NewsCVE-2026-2256: Microsoft Agent Framework RCEMicrosoft MSRC·high signalXBlueskyLinkedInCopy linkCritical RCE in Microsoft Agent Framework via crafted MCP tool responses. CVSS 9.1. Patch available in v0.4.2.SourceSource pageMicrosoft MSRC↳ Follow the threadStack layer / Threat patternMCPHub before 1.0.32 lets an intercepted OAuth authorization code be redeemed for tokensNVDStack layer / ContrastCognition ships SWE-2 on a Kimi K3 base: 92.8% on Terminal-Bench 2.1, and within a point of Fable 5.1 on FrontierCode at 64% lower costCognitionPolicy dependency / Stack layerClaude Code's agent view adds a peek panel so you can answer a blocked session without leaving the listClaude Code DocsStack layer / Update threadSpecGuard Turns Speculative Decoding's Acceptance Rate Into a Free Runtime Backdoor DetectorarXivStack layer / ContrastOne operator ran hundreds of Codex- and DeepSeek-driven agents to compromise 440+ PaperCut servers at 395 organizations in 48 countriesGreyNoiseStack layer / ContrastTrueFoundry open-sources TrueForge, an MIT-licensed agent harness pitched against Claude Managed AgentsTrueFoundryThreat pattern / Update threadCROSS-CATEGORY: Five Launches in 48 Hours Shipped an MCP Server as the Product, Not a Web App With an APIProduct Hunt daily leaderboards for 2026-09-11 and 2026-09-12, plus the Hacker News Show HN feedStack layer / Threat patternClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)