Stack layer / Threat pattern
16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shell
arXiv
Stack layer / Threat pattern
Claude Code's Artifact tool now treats an artifact written by someone else as untrusted and flags embedded instructions instead of relaying them
Claude Code Changelog
Policy dependency / Stack layer
NSA, CISA and FBI Name Six Chinese AI Firms in a Joint Advisory on Industrial-Scale Distillation
CISA
Policy dependency / Threat pattern
Agents hit 80% F1 deciding whether a dependency CVE is exploitable, but fall below 70% explaining why
arXiv 2609.08040
Stack layer / Contrast
CROSS-CATEGORY: Four Independent Moves in 48 Hours All Attack the Same Line Item, the Per-Token Inference Bill
Inception Labs, DeepSeek, Desert Ant Labs and argonautlabsai/deltafin (four independent primary sources)
Stack layer / Contrast
NVIDIA and MiniMax released Sol-H3, which generates five seconds of video in 1.653 seconds
NVIDIA Research (corroborated by Enze Xie on X)
Stack layer / Threat pattern
Simon Willison on the Navier-Stokes race: the uncomfortable question is what "improving model performance" means for your Codex sessions
simonwillison.net
Policy dependency / Stack layer
MCP Inspector 2.6.0 raised its declared hono floor rather than trusting its lockfile, and documented why
GitHub