SourcesGemini MCP Tool 0-Day CVE-2026-0755 CVSS 9.8CyberSecurityNews·high signalXBlueskyLinkedInCopy linkCritical command injection in gemini-mcp-tool. execAsync passes user input directly to system call. CVSS 9.8, no official patch.SourceSource pageCyberSecurityNews↳ Follow the threadStack layer / Threat patternllmfit v1.1.10 Adds RamaLama Runtime Discovery and Publishes the First MLX vs llama.cpp Metal Head-to-Head on Identical HardwareGitHubStack layer / Threat patternQwen Code v0.21.13 hardens its /review agent workflow against review loops with a round-5 severity cutoff and worktree lease locksGitHub (QwenLM/qwen-code)Policy dependency / Stack layerGortex v0.63.4 Adds C# Solution Pinning and Exempts Python Dunders From Dead-Code Analysis in a 257-Language Code GraphGitHubPolicy dependency / Stack layerShow HN: PyScrappy Pairs Self-Healing Scraper Selectors With an MCP Server So Agents Can Re-Target Broken PagesGitHub / Hacker NewsStack layer / Threat patternbrowser-use 0.13.8 adds first-party OpenClaw skill support and marks read-only MCP tools with readOnlyHint annotationsGitHub (browser-use/browser-use)Stack layer / Threat patternCROSS-CATEGORY: MCP Is Quietly Replacing the Vendor Dashboard — ElevenLabs, ZoomInfo and S&P Global All Shipped Connectors That Make Their Own UI OptionalElevenLabs (corroborated by The New Stack, ZoomInfo IR, and S&P Global/Microsoft announcements Aug 11-12)Stack layer / Threat patternContext bombs: plant a prompt injection in your AWS secrets and offensive AI agents refuse to continue (57% → 5% admin escalation)TracebitStack layer / Threat patternAWS ships aws-agents-pay so OpenClaw agents can spend stablecoins under hard authority boundsAWS Machine Learning Blog