Vibe CodingDXT Zero-Click RCE — CVSS 10.0 Across 50+ Claude Desktop ExtensionsInfosecurity Magazine·high signalXBlueskyLinkedInCopy linkLayerX: malicious calendar event chains low-risk connector to high-risk local executor. Full RCE without user click. Anthropic declined fix.SourceSource pageInfosecurity Magazine↳ Follow the threadPolicy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubPolicy dependency / Stack layerTraceCrate v0.2 reads Claude Code, Codex and OTLP traces in one local workbenchGitHubStack layer / Threat patternAgentsDock Open-Sources an IDE That Collapses Termius, Cursor and Claude Code Into One DockAgentsDock (surfaced on Hacker News item 49678435)Policy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterStack layer / Threat patternCROSS-CATEGORY: Five Launches in 96 Hours Sold Self-Hosting and Air-Gapping as the Entire DifferentiatorCoder blog, GitHub API and Hacker News Show HN (five independent launches)Stack layer / Threat patternSureForge encodes a research-plan-verify-review gate sequence as a plain-text agent skillGitHubStack layer / Threat patternAlibaba's open-code-review shipped v1.12.1 today and claims 4.7x the precision of Claude Code at a fourteenth of the tokensGitHub TrendingStack layer / Threat patternGemini CLI ships an external-context processor to stop indirect prompt injection through build filesGitHub