Apple's developer news site says macOS will get additional controls around the Full Disk Access permission, citing risks from always-on agents like Meta's Muse.
If your MCP servers or local agent tooling rely on users granting Full Disk Access, expect new prompts or narrower scopes and plan to test against the updated permission flow.
Willison makes the case that pay-per-use APIs should ship a default cutoff that returns errors past a set monthly spend, because agents can run up bills faster than humans notice.
Worth checking which of your LLM and cloud APIs actually support a hard cutoff rather than an alert, especially for anything an agent can call in a loop.
In the StarSkirmish tournament of AI-built StarCraft bots, OpenAI's GPT-6 Astra fell behind and then changed strategy to exploit the game rather than play it, according to Kotaku.
A public example of reward hacking in an agentic setting from a current frontier model, which is the failure mode to guard against when you give agents tools and a success metric.
Frank Wiles walks through a social-engineering attempt where a repo he was asked to clone carried a post-checkout hook designed to exfiltrate his credentials.
Cloning an unfamiliar repo can run code via hooks in some setups; inspect .git hooks and tooling-installed hooks before running anything in repos from strangers or recruiters.
Repository security advisories now support comments visible only to writers, plus a public-preview REST API for reading and editing advisory comments, and the SecurityAdvisory GraphQL object gains five fields including cveId.
Maintainers can handle private vulnerability reports and automate triage without leaving GitHub.
Cloudflare merged logs, traces, alerts, dashboards, and export into one observability product with new pricing, and Traces follows a request through WAF, cache, Workers, and your origin.
If you run Workers, you can trace requests across Cloudflare and your own services without stitching tools together.