Today’s lead · thehackernews.com
A single webpage can turn AutoGen Studio into an RCE path
Microsoft researchers disclosed AutoJack, an exploit chain where an AI browsing agent loads a hostile page, the page reaches AutoGen Studio’s local MCP WebSocket service, and an unauthenticated command path can spawn a host process. The vulnerable surface was not in the stable 0.4.2.2 PyPI release, but did ship in 0.4.3.dev1 and 0.4.3.dev2; the hardening is in GitHub main at commit b047730, not yet a PyPI build. This is the production-agent failure mode I care about most: localhost trust, browser context, MCP, and tool execution collapsing into one boundary.

Top signals
21 moreTools & repos
3 selectedDeusData/codebase-memory-mcp
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
google-research/timesfm
TimesFM (Time Series Foundation Model) is a pretrained time-series foundation model developed by Google Research for time-series forecasting.
palmier-io/palmier-pro
macOS video editor built for AI
Blogs worth your time
0 readsNo long-form read was strong enough to recommend today.
Funding & acquisitions
5 movesUpstream
The inbox designed for humans and agents
Honestly
See what Reddit and TikTok honestly think about your product
Jesse
Stop building Apollo/Clay lists. Search the live internet.
Tabstack Dev Tools
Ditch your scraper. Make one API call with any tool.
Elvin
Proactive AI that finds and finishes work before you ask
Bengaluru radar
0 eventsThere are no relevant Bengaluru events to highlight today.










