Fetching from the wire…
Security2026-08-28 · source-backed
arXiv 2608.27299 shows harnesses silently promote low-privilege content to a higher instruction level while assembling context for each model call, defeating model-side instruction hierarchy. With unrestricted action execution the attacks achieved every objective across confidentiality, integrity, availability and RCE on all six harnesses, and under automatic permission review they still hit all 13 on all three harnesses offering that mode. The authors reproduce it through persistent goals and scheduled tasks, so a cron-driven agent loop inherits the hole.
Each link below shares sources, entities, or timing with this story.
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (agent, attack, author, call, context).
Shared entity: RCE / Shared topic / Earlier coverage / Tension
Both cover RCE; overlapping topics (agent, attack, context); earlier RCE coverage from 2026-02-20.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (action, agent, context, harness); pushes against this story (but).
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (action, agent, attack, call, harness).
Shared entity: RCE / Shared topic / Earlier coverage / Tension
Both cover RCE; overlapping topics (agent, attack); earlier RCE coverage from 2026-03-20.
Shared entity: RCE / Shared topic / Earlier coverage
Both cover RCE; overlapping topics (agent, attack, context); earlier RCE coverage from 2026-03-25.
Both cover RCE; overlapping topics (action, agent, attack); earlier RCE coverage from 2026-03-05.
Both cover RCE; overlapping topics (action, agent, attack); earlier RCE coverage from 2026-02-27.