A follow-up security fix shows why wrapper capabilities need path restrictions as well as origin checks: tinyjs 0.48.0 now confines direct PDF writes and requires user confirmation for other locations.
The exploitation signal has strengthened again: CISA added CVE-2026-87902 to KEV on September 25. That turns earlier vendor and security-company telemetry into formal U.S. government confirmation of in-the-wild exploitation.
A new npm granular-token scope lets CI stage package versions without permission to publish them, extending npm’s broader move toward least-privilege publishing after its install-script, trusted-publishing and malware-gate changes.
DuckDB's agent-aware CLI aims to make tool output safer and more compact for coding agents. Its own experiment showed 59% fewer CLI-output tokens but only about 0.5% lower total input cost, so practical gains need careful interpretation.
The bug is a useful warning for AI application plumbing: turning a user-supplied URL into a model attachment also turns the application server into a network client unless the adapter enforces an outbound trust boundary.
This is a useful reminder that exploitation pressure does not scale neatly with plugin popularity: Wordfence says it has blocked more than 250,000 attempts against a plugin with a five-figure install base.
Funes treats agent memory as user-owned data rather than a hosted account feature: retrieval and reranking run locally, provenance stays attached to recalled passages, and cross-machine sharing is optional. The main risk is that publishing session-derived memory can still expose secrets if redaction misses them.
Muse packages persistent autonomous execution, credentials, payments, app access and memory into a mainstream consumer product. A September macOS hotfix now provides an early real-world lesson: agent containment has to protect not only the cloud runtime but also the local control path into the agent.
WebMCP is no longer a Chrome-only browser experiment: Microsoft Edge now has its own active origin trial, while ChatGPT’s built-in browser and WordPress Playground show agent-client and platform implementation paths.
The change creates an authentication compatibility boundary for server-to-server Gemini integrations: an architecture that works in an existing project may not be reproducible with a newly introduced service account, and Google has not published an end date for the restriction.
A security fix for a widely used PostgreSQL vector extension makes index-build permissions and extension patching part of AI search infrastructure hygiene.
The October major release simplifies SvelteKit's architecture but breaks familiar config files and legacy imports. Teams should run the codemod and verify adapters and deployments.
Click2Shell turns a theme-preview parsing bug into a supply-path problem: an attacker can force official catalog code onto a site without the administrator choosing Install, then potentially reach executable pre-activation theme code.
This is not one headline vulnerability fix. Gemini CLI 0.60 is a coordinated hardening pass across the plumbing that lets extensions, sandboxes, filesystem paths and MCP authentication influence an agent’s execution environment.
The checkout ScriptTag shutdown already had an earlier deadline; this is the separate storefront cutoff. Pinning an old Admin API version will not preserve write access after October, and any feature still depending on an injected storefront script stops working in March.
Self-Hosted Machines changes the architecture of Cursor’s Cloud Agents more than another model option would. Teams can keep code, build outputs, secrets and terminal/browser actions on infrastructure they control, but the planning/inference loop remains a Cursor service and enterprise teams become responsible for worker images, scaling, secrets and production validation.
AMD is not just buying another AI software company. It is buying a frontier model lab so the workloads behind spatial intelligence, robotics and simulation can help shape the compute stack AMD builds next.
This is not a speculative browser bug. The vulnerable code sits in Chrome’s JavaScript and WebAssembly engine, exploitation is confirmed, and the remediation boundary is concrete: desktop Chrome needs the September 3 patched build or later.
The architectural shift is from application-wide container configuration toward individually managed stateful compute. A Durable Object can now start its own image and size, keep an independent lifecycle and restore filesystem state without treating every instance as part of one rollout.
Docker’s new agent stack combines pay-as-you-go microVM sandboxes with an OCI-based Kit format for declaring what an agent can use. Cloud sessions cost from $0.07 to $1.12 an hour, and Docker says it plans to take the Kit specification toward CNCF neutral governance.