Stack layer / Threat pattern
Co-signed DAG attestation is the only design that survives child-key compromise in cross-deployer agent delegation
arXiv
Stack layer / Threat pattern
OpenAI Says Astra Is Its First Model to Cross the Critical Cyber Threshold, and It Is Shipping It Behind Gates Anyway
OpenAI / Axios / CSO Online
Stack layer / Threat pattern
Three of Four Major Agent Frameworks Provide No Built-In Confinement for Delegated Authority
arXiv 2609.00267
Stack layer / Threat pattern
A nine-stage lifecycle for agentic skills, from autonomous discovery through marketplace governance
arXiv
Policy dependency / Stack layer
Top open source AI projects are auto-closing external PRs and letting agent "software factories" write a third of merged code
Latent Space
Stack layer / Contrast
Context Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and Codex
arXiv 2609.01222
Stack layer / Update thread
CIPR: how you phrase a request changes whether a poisoned repo compromises your coding agent
arXiv
Stack layer / Contrast
CROSS-CATEGORY: Four Same-Day Launches All Attack Subscription Billing for Agent Infrastructure
Product Hunt and Hacker News Show HN (Monid, SandrPod, ToolJet, C1)