Stack layer / Threat pattern
Keeper's MCP secrets teardown: plaintext config credentials, sprawl, and over-permissioning that survives into production
The Hacker News
Stack layer / Threat pattern
How you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success rate
arXiv 2608.14876
Stack layer / Threat pattern
AWS ships aws-agents-pay so OpenClaw agents can spend stablecoins under hard authority bounds
AWS Machine Learning Blog
Stack layer / Contrast
llmfit v1.1.10 Adds RamaLama Runtime Discovery and Publishes the First MLX vs llama.cpp Metal Head-to-Head on Identical Hardware
GitHub
Stack layer / Contrast
Coloring Positive Words Green Shifts VLM Sentiment Predictions — a Styling-Only Prompt Injection Channel
arXiv 2608.14286
Stack layer / Contrast
oMLX 0.6.0 Ships Distributed LLM Serving Across Multiple Macs — Qwen3.6-27B Goes 16.1 → 28.6 tok/s on Two Machines
GitHub
Policy dependency / Stack layer
Show HN: PyScrappy Pairs Self-Healing Scraper Selectors With an MCP Server So Agents Can Re-Target Broken Pages
GitHub / Hacker News
Stack layer / Threat pattern
MCP tools that write, not read, went from 27% to 65% of tool use - and measured defenses stop under 30% of attacks
arXiv 2608.17275