NewsPleaseFix Zero-Click Agent Hijack in Agentic BrowsersZenity Labs·high signalXBlueskyLinkedInCopy linkZenity Labs disclosed PleaseFix vulnerabilities in Perplexity Comet — zero-click file exfiltration via poisoned calendar invites and credential theft through password manager manipulationSourceSource pageZenity Labs↳ Follow the threadStack layer / Threat patternCyberFactory Turns CVEs From the Wild Into Executable Training Tasks; Aegis Hits 52.4% Pass@1 on CyberGym, +22.8 Over Its BasearXiv 2608.23181Stack layer / Threat patternUnlose Takes Windows VSS Snapshots Before Coding Agents Run, Rejecting the Command-Blocking ApproachGitHub (via Show HN, 2026-08-25)Stack layer / Threat patternCROSS-CATEGORY: The Guardrail Layer Around Coding Agents Shipped at Four Different Points in the Lifecycle in 48 HoursHacker News Show HN and Product Hunt (2026-08-24 and 2026-08-25)Stack layer / Threat patternGemini CLI Closes a macOS Seatbelt Escape Through the Docker Desktop SocketGitHubStack layer / Threat patternOnly 4-16% of security rules written in CLAUDE.md have a matching Claude Code built-in controlarXivStack layer / Threat patternVercel Puts MiniMax M3 and M2.7 on AI Gateway Free Through September 6Vercel ChangelogStack layer / Threat patternSecurity-Oriented Prompts Redistribute Rather Than Reduce Vulnerabilities in LLM-Generated Python, and Silently Rewrite Requested CodearXiv 2608.24857Stack layer / Threat patternMobilePA-Bench Tests On-Device Agents on 212 Real Mobile Tools With Live Application DatabasesarXiv 2608.23035