“Hardcoded credential” — 11 distilled results

Wave of cybersecurity vulnerabilities disclosed across platforms

Between August 6 and August 20, 2026, multiple critical security flaws were disclosed: the Clop extortion group exploited CVE-2026-12569 in PTC Windchill to steal engineering data; Microsoft patched CVE-2026-24301 affecting Copilot Personal; and a high-severity vulnerability (CVE-2026-0075) in Android's ContactsProvider was made public, affecting Android versions 14–16.

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.

Tech firms launch coalition against AI cyberattacks

OpenAI led an open letter signed by more than 100 organizations, including Anthropic, Microsoft, Google, Amazon, and others, on August 27–29, 2026, calling for coordinated defense against rising AI-enabled cyberattacks. Nvidia's new safety platform received cautious praise by November 2026, with experts noting no single solution exists to AI security risks.