Policy dependency / Stack layer
CROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated Intent
Product Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)
Threat pattern / Contrast
Shopify Abandons React Native for Swift and Kotlin, Saying Coding Agents Made Building Twice Cheaper Than Sharing One Codebase
Shopify Engineering / Hacker News (1110pts, 804 comments)
Stack layer / Threat pattern
Anthropic's September threat report documents autonomous agent swarms, 13 unsupervised collection agents, and a developer token escalated to full admin in three hours
Anthropic
Stack layer / Threat pattern
Sequoia doubled down on Cymphony, which tracks AI agents as identities alongside employees
TechCrunch
Stack layer / Threat pattern
One in Seven Python Samples That Pass Bandit and Semgrep Still Carries a Runtime-Confirmed Exploit
arXiv
Stack layer / Threat pattern
Statement coverage, branch coverage and mutation testing all detect close to zero of the hard faults in LLM-generated code
arXiv 2609.09315
Stack layer / Threat pattern
IBM released Granite Time Series PatchTST-FM-r2 with a commercial-friendly license
Hugging Face Blog (IBM Research)
Stack layer / Threat pattern
AWS Security Agent MCP server could hand a scanned workspace's source archive, credentials included, to an attacker-owned S3 bucket
NVD