Fetching from the wire…
Infra2026-08-08 · source-backed
The AWS Generative AI Innovation Center built a two-part solver: a 0-day CP-SAT model on Google OR-Tools testing whether any scenario exists where a team misses, plus an n-day lookahead using custom tree search where each layer is a game day and each node an outcome, calling the 0-day solver at every node. Median runtime in minutes for 1-day scenarios, pruning efficiency near 100%, validated against four NHL seasons where output matched published scenarios exactly. Seven cascading tiebreakers requiring exact verification is precisely where a probabilistic model is wrong, and a team inside a generative AI org said so in public.
Each link below shares sources, entities, or timing with this story.
1. Set package cooldown to 72 hours across all your package managers. pnpm: resolution-time=72h, uv: --exclude-newer, npm via .npmrc. This single config change would have protected you from the LiteLLM attack. Willison's survey covers all seven managers. 2. Install Lasso Secur...
Two thirds. Not two thirds of a contrived jailbreak set. Two thirds of realistic malicious issue requests, against the exact three tools most of the people reading this run daily. Ankur Singh, Jinqiu Yang, and Tse-Hsun Chen built IssueTrojanBench across four attack categories...
First-party pricing, counts toward AWS commitments, Codex via CLI and IDE plugins for VS Code, JetBrains, and Xcode, across commercial and GovCloud (AWS). This removes the procurement and compliance wall for AWS shops that couldn't touch OpenAI under existing contracts. Distri...
Stripe published Part 2 of its Minions engineering blog, and it's the most detailed production agent architecture I've read from any company this year. The numbers alone are worth the read: 1,300+ weekly merged PRs from coding agents. But the architecture decisions matter more...
The single biggest cross-agent story this week isn't one CVE. It's that MCP became the dominant agent-hijack surface, and this is the defense that actually stops it. The pattern across a dozen findings: Sentry's MCP server weaponized via fake error events for an 85% agent-hija...
Sondera intercepts every shell command, file operation, and web request from coding agents and adjudicates them with Cedar — the same formal policy engine used by AWS. Unlike probabilistic LLM guardrails, these rules are deterministic. Rust binaries, stateful trajectory stores...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.