Fetching from the wire…
Security2026-09-07 · source-backed
A four-stage propagation model evaluated against four open-source SBOM tools using Log4j finds systematic support for Structural Exposure and Vulnerability Class Presence, and none at all for Code Reachability or Taint Path Analysis (arXiv 2609.05380). Your SBOM tells you a vulnerable component is present. It does not tell you whether that code path is reachable in your build, which is the question anyone triaging an advisory actually has.
Each link below shares sources, entities, or timing with this story.
An online skill-evolution framework turns interaction trajectories and evaluator feedback into a persistent versioned library, with each iteration executing against a frozen snapshot so evidence-guided updates only reach later iterations and no model parameters change (arXiv 2...
Context Privilege Escalation names two classes, M-CPE where attacker-controlled low-privilege content gets folded into a higher-privileged message role, and X-CPE where it persists past the context that introduced it. The authors ran it against 12 production harnesses includin...
It synthesizes attack tool-chains in a sandbox, verifies them, renders the verified chain as one natural-looking prompt, embeds state-transition cues in target tool descriptions, and corrects drift mid-run (arXiv 2608.30441). Against Codex, Claude Code and OpenClaw-style harne...
Skill-α (arXiv 2608.01678) reframes skill generation as RL over sequential edits, decomposing skill construction into individually evaluable changes. The novel signal is a rollback reward that scores each modification by comparing downstream task execution using the original s...
LangChoiceBench covers 28 projects across seven software areas where Python is a poor default, run against 25 LLMs. Python stays heavily over-selected, recommendation-implementation consistency is low, and smaller open-weight models show stronger bias. Analysis of 9,826 reason...
arXiv 2607.23710 evaluated authentication systems from five prominent assistants against NIST SP 800-63B using static analysis plus dynamic pentesting across four prompting strategies. Functional and generically "secure" prompts consistently omitted brute-force resistance, sou...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.