nvidia's new safety platform received cautious praise by November 2026, with experts noting no single solution exists to AI security risks.
Cluster mixes Fairphone Linux phone charging, Middle East defense pact, DOE nuclear projects, and RDP honeypot data with no single story. Reports span consumer hardware, international security, energy policy, and cybersecurity intelligence.
Security researchers at VulnCheck disclosed on August 28, 2026, multiple undocumented factory-installed surveillance implants in firmware for ZBT routers manufactured by Shenzhen Zhibotong Electronics, potentially allowing unauthenticated root access to devices sold worldwide.