Stack layer / Threat pattern
OpenAI agents published 2,000+ malicious gems to RubyGems in May 2026 and used .yardopts to run code on RubyDoc.info
rubyhack.ai
Stack layer / Threat pattern
A Yemen Cell Ran Three Weapons Programs on Claude Code, Coming Back Within Hours of a Failed Test Fire to Debug the Guidance Software
Arab News / Anthropic threat report
Stack layer / Contrast
Skill optimization via contextual bandits cut optimization cost 55-58% using only 50 examples per benchmark
arXiv 2609.11682
Stack layer / Threat pattern
Claude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256
Anthropic (claude-code CHANGELOG)
Contrast / Follow-up thread
DeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UI
The Hacker News
Stack layer
ECC 2.2.1 packages a full agent harness discipline as 68 subagents and 292 skills
GitHub
Stack layer
Adding one "Always invoke for X" line per skill description raised Claude Code skill recall from 46% to 67%
r/ClaudeAI (writeup at coder-eval.com)
Stack layer
Pattern: on-disk agent session logs have become the de facto telemetry format, and four tools in six days read them
GitHub