Fetching from the wire…
Security2026-07-27 · source-backed
arXiv 2607.23444 defeats per-user memory isolation without violating it. Agents routinely embed LTM-retrieved data in tool-call parameters, so a malicious tool exfiltrates memory while every user-ID binding stays intact. SPORE decouples the adversarial command from retrieval anchors by persisting the command in short-term memory, then runs geometric coverage optimization over the embedding space to steer anchors toward unexplored regions. 80.0% extraction with unlimited triggers, 47.0% with only 20. It also persists reactivation payloads that resume across sessions with no further user action. Anyone wiring mem0-style memory behind third-party tools should read this today.
Each link below shares sources, entities, or timing with this story.
An edit cannot un-authorize a permission already granted or un-send a tool request already in flight, and the paper shows an unsafe edit can authorize the same action twice, discard a result the task still needs, or conflict with a call that started before the edit (arXiv 2608...
2,910 programmatically verified tasks built from an ontology of 97 canonical UI components. Holding the harness fixed and changing only observation and action space, GPT-5 mini scores 83.1% with accessibility-tree observations and 48.9% with coordinate-only pixel control. Acro...
A June 26 paper (arXiv:2606.26294) describes a self-improving architecture where the agent and the evaluator that scores it evolve together, specifically to avoid the stagnation of optimizing against a fixed, gameable reward. (arXiv) Anyone building a self-improving harness ha...
MemSyco-Bench points out that memory benchmarks test whether memories are correctly stored, retrieved, and updated, never whether the retrieved memory should have influenced the decision at all. Its five tasks check whether agents can reject memory as factual evidence, respect...
arXiv 2608.24358 switched models mid-run on long coding tasks using cheap/expensive pairs from the Claude and GPT families. Full-trajectory escalation from weak to strong recovers under half the gap while costing a substantial premium, which the authors call the handoff tax. D...
Wu et al. name history reliability as a distinct failure mode: trace entries that stay structurally valid and semantically plausible after they stop being authoritative. On Qwen3-1.7B, polluted history flipped 32.1% of decisions correct under the original trajectory, usually v...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.