Today’s lead · thehackernews.com
A hostile webpage can break out through an agent host
Microsoft researchers detailed AutoJack, an exploit chain against AutoGen Studio where a browsing agent that opens an attacker page can reach a privileged local MCP WebSocket and trigger host command execution. The vulnerable code shipped in the 0.4.3.dev1 and 0.4.3.dev2 PyPI pre-releases, while the fix is currently in GitHub main at commit b047730 rather than a patched PyPI release. This caught my attention because it is the exact production failure mode agent builders keep underestimating: untrusted web content, localhost assumptions, MCP-style tool surfaces, and code execution all living too close together.

Top signals
19 moreTools & repos
3 selectedDeusData/codebase-memory-mcp
High-performance code intelligence MCP server. Indexes codebases into a persistent knowledge graph — average repo in milliseconds. 158 languages, sub-ms queries, 99% fewer tokens. Single static binary, zero dependencies.
google-research/timesfm
TimesFM (Time Series Foundation Model) is a pretrained time-series foundation model developed by Google Research for time-series forecasting.
palmier-io/palmier-pro
macOS video editor built for AI
Blogs worth your time
0 readsNo long-form read was strong enough to recommend today.
Funding & acquisitions
5 movesClaude Code Artifacts
Preview and share your coding work live as it happens
Zernio WhatsApp API
One API for WhatsApp: messaging, calling, and AI agents
Midjourney Scanner
60 second ultrasound-based full-body scanner that beats MRI
Firecrawl Research Index
An index for agents pushing the frontier of AI/ML research
API to MCP
Turn any API into an MCP server for AI agents
Bengaluru radar
0 eventsThere are no relevant Bengaluru events to highlight today.













