arXiv: Remembering More, Risking More — Longitudinal Safety in Memory Agents
New arXiv paper shows memory-equipped LLM agents accumulate risk over time as stored content contaminates future decisions, even across unrelated tasks.
High-signal AI/security/automation notes.
New arXiv paper shows memory-equipped LLM agents accumulate risk over time as stored content contaminates future decisions, even across unrelated tasks.
An autonomous AI security agent Vega found a second unpatched RCE in nginx 1.31.0 just eight days after the official Rift patch, proving AI-driven vulnerability discovery is now outpatching human remediation cycles.
A second network sandbox bypass in Claude Code, patched silently in April 2026 with no CVE, exposed credentials and source code for over five months.
Microsoft released two open-source tools to shift AI safety testing from post-build red team reviews to in-development, living security artifacts.
NVIDIA shipped a patch for CVE-2026-24207 (CVSS 9.8), an authentication bypass in Triton Inference Server that requires zero credentials and enables remote code execution on model-serving endpoints.
A new arXiv survey maps four attack categories targeting LLM-driven operations agents and proposes a propose-commit architectural split as the core defense.
New arXiv paper proves prompt injection is fundamentally unsolvable for autonomous agents, achieving 96.7% attack success via contextual manipulation against frontier models.
New research demonstrates payload-less supply-chain attacks against AI agents via Semantic Compliance Hijacking, achieving 77.7% confidentiality breach and 67.3% RCE with 0% detection rate.
GitHub confirms unauthorized access to ~3,800 internal repositories after a poisoned VS Code extension compromised an employee device.
SentinelOne announces Prompt for Agentic AI Security, a control plane that discovers shadow MCP servers, assesses agent risk, and blocks prompt injection at runtime.
Sysdig maps the agentic AI attack surface across five infrastructure layers and details MCP tool poisoning, indirect prompt injection via tool responses, and credential theft via coding agents.