AgentsCVE-2026-27952 Agenta-API Sandbox Escape via NumPyTheHackerWire·high signalXBlueskyLinkedInCopy linkSandbox escape in Agenta-API via incorrectly allowlisted numpy. Same dangerous allowlist pattern as n8n and Langflow.SourceSource pageTheHackerWire↳ Follow the threadShared entity / Actor rolen8n 2.39.0 stops advertising instance MCP OAuth discovery when MCP access is disabledGitHubShared entityn8n 2.38.4 fixes Anthropic agent threads that broke permanently, and keeps a working secrets provider alive when its replacement failsGitHubStack layer / Update threadThe Agentic SDLC Throughput Paradox: Coding Gains Attenuate Sharply Between Writing Code and Shipping ItarXiv 2609.04681Policy dependency / Stack layerHierarchical Ransomware Agents Escalate to Dynamic and Memory Analysis Only on Specialist DisagreementarXiv 2609.04820Stack layer / Update threadOpenAI Agents SDK 0.22.1 adds server-wide guardrails on MCP tools and configurable Unix-local sandbox isolationGitHubStack layer / ContrastNVIDIA and MiniMax released Sol-H3, which generates five seconds of video in 1.653 secondsNVIDIA Research (corroborated by Enze Xie on X)Policy dependency / Stack layerCodex routes MCP elicitations and tool approvals through one decision API, with model policy overriding the legacy review flagGitHubStack layer / Update threadPractitioners running multiple coding agents still have no orchestration layer and are managing sessions by handr/ClaudeAI (68 upvotes, 58 comments)