NewsPleaseFix Zero-Click Agent Hijack in Agentic BrowsersZenity Labs·high signalXBlueskyLinkedInCopy linkZenity Labs disclosed PleaseFix vulnerabilities in Perplexity Comet — zero-click file exfiltration via poisoned calendar invites and credential theft through password manager manipulationSourceSource pageZenity Labs↳ Follow the threadStack layer / Threat patternCohere Released an Open-Weight 218B Translation Model That Beats DeepL and Google Translate on WMT26Hugging Face (Cohere Labs)Stack layer / Threat patternA2ABreak extracts a 37-state machine from the A2A spec and finds 11 protocol-level flaws that a fully compliant attacker can exploitarXivStack layer / Threat patternGreyNoise Traced One Attacker Running OpenAI's Codex Harness With a DeepSeek Model Through 395 Organizations in 48 CountriesHelp Net SecurityStack layer / Threat patternMinitap Accuses Google's Artemis of Copying Its Apache-2.0 Mobile-Agent Code and Force-Pushing the Authors' Names OutMinitapThreat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsThreat pattern / ContrastTwo agent IDEs now ship the same sentence, and one of them has more open PRs than open issuesGitHubStack layer / Threat patternOne in Seven Python Samples That Pass Bandit and Semgrep Still Carries a Runtime-Confirmed ExploitarXivStack layer / Threat patternResearchers Say Coding-Agent Sandboxes Leak in Claude Code, Codex and Cursor, and Anthropic Took 50 Days to PatchUpstarts Media