Stack layer / Threat pattern
DSPy adds LocalInterpreter, a persistent CPython worker that the release notes explicitly refuse to call a sandbox
GitHub
Stack layer / Contrast
EvoSafeHarness searches policies and code together to build a per-model safety harness, cutting attack success from 45.6% to 10.0%
arXiv (2609.05903)
Stack layer / Update thread
Minitap Accuses Google's Artemis of Copying Its Apache-2.0 Mobile-Agent Code and Force-Pushing the Authors' Names Out
Minitap
Stack layer / Threat pattern
Claude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256
Anthropic (claude-code CHANGELOG)
Policy dependency / Stack layer
A replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policies
GitHub
Stack layer / Follow-up thread
Two More Safety Researchers Quit Anthropic and Google DeepMind for METR, Citing the July Hugging Face Agent Attack
NBC News
Policy dependency / Stack layer
SGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four Weeks
CERT Coordination Center
Stack layer
A 27B tuned on 125,217 human-to-human messages topped r/LocalLLaMA, and the sub's best rebuttal is that a system prompt does the same
r/LocalLLaMA