Fetching from the wire…
Agents2026-09-17 · source-backed
arXiv 2609.18411 targets the case where the human-in-the-loop confirmation is itself attacker-influenced, which is where most agentic-browser defenses quietly assume safety. The Verifiable Action Card reconstructs approval text from the pending browser action and trusted intent provenance, renders it out-of-band in browser chrome, and re-verifies the exact action at dispatch. On a 24-scenario benchmark covering confused-deputy attacks, Lies-in-the-Loop dialog forging and adaptive action substitution: 68-100% attack success without it, 0% on every model with it, at 78% legitimate-task completion and a 0% false-block rate. The zero false-block number is what makes this shippable rather than academic.
Each link below shares sources, entities, or timing with this story.
I've spent real hours tuning the CLAUDE.md in my own repos. Rewriting architecture notes. Adding conventions. Trimming when it got long. So this one stung. arXiv 2607.27250 ran a two-agent ablation across Claude Code and Codex: 17 real tasks from 3 repositories, 288 gold-test-...
If you have a CLAUDE.md, you're in scope. Today. arXiv 2607.14611 (cs.CR, filed July 16) evaluates prompt injection planted in the persistent memory files that agentic coding systems write and re-read across sessions. The researchers tested both Anthropic's Claude Code and Ope...
July 17, Product Hunt's #1 product was Unabyss for Claude: shared memory across all apps and LLMs, 598 votes. July 18, #1 was ZooData: "the data layer for AI agents," 606 votes. Neither is an application. Both are substrate. (Product Hunt) One launch is noise. Two consecutive...
A GitHub Issue. No code, no credentials, no access. Just a paragraph of English that tells an AI agent to copy your private repo into a public comment. That's GitLost, and it works whether the agent runs on Copilot, Claude, Gemini, or Codex. (Noma Security) Noma Security discl...
claude-mem hit 80,189 stars at v12.6.4, with 1,840 commits and 109 contributors. It hooks five agent lifecycle events to capture observations, compresses them through Claude's agent SDK into SQLite, and reinjects relevant context on new sessions. No manual tagging. One npx com...
Microsoft Research dropped a paper that should change how every builder thinks about their agent configuration files. SkillOpt (arXiv 2605.23904) treats a Markdown document as an external parameter of a frozen LLM and applies learning rate, batch, and momentum concepts in text...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.