{
  "schema_version": 1,
  "updated_at": "2026-09-12T12:54:58.763Z",
  "policy": {
    "new_story_target": 0.6,
    "max_source_share": 0.4,
    "lead_cooldown_editions": 3,
    "min_source_families": 3
  },
  "theme_catalog": [
    {
      "id": "authorization",
      "name": "Agent permissions and delegation"
    },
    {
      "id": "supply_chain",
      "name": "Software supply chain"
    },
    {
      "id": "ai_offense",
      "name": "AI-assisted cyber operations"
    },
    {
      "id": "identity",
      "name": "Identity and access"
    },
    {
      "id": "evaluation",
      "name": "Agent evaluation"
    },
    {
      "id": "agent_builders",
      "name": "Agents building agents"
    },
    {
      "id": "memory",
      "name": "Persistent memory and poisoning"
    },
    {
      "id": "host_security",
      "name": "Host vulnerabilities"
    },
    {
      "id": "ci_security",
      "name": "Agentic CI security"
    },
    {
      "id": "detection",
      "name": "Detection engineering"
    },
    {
      "id": "privacy",
      "name": "Privacy and data protection"
    },
    {
      "id": "formal_methods",
      "name": "Formal methods"
    },
    {
      "id": "multi_agent",
      "name": "Multi-agent coordination"
    },
    {
      "id": "model_security",
      "name": "Model and inference security"
    }
  ],
  "sources": [
    {
      "id": "ruby-central",
      "name": "RubyGems / Ruby Central",
      "family": "ruby-central",
      "first_seen": "2026-09-12"
    },
    {
      "id": "nightingale",
      "name": "Nightingale Collective",
      "family": "nightingale",
      "first_seen": "2026-09-12"
    },
    {
      "id": "zast-ai",
      "name": "CONTINUITY authors / ZAST AI",
      "family": "zast-ai",
      "first_seen": "2026-09-12"
    },
    {
      "id": "anthropic",
      "name": "Anthropic",
      "family": "anthropic",
      "first_seen": "2026-09-12"
    },
    {
      "id": "microsoft",
      "name": "Microsoft / MSRC",
      "family": "microsoft",
      "first_seen": "2026-09-12"
    },
    {
      "id": "sierra-princeton",
      "name": "Hyper-τ-Bench authors / Sierra & Princeton",
      "family": "sierra-princeton",
      "first_seen": "2026-09-12"
    },
    {
      "id": "capture-authors",
      "name": "CAPTURE authors",
      "family": "capture-authors",
      "first_seen": "2026-09-12"
    },
    {
      "id": "cisa",
      "name": "CISA",
      "family": "cisa",
      "first_seen": "2026-09-12"
    },
    {
      "id": "nist",
      "name": "NIST NVD",
      "family": "nist",
      "first_seen": "2026-09-12"
    },
    {
      "id": "google",
      "name": "Google / Gemini CLI",
      "family": "google",
      "first_seen": "2026-09-12"
    }
  ],
  "articles": [
    {
      "title": "RubyGems update on the May spam campaign",
      "url": "https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html",
      "source_id": "ruby-central",
      "kind": "article",
      "published_date": "2026-09-11",
      "summary": "Maintainer reports package removals and registration pause; successful key theft and AI attribution remain unconfirmed.",
      "event_date": "2026-05",
      "evidence": "maintainer statement",
      "id": "a-67402935155ca6d3748f",
      "aliases": [
        "https://blog.rubygems.org/2026/09/11/update-may-spam-publishing-campaign.html"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "RubyHack investigation",
      "url": "https://rubyhack.ai/",
      "source_id": "nightingale",
      "kind": "report",
      "published_date": "2026-09-11",
      "summary": "Artifact-based attribution of package abuse to agents; internal traces and motivation are incomplete.",
      "evidence": "researcher investigation",
      "id": "a-1b17405a376aebe8441d",
      "aliases": [
        "https://www.rubyhack.ai/"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CONTINUITY: authorization across agent components",
      "url": "https://arxiv.org/abs/2609.05269",
      "source_id": "zast-ai",
      "kind": "paper",
      "published_date": "2026-09-04",
      "summary": "Authenticated context and contracts bind permissions to external effects; deterministic conformance evidence, not universal security.",
      "aliases": [
        "https://arxiv.org/abs/2609.05269",
        "https://arxiv.org/html/2609.05269v1#S12"
      ],
      "identifiers": [
        "arxiv:2609.05269"
      ],
      "evidence": "preprint",
      "id": "a-7ed49810d5b80c239103",
      "first_seen": "2026-09-12"
    },
    {
      "title": "September 2026 threat intelligence report",
      "url": "https://anthropic.com/threat-intelligence-report-september-2026",
      "source_id": "anthropic",
      "kind": "report",
      "published_date": "2026-09-10",
      "summary": "Provider observations of AI-assisted espionage and adaptation after detection.",
      "independence_note": "Credits cross-provider collaboration; not independent corroboration of Microsoft.",
      "evidence": "provider telemetry",
      "id": "a-7cf7dcdfb3244d7263d1",
      "aliases": [
        "https://www.anthropic.com/threat-intelligence-report-september-2026"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CaptiveCrunch: Midnight Blizzard targets travelers",
      "url": "https://microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft",
      "source_id": "microsoft",
      "kind": "report",
      "published_date": "2026-07-31",
      "summary": "Hospitality networks, credential theft, and hunting guidance; earlier context for the September threat report.",
      "independence_note": "Collaborative reporting with Anthropic and OpenAI.",
      "evidence": "provider investigation",
      "id": "a-9b1f619a2748525c8a74",
      "aliases": [
        "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "Hyper-τ-Bench",
      "url": "https://arxiv.org/abs/2609.04611",
      "source_id": "sierra-princeton",
      "kind": "paper",
      "published_date": "2026-09-04",
      "summary": "Benchmark evaluates agents that build agents from incomplete requirements, with simulated stakeholders and limited trials.",
      "identifiers": [
        "arxiv:2609.04611"
      ],
      "evidence": "preprint",
      "id": "a-2490f63ce48f127d9692",
      "aliases": [
        "https://arxiv.org/abs/2609.04611"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "sierra-research/hyper-tau-bench",
      "url": "https://github.com/sierra-research/hyper-tau-bench",
      "source_id": "sierra-princeton",
      "kind": "repo",
      "published_date": null,
      "summary": "MIT benchmark artifact with construction tasks and execution traces; Docker and model APIs.",
      "date_note": "Associated with September 4 paper; repository creation date not asserted.",
      "id": "a-9b99333e3b60bc727ead",
      "aliases": [
        "https://github.com/sierra-research/hyper-tau-bench"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CAPTURE: memory preference authenticity",
      "url": "https://arxiv.org/abs/2609.02265",
      "source_id": "capture-authors",
      "kind": "paper",
      "published_date": "2026-09-02",
      "summary": "Evaluates genuine preference updates versus poisoning; adaptive attackers outperform a fixed attack policy.",
      "identifiers": [
        "arxiv:2609.02265"
      ],
      "evidence": "preprint; code forthcoming",
      "id": "a-d8421147fdba635d9151",
      "aliases": [
        "https://arxiv.org/html/2609.02265v1"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "zast-ai/continuity",
      "url": "https://github.com/zast-ai/continuity",
      "source_id": "zast-ai",
      "kind": "repo",
      "published_date": null,
      "summary": "MIT reference verifier, faults, ablations, and raw results; research prototype.",
      "date_note": "Associated with September 4 paper; repository creation date not asserted.",
      "id": "a-988a212a0b09849620e8",
      "aliases": [
        "https://github.com/zast-ai/continuity"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CISA adds four known exploited vulnerabilities",
      "url": "https://cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog",
      "source_id": "cisa",
      "kind": "advisory",
      "published_date": "2026-09-08",
      "summary": "KEV addition provides exploitation evidence for the two Windows entries covered in this issue.",
      "evidence": "government catalog update",
      "id": "a-7cb5ade2b45222621522",
      "aliases": [
        "https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CVE-2026-85880 — NVD",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85880",
      "source_id": "nist",
      "kind": "advisory",
      "published_date": "2026-09-08",
      "summary": "Windows ALPC local privilege escalation; vulnerability record.",
      "identifiers": [
        "CVE-2026-85880"
      ],
      "id": "a-63606981a9bfa6b45a16",
      "aliases": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-85880"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CVE-2026-85880 — vendor update",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880",
      "source_id": "microsoft",
      "kind": "advisory",
      "published_date": "2026-09-08",
      "summary": "Windows ALPC local privilege escalation; vendor remediation by Windows build.",
      "identifiers": [
        "CVE-2026-85880"
      ],
      "id": "a-d96555330a2516a65e25",
      "aliases": [
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CVE-2026-81963 — NVD",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81963",
      "source_id": "nist",
      "kind": "advisory",
      "published_date": "2026-09-08",
      "summary": "Windows Update Stack local privilege escalation; vulnerability record.",
      "identifiers": [
        "CVE-2026-81963"
      ],
      "id": "a-2dabc82b4f68124bd55c",
      "aliases": [
        "https://nvd.nist.gov/vuln/detail/CVE-2026-81963"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "CVE-2026-81963 — vendor update",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963",
      "source_id": "microsoft",
      "kind": "advisory",
      "published_date": "2026-09-08",
      "summary": "Windows Update Stack local privilege escalation; vendor remediation by Windows build.",
      "identifiers": [
        "CVE-2026-81963"
      ],
      "id": "a-c831ac3e3a379065cda7",
      "aliases": [
        "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "title": "Gemini CLI headless trust advisory",
      "url": "https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g",
      "source_id": "google",
      "kind": "advisory",
      "published_date": "2026-04-24",
      "summary": "Older context on workspace trust and tool allowlisting in automated agent workflows.",
      "identifiers": [
        "GHSA-wpqr-6v78-jr5g"
      ],
      "evidence": "vendor advisory",
      "id": "a-7e4ec012e8713487e9fc",
      "aliases": [
        "https://github.com/google-github-actions/run-gemini-cli/security/advisories/GHSA-wpqr-6v78-jr5g"
      ],
      "first_seen": "2026-09-12"
    }
  ],
  "stories": [
    {
      "id": "rubygems-agent-abuse-2026",
      "title": "Package abuse and contested agent attribution",
      "identifiers": [],
      "first_seen": "2026-09-12"
    },
    {
      "id": "continuity-security-contracts",
      "title": "Preserving authorization across components",
      "identifiers": [
        "arxiv:2609.05269"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "id": "captivecrunch-ai-espionage-2026",
      "title": "AI-assisted espionage and adaptation",
      "identifiers": [],
      "first_seen": "2026-09-12"
    },
    {
      "id": "hyper-tau-bench",
      "title": "Agents building agents under realistic constraints",
      "identifiers": [
        "arxiv:2609.04611"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "id": "capture-memory-poisoning",
      "title": "Memory updates under adaptive attack",
      "identifiers": [
        "arxiv:2609.02265"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "id": "cve-2026-85880",
      "title": "CVE-2026-85880 — exploited Windows vulnerability",
      "identifiers": [
        "CVE-2026-85880"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "id": "cve-2026-81963",
      "title": "CVE-2026-81963 — exploited Windows vulnerability",
      "identifiers": [
        "CVE-2026-81963"
      ],
      "first_seen": "2026-09-12"
    },
    {
      "id": "gemini-cli-headless-trust",
      "title": "Gemini CLI trust in automated workflows",
      "identifiers": [
        "GHSA-wpqr-6v78-jr5g"
      ],
      "first_seen": "2026-09-12"
    }
  ],
  "editions": [
    {
      "id": "2026-09-12",
      "date": "2026-09-12",
      "title": "Keep authority attached to agent actions.",
      "summary": "Package abuse, authorization contracts, AI-assisted espionage, and the security of persistent agent workflows.",
      "path": "editions/2026-09-12.html",
      "lead_theme_ids": [
        "authorization"
      ],
      "coverage": [
        {
          "story_id": "rubygems-agent-abuse-2026",
          "theme_ids": [
            "supply_chain",
            "authorization"
          ],
          "pillars": [
            "agentic_ai",
            "cybersecurity"
          ],
          "novelty": "new",
          "article_ids": [
            "a-67402935155ca6d3748f",
            "a-1b17405a376aebe8441d"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "continuity-security-contracts",
          "theme_ids": [
            "authorization",
            "evaluation"
          ],
          "pillars": [
            "agentic_ai",
            "cybersecurity",
            "research"
          ],
          "novelty": "new",
          "article_ids": [
            "a-7ed49810d5b80c239103",
            "a-988a212a0b09849620e8"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "captivecrunch-ai-espionage-2026",
          "theme_ids": [
            "ai_offense",
            "identity",
            "detection"
          ],
          "pillars": [
            "agentic_ai",
            "cybersecurity"
          ],
          "novelty": "new",
          "independence_note": "The two reports are related and collaborative, not fully independent corroboration.",
          "article_ids": [
            "a-7cf7dcdfb3244d7263d1",
            "a-9b1f619a2748525c8a74"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "hyper-tau-bench",
          "theme_ids": [
            "agent_builders",
            "evaluation"
          ],
          "pillars": [
            "agentic_ai",
            "research"
          ],
          "novelty": "new",
          "article_ids": [
            "a-2490f63ce48f127d9692",
            "a-9b99333e3b60bc727ead"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "capture-memory-poisoning",
          "theme_ids": [
            "memory",
            "evaluation"
          ],
          "pillars": [
            "agentic_ai",
            "cybersecurity",
            "research"
          ],
          "novelty": "new",
          "article_ids": [
            "a-d8421147fdba635d9151"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "cve-2026-85880",
          "theme_ids": [
            "host_security"
          ],
          "pillars": [
            "cybersecurity"
          ],
          "novelty": "new",
          "urgent_reason": "CISA KEV addition on 2026-09-08; prioritize verified exposure.",
          "article_ids": [
            "a-7cb5ade2b45222621522",
            "a-63606981a9bfa6b45a16",
            "a-d96555330a2516a65e25"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "cve-2026-81963",
          "theme_ids": [
            "host_security"
          ],
          "pillars": [
            "cybersecurity"
          ],
          "novelty": "new",
          "urgent_reason": "CISA KEV addition on 2026-09-08; prioritize verified exposure.",
          "article_ids": [
            "a-7cb5ade2b45222621522",
            "a-2dabc82b4f68124bd55c",
            "a-c831ac3e3a379065cda7"
          ],
          "is_first_coverage": true
        },
        {
          "story_id": "gemini-cli-headless-trust",
          "theme_ids": [
            "ci_security",
            "authorization"
          ],
          "pillars": [
            "agentic_ai",
            "cybersecurity"
          ],
          "novelty": "context",
          "article_ids": [
            "a-7e4ec012e8713487e9fc"
          ],
          "is_first_coverage": true
        }
      ],
      "variety": {
        "new_story_share": 0.875,
        "source_family_counts": {
          "ruby-central": 1,
          "nightingale": 1,
          "zast-ai": 2,
          "anthropic": 1,
          "microsoft": 3,
          "sierra-princeton": 2,
          "capture-authors": 1,
          "cisa": 1,
          "nist": 2,
          "google": 1
        },
        "warnings": [],
        "errors": [],
        "override_reason": null
      },
      "payload_sha256": "ac1d66d77f9399df86bd227ef89922973576c6d8d1c751a21f97a3d1ec6ccb1f"
    }
  ]
}
