The loudest security story of the day was T3MP3ST, released by jailbreak researcher Pliny: a multi-agent offensive framework that plugs into your existing Claude Code, Codex, or Hermes login and drives real recon — nmap, DNS, HTTP probes — through the agent. What made it spread was that every finding is provenance-gated (you can re-derive each number with a verify-claims command) and kill-chain phases past recon are labeled honestly instead of faked. It reframes a coding-agent subscription as a full red-team console.
International Cyber Digest laid out the framing, and the rest of the feed was unusually concrete: Strix packaged pentest agents you point at your own app, a 1.5B local security model did Blue/Red-team reasoning on CPU, a warning landed that every unknown "AI browser" is a prompt-injection liability, a "Bad Epoll" Linux/Android root 0-day made the rounds, and Stanford's Real World AI Security Conference showcased fresh attack research.