Fetching from the wire…
Security2026-09-13 · source-backed
arXiv 2609.11814 breaks the assumption underlying a decade of super-app security work, that the host is a trusted intermediary. Using MAX as the case study, the authors show the host can capture mini-app UI, read and write mini-app local storage, inject arbitrary JavaScript into the mini-app runtime, mediate network traffic, and control authentication context well enough for silent user impersonation, with no trace left. None of it is a bug. Every capability follows from privileges the architecture grants by design, which puts the fix on mobile OS and app store integration and leaves individual mini-app developers with nothing to patch.
Each link below shares sources, entities, or timing with this story.
Comparing SFT, reasoning-augmented fine-tuning on safety-justifying chains, and ORPO across Llama-3.1-8B, Gemma-2-9B and Qwen3-8B, the training method reshapes the internal refusal computation, with reasoning-augmented training producing a distinct circuit visible in all three...
Released July 11, it adds static-analysis queries that flag prompt-injection vulnerabilities in JavaScript and TypeScript, plus Kotlin 2.4.0 support (GitHub). Treating untrusted-input-into-LLM flows as a first-class security defect class is the right call. If you're wiring LLM...
Researchers loaded five systems with a revoked policy and its replacement, then measured retrieval and downstream action across nine policy scenarios, nine models and six defense conditions. Wherever the revocation label was visible to the retrieval layer, the revoked fact cam...
At its June 24 Investor Day, Qualcomm agreed to acquire Modular (Mojo language, MAX inference engine, founded by LLVM/Swift creator Chris Lattner) all-stock at $3.92B, and unveiled the Dragonfly C1000 data-center CPUs with Meta as launch customer. It's a ~$14B RISC-V-plus-open...
Lightfield took $47M led by a16z to rebuild CRM so agents can read and write the schema natively, on the premise that Salesforce's objects and fields assume a human is typing and reading. Euno took $23M for a live context graph of lineage, usage, ownership, business logic and...
Translating key-value state from one model into a form another can consume works across scale, architecture, attention configuration, tokenizer and family (arXiv 2608.30963). Llama3.1-70B to Qwen2.5-7B reaches 44.0% accuracy against 45.7% native while dropping latency to 138ms...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.