01 / The wire
Recent briefings
-
August 21, 2026 · morning
Four vendors shipped narrower permissions at the exact moment an agent acts, and a Rust crate that ran malware during cargo build showed why the moment of execution is the only place the control matters.
-
August 20, 2026 · afternoon
The agent skill turned into a package format this year, and the packaging shipped well ahead of the registry, the signature, and the scanner that a package format normally needs.
-
August 20, 2026 · morning
Every launch in the last 48 hours assumes nobody will actually read the agent's work, and ships a substitute for reading it.
-
August 19, 2026 · afternoon
Every significant capability gain published in the last 48 hours came from changing the harness around the model instead of the model itself, and none of it shipped with a security evaluation.
-
August 19, 2026 · morning
Three labs spent this week engineering containment against their own models, and the thing being contained is offensive security capability that arrived faster than any of them planned for.
-
August 18, 2026 · afternoon
Five gates went up around the AI stack in forty-eight hours, and the GitHub daily board is quietly voting for everything you can pick up and carry out.
-
August 18, 2026 · morning
AI now reviews code and attacks it, and only the attacking side gets to iterate against live feedback.
-
August 17, 2026 · afternoon
Three separate moves in 48 hours all changed the layer between your app and the model, and not one of them was a model.
02 / Under the surface
Latest analysis
-
The arrayref Attack Turned Cargo's Yank Warning Into the Delivery Mechanism
The arrayref attacker yanked every clean release 24 seconds after publishing the poisoned one, which made Cargo's own deprecation warning…
-
Tencent's AI-Infra-Guard Will Scan Your Agent Stack. Its Own README Says Don't Put It on a Public Network.
AI-Infra-Guard's skills and MCP scan is the most useful free thing you can point at an agent stack, but the platform running it holds your…
-
Ray Guarded Its Job API by Checking Whether Your Browser Said "Mozilla"
Ray protected an unauthenticated job-submission endpoint with a string check on the User-Agent header, and DNS rebinding turned any open…
-
CopilotKit's OpenBot Writes the Audit Row Before the Action
OpenBot's reusable idea is the ordering rather than the sandbox: the audit row is written before the action so a crashed or refused call…
-
817 Cybersecurity Skills, Six Frameworks, and a Coverage Table That Contradicts the Headline
The reusable idea in Anthropic-Cybersecurity-Skills is the per-skill framework mapping rather than the skill count, and the repo's own…
-
Code Review Became Sampling and Nobody Wrote It Down
Teams with coding agents went from 21 to 65 pull requests a week while the number of humans reading them stayed flat, so review has already…
-
StateM Reports 95.3% on Terminal-Bench 2.1 With Frozen Weights. The Word Doing the Work Is 'Raw'
StateM's reproducible claim is the roughly $15 price rather than the 95.3% score, because Terminal-Bench's published leaderboard subtracts…
-
Google Bought 100 Million Spirit Airlines Emails Out of Bankruptcy Court
Bankruptcy court has become a training-data supply line, and the privacy machinery in the code protects the customers a dead company had,…
04 / Coverage map
Topics we track
Claude Code 31 Codex 14 OpenAI 11 Kimi K3 9 Agent Skills 8 DeepSeek Harness 8 Model Context Protocol 8 Hugging Face 7 MCP 7 MCP 2026-07-28 7 Anthropic 6 Anthropic Frontier Red Team 5 Claude Code auto mode 5 Claude Opus 5 5 GLM-5.3 5 GPT-5.6 Sol 5 GPT-5.6-Cyber 5 OpenAI Presence 5 Claude Code self-hosted environments 4 GPT-5.6 Luna 4 grok-build 4 MAI-Cyber-1-Flash 4 Muse Glimmer 4 QM 4