The Week in 60 Seconds
Security & Exploitation
Manic Android malware analysis
What happened
ThreatFabric’s Mobile Threat Intelligence team identified Manic, an Android malware active in the wild since at least February 2026 and still under development as of July. [5]
Manic combines banking fraud and spyware, targeting 169 Android applications across banking, payments, government and identity services, cryptocurrency, messaging, browsers, email and 2FA. [5]
Why it matters
The malware provides attackers with WebRTC-based remote screen viewing and interaction, can conceal activity with black or fake screens and messages, and can remove itself from the app launcher while remaining activatable through a wrapper or deep link. [5]
GeoServer vulnerability probing
What happened
GeoServer’s jsonArrayContains functionality has a publicly disclosed, unpatched zero-day enabling unauthorised SQL injection; it has not yet received a CVE identifier. [2]
Under some configurations, particularly when GeoServer can reach a privileged database account, the SQL-injection path may lead to remote code execution. [2]
Why it matters
Within hours of disclosure, WatchTowr observed hundreds of exploitation attempts from a small number of IP addresses; the source reports probing but no observed follow-up activity yet. [2]
AI & Agent Security
Microsoft Copilot security-boundary research
What happened
Varonis Threat Labs reported a Microsoft Copilot Personal vulnerability named CoSnitch to Microsoft in December 2025; the source says Microsoft planned a patch and CVE identification, but had not responded before publication. [6]
The flaw involved Copilot disclosing technical details during repeated questioning about why automatic prompt execution was impossible, including an undocumented autorun=1 parameter and the session conditions needed to use it. [6]
Why it matters
Depending on the prompt, the attack could expose session context, messages, emails, connected applications and memory, including through OAuth-connected Gmail, Google Drive and Google Calendar. [6]
LLMs and contextual integrity research
What happened
CIMemories evaluates whether LLMs control information flow from persistent memory according to task context, using synthetic user profiles with more than 100 attributes and diverse tasks. [7]
The CIMemories evaluation reports up to 69% attribute-level violations, with lower violation rates sometimes accompanied by reduced task utility. [7]
Why it matters
In the reported GPT-5 results, violations increased from 0.1% after one task to 9.6% after 40 tasks, and reached 25.1% when the same prompt was run five times; the source characterizes the behavior as arbitrary and unstable. [7]
Federal warning on AI-assisted infrastructure attacks
What happened
U.S. agencies warned that attackers are targeting Siemens S7 Series PLCs in water, food, energy, chemical, manufacturing and commercial facilities, using AI in the attacks. [8]
The agencies characterized the attacks as an active threat and said they could disrupt industrial processes, cause safety incidents or compromise sensitive data. [8]
Why it matters
The alert says threat actors use Internet scanning services to find Internet-exposed PLCs running outdated software or otherwise poorly protected, then use AI-generated exploitation scripts disguised as legitimate monitoring tools. [8]
Cloud & Platform
Dependabot malware-alert coverage expansion
What happened
GitHub’s Dependabot malware alerts previously monitored npm data alone, according to the source. [4]
The source states that Dependabot malware alerts were expanded to cover eight ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer in addition to npm. [4]
Why it matters
Before the change, the source says users pulling malicious packages from the other named ecosystems received no warning from GitHub’s malware detection. [4]
SAP Commerce Cloud exploitation reporting
What happened
CVE-2026-58231 affects SAP Commerce Cloud, has a CVSS score of 10.0, and was reportedly under active exploitation days after SAP released a patch. [1]
The vulnerability involves insufficient authorization checks and input validation; an unauthenticated attacker can abuse a default authentication client and submit crafted input to vulnerable functions. [1]
Why it matters
Successful exploitation could enable arbitrary code execution and compromise internal application components, with high potential impact to confidentiality, integrity, and availability. [1]
Policy & Industry
Apollo breach disclosure
What happened
Apollo said attackers obtained unauthorized access to some of its cloud platforms from July 6 to July 10 in a social-engineering attack affecting financial institutions. [3]
Apollo determined on Aug. 12 that compromised personal data included names, dates of birth, contact information, home addresses, and Social Security numbers. [3]
Why it matters
Apollo said it had not found evidence that the compromised data was posted online or used for identity theft or fraud, but it did not disclose how many people were affected. [3]