Stack layer / Threat pattern
A Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full Set
arXiv 2609.11814
Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Policy dependency / Stack layer
A replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policies
GitHub
Stack layer / Threat pattern
Elva Launches Against Postman With Flat Workspace Pricing and Specs Generated From Repo Commits
Elva (surfaced via the Product Hunt daily leaderboard for 2026-09-14)
Stack layer / Follow-up thread
Benchmark Radar Ships a Daily-Updated Catalog of 1,283 AI Benchmarks With 12,916 Numeric Score Observations
arXiv 2609.11115
Policy dependency / Stack layer
SGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four Weeks
CERT Coordination Center
Stack layer / Threat pattern
Unlearning Methods That Pass TOFU and MUSE Still Leak the Secret on 22-86% of Queries Once the Model Is an Agent
arXiv 2609.12808
Stack layer / Threat pattern
Gemini CLI ships an external-context processor to stop indirect prompt injection through build files
GitHub