PTIR — Daily Briefing — 2026-10-07
by
Executive Summary
Today’s first move is a dependency check, not a blanket emergency: Java and Kotlin projects that resolve Bouncy Castle should move to 1.86. The release fixes thirteen disclosed vulnerabilities across MLS, OpenPGP, CMS, PKIX, password-based key derivation, and post-quantum implementations.
For a short, bounded build experiment, Google’s open-source Agent Development Kit for Kotlin 1.0 is now a credible candidate. It reaches feature parity with ADK 1.0 Core, uses Kotlin Symbol Processing for type-safe tools, and adds Android-oriented local-model, persistence, and human-confirmation components.
Action Queue
1. Audit Java and Kotlin dependency graphs for Bouncy Castle
Bouncy Castle Java 1.86 fixes thirteen CVEs, including CVE-2026-71885, where an MLS X.509 credential was not bound to the LeafNode signature key. Other corrections cover OpenPGP certification and truncation handling, CMS authenticated attributes and key-size validation, X.509 name constraints, unbounded password-KDF parameters, and timing leaks in NTRU and HQC.
Action: Search Gradle, Maven, application SBOMs, and transitive dependency trees for org.bouncycastle. If present, confirm that the resolved version is 1.86 or a vendor-supported release containing the relevant fixes; then run interoperability and signature/encryption regression tests before deployment.
- Urgency: Immediate when Bouncy Castle is present
- Importance: ★★★★★
- Verified active: October 7, 2026
- Deadline: No fixed deadline
- Cost: Free and open source; commercial support is separate
- Requirements: A Java or Kotlin project, build dependency report or SBOM, and normal cryptographic regression tests
- Official release and download: Bouncy Castle Java 1.86
2. Run a synthetic-data ADK for Kotlin experiment

Google released ADK for Kotlin 1.0 as a production-ready open-source agent framework for Kotlin/JVM, Kotlin Multiplatform, and Android. Core features include hierarchical agents, resumable sessions, context compaction, skills, long-running tools, and human-in-the-loop confirmation. Android extensions add Room and AppSearch persistence plus on-device inference through LiteRT-LM and ML Kit; Google labels the ML Kit artifact beta.
Action: Build one read-only agent against synthetic data and measure setup friction, model cost, traceability, and whether confirmation gates really contain consequential tool calls. Keep API keys out of mobile binaries, and do not treat “production-ready framework” as proof that an application built with it is production-safe.
- Urgency: This week
- Importance: ★★★★☆
- Verified active: October 7, 2026
- Deadline: No deadline
- Cost: Framework is free and open source; model, Firebase, Vertex AI, Cloud Run, or other hosting usage may incur separate charges
- Requirements: JDK/Kotlin build environment; a model provider and credentials for cloud inference, or compatible on-device hardware and model support
- Official announcement and setup: Google Developers Blog: ADK for Kotlin 1.0
- Official documentation: Agent Development Kit
PKb Candidates
Agent frameworks need two separate readiness judgments
A framework can be stable while a particular agent remains unsafe. Evaluate the framework’s release maturity separately from the application’s permissions, model behavior, data handling, observability, rollback path, and human-confirmation design.
Cryptographic libraries deserve transitive-dependency visibility
Applications may inherit Bouncy Castle without declaring it directly. Preserve an SBOM or repeatable dependency-tree check so cryptographic patch decisions are based on the resolved runtime artifact rather than only top-level build files.
tags: Java - Kotlin - cybersecurity - Bouncy Castle - AI agents - local AI - open source