Policy dependency / Stack layer
Hierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist Disagreement
arXiv 2609.04820
Policy dependency / Stack layer
CONTINUITY names "security-context discontinuity" as the failure mode where individually correct agent security controls compose into an insecure system
arXiv
Stack layer / Threat pattern
Deleting an agent's memory record changes leakage not at all, and instruction-based forgetting fails on every probe
arXiv 2609.04875
Stack layer / Threat pattern
SBOM Tools Cover Only the First Two of Four Supply-Chain Propagation Stages
arXiv 2609.05380
Stack layer / Threat pattern
LLM decompiler output that recompiles and passes every shipped test still diverges on other inputs, and can silently erase a disclosed CVE
arXiv 2609.05370
Stack layer / Threat pattern
TIER Replaces Binary Safety Scores With a Six-Label Behavior Scale Across Four Threat-Implicitness Levels
arXiv 2609.05117
Stack layer / Contrast
CUA-Universe builds hybrid GUI+CLI agent environments automatically, on the argument that GUI-only computer-use agents produce inefficient trajectories
arXiv
Stack layer / Threat pattern
19,325 CVEs compiled into 1,033 detection rules packaged as 172 agent skills, producing runtime evidence for 644 findings
arXiv 2609.05335