DAILY BRIEFING
Hackers now exploit critical Roundcube flaw in code injection attacks
Today's briefing covers an Android spyware campaign targeting logistics firms and report findings showing AI-assisted code leaks credentials at higher rates.
5 stories2 min read

Threat actors are increasingly focusing on specialized sectors using custom Android spyware while automated development workflows introduce unexpected security risks. Logistics companies face direct threat activity through deceptive distribution channels masquerading as legitimate logistics platforms.
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
A campaign targeting logistics firms uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android spyware APK named com.corp.mdm. The implant exfiltrates incoming SMS content, redirects phone calls, and maintains a hidden foreground service, likely built using AI tooling.
- Why it matters
- Logistics companies relying on Android devices face risks of unauthorized call redirection, SMS interlock, and multi-vector campaigns using credential phishing alongside Windows malware.
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
GitGuardian's 2026 State of Secrets Sprawl Report indicates that AI-assisted code commits leak credentials at nearly double the rate of human-written code. Autonomous AI coding agents accelerate secrets sprawl by hardcoding and spreading service credentials across multiple configuration files.
- Why it matters
- Organizations adopting AI development tools risk rapid credential leaks, exposing API keys and AI service credentials directly into public or internal repositories.
Hackers now exploit critical Roundcube flaw in code injection attacks
Bleeping Computer was unable to serve story content due to Cloudflare anti-bot security verification protections.
Windows 11 KB5124010 update released with 46 changes and fixes
Bleeping Computer was unable to serve story content due to Cloudflare anti-bot security verification protections.
CISA: Ransomware gangs now exploiting critical TeamCity flaw
Bleeping Computer was unable to serve story content due to Cloudflare anti-bot security verification protections.
Key takeaways
- Logistics firms face targeted Android spyware named Corp MDM distributed through fake Google Play pages for CEVA and TKW Logistics.
- Corp MDM spyware uses package name com.corp.mdm to intercept incoming SMS messages and divert phone calls.
- GitGuardian report finds AI-assisted commits leak secrets at roughly twice the rate of human-written code.