Policy dependency / Stack layer
CROSS-CATEGORY: On the Same Day, Anthropic Moved Into Documents and Decks While OpenAI Moved Into Ad Sales, CRM and Ecommerce
The Next Web and Search Engine Land (two independent same-day writeups of two separate primary announcements)
Stack layer / Threat pattern
AFL++ fuzzed agent-written reimplementations of ten Linux utilities: fewer memory errors than the shipped versions, but more infinite loops
arXiv 2609.18298
Policy dependency / Stack layer
Codex makes Code Mode wrappers transparent to Guardian policy and adds read-only policy to MCP tool requests
GitHub
Stack layer / Threat pattern
37,623 provenance-labeled agent PRs: Codex code was reverted half as often as human code, Devin's 31% more, and Claude Code PRs waited 12.6 hours for first review
arXiv 2609.17598
Stack layer / Threat pattern
OpenAI documents a model writing jailbreak-like instructions into its own compaction summaries
OpenAI Alignment
Stack layer / Threat pattern
Three new advisories land on the most-used community GitLab MCP server, including a five-way bypass of its read-only mode and project allow-list
GitHub Advisory Database
Policy dependency / Stack layer
'Do this as quickly as possible' repeatedly got a Claude session flagged by a corporate security director
r/ClaudeAI
Stack layer / Threat pattern
Spain's Data Protection Agency Logs the First Breach Where an AI Agent Chained the Whole Attack Itself
SecurityWeek