Vibe CodingDXT Zero-Click RCE — CVSS 10.0 Across 50+ Claude Desktop ExtensionsInfosecurity Magazine·high signalXBlueskyLinkedInCopy linkLayerX: malicious calendar event chains low-risk connector to high-risk local executor. Full RCE without user click. Anthropic declined fix.SourceSource pageInfosecurity Magazine↳ Follow the threadPolicy dependency / Stack layerSpotify Opened Xirp to Public Beta — an Incumbent Shipping the Meta-Harness Layer Above Claude Code, Codex and Gemini CLISpotify Portal Engineering Blog (corroborated by Product Hunt Aug 11 and Spotify Engineering on X)Policy dependency / Stack layerOpenAI Agents SDK 0.20.0 switches the default model to gpt-5.6-luna and takes a breaking MCP v2 dependencyGitHub (openai/openai-agents-python)Stack layer / Threat patternNVIDIA Rewrote Its LLM Routing Proxy in Rust — Switchyard v0.2.0 Lands 193 Commits and Splits Into Five CratesGitHubPolicy dependency / Stack layerSplit your agent's safety into four evolvable artifacts — system prompt, rule bank, safety memory, tool policy — for a 3.1x attack-success reductionarXiv 2608.09885Policy dependency / Stack layerRangeBench: 1,148 Multi-Hop Cyber Ranges Show Attack Agents Get a Foothold Then Stall — 24.5–47.0% Never Finish the ChainarXiv 2608.09526Policy dependency / Stack layerPOLIS 5,280-Episode Study: Provenance-Aware Guards Block Authority Laundering That Local-State Guards Miss in 22 of 96 EpisodesarXiv 2608.09828Stack layer / Threat patternZoom patches 'Zoomsday' zero-click RCE chain that researchers weaponized in under 24 hours with fewer than 20 AI promptsSecurity AffairsStack layer / Threat patternIBM Research's ALTK-Evolve beats ACE on AppWorld while using ~40% of its tokens — retrievable guidelines vs one giant playbookHugging Face Blog (IBM Research)