NewsPleaseFix Zero-Click Agent Hijack in Agentic BrowsersZenity Labs·high signalXBlueskyLinkedInCopy linkZenity Labs disclosed PleaseFix vulnerabilities in Perplexity Comet — zero-click file exfiltration via poisoned calendar invites and credential theft through password manager manipulationSourceSource pageZenity Labs↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Four Unrelated Vendors Shipped Agent Authorization Control Planes Inside 48 HoursJetStream (corroborated by Genesys Xperience 2026 coverage, aiagentstore.ai and Hacker News Show HN)Policy dependency / Stack layerFour advisories land on Databricks' Omnigent meta-harness, one critical, all reported by an autonomous security agentGitHub Security AdvisoriesStack layer / Threat patternAccuKnox Ships AgentZ, a Model-Agnostic Agent Platform With Air-Gapped Deploymentaiagentstore.ai daily AI agent newsStack layer / Threat patternThe Post-Training Method, Not the Data, Decides How Refusal Is Computed Inside a ModelarXiv 2609.03887Stack layer / Threat patternsanoTTS puts a complete neural TTS stack in 294k parameters and 337 KB, running on a $3 microcontrollerGitHub (via r/LocalLLaMA, 332 upvotes)Policy dependency / Stack layerCopilot CLI 1.0.83-4 granted sandboxed file tools access to token-bearing configs like ~/.npmrcGitHubStack layer / Threat patternQwen Code 0.23.0 adds scoped workspace memory with enforced filesystem boundaries and cross-session agent messagingGitHubStack layer / Threat patternIn a 100-agent research swarm, one agent's eval exploit spread through the shared knowledge library and other agents organized to stop itarXiv 2609.04170