Shared entity / Threat pattern
The MCP Python SDK backported the same session-expiry and issuer-validation defaults to the 1.x line the same afternoon
GitHub
Policy dependency / Stack layer
Hierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist Disagreement
arXiv 2609.04820
Policy dependency / Stack layer
Codex routes MCP elicitations and tool approvals through one decision API, with model policy overriding the legacy review flag
GitHub
Stack layer / Threat pattern
CROSS-CATEGORY: Four Independent Projects in 48 Hours Built the Portability Layer That Moves Lock-In Off the Agent Vendor
Engrim, Kit, Yurei and Crew (via Hacker News Show HN and Product Hunt)
Stack layer / Threat pattern
OpenAI Agents SDK 0.22.1 adds server-wide guardrails on MCP tools and configurable Unix-local sandbox isolation
GitHub
Stack layer / Threat pattern
Codex users are getting 'Cyber Abuse' warnings from OpenAI for security-reviewing their own code, with appeals rejected then reversed
r/OpenAI (79 upvotes, 58 comments)
Stack layer / Threat pattern
Claude Code shipped four releases in five days and the npm 'stable' tag is 27 versions behind 'latest'
Creative AI News (verified against npm dist-tags for @anthropic-ai/claude-code)
Stack layer / Threat pattern
Daniel Vaughan: removing the recovery loop drops agent task completion from 95.0% to 12.9%
Codex Knowledge Base (Daniel Vaughan)