Policy dependency / Stack layer
Agents hallucinate tools that do not exist, a 675B model does it as often as a 7B one, and merging MCP servers adds new failure surfaces
arXiv 2609.19425
Stack layer / Threat pattern
Plugin4Shell: One SHA-Pinning Bug Gives Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
Help Net Security (corroborated by The Register)
Policy dependency / Stack layer
CrowdSec discloses a May 2026 private-repo leak via a backdoored TanStack component, found four months later
CrowdSec
Stack layer / Threat pattern
37,623 provenance-labeled agent PRs: Codex code was reverted half as often as human code, Devin's 31% more, and Claude Code PRs waited 12.6 hours for first review
arXiv 2609.17598
Stack layer / Threat pattern
Pattern: identity and account boundaries are now a named class of coding-agent bug
GitHub
Stack layer / Threat pattern
A researcher claims the Jev architecture everyone is discussing matches his March 2025 open-source paper
r/LocalLLaMA
Stack layer / Threat pattern
DeepSeek V4.1 Flash Popped All 11 Vulnerable Targets in Enclave's Offensive Security Benchmark for $5.14
Enclave (model release corroborated by DeepSeek) / Hacker News (167pts, 66 comments)
Policy dependency / Stack layer
LangChain ships a first-party integration that deliberately does not wrap the vendor's SDK
GitHub