“Splunk” — 40 distilled results

Wave of cybersecurity vulnerabilities disclosed across platforms

Between August 6 and August 20, 2026, multiple critical security flaws were disclosed: the Clop extortion group exploited CVE-2026-12569 in PTC Windchill to steal engineering data; Microsoft patched CVE-2026-24301 affecting Copilot Personal; and a high-severity vulnerability (CVE-2026-0075) in Android's ContactsProvider was made public, affecting Android versions 14–16.

Multiple critical vulnerabilities published in CISA KEV catalog

CISA published six newly disclosed software vulnerabilities affecting LiteSpeed cPanel, Nx Console, TanStack, DD-WRT, Check Point SmartConsole, and Microsoft SharePoint, ranging from privilege escalation to remote code execution. These CVEs pose significant security risks to enterprise and open-source users.

json:cisa-kev 103d ago

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

21929v1 Announce Type: new Abstract: Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution.