NewsCVE-2026-2256: Microsoft Agent Framework RCEMicrosoft MSRC·high signalXBlueskyLinkedInCopy linkCritical RCE in Microsoft Agent Framework via crafted MCP tool responses. CVSS 9.1. Patch available in v0.4.2.SourceSource pageMicrosoft MSRC↳ Follow the threadStack layer / ContrastQwen Code v0.21.13 hardens its /review agent workflow against review loops with a round-5 severity cutoff and worktree lease locksGitHub (QwenLM/qwen-code)Policy dependency / Threat patternStrix Adds Contextual CVSS and Source-to-Sink Reachability Evidence to Dependency Findings — Seven Commits on 2026-08-17 AloneGitHubStack layer / Contrastllmfit v1.1.10 Adds RamaLama Runtime Discovery and Publishes the First MLX vs llama.cpp Metal Head-to-Head on Identical HardwareGitHubPolicy dependency / Stack layerGortex v0.63.4 Adds C# Solution Pinning and Exempts Python Dunders From Dead-Code Analysis in a 257-Language Code GraphGitHubStack layer / ContrastoMLX 0.6.0 Ships Distributed LLM Serving Across Multiple Macs — Qwen3.6-27B Goes 16.1 → 28.6 tok/s on Two MachinesGitHubPolicy dependency / Stack layerShow HN: PyScrappy Pairs Self-Healing Scraper Selectors With an MCP Server So Agents Can Re-Target Broken PagesGitHub / Hacker NewsStack layer / Update threadPattern: Agent Configuration Is Being Deliberately Decoupled From the Vendor, and Three Moves This Month Prove ItGitHub Changelog / OpenAI Codex ChangelogStack layer / Update threadbrowser-use 0.13.8 adds first-party OpenClaw skill support and marks read-only MCP tools with readOnlyHint annotationsGitHub (browser-use/browser-use)