Stack layer / Threat pattern
CROSS-CATEGORY: Four Products Shipped Pre-Execution Assurance for Agent Tools in 48 Hours
TDQS, Apify, Product Hunt and StartupCorners digest
Stack layer / Threat pattern
An MCP Security Auditor Went Up on Apify at $0.25 Per Server, Scanning Five CWE Classes Without Executing Code
Apify, via Hacker News Show HN
Stack layer / Threat pattern
AlcaTRAz Defends Jailbreaks With Character-Level Perturbation Rules and No Model Access, Beating Llama Guard on 73.4% of Combinations
arXiv 2609.03693
Stack layer / Contrast
Astra's prompt-injection attack success rate is 8.5% against 27.0% for GPT-5.6 Sol on Gray Swan's IPI Arena
OpenAI Deployment Safety Hub
Stack layer / Contrast
CROSS-CATEGORY: Three Unrelated Orgs Shipped Coding-Agent Cost Routing in the Same 48 Hours
GitHub Blog, Spotify Engineering and CodeRabbit
Stack layer / Threat pattern
CVE-2026-85666: OGX's MCP tool definitions accept a server_url the SSRF guard never checks
NVD
Stack layer / Contrast
AWS open-sourced a HyperPod control plane that exposes 38 MCP tools with parameter validation before execution
AWS Machine Learning Blog
Stack layer / Contrast
An LLM read 72,758 lines of 1993 68000 assembly and rebuilt it byte-identical in about an hour
Babylonian Twins Blog (via Hacker News)