Policy dependency / Threat pattern
Rust's crates security team warns of an active campaign social-engineering maintainers over fake video calls
Simon Willison's Blog (Rust Blog)
Stack layer / Update thread
CROSS-CATEGORY: Three Vendors in Three Days Redefined the Seat as a Credit Allowance Rather Than Killing It
Synthesis of about.gitlab.com (2026-09-17), Martech Notes on HubSpot Analyst Day (2026-09-17) and Penguin Strategies UNBOUND roundup
Stack layer / Threat pattern
Plugin4Shell: One SHA-Pinning Bug Gives Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
Help Net Security (corroborated by The Register)
Policy dependency / Stack layer
LangChain ships a first-party integration that deliberately does not wrap the vendor's SDK
GitHub
Stack layer / Update thread
pydantic-ai 2.46.0 lets enum member docstrings become the option descriptions the model sees
GitHub
Policy dependency / Stack layer
CrowdSec discloses a May 2026 private-repo leak via a backdoored TanStack component, found four months later
CrowdSec
Policy dependency / Threat pattern
Gary Marcus: the near-term threat is agentic AI hacking, not rogue superintelligence, and labs should be liable
Marcus on AI (Gary Marcus)
Policy dependency / Stack layer
Claude Code 2.1.277 reads AGENTS.md when there is no CLAUDE.md, and subagent output now carries an anti-spoofing header
Claude Code changelog