NewsSOUL.md Memory Poisoning: Persistent Agent Compromise via ConfigurationInvariant Labs·high signalXBlueskyLinkedInCopy linkNew attack vector: malicious repos plant hidden instructions in SOUL.md/CLAUDE.md files that persist across sessions.SourceSource pageInvariant Labs↳ Follow the threadPolicy dependency / Stack layerMemSentry gates persistent memory writes on a signed security-state delta rather than on content classificationarXivPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Policy dependency / Stack layerNSA, CISA and FBI Name Six Chinese AI Firms in a Joint Advisory on Industrial-Scale DistillationCISAStack layer / Threat patternAgentAudit attaches to a running agent and scores its trace on ten dimensions, exposing 95.1 vs 22.6 trust spreads at similar task completionarXivPolicy dependency / ContrastA Fine-Tuned 4B Qwen in 2.6 GB Beats GPT-5.6 on a Transit-Kiosk Agent Benchmark, and PEFT Gains Vanish by 27BarXiv 2609.10016Stack layer / ContrastEdge0 runs a 35B MoE on Apple Silicon in 2.9 GB of active memory by streaming experts off SSDGitHubStack layer / Threat patternGoogle's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session ReplayOffSeq Threat RadarStack layer / ContrastA weaker agent recovered 80% of a stronger proprietary agent's capability gap from black-box execution differences alonearXiv 2609.07131