Stack layer / Threat pattern
CROSS-CATEGORY: The Guardrail Layer Around Coding Agents Shipped at Four Different Points in the Lifecycle in 48 Hours
Hacker News Show HN and Product Hunt (2026-08-24 and 2026-08-25)
Policy dependency / Stack layer
A vision paper separates access from control and argues AI concentrates software power rather than democratizing it
arXiv 2608.24720 (submitted 2026-08-25)
Policy dependency / Stack layer
Halofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasure
GitHub
Stack layer / Threat pattern
TrustShiftProbe: a compromised MCP server that behaves for N calls then defects hits 69.5% attack success, and the best defense only halves it
arXiv
Policy dependency / Threat pattern
mcp-shell Ships Security Off in One Deploy Path and Bypassable in the Other (CVE-2026-55580/55581/55582)
GitHub Security Advisories
Threat pattern / Update thread
browser-use/browser-harness v0.1.10 is a pure agent-security release: CDP credentials redacted from logs and orchestrator daemons now fail closed
GitHub
Stack layer / Threat pattern
QWED-MCP, a Verification Gateway, Passed Attacker Math Straight to SymPy parse_expr (CVE-2026-55546, 9.8)
GitHub Security Advisories
Stack layer / Threat pattern
Bash Allow Rules With a Wildcard Before the Subcommand Match More Than You Wrote
Claude Code Changelog