RedditPleaseFix: Zero-Click Agent Hijacking via Calendar Invites in Perplexity CometWweb·medium signalXBlueskyLinkedInCopy linkZenity Labs disclosed PleaseFix vulnerability family in agentic browsers. Two exploit paths: zero-click file exfiltration via calendar invites and 1Password vault takeover. Prompt injection via Reddit comments demonstrated. Perplexity patched pre-disclosure. Most alarming agentic security disclosure yet.↳ Follow the threadShared entity / Threat patternPerplexity's India numbers after the Airtel giveaway: 22M peak users down to 14M, revenue up 60%TechCrunchStack layer / Threat patternHow you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success ratearXiv 2608.14876Policy dependency / Stack layerGortex v0.63.4 Adds C# Solution Pinning and Exempts Python Dunders From Dead-Code Analysis in a 257-Language Code GraphGitHubStack layer / Threat pattern'Coherence Debt': Withheld Facts Make Coding Agents Fabricate Rather Than Stall, and Harnesses Differ Tenfold in Tokens for Identical ResultsarXiv 2608.16630Policy dependency / Stack layerCodex 0.148.0 Ships Stable With `codex exec fork`, `/export` to Markdown and Bedrock as a Built-In ProviderOpenAI Codex ReleasesStack layer / Threat patternCherry Studio v2.0.7 Retires the Per-Agent max_turns Cap and Adds Auto Permission Mode for Pi AgentsGitHubStack layer / Threat patternVercel Labs releases fx, a 6MB Zig coding agent that cold-starts in 10 microseconds and runs in WebAssemblyVercel Labs (fx.sh)Stack layer / Threat patternpi-from-scratch Hits 1,057 Stars in Nine Days Teaching a 600-Line TypeScript Coding Agent Line by LineGitHub