Policy dependency / Stack layer
SGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four Weeks
CERT Coordination Center
Stack layer / Threat pattern
AgentsDock Open-Sources an IDE That Collapses Termius, Cursor and Claude Code Into One Dock
AgentsDock (surfaced on Hacker News item 49678435)
Stack layer / Threat pattern
Gemini CLI ships an external-context processor to stop indirect prompt injection through build files
GitHub
Policy dependency / Threat pattern
An audit of a production agent pipeline found a reported p99 latency of 2,147,483,647 ms, the signed 32-bit maximum, from a lifecycle clamp
arXiv 2609.12017
Stack layer / Threat pattern
A Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full Set
arXiv 2609.11814
Stack layer / Threat pattern
Real-SWE Benchmarks Coding Agents on Licensed Private Production Codebases: Fable 5.1 Tops It at 38.8%, GPT-6 Astra 33.8%
Specific Labs / Hacker News (248pts, 137 comments)
Stack layer / Threat pattern
Archestra platform 1.4.0-beta.8 switches to native Claude Code sign-in for personal subscriptions and exposes durable runtime health metrics
GitHub
Stack layer / Threat pattern
Calif.io's OEMpocalypse chains one strategy from an unprivileged Android app to root on Samsung, Xiaomi and Oppo flagships
Calif.io Research (395 points on Hacker News)