Stack layer / Threat pattern
Willison and Alex Garcia ship Datasette security releases from their first frontier-model code audit, using three models
Datasette Blog
Stack layer / Threat pattern
GreyNoise Traced One Attacker Running OpenAI's Codex Harness With a DeepSeek Model Through 395 Organizations in 48 Countries
Help Net Security
Stack layer / Threat pattern
OpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.info
rubyhack.ai
Policy dependency / Stack layer
Holding Back Ready Agent Turns Instead of Releasing Them Eagerly Cuts P95 Workflow Latency up to 3.50x
arXiv 2609.10964
Stack layer / Contrast
Cohere Released an Open-Weight 218B Translation Model That Beats DeepL and Google Translate on WMT26
Hugging Face (Cohere Labs)
Stack layer / Threat pattern
Anthropic's September threat report documents autonomous agent swarms, 13 unsupervised collection agents, and a developer token escalated to full admin in three hours
Anthropic
Stack layer / Threat pattern
Anthropic attributes its largest measured distillation campaign to Alibaba: 3 million chain-of-thought exchanges a day from 3,500 fake accounts
Anthropic
Stack layer / Update thread
LLMVul: 21,430 LLM-Generated C/C++ Functions Mined From 226 Production Repos, 1,540 Vulnerable Across 17 CWEs
arXiv 2609.10945