Latest Issue #09
A "Super Intelligence Force", an unpatched MCP fetch server, and harnesses that memorize their tests
Washington puts a named task force on a voluntary safety accord with no enforcement, MCP's reference fetch server carries a published SSRF with no merged fix, and Google research shows self-improving agent harnesses mostly learn their tests unless regularized.
Items in this brief 15 across 5 sections
Reading time 6min at a relaxed pace
In the archive 9issues Open archive Feed RSS Subscribe Inside the brief
What’s in today’s issue
6 items Today The White House forms a "Super Intelligence Force" under DNI Jay Clayton, on top of the 29 September accord, which has… Essay AI On Sunday, President Trump announced on Truth Social a "Super Intelligence Force" led by Director of National… Essay Tech NVD published CVE-2026-104120 on 2 October against mcp-server-fetch and mcp-server-everything up to 2026.6.4. The… 8 items Also noted Altman to Politico: "the world should accept some bad things happening" for AI's benefits, framed as daylight with… 1 item Papers RRSI: Regularized Recursive Self-Improvement of Agent Harnesses, Google Cloud AI Research (see the AI section above).
Previously
Recent issues
Issue #08 MCP client patches, a safety exit, and eval sandboxes under glass Reference MCP clients patched redirect and session bugs that scanners miss, OpenAI's safety-report lead resigned over culture, UK AISI resumed most testing after cutting agent internet access, and Digst launched a navigable map of digital EU law. 10 items 5 min 4 sections Issue #07 Eval sandboxes, MCP credentials, and agent cloud computers UK AISI hardens and restarts most dangerous-capability evals, official MCP client SDKs disclose OAuth issuer-trust flaws, and dedicated agent cloud computers raise the question of who decides what leaves the box. 11 items 6 min Issue #06 Eval sandboxes harden, attackers lead on AI, banks scale Claude UK AISI restarts most dangerous-capability evaluations after a security rebuild, Microsoft says attackers are capturing AI speed first, OpenAI details a distillation campaign, and Barclays plus Claude Code mods sharpen the enterprise control-plane story. 13 items 6 min Issue #05 Gemini 4 Argon, a Moonshot distillation campaign, and rails for paying agents Google opens Gemini 4 Argon to trusted cyber defenders first, OpenAI says it disrupted a July distillation campaign tied to a Moonshot cluster, and Cloudflare and Microsoft ship clearer rails for paying agents and approving MCP tools. 8 items 6 min Issue #04 OpenAI DevDay: Dots, Astra hold, Sol, and GLM-5.3 cyber OpenAI's DevDay puts always-on Dots agents and the cheaper GPT-6.1 Sol on the table while GPT-6.1 Astra stays withheld, and Anthropic warns that open-weight GLM-5.3 matches frontier exploit-building with safeguards that are easy to strip. 10 items 6 min