Policy dependency / Stack layer
CROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated Intent
Product Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)
Policy dependency / Stack layer
Retrieval that crosses into your dependencies' source, not just your repo, adds up to 6.3% pass@1 and survives version changes
arXiv 2609.09987
Stack layer / Threat pattern
DeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UI
The Hacker News
Stack layer / Threat pattern
A certification protocol that grants an AI research claim only after matched agents fail to recover the result without its history
arXiv 2609.09219
Policy dependency / Stack layer
Hawley Opens a Senate Investigation Into OpenAI's Handling of the Hugging Face Breach, 16 Questions Due October 1
Axios
Stack layer / Threat pattern
Vibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same Trial
arXiv 2609.09560
Stack layer / Threat pattern
NCP-ArchPreview reaches OLMo-3-7B's final pretraining loss on 51.3% of the tokens by predicting multi-token concepts
arXiv / HuggingFace Daily Papers
Stack layer / Threat pattern
MCPSEC flags indirect-prompt-injection-prone MCP tools from registration metadata alone at 98.9% recall
arXiv 2609.10854