Stack layer / Threat pattern
CWEEP Triples Correct-Warning Rate on RTL Security Bugs Without Requiring a Security Spec
arXiv 2607.29604
Stack layer / Threat pattern
Splitting one web agent into a multi-agent crew opens an attack that is inert against single agents: 80% success via a cross-delegation "Telephone Loop"
arXiv 2608.00202
Stack layer / Threat pattern
Snyk's Second Agentic Adoption Report Says Security Teams See Only a Third of Their Real AI Footprint
Snyk (corroborated by TipRanks and Futurum Group)
Stack layer / Threat pattern
Pattern: Roughly 8,000 of 10,000 Vibe-Coded Startups Have Needed Rescue Engineering, and It's Now a Named Specialty
r/SaaS
Policy dependency / Stack layer
Claude Agent SDK 0.2.129 patches an --allowedTools injection where a crafted skill name could grant itself extra permissions
GitHub (anthropics/claude-agent-sdk-python)
Policy dependency / Stack layer
FTC Bans Foreign Robot Imports, and 90% of Recent US University Robotics Papers Depended on the Banned Hardware
MIT Technology Review
Stack layer / Update thread
NVIDIA Ships NemotronLabs VoiceChat 11B — First Open Full-Duplex Speech Model With Tool Calling, ~450ms Turn-Taking
Hugging Face (nvidia), via r/LocalLLaMA (177 upvotes / 35 comments)
Stack layer / Threat pattern
mpai makes existing Claude Code and Codex sessions multiplayer over Tailscale, without shell access
Product Hunt