Fetching from the wire…
Security2026-08-09 · source-backed
James Kettle published the whitepaper August 5, presented at Black Hat and DEF CON (PortSwigger). The architecture detail is what agent builders should copy: Turbo Intruder got an MCP interface plus Python orchestration, and the exploitation agent's script was deliberately split so the LLM could not modify the deterministic segment that judges whether an attack succeeded. Actor separated from verifier, structurally. It brainstormed sixteen response-queue-poisoning hypotheses and autonomously evaluated each against every authorized bug-bounty target, yielding new desync triggers that compromised banks, security products, and government infrastructure. The answer to "can an agent invent, not just find" appears to be yes, when you refuse to let it grade its own work.
Each link below shares sources, entities, or timing with this story.
Three separate Anthropic changes over about two weeks point the same direction, and none of them announced themselves as a strategy. Claude Code 2.1.238 added claude self-hosted-runner --defer-shutdown-max-min, which keeps serving attached sessions on SIGTERM, parks whatever's...
A10 Networks made its AI Gateway generally available on August 14, pitched as a "centralized control plane for unified routing, cost management, and governance across every AI agent, application and large language model" (Help Net Security). SelectHub launched DataGrout the sa...
Raj Nagulapalle's FetchSandbox MCP took 107 votes on August 23, wiring 70+ API sandboxes into Cursor or Claude Code via MCP config. The claim is narrower and more testable than most agent tooling: reproduce the real integration failure against a sandbox, apply the fix, re-run...
Anaconda announced the acquisition August 4, folding in pre-deployment red-teaming across 300+ attack categories, runtime jailbreak and data-leak guardrails, and compliance mapping to NIST AI RMF and the EU AI Act, whose obligations went active August 2. That 73% number should...
The core team released lemans on August 24 after deciding the Ruby community shouldn't have to run Python-based Harbor, and benchmarked four models on 63 Rails tasks (Rails). ox-alpha 52/63; Terra 49/63 at $0.20 and a 182-second median; open-weight Qwen 3.8-27B 48/63 but at a...
OneMCP posted to Show HN on August 23, unifying 20+ MCP servers behind one portal endpoint exposing only search, describe and execute, letting the model script against tools in code rather than reading every schema. The page credits Cloudflare's Code Mode portal pattern as pri...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.