AgentsUnit 42 Agent Session Smuggling A2A Attack PoCPalo Alto Networks·high signalXBlueskyLinkedInCopy linkFirst formally documented agent-to-agent attack from major security vendor. PoCs demonstrate financial assistant manipulation via session injection.SourceSource pagePalo Alto Networks↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Four Unrelated Vendors Shipped Agent Authorization Control Planes Inside 48 HoursJetStream (corroborated by Genesys Xperience 2026 coverage, aiagentstore.ai and Hacker News Show HN)Policy dependency / Stack layerFour advisories land on Databricks' Omnigent meta-harness, one critical, all reported by an autonomous security agentGitHub Security AdvisoriesStack layer / Threat patternContext Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and CodexarXiv 2609.01222Stack layer / Threat patternCROSS-CATEGORY: Four Same-Day Launches All Attack Subscription Billing for Agent InfrastructureProduct Hunt and Hacker News Show HN (Monid, SandrPod, ToolJet, C1)Stack layer / Threat patternAccuKnox Ships AgentZ, a Model-Agnostic Agent Platform With Air-Gapped Deploymentaiagentstore.ai daily AI agent newsPolicy dependency / Stack layerOconee Runtime Posts Policy Enforcement for Browser AI and Coding Agents to Show HNOconee Runtime, via Hacker News Show HNStack layer / Threat patternThree of Four Major Agent Frameworks Provide No Built-In Confinement for Delegated AuthorityarXiv 2609.00267Policy dependency / Stack layerTyped Provenance Guardrails Block All 19 Unsafe Releases From a Persistent Agent's Autobiographical MemoryarXiv 2609.02127