SourcesNIST Concept Paper on AI Agent Identity and AuthorizationNIST NCCoE·high signalXBlueskyLinkedInCopy linkNIST proposes identity/auth standards for AI agents. Covers agent identification, authorization, access delegation, logging. Comments due April 2.SourceSource pageNIST NCCoE↳ Follow the threadStack layer / Threat patternCodex users are getting 'Cyber Abuse' warnings from OpenAI for security-reviewing their own code, with appeals rejected then reversedr/OpenAI (79 upvotes, 58 comments)Stack layer / Threat patternSBOM Tools Cover Only the First Two of Four Supply-Chain Propagation StagesarXiv 2609.05380Stack layer / ContrastCROSS-CATEGORY: Four Independent Projects in 48 Hours Built the Portability Layer That Moves Lock-In Off the Agent VendorEngrim, Kit, Yurei and Crew (via Hacker News Show HN and Product Hunt)Stack layer / Threat patternLLM decompiler output that recompiles and passes every shipped test still diverges on other inputs, and can silently erase a disclosed CVEarXiv 2609.05370Policy dependency / Threat patternCONTINUITY names "security-context discontinuity" as the failure mode where individually correct agent security controls compose into an insecure systemarXivPolicy dependency / Stack layerHierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist DisagreementarXiv 2609.04820Stack layer / Follow-up threadA Review Through 31 August 2026 Finds Agent Action Surfaces Expanded Far More Than Reliable Completion DidarXiv 2609.04894Stack layer / ContrastBrazil pushes for a sovereign Portuguese-language model, joining the national-AI waver/singularity (111 upvotes, 132 comments)