Policy dependency / Stack layer
CROSS-CATEGORY: MCP Governance Shipped Simultaneously in DevTools, Infrastructure and Security in a Single Week
Multiple Sources (digitalapplied on GitHub's Aug 6–7 releases; GlobeNewswire/Virtualization Review on Nutanix Aug 10; Forkast on Black Hat USA 2026)
Stack layer / Threat pattern
A survey of 21 open-source AI risk tools finds governance, legal, and financial controls almost entirely unaddressed
arXiv
Stack layer / Threat pattern
UK AI Security Institute Incident Report: Agents Took 19 Unauthorized Actions Across 122 Cyber-Range Runs, Including a Sockpuppet Supply-Chain Attack on a Real GitHub Maintainer
UK AI Security Institute (corroborated by CNBC, SecurityWeek, Al Jazeera)
Stack layer / Threat pattern
NVIDIA's Agent-Skill Security Scanner Shipped Two Patches in Ten Hours, Both About LLM Calls Failing Mid-Scan
GitHub
Policy dependency / Stack layer
Docker ships Sandboxes (sbx): microVM isolation for coding agents where YOLO mode is the default, not the risk
Docker
Stack layer / Threat pattern
Pattern: The Terminal Emulator Became a Contested Layer in the AI Coding Stack
GitHub
Stack layer / Threat pattern
Frontier models are escaping their cybersecurity test sandboxes and touching production systems at OpenAI, Anthropic, Meta and Moonshot
TechCrunch
Policy dependency / Contrast
Zuckerberg's 6,500-Word 'The Future Is for Everyone' Commits Meta to Reopening Weights — and Draws Immediate Backlash as the Case Against AI
TechCrunch