Topics · Category
Developer tools
146 items briefed across the archive.
-
AUG 8, 2026 — AI learns to write genomes, and to outlast a shutdown
NVIDIA open-sources NOOA, turning an AI agent into a single Python classThe model-agnostic framework collapses prompts, tool schemas, and workflow graphs into one class, and scored 86.8% on a vulnerability-rediscovery benchmark using GPT-5.5.
MarkTechPost
-
AUG 8, 2026 — AI learns to write genomes, and to outlast a shutdown
Cursor open-sources Mixture-of-Kittens, its MoE training megakernelThe Apache-2.0 kernel fuses all mixture-of-experts communication into one deterministic pass on GB300 NVL72 racks, claiming a 2.37x speedup while training Cursor's own Composer model.
MarkTechPost
-
AUG 8, 2026 — AI learns to write genomes, and to outlast a shutdown
xAI ships Grok Build 1.0, a CLI and dashboard for agentic coding runsThe first stable release polishes xAI's agentic coding tool with dashboard and CLI improvements, landing the same week Musk says Grok 4.6 is due.
xAI
-
AUG 7, 2026 — Google's brain drain meets AI's accountability gap
Swiftlet runs an 80B-parameter Qwen model in 4.3GB of RAM on a MacThe open-source runtime streams expert weights from storage instead of holding them in memory, and gets a 35B model running natively on an iPhone for the first time.
Hacker News / Show HN
-
AUG 7, 2026 — Google's brain drain meets AI's accountability gap
Tricentis acquires Tabnine to ground its testing agents in real codebasesThe enterprise testing vendor buys the AI coding assistant to give its QA agents the kind of codebase context that generic test generators lack.
Business Wire
-
AUG 6, 2026 — The scaffolding cracks before the models do
Firecrawl open-sources anydoc, a sub-5ms Rust document-to-Markdown parserThe MIT-licensed engine converts 14 formats — PDF, Word, PowerPoint, EPUB, and more — to clean Markdown with no ML models and no external services.
GitHub
-
AUG 6, 2026 — The scaffolding cracks before the models do
MCP's new stateless spec is reshaping agent tooling almost overnightThe 2026-07-28 Model Context Protocol update drops session state, and Simon Willison calls it the most significant change to the spec since it launched.
Simon Willison
-
AUG 5, 2026 — The week everyone argued about who's driving
Rust adopts a formal LLM contribution policy after months of 'slop PR' fightsThe rust-lang/rust repo now bans LLM-authored PRs outright while permitting private use for review, questions, and suggestions — contributors must disclose LLM use.
Inside Rust Blog
-
AUG 5, 2026 — The week everyone argued about who's driving
Simon Willison ships an LLM tool update with reasoning-trace and server-side tool supportThe new release of his LLM command-line tool adds OpenAI Responses support and smarter logging for agentic workflows.
Simon Willison
-
AUG 4, 2026 — A billion users, a nuclear bet, and a price war
"Devtools must be open source," argues exe.devThe pitch: an open-source agent like Shelley lets users personalize a tool by prompting it to change its own source, no config system required.
exe.dev, via Simon Willison
-
AUG 3, 2026 — AI aces the math, but everything downstream is creaking
Y Combinator open-sources QM, the multi-agent harness it runs itself onMIT-licensed and cloud-first, YC uses the Slack- and web-native harness across its own accounting, legal, and engineering work — including building QM itself.
Y Combinator
-
AUG 2, 2026 — Robots got bodies while regulators got teeth
GitHub Copilot in Visual Studio gets an SDK-based agentJuly's update adds an agent built on the Copilot SDK, built-in .NET/Azure skills, inline code review, and org-wide custom instructions.
GitHub
-
AUG 2, 2026 — Robots got bodies while regulators got teeth
Keychron open-sources gaming mouse firmwareZGM, built on Zephyr RTOS under GPL 3.0, is the first open-source firmware for gaming mice — a shot at an industry of closed, unauditable peripherals.
PC Gamer
-
AUG 1, 2026 — The build-out gets bigger, the frontier gets cheaper
GitHub launches Stacked PRs in public previewA first-party workflow for chaining dependent pull requests, handling the rebase and merge-sequencing pain that made the pattern painful before.
GitHub
-
JUL 31, 2026 — The buildout outruns the guardrails
"2x, not 10x": a developer's sober accounting of what LLMs actually save in 2026Today's top Hacker News post argues further model gains won't unlock 10x productivity — the remaining gains come from retooling workflows around what models can already do.
obryant.dev
-
JUL 31, 2026 — The buildout outruns the guardrails
xAI open-sources Grok Build, its Rust-based terminal coding agentThe full agent harness, TUI, and tool layer behind xAI's coding CLI is now Apache 2.0, weeks after researchers caught it over-uploading users' repos.
MarkTechPost
-
JUL 31, 2026 — The buildout outruns the guardrails
Anatomy of a frontier lab agent intrusion: a technical timelineA detailed technical walkthrough of how an OpenAI agent escaped its test sandbox and reached Hugging Face's infrastructure, pieced together from public disclosures.
Simon Willison
-
JUL 30, 2026 — Washington becomes AI's banker and its bouncer
Open-source engine runs Gemma 4's 26B model in ~2GB of RAM on any M-series MacTurboFieldfare streams the mixture-of-experts model's inactive weights from SSD, keeping only a 1.35GB core in memory — a real squeeze on consumer hardware.
Hacker News
-
JUL 29, 2026 — The week AI got good at finding cracks — including its own
GitHub Models shuts down for good tomorrowThe playground, catalog, inference API, and BYOK all go dark July 30 for every customer — a deadline worth checking your pipelines against today.
GitHub Changelog
-
JUL 29, 2026 — The week AI got good at finding cracks — including its own
Simon Willison's field guide to which AI to actually useA practical, opinionated rundown of which model fits which job now that the interesting comparisons are agentic, not just chat quality.
Simon Willison
-
JUL 27, 2026 — The week nothing stayed inside its walls
BitChat's mesh network gets live push-to-talk voiceThe offline Bluetooth-mesh chat app added signed, streaming voice bursts over its encrypted mesh, no phone number or account required.
GitHub
-
JUL 27, 2026 — The week nothing stayed inside its walls
Sophos: AI coding agents keep tripping the alarms built for hackersClaude Code, Cursor, and Codex routinely fire endpoint-security rules for credential access and persistence because their normal work looks exactly like an intrusion.
The Hacker News
-
JUL 27, 2026 — The week nothing stayed inside its walls
TypeScript 7.0 ships with its compiler rewritten in GoThe native Go port of the TypeScript compiler is generally available, cutting full-build type-checking times by 8x to 12x.
Microsoft
-
JUL 27, 2026 — The week nothing stayed inside its walls
Decker, a HyperCard-flavored hypermedia tool, tops Hacker NewsA free, 1-bit-graphics revival of HyperCard's card-and-script model for e-zines and point-and-click games hit #1 on HN's front page.
Hacker News
-
JUL 26, 2026 — Open weights become a loyalty test
A Mesosphere co-founder argues open-weight AI needs its 'Kubernetes moment'The essay topped Hacker News within a day, arguing labs must standardize model formats now or lock developers into competing ecosystems permanently.
Tobi Knaup
-
JUL 26, 2026 — Open weights become a loyalty test
An open-source Claude skill strips 20+ tics of AI-sounding writingPeter Yang's /no-ai-slop tool edits out fake-profound closers and throat-clearing openers while explaining every change, and hit 1,000 stars in a day.
GitHub
-
JUL 25, 2026 — Bug-hunting becomes an AI product category
Linux kernel publishes 440 CVE advisories in 24 hours, a quarter traced to AI auditingAt least 24 of the disclosures explicitly credit 'Sashiko,' the kernel's AI code-review system, for catching memory-safety bugs across XFS, Bluetooth, and KVM.
Cybersecurity News
-
JUL 24, 2026 — AI's capex race outruns its safety margins
Show HN: Bento packs an entire editable, collaborative slide deck into one 560KB HTML fileNo install, no cloud login, no server — open the file in a browser and you can edit, present, and collaborate on the spot.
Hacker News
-
JUL 24, 2026 — AI's capex race outruns its safety margins
AegisAI, founded by ex-Google security execs, raises $36M to fight AI-crafted phishingBattery Ventures leads a round for agents that catch AI-written spear-phishing the way a human would, not by rule-matching.
TechCrunch
-
JUL 23, 2026 — The week nothing stayed inside its box
Claude Code v2.1.217 adds emoji shortcode autocomplete and reliability fixesType :heart: for ❤️, get warnings when transcript writes fail, and tighter limits on subagent behavior round out the release.
GitHub
-
JUL 23, 2026 — The week nothing stayed inside its box
Gemini quietly deprecates temperature, top_p, and top_k on its newest modelsThe sampling parameters are now accepted and silently ignored on Gemini 3.6 Flash and beyond; Google says future versions will reject them outright.
Hacker News
-
JUL 21, 2026 — The sandbox stopped holding
Four separate AI-agent security disclosures this month share one root flawCursor's DuneSlide, Claude for Chrome's ClaudeBleed, Grok Build's silent uploads, and an npm credential-stealer all trace back to trusting an origin nobody verified.
The Next Web
-
JUL 20, 2026 — Every gate in AI got tested at once
'ClaudeBleed' reopened: Claude for Chrome still lets rogue extensions read your GmailEight releases after Anthropic was first warned in May, any extension can still trick the side panel into reading Gmail, Docs, and Calendar.
Manifold Security
-
JUL 20, 2026 — Every gate in AI got tested at once
npm v12 blocks install scripts by default in its biggest security overhaul yetThe release also curbs Git dependencies and remote sources after a year of worm-like supply-chain attacks targeting developer credentials.
Tech Times
-
JUL 19, 2026 — The week AI got physical
Apache Ossie enters the ASF Incubator as a vendor-neutral metadata standardThe renamed Open Semantic Interchange project, backed by Snowflake, Databricks, and Salesforce, wants one shared spec for exchanging semantic metadata across BI and AI platforms.
Apache Software Foundation
-
JUL 19, 2026 — The week AI got physical
JetBrains Rider 2026.2 RC bakes in native GitHub Copilot and 'agent skills'The release candidate exposes Rider's profiler, coverage, and code-analysis data to AI agents via official Microsoft .NET, Aspire, and Azure skills.
The JetBrains Blog
-
JUL 19, 2026 — The week AI got physical
Visual Studio's July release adds built-in AI-powered skills for agentic workflowsThe update ships pre-built 'skills' from the .NET and Azure teams for agent-driven coding, alongside a new theme-customization page.
Microsoft Learn
-
JUL 19, 2026 — The week AI got physical
'Hallmark,' an anti-AI-slop design skill for coding agents, tops 11,000 GitHub starsThe Together AI-built skill runs 57 'slop-test' gates to stop Claude Code, Cursor, and Codex from defaulting to the same purple-gradient hero section every time.
GitHub
-
JUL 17, 2026 — The week everyone claimed to be open
Claude Code v2.1.212 adds session-wide spawn and search capsThe release caps WebSearch calls and subagent spawns at 200 per session, auto-backgrounds MCP calls over two minutes, and adds a `/subtask` command replacing the old subagent behavior.
GitHub
-
JUL 17, 2026 — The week everyone claimed to be open
GitHub Copilot CLI ships a prompt-refinement command and a plugin marketplaceVersion 1.0.71 adds a `/refine` command, repo-level settings via `.github/copilot/settings.json`, and plan-mode file-modification blocking, among 60-plus changes.
GitHub
-
JUL 17, 2026 — The week everyone claimed to be open
Anaconda acquires Kilo Code, the open-source coding agent used by 3M+ developersKilo, which orchestrates roughly 10 trillion tokens a month across VS Code, JetBrains, and CLI, joins Anaconda's platform and stays unchanged for existing users — for now.
Anaconda
-
JUL 15, 2026 — The guardrails show up all at once
Compromised AsyncAPI npm packages deliver multi-stage botnet malwareAttackers used a GitHub Actions token exploit to backdoor four packages with 3M+ weekly downloads, dropping an info-stealer and RAT via IPFS.
The Hacker News
-
JUL 15, 2026 — The guardrails show up all at once
Malicious jscrambler npm release drops a Rust infostealer targeting AI coding-tool credentialsA hijacked publishing token pushed five poisoned versions harvesting cloud, crypto, and Claude Desktop/Cursor/Windsurf/Zed credentials before being caught within hours.
The Hacker News
-
JUL 15, 2026 — The guardrails show up all at once
TypeScript 7.0 reaches general availability with a native Go compilerThe Go-ported compiler runs 8–12x faster on large codebases — VS Code's 2.3M-line project drops from 125.7s to 10.6s to type-check.
Microsoft DevBlog
-
JUL 14, 2026 — The bill comes due for moving fast
Claude Code sends 33,000 tokens before it even reads your promptA teardown finds Claude Code's system prompt and tool schemas cost 4.7x more overhead than OpenCode's, eating a sixth of the context window before you type anything.
GIGAZINE
-
JUL 13, 2026 — Nobody's checking anybody's homework
Grok Build ships usage tracking, voice mode, and better agent handlingVersion 0.2.98 adds richer cost tracking, Voice mode for API-key sessions, and smoother MCP handling for xAI's coding CLI.
xAI
-
JUL 12, 2026 — The week scale ran into friction
Attackers backdoor an Injective Labs SDK on npm to steal crypto wallet keysA compromised maintainer account pushed a poisoned @injectivelabs/sdk-ts release that harvested private keys and seed phrases before it was pulled less than an hour later.
The Hacker News
-
JUL 12, 2026 — The week scale ran into friction
LangChain ships OpenWiki, a CLI that keeps AI agents' documentation of your codebase currentThe open-source tool auto-generates and maintains an 'agent wiki' via a scheduled GitHub Action, so coding agents get codebase context without bloated instruction files.
LangChain
-
JUL 11, 2026 — This week, everybody crossed a line
GPT-5.6's Sol, Terra, and Luna land in GitHub Copilot the same week they shippedAll three GPT-5.6 tiers reach general availability in Copilot simultaneously, from hard agentic coding (Sol) to a cheap fast option (Luna).
GitHub Changelog
-
JUL 11, 2026 — This week, everybody crossed a line
"Friendly Fire": coding agents can be tricked into running malicious code via a repo's READMEA hidden-instruction proof-of-concept gets both Claude Code and OpenAI Codex to execute an attacker's payload when asked to "review" a repo — a design flaw, not a patchable bug.
The Hacker News
-
JUL 11, 2026 — This week, everybody crossed a line
OpenClaw ships v2026.7.1-beta.5 with AI-guided onboarding and a redesigned session UIThe 210K-star open-source agent adds GPT-5.6 and Muse Spark 1.1 support plus an `openclaw attach` command for external harness sessions.
GitHub
-
JUL 11, 2026 — This week, everybody crossed a line
Bun's creator rewrote it from Zig to Rust — largely by letting a pre-release Claude Fable 5 do it960,000 lines ported in 11 days, ~$165K in API spend, 64 parallel Claude instances running an implementer/reviewer workflow against each other.
Bun (Jarred Sumner)
-
JUL 10, 2026 — The week the frontier outran its guardrails
Cognition's SWE-1.7 lands in Devin, built on a Kimi K2.7 baseCognition's coding model adds 12 points of post-training on top of Moonshot's Kimi K2.7, hitting near-frontier scores on Devin at a fraction of the cost.
Cognition
-
JUL 10, 2026 — The week the frontier outran its guardrails
Ollama raises $65M Series B as its model runner nears 9 million developersTheory Ventures led the round, taking Ollama's total to $88M as weekly installs keep climbing and Fortune 500 adoption reaches 85%.
TechCrunch
-
JUL 9, 2026 — Every lab picked a new frontier this week
npm v12 blocks install scripts and Git dependencies by defaultnpm's biggest security overhaul in 16 years disables auto-running install scripts by default, after two North Korean supply-chain campaigns this year.
Tech Times
-
JUL 8, 2026 — Three labs just failed their own safety report card
Herdr turns your terminal into a control room for juggling multiple AI coding agentsThe open-source Rust tool tracks whether Claude Code, Copilot, Devin, and a dozen other agents are working, blocked, or done, right in a terminal sidebar.
GitHub
-
JUL 8, 2026 — Three labs just failed their own safety report card
JetBrains lets teams run Claude, Copilot, and Codex agents side by side from one pickerA new Skills Manager and credit-usage dashboard aim to turn scattered individual AI usage into coordinated, team-visible development.
JetBrains Blog
-
JUL 8, 2026 — Three labs just failed their own safety report card
Tencent open-sources Hy3, a 295B coding model it says beats DeepSeek-V3The Apache-2.0 MoE model routes between fast and deep-reasoning experts and claims sharply lower hallucination rates than its April preview.
MarkTechPost
-
JUL 7, 2026 — The week AI oversight got teeth
Simon Willison: stop burning your best model's usage limit on grunt workHis new rule of thumb — route routine implementation to a cheap subagent, keep judgment and review in the main loop — is stretching his Fable allowance noticeably further.
Simon Willison
-
JUL 5, 2026 — The bill for agentic AI starts arriving
sqlite-utils 4.0rc2 ships, mostly written and reviewed by Claude FableFable caught five release-blocking bugs, including one that silently poisoned the database connection on delete.
Simon Willison
-
JUL 4, 2026 — The record streak nobody wants credit for
Kimi K2.7 Code is now generally available in GitHub CopilotMoonshot AI's open-weight model becomes the first non-proprietary option in Copilot's model picker, rolling out first to Pro, Pro+, and Max plans.
GitHub Changelog
-
JUL 4, 2026 — The record streak nobody wants credit for
GitHub Models is being fully retired on July 30The free model playground, catalog, and inference API shut down for all customers after two brownout tests, with Azure AI Foundry as the pitched migration path.
GitHub Changelog
-
JUL 4, 2026 — The record streak nobody wants credit for
pxpipe cuts Claude Code bills by rendering context as imagesA local proxy renders bulky prompt context as PNGs to exploit image-vs-text token pricing, cutting bills 59-70% — at the cost of occasionally garbling exact strings.
GitHub
-
JUL 3, 2026 — The chip market flinched, the money didn't
Ornith-1.0: open coding models that write their own RL scaffoldsThis MIT-licensed coding model family generates its own task-specific training scaffold instead of a human-designed one; the 397B flagship beats Claude Opus 4.7 on SWE-Bench Verified.
Simon Willison / DeepReinforce
-
JUL 3, 2026 — The chip market flinched, the money didn't
Anthropic removes Claude Code's covert marker for Chinese usersSince April, Claude Code had silently swapped one of four identical-looking Unicode apostrophes to encode a user's timezone and proxy signals, discovered when a Reddit user reverse-engineered a disabled feature.
The Register
-
JUL 2, 2026 — Washington wants equity in AI, not just oversight
GitHub Copilot's in-editor browser tools reach general availabilityCopilot agents in VS Code can now drive a real browser by default — navigate, click, screenshot, read console errors.
GitHub
-
JUL 2, 2026 — Washington wants equity in AI, not just oversight
VS Code 1.127 adds multi-session chat and terminal sandboxingA redesigned agent UI lets users run several Copilot chats at once, plus sandboxed terminal execution for safer agent commands.
Microsoft
-
JUL 1, 2026 — Loosen the model, tighten the rules
Rust 1.96.1A patch release fixes a Cargo retry bug and a rustc MIR-optimization miscompilation, plus libssh2 security patches for three CVEs.
Rust Blog
-
JUL 1, 2026 — Loosen the model, tighten the rules
Cursor Mobile App for iOSCursor, now part of SpaceX after its $60B acquisition, shipped a public-beta iOS app for launching and steering coding agents, reviewing diffs, and merging PRs from a phone.
Cursor
- xAI launches /goal in Grok Build, adding long-running autonomous execution with built-in verification
Grok Build's new /goal mode builds its own task checklist, executes each step, and runs a verification pass before marking the task done — pulling Grok deeper into the same autonomous coding lane as Codex and Claude Code.
MarkTechPost
- Exclusive: Agentic coding startup Baz brings code reviews to the planning stage with $17M in seed funding
Baz Planner intercepts implementation plans before a line of code is committed, routing ideas through AI loops that root-cause vulnerabilities in the design itself — early customers report 65% fewer reverts and hotfixes post-merge.
SiliconANGLE
-
JUN 27, 2026 — Access by appointment only
Gemini in Chrome adds 'Select from screen'Gemini in Chrome can now pull any visible tab content into a conversation without copy-pasting — a quiet quality-of-life feature that shipped alongside the Gemini 3.5 Flash computer use announcement.
9to5Google
-
JUN 27, 2026 — Access by appointment only
Google transitions Gemini CLI to Antigravity CLI, removes free personal tierGoogle rebuilt its open-source terminal AI agent in Go for speed, rebranded it Antigravity CLI, and dropped the free personal-account access tier that had made the original a popular entry point.
Google Developers Blog
-
JUN 23, 2026 — The receipts came in
DifyTap flaws let attackers silently read AI chats across Dify tenantsZafran found four bugs in the open-source agent platform — two unauthenticated, three with cross-tenant reach — letting attackers wiretap other customers' AI conversations on a platform powering 1M+ apps.
The Hacker News
-
JUN 22, 2026 — The week the U.S. took the keys
OpenCode hits 160K stars as MCP becomes the agent lingua francaThe open-source coding agent now claims 7.5M monthly active developers and 75+ provider integrations; MCP servers and air-gapped deployment look increasingly like table stakes.
byteiota
-
JUN 21, 2026 — The grip keeps slipping
Headroom, a context-compression tool for AI agents, hits #1 on GitHub trendingBuilt by a Netflix engineer, Headroom strips 60–95% of tokens from tool outputs and logs before they hit the LLM, without moving benchmark scores.
Trendshift
-
JUN 21, 2026 — The grip keeps slipping
Mistral ships a Vibe coding extension for VS Code, still eyeing its own chipsVibe's new VS Code extension runs project-wide coding tasks on Mistral Medium 3.5, as CEO Arthur Mensch keeps floating in-house chip design to cut token costs.
Mistral AI
-
JUN 21, 2026 — The grip keeps slipping
13 words in a Reddit comment can poison what AI search agents recommendCornell's WARP attack got deep-research agents to cite a fake restaurant and dating app in up to 62% of runs, with no new pages planted.
arXiv (Cornell Tech)
-
JUN 21, 2026 — The grip keeps slipping
Grok lands natively on Databricks Agent BricksAnnounced at Databricks' Data + AI Summit, Grok is now one selection away for any enterprise already running pipelines on Databricks' Lakehouse.
xAI
-
JUN 20, 2026 — The control layer underneath the hype
One-click M365 Copilot flaw could've leaked emails and MFA codesVaronis found a chained exploit (CVE-2026-42824) using prompt injection and an SSRF to exfiltrate Microsoft 365 Copilot data with a single click; Microsoft patched it pre-disclosure.
The Hacker News
-
JUN 20, 2026 — The control layer underneath the hype
Klue OAuth breach lets 'Icarus' group raid Salesforce CRMsA stolen OAuth token from Klue's abandoned Salesforce integration let the Icarus extortion group steal CRM data from Recorded Future, Tanium, Jamf, and others.
BleepingComputer
-
JUN 20, 2026 — The control layer underneath the hype
CISA warns FortiBleed leak exposes 74,000 VPN devicesCISA says leaked FortiGate SSL VPN credentials, cracked from intercepted auth hashes with a 45-GPU cluster, are being used to hijack Windows Active Directory domains.
The Hacker News
-
JUN 20, 2026 — The control layer underneath the hype
Epic Games open-sources Lore, a Git rival for big filesEpic open-sourced Lore, a Rust-based, MIT-licensed version control system for projects mixing code with huge binary assets — a free alternative to Perforce.
Phoronix
-
JUN 19, 2026 — Who's allowed to decide what AI can do
F5 Patches Two Critical NGINX Flaws Enabling Remote Code ExecutionF5 patched a critical NGINX HTTP/3 flaw (CVSS 9.2) that lets unauthenticated attackers crash or potentially execute code via a crafted QUIC session; fixes exist for only two of four affected products.
The Hacker News
-
JUN 19, 2026 — Who's allowed to decide what AI can do
Google Ends Unrestricted Gemini API Keys to Curb AbuseStarting today, Google's Gemini API rejects requests from standard API keys with no restrictions applied, closing a long-telegraphed loophole that let leaked or scraped keys rack up abuse on someone else's bill.
Cybernews
-
JUN 19, 2026 — Who's allowed to decide what AI can do
LiteLLM Bug Chain Let Low-Privilege Users Seize Admin and Run CodeResearchers chained three LiteLLM bugs (CVSS 9.9) to escalate from low-privilege user to full admin and remote code execution on AI gateway servers, exposing every provider key the proxy holds.
The Hacker News
-
JUN 18, 2026 — Every layer of the stack creaked this week
Malicious JetBrains plugins quietly stole AI API keysFifteen marketplace plugins posing as AI coding assistants — installed nearly 70,000 times — forwarded users' OpenAI and DeepSeek API keys to an attacker-controlled server in plaintext.
BleepingComputer
-
JUN 18, 2026 — Every layer of the stack creaked this week
Apple ships container 1.0, an open-source Docker Desktop rivalThe Swift-native tool runs each Linux container in its own lightweight VM on Apple Silicon, beating Docker on throughput but still missing Compose and full DevContainer support.
byteiota
-
JUN 18, 2026 — Every layer of the stack creaked this week
Nvidia open-sources a scanner for malicious AI agent skillsReleased the same week as the Mastra npm attack, SkillSpector scans installable agent skills for known vulnerability patterns — research behind it found 26% are flawed.
MarkTechPost
-
JUN 17, 2026 — The jailbreak that wasn't
ponytail: a GitHub-trending skill that makes coding agents think like 'the laziest senior dev in the room'Before writing a line, the agent checks whether the code needs to exist at all, then whether stdlib or an existing dependency already does it — claims 80-94% less generated code.
GitHub
-
JUN 17, 2026 — The jailbreak that wasn't
Chrome's last Manifest V2 workaround dies June 30, taking uBlock Origin's full filtering with itGoogle is removing the flag developers used to keep old-style ad blockers alive in Chrome; without dynamic filtering, uBlock Origin Lite is the most powerful version that survives.
Digital Trends
-
JUN 15, 2026 — Fable 5 had a three-day run
Perplexity Open-Sources Bumblebee: A Supply-Chain Scanner for Dev EndpointsRead-only Go scanner for macOS and Linux checks npm, PyPI, Go modules, and eight other package ecosystems, plus MCP configs and editor extensions for known compromises.
Perplexity
-
JUN 15, 2026 — Fable 5 had a three-day run
OpenAI Acquires Astral (uv, Ruff, ty) and Promptfoo in Back-to-Back DealsAstral's Python tooling moves into Codex; Promptfoo's AI security testing platform goes into OpenAI Frontier — both projects remain open-source.
OpenAI
-
JUN 14, 2026 — Ten thousand bugs, one Gemini phishing kit
Linux Kernel 7.0 officially drops the 'experimental' label from RustReleased in April, Kernel 7.0 formally promotes Rust to stable — the first time in the kernel's 35-year history that a language other than C has been officially sanctioned for driver development.
Linuxiac
-
JUN 13, 2026 — Open weights, open markets
Koog 1.0: JVM-native framework by JetBrains for building AI agentsJetBrains shipped Koog 1.0 at KotlinConf 2026 — an open-source, stable AI agent framework for Kotlin and Java with a 1-year API stability guarantee and Spring Boot integration.
JetBrains
-
JUN 13, 2026 — Open weights, open markets
AI dev tool power rankings & comparison [June 2026]Claude Code is the most-loved coding tool at 46% developer preference — nearly 2.5x Cursor's share — with 55% of surveyed developers now regularly using AI agents.
LogRocket
-
JUN 12, 2026 — The labs are going public
Upcoming breaking changes for npm v12npm v12 will disable install scripts from all dependencies by default — GitHub calls lifecycle scripts 'the single largest code-execution surface in the npm ecosystem.'
GitHub Changelog
-
JUN 11, 2026 — The labs race to Wall Street
Copilot SDK is now generally availableGitHub's Copilot agentic engine is now embeddable in any app via a stable SDK across six languages, with MCP server support, custom tool registration, and fine-grained system prompt control.
GitHub
-
JUN 11, 2026 — The labs race to Wall Street
GitHub Copilot app: The agent-native desktop experienceA standalone Copilot desktop app launched with 'canvases'—persistent workspaces where agent work takes shape visibly before landing in your repo.
GitHub
-
JUN 11, 2026 — The labs race to Wall Street
Updates to GitHub Copilot billing and plansAll Copilot plans switched to GitHub AI Credits usage-based billing on June 1, with a new $100/month Copilot Max tier for heavy agentic users.
GitHub
-
JUN 10, 2026 — Fable 5, an IPO filing, and Musk's cloud
GitHub Copilot gains Max plan and remote session control from mobileGitHub's new Copilot Max tier ($100/month in AI credits) includes remote control for active CLI sessions — kick off an agent in the terminal, then steer or pause it from your phone or browser mid-run.
GitHub Blog
-
JUN 10, 2026 — Fable 5, an IPO filing, and Musk's cloud
OpenCV 5.0 ships with built-in LLM/VLM support and a rewritten DNN engineOpenCV 5 — released today, timed with CVPR 2026 — adds native LLM and VLM inference inside the DNN module, covers 80%+ of the ONNX spec (up from 23% in v4), and drops the legacy C API in favor of C++17.
OpenCV
-
JUN 8, 2026 — The recursion arrives, and Apple waves it in
GitHub Copilot App: The Agent-Native Desktop ExperienceGitHub's new standalone Copilot desktop app surfaces active sessions, issues, PRs, and background automations in a single My Work view — available in technical preview for paid Copilot users.
GitHub Blog
-
JUN 8, 2026 — The recursion arrives, and Apple waves it in
MAI-Code-1-Flash: Microsoft's Copilot-Native Coding Model Has Different Benchmarks Than You'd ExpectMicrosoft's first homegrown coding model was trained inside Copilot's production tool harness, uses 60% fewer tokens than comparable models on hard tasks, and is already live in the Copilot model picker.
ChatForest / Microsoft Build
-
JUN 8, 2026 — The recursion arrives, and Apple waves it in
Google and Kaggle Relaunch Free 5-Day AI Agents Course with Vibe CodingThe free five-day intensive returns June 15–19, this time focused on building production-ready agents using natural-language-first workflows — registration open now on Kaggle.
Google Blog
-
JUN 7, 2026 — The week AI went public — and personal
Koog 1.0 Is Out: Stable Core, Better Interop, and Multiplatform ObservabilityJetBrains' open-source AI agent framework for Kotlin and Java ships its first stable release with a one-year API guarantee, OpenTelemetry support, and a Mercedes-Benz production case study.
JetBrains
-
JUN 7, 2026 — The week AI went public — and personal
Microsoft and Google Take On Anthropic and OpenAI in AI Coding ModelsMicrosoft and Google are mounting direct challenges to Claude Code and OpenAI Codex with their own enterprise AI coding tools, opening a new front in the coding assistant wars.
CNBC
-
JUN 5, 2026 — The week Washington found its AI voice
Kotlin 2.4 ships with an 18-month security support policyKotlin 2.4 adds a formal security support policy backporting fixes to all active release lines for 18 months — a quiet but meaningful enterprise-readiness signal.
JetBrains Kotlin Blog
-
JUN 4, 2026 — The bill for AI arrives
Anthropic Claude Agent SDK: TypeScript and Python toolchain for MCP-native agentsAnthropic's new Agent SDK lets developers wire Claude Sonnet and Opus directly into MCP servers and sub-agent hierarchies with first-party TypeScript and Python tooling.
devFlokers
-
JUN 4, 2026 — The bill for AI arrives
OpenClaw hits 210k GitHub stars — local AI gateway for WhatsApp, Slack, and 50+ integrationsThe personal AI assistant that runs locally and routes across 50+ messaging and productivity integrations has become one of the fastest-growing open-source projects of 2026.
OSSInsight
-
JUN 4, 2026 — The bill for AI arrives
Perplexity open-sources Bumblebee, a read-only supply-chain scanner for developer endpointsBumblebee scans npm, PyPI, Go modules, editor extensions, browser extensions, and MCP configs for supply-chain exposure — zero dependencies, single static binary, Apache 2.0.
GitHub / Perplexity AI
-
JUN 3, 2026 — Washington blinks first at frontier AI
Supply chain attack hits 32 Red Hat npm packagesAttackers compromised a Red Hat GitHub account to inject the Miasma credential-stealing worm into 32 @redhat-cloud-services packages, with hooks targeting Claude, Codex, Gemini, Copilot, and GitHub Actions tokens.
Wiz
-
JUN 3, 2026 — Washington blinks first at frontier AI
TrustFall: coding agent security flaw enables one-click RCE in Claude, Cursor, Gemini CLI, and GitHub CopilotA single Enter keypress can hand attacker code full developer machine access across four major AI coding platforms via malicious MCP server auto-approval embedded in a poisoned repository.
Adversa AI
-
JUN 3, 2026 — Washington blinks first at frontier AI
SymJack: symlink-hijack RCE in five AI coding agentsA booby-trapped repository can silently overwrite an AI coding agent's config via a disguised symlink, triggering attacker code on the next restart — confirmed against Claude Code, Cursor, Gemini CLI, Copilot, Grok Build, and Codex CLI.
Adversa AI
-
JUN 3, 2026 — Washington blinks first at frontier AI
Our response to the TanStack npm supply chain attackOpenAI describes its mitigations after Codex developer tokens were targeted by the Mini Shai-Hulud npm supply chain campaign that hit TanStack in May.
OpenAI
-
JUN 2, 2026 — AI bills come due
Angry devs vow to flee GitHub Copilot as metered billing takes holdStarting June 1, Copilot PR reviews also drain GitHub Actions minutes on top of AI Credits — a double-billing that caught many teams off guard.
The Register
-
JUN 2, 2026 — AI bills come due
Anthropic designs three-agent harness for long-running full-stack AI developmentA plan/generate/evaluate architecture splits responsibilities across three specialized agents to keep autonomous workflows from drifting on long tasks.
InfoQ
-
JUN 2, 2026 — AI bills come due
51% of code committed to GitHub is now AI-generated or substantially AI-assistedThe share crossed the halfway mark in Q1 2026, up from roughly a third a year ago, with the biggest gains in test generation and boilerplate.
Sourcery Intel
-
JUN 1, 2026 — The meter drops on AI coding
Cursor reportedly raising at $50B valuation after hitting $2B ARRCursor hit $2B in annualized revenue by February — the fastest SaaS company to that milestone — and is seeking new funding at a $50B valuation.
TechCrunch
-
MAY 31, 2026 — The week the agent became the story
Grok Build, xAI's terminal coding agent, expands to all SuperGrok subscribers at $30/monthThe 16-subagent parallel CLI runs on a 2M token context window and is now the cheapest full-featured terminal coding agent in the category after last week's tier expansion.
xAI
-
MAY 31, 2026 — The week the agent became the story
Cursor 3.5 ships cloud agents in isolated VMs with multi-repo and async reportingCursor's cloud agents run full-terminal sessions across multiple repositories and notify you when work is complete, removing the need to babysit agent runs.
Cursor
-
MAY 31, 2026 — The week the agent became the story
Claude Code v2.1 adds /goal command, plugin loading from URLs, and broader MCP supportThe CLI now tracks cross-turn completion conditions via /goal, loads plugins from .zip archives or URLs, and gains global Ctrl+R history search.
Anthropic / Releasebot
-
MAY 30, 2026 — The labs are buying the scaffolding
Simon Willison: vibe coding and agentic engineering are convergingIn a widely-discussed post, Willison admits that the line he once carefully drew between disciplined agentic engineering and looser vibe coding has 'started to converge' in his own workflow.
Simon Willison's Weblog
-
MAY 30, 2026 — The labs are buying the scaffolding
Malicious VS Code extension stole credentials in 18 minutesA trojanized Nx Console extension lived on the VS Code Marketplace for 18 minutes but harvested 1Password, Claude Code, npm, and AWS credentials before removal.
The Hacker News
-
MAY 29, 2026 — Faster models, stubbornly flat gains
Harness engineering: OpenAI uses Codex to improve CodexOpenAI's Codex now generates the majority of its own codebase — the team says the improvement curve has been steep, consistent, and faster than purely human-driven development.
OpenAI
-
MAY 28, 2026 — The battle for AI's implementation layer
Andrej Karpathy's CLAUDE.md behavioral principles repo hits 156K GitHub starsA developer turned Karpathy's viral observations about LLM coding pitfalls into a single CLAUDE.md file with four behavioral principles — and the community responded with one of the fastest star climbs ever.
Professor Glitch / GitHub
-
MAY 28, 2026 — The battle for AI's implementation layer
Cursor 3.4 launches Cloud Agent Environments with multi-repo workspacesCursor's cloud agent environments support multi-repo workspaces with Dockerfile-based configuration and 70% faster cached image layers, moving AI coding agents closer to production-grade infrastructure work.
SD Times
-
MAY 28, 2026 — The battle for AI's implementation layer
OpenClaw reaches 210,000 GitHub stars — fastest-growing open-source AI project of the yearOpenClaw is a local personal AI assistant connecting models to 50+ integrations with no cloud dependency — it surged from 9K to 210K stars, suggesting strong demand for privacy-first AI orchestration.
Professor Glitch / GitHub
-
MAY 27, 2026 — The $900 billion bet, and what surrounds it
Gemini Interactions API: Breaking changes migration guide (May 2026)Google's v1beta Interactions API replaced the outputs array with a steps schema on May 26 — the legacy format is permanently removed June 8, so integrations need updating now.
Google AI for Developers
-
MAY 27, 2026 — The $900 billion bet, and what surrounds it
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIOA 34-package cross-ecosystem campaign targeted crypto and AI developers, with a new technique: poisoning CLAUDE.md and .cursorrules files to hijack AI coding assistants into exfiltrating credentials.
The Hacker News
-
MAY 26, 2026 — Capital piles in. The Pope speaks. Agents go ambient.
GitHub Copilot shifts to usage-based billing on June 1All Copilot plans move to credit-based consumption pricing next week, a pricing model change driven by agentic workflows that render flat per-seat rates unworkable.
GitHub Blog
-
MAY 26, 2026 — Capital piles in. The Pope speaks. Agents go ambient.
Claude Code skills repo tops GitHub trending with 55K+ starsMatt Pocock's 'skills' repository — reusable Claude Code agent capabilities — hit #1 on GitHub trending this week, a signal of how fast the Claude Code ecosystem is expanding.
GitHub Trending
-
MAY 26, 2026 — Capital piles in. The Pope speaks. Agents go ambient.
Google Antigravity 2.0 unifies agentic development under one platformGoogle's Antigravity 2.0 is a desktop app for managing multiple AI agents simultaneously, positioned as the single development environment for agent-first applications.
Google Cloud Blog
-
MAY 25, 2026 — Everything's on sale except the company building it
ServiceNow Build Agent now works inside every major AI coding tool, governed by defaultServiceNow's Build Agent is now generally available and embeds directly into Cursor, Windsurf, Claude Code, and GitHub Copilot with enterprise governance turned on by default.
ServiceNow
-
MAY 25, 2026 — Everything's on sale except the company building it
5 xAI Grok Updates You May Have Missed This MayGrok Skills — persistent custom expertise that carries across sessions — went live May 18, alongside new integrations with Vercel, Canva, Gamma, and S&P Global market data.
Basenor
-
MAY 24, 2026 — The proof, the hire, the lecture
Cursor hits $2B ARR — the fastest B2B SaaS ramp on recordThe AI code editor doubled its ARR in three months to reach $2B — faster than Slack, Zoom, or Snowflake — and is now raising $2B more at a $50B valuation with Nvidia as co-investor.
TechCrunch
-
MAY 24, 2026 — The proof, the hire, the lecture
Parallel Web Systems hits $2B valuation with $230M raised for AI agent infrastructureParallel builds web-search and research APIs specifically for AI agents; used by Clay, Harvey, and Notion, and backed by Sequoia, Index, and Kleiner Perkins.
TechCrunch
-
MAY 24, 2026 — The proof, the hire, the lecture
Top 5 Trending AI GitHub Repos — May 2026 (Week 18)Nous Research's Hermes Agent framework crossed 105K stars and took the top spot; agent orchestration and reusable skills repos now dominate GitHub trending over general-purpose utilities.
Professor Glitch
-
MAY 23, 2026 — The trillion-dollar week
WebMCP | AI on Chrome | Chrome for DevelopersGoogle proposed WebMCP as an open standard for exposing structured JavaScript tools to browser AI agents, with an origin trial in Chrome 149 and early implementation commitments from Booking.com and Shopify.
Chrome for Developers
-
MAY 23, 2026 — The trillion-dollar week
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential StealerAttackers injected a 5,900-line credential stealer into 700-plus Laravel-Lang package versions via GitHub tag injection, harvesting cloud keys and browser passwords silently through Composer's autoloader.
The Hacker News
-
MAY 21, 2026 — The AI compute bill comes due
xAI introduces its coding agent called Grok BuildxAI's Grok Build runs up to 8 parallel agents on Grok 4.3 beta with a 2M-token context window; currently in early beta for $300/month SuperGrok Heavy subscribers only.
Engadget
-
MAY 21, 2026 — The AI compute bill comes due
ServiceNow Build Agent now works inside every major AI coding tool, governed by defaultServiceNow's AI build agent is now embedded in Cursor, Windsurf, Claude Code, and GitHub Copilot, extending enterprise governance into whatever IDE a developer happens to use.
ServiceNow Newsroom
-
MAY 21, 2026 — The AI compute bill comes due
All the news from the Google I/O 2026 Developer keynoteAntigravity 2.0 ships with a new CLI, cross-platform terminal sandboxing, and specialized subagents — Google's agent orchestration layer, now with a proper developer-facing API.
Google Developers Blog
-
MAY 21, 2026 — The AI compute bill comes due
codegraph: pre-indexed code knowledge graph for Claude CodeA trending open-source tool that pre-indexes codebases into structural knowledge graphs for Claude Code, letting agents navigate large repos with less per-request context churn.
GitHub
-
MAY 20, 2026 — Frontier models cheat, find zero-days, get deployed anyway
Introducing Composer 2.5Cursor's in-house model, built on a Kimi K2.5 base with 85% of compute on proprietary RL post-training, scores 79.8% on SWE-Bench Multilingual—tied with Claude Opus 4.7's 80.5%.
Cursor
-
MAY 20, 2026 — Frontier models cheat, find zero-days, get deployed anyway
Compose Multiplatform 1.11.0 Is Now AvailableThe release ships native UIView-based text input for iOS—with system autocomplete, handles, and Translate—and reworked touch processing to fix long-lagging web scrolling performance.
JetBrains