Fetching from the wire…
Agents2026-07-28 · source-backed
arXiv 2607.23999 argues terminal attack/policy labels hide what actually happens after an injection lands, and measures endpoint compliance, logged propagation, recovery and authorized-action completion separately. In a pre-specified 17,640-rollout study, all 600 matched active-tainted pairs comparing taint-only versus intent-aware enforcement produced identical zero committed-harm outcomes, yet 73.5% differed in logged trajectory or retained utility. Taint-only completed 0.1642 of authorized tainted workflows; trusted-ledger 0.8567; a strong tool-boundary baseline 0.9233. Synthetic and single-model, but "no harm committed" is clearly not a sufficient statistic. (arXiv 2607.23999)
Each link below shares sources, entities, or timing with this story.
APPA replaces permanent context contamination with engine-managed branching: when the agent is about to acquire unvetted data, the system spawns an isolated trajectory to inspect it and returns only a bounded derivative through a trusted sanitizer to an unchanged parent contex...
arXiv 2608.26733 presents an execution-only attack that reconstructs a hosted agent skill without ever asking the victim to reveal it, submitting crafted but ordinary tasks whose results discriminate between candidate hidden behaviors. At the weakest access level, final respon...
arXiv 2608.12990 from Dongfang Li, Baotian Hu, Min Zhang and colleagues replaces turn-level memory consolidation with semantic boundary detection, reporting 89.22% on LoCoMo and 92.20% on LongMemEval-S while cutting construction tokens 86.0% and 75.9% versus the A-Mem baseline...
Sergey Rodionov's paper tests four Codex-based agent variants to isolate what actually drives performance. Verification (simplification plus exact observation reproduction) ranked highest in every setting, but at substantially higher cost. The textual baseline beat the executa...
Researchers introduced ShareLock, a tool-poisoning attack against MCP that distributes a malicious instruction across several tool descriptions, defeating the assumption that a reviewer reading one tool will catch it. Per-tool review is now insufficient. The attack surface is...
StartupBench (arXiv 2608.17800) inverts benchmark construction. Instead of researcher-invented tasks, the authors studied AI startup products with demonstrated market adoption, their workflows, and their users, then translated those into complete deliverable-oriented tasks wit...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.