Fetching from the wire…
Security2026-09-13 · source-backed
arXiv 2609.10294 compares five public regex vulnerability detection tools plus one correction tool across three datasets, then analyzes every ReDoS entry in NVD against non-ReDoS entries. ReDoS is both more prevalent and much more likely to be exploited. The tools show substantial disagreement on individual regexes, so one clean scan is not evidence of anything. Run two tools and treat the disagreement set as your review queue.
Each link below shares sources, entities, or timing with this story.
GitHub published four medium-severity vLLM advisories on September 4 against the inference server most self-hosted agent stacks run on. GHSA-pr7f-p5mw-fc87 shows the CVE-2025-62164 remediation can be bypassed using concurrent prompt parts. GHSA-48jh-3gj7-fg8v is a ReDoS throug...
RAGAS-style evaluation checks correctness against a frozen snapshot, which means routine document updates and corrections can silently break production without moving a dashboard. This ASE 2026 paper defines 11 mutation operators perturbing at both the pre-chunk index level an...
A four-stage propagation model evaluated against four open-source SBOM tools using Log4j finds systematic support for Structural Exposure and Vulnerability Class Presence, and none at all for Code Reachability or Taint Path Analysis (arXiv 2609.05380). Your SBOM tells you a vu...
Evaluating AI-generated clinical notes, judges verify presence but not absence, and no single-note judge design flagged omissions more reliably than it flagged perfect notes (arXiv 2608.31016). Restructuring to first enumerate transcript facts then verify each against the note...
Poisoned entries in persistent memory force unintended tool selection during retrieval — even against explicit user instructions. Unlike prompt injection targeting input, MCFA targets the memory store, making it persistent and harder to detect. If your agent has long-term memo...
First defense against MCP Tool Poisoning Attacks using a Decision Dependence Graph that correlates LLM attention with tool invocation decisions. 97%+ detection accuracy with zero token overhead. Key insight: behavior-level defenses are fundamentally ineffective against TPA bec...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.