Policy dependency / Stack layer
SGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four Weeks
CERT Coordination Center
Stack layer / Threat pattern
Benchmark Radar Ships a Daily-Updated Catalog of 1,283 AI Benchmarks With 12,916 Numeric Score Observations
arXiv 2609.11115
Stack layer / Threat pattern
A Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full Set
arXiv 2609.11814
Stack layer / Threat pattern
Snyk put its agent-skill scanner behind a free web page called Skill Inspector
Snyk Labs
Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Policy dependency / Stack layer
A replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policies
GitHub
Stack layer / Threat pattern
cfo.ai Renames the Whole Company After Its Agent and Abandons Accounting Software for a Virtual CFO
SiliconANGLE (corroborated by the cfo.ai PR Newswire release)
Stack layer / Threat pattern
Pattern: local, file-backed memory for coding agents is having a moment, and the good ones publish verdicts
GitHub