Latest news across AI, security, and the OpenClaw ecosystem.
AIPS v7.0 is a Claude Code plugin that moves shared AI setup into global files under ~/.claude/ while keeping only the minimum project-specific state in each repo. The project says this reduces repeated setup work, preserves sessions after /clear or crashes, and supports migration from v6.0 with one command.
Source: HN Show HNAnthropic has revised its disclosure policy for Mythos, its unreleased cybersecurity-focused AI model in Project Glasswing. Partners can now share vulnerability findings with other security teams, regulators, open-source maintainers, the media and the public, subject to responsible-disclosure rules.
Source: The Next WebDify v1.14.2 is a patch release that tightens tenant isolation, restricts tool credential changes, and fixes several workflow, tracing, and knowledge-base issues. The update also changes Docker environment file layout and requires a database migration for configurable Explore app categories.
Source: Dify ReleasesMicrosoft Threat Intelligence says the group Storm-2949 used social engineering and abused password reset flows to take over Microsoft Entra ID accounts, then exfiltrated data from Microsoft 365 and Azure resources. The attack spread across App Service, Key Vault, Storage, SQL, and virtual machines, according to Microsoft.
Source: Microsoft Security BlogPeter Steinberger, the creator of OpenClaw and an engineer at OpenAI, said his team spent $1.3 million on OpenAI API tokens in 30 days. The bill came from running about 100 Codex instances and covered 603 billion tokens across 7.6 million requests.
Source: The Next WebOpenClaw’s 2026.5.18 release adds new CLI plugin commands, expanded QA-Lab runtime parity checks, and multiple Gateway and agent fixes. The update also raises the minimum supported Node.js version to 22.19 and changes the Docker/Podman image build flow for extra apt packages.
Source: OpenClaw ReleasesRed Hat says Ansible is becoming the trusted execution layer for agentic AI in IT operations. The company also introduced a new automation orchestrator in Ansible Automation Platform 2.7 and made its Model Context Protocol server generally available.
Source: SiliconANGLEForcepoint says the TeamPCP threat group used a supply chain attack to turn two LiteLLM PyPI releases into credential-stealing malware. The malicious code targeted cloud and AI credentials, including keys for OpenAI, Anthropic, Microsoft Azure, AWS and Google Cloud.
Source: SiliconANGLEOpenAI and Dell Technologies are working together to make Codex available in hybrid and on-premises enterprise environments. The integration is meant to help companies use Codex closer to their data, systems, and workflows, including Dell AI Data Platform and Dell AI Factory setups.
Source: OpenAI NewsAgetor is an open-source, local-first app for orchestrating CLI coding agents such as Claude Code and OpenAI Codex. It runs on the user’s machine, isolates each task in a git worktree, and shows approvals, questions, and run output in a kanban-style UI.
Source: HN Show HNOpenAI has merged ChatGPT, Codex, and its developer API into one product organization under co-founder Greg Brockman, according to an internal memo viewed by Wired. The company says it is focusing on a single agentic platform ahead of a planned IPO, while several side projects have been shut down or paused.
Source: The Next WebApple said Mac mini and Mac Studio supply is sold out in several configurations, and Tim Cook linked demand to agentic AI tools and workflows. Perplexity, OpenClaw, and Hermes Agent all now point developers toward Mac mini as a recommended always-on host for persistent AI agents.
Source: The New StackA new Claude Code skill scans a codebase for OpenAI and Anthropic API calls, classifies what each call is doing, and flags places where deterministic code could replace a model. The skill produces a Markdown audit report and only rewrites code if the user opts in.
Source: HN Show HNMicrosoft employees have open-sourced AI Engineer Coach, a VS Code extension that reads local AI coding session logs and turns them into usage analytics. The tool tracks patterns, flags anti-patterns, and scores context health without sending data off the machine.
Source: HN Show HNAgenda Intel MD is an open-source protocol, schema set, CLI, and MCP server for validating and scoring strategic-risk agent output. The project is aimed at policy, sanctions, regulation, and geopolitical-risk agents, and it checks structure and evidence discipline rather than factual truth.
Source: HN Show HNGitHub has released a technical preview of a standalone Copilot desktop app that manages coding agents, issues, pull requests, and development sessions in one place. The app is available on macOS, Windows, and Linux for Copilot Business and Enterprise users, with Pro users able to join a waitlist.
Source: The New StackCyera says four chainable OpenClaw vulnerabilities, dubbed Claw Chain, could let attackers steal data, escalate privileges, and plant backdoors. OpenClaw says the issues affect its OpenShell sandbox backend and MCP loopback runtime and were fixed in version 2026.4.22.
Source: The Next WebHermes Agent v0.14.0, released May 16, 2026, adds early beta native Windows support, a new PyPI package, and an OpenAI-compatible local proxy for OAuth-only providers. The release also cuts cold-start time, speeds up browser tool calls, and adds new messaging, model, and verification features.
Source: Hermes Agent ReleasesKilo Code says its v7 VS Code rewrite shipped fast but felt too hands-off for some developers. The company has since added expanded reasoning, pre-approval diffs, a unified Changes panel, and other human-in-the-loop fixes, while more review features remain in progress.
Source: Kilo BlogKnowBe4 said it is extending its agent risk management tools to cover both human workers and AI agents. Vice president of AI and data Matt Duren said the company is adding visibility, explainability and tailored training as enterprises deploy more non-human digital workers.
Source: SiliconANGLEOpenAI launched preview personal finance tools for ChatGPT Pro users in the U.S., including bank account connections through Plaid. The company said users can see spending, subscriptions, portfolio performance, and upcoming payments, and it plans to expand support to Intuit later.
Source: TechCrunchChuddy is a self-hosted Telegram bot that downloads audio and video from more than 1,000 yt-dlp-supported sites. It also adds OCR, translation, and a REST API for managing download tasks.
Source: HN Show HNAnthropic is changing Claude subscription pricing so programmatic use will be billed with dedicated monthly credits at API rates, while interactive use through its own tools remains subsidized. The change follows a months-long rollout of blocks on third-party tools such as OpenCode and OpenClaw.
Source: Kilo BlogCyera says four OpenClaw vulnerabilities, nicknamed Claw Chain, can be chained to steal data, escalate privileges, and maintain persistence. OpenClaw says the issues were fixed in version 2026.4.22 and credits researcher Vladimir Tokarev for reporting them.
Source: The Hacker NewsA new MCP server called answering-machine lets Claude Code users leave messages for other users to pick up later. The project says messages are encrypted on the sender’s machine, stored unreadable by the postbox, and deleted after pickup or seven days.
Source: HN Show HNOpenAI said two employee devices were affected by the Mini Shai-Hulud supply chain attack on TanStack, but no user data, production systems, or intellectual property were compromised. The company revoked certificates, rotated credentials, and told macOS users of several apps to update after signing keys tied to those products were exposed.
Source: The Hacker NewsOpenAI has made its Codex coding assistant available on iOS and Android through ChatGPT. The company also added Hooks, Remote SSH, programmatic access tokens and HIPAA support for the standalone client and embedded versions.
Source: SiliconANGLEGitHub announced a technical preview of the GitHub Copilot App as part of a wider shift toward agent-first developer tools. The release comes alongside new Codex mobile features from OpenAI, multi-agent updates in VS Code, and fresh agent infrastructure from LangChain.
Source: Latent SpaceTeamPCP says it is selling nearly 450 repositories tied to Mistral AI for $25,000, and claims it will leak the data if no buyer appears within a week. Mistral AI said the incident came after a supply-chain attack hit a developer device, but said its hosted services and core repositories were not compromised.
Source: BleepingComputerOpenAI has added Codex controls to the ChatGPT app on iOS and Android, letting users monitor and manage coding workflows from a phone. The preview feature is available across all plans, and OpenAI said it lets users review outputs, approve commands, change models, and start new tasks remotely.
Source: TechCrunchOpenAI said two employees’ devices were breached in the TanStack supply chain attack that hit hundreds of npm and PyPI packages. The company said customer data, production systems, and deployed software were not affected, but it rotated code-signing certificates and is requiring some macOS users to update before June 12, 2026.
Source: BleepingComputerIBM has released two Apache 2.0 multilingual embedding models built on ModernBERT: a 97M-parameter compact model and a 311M-parameter full-size model. The company says both support 200+ languages, 32K-token context, and code retrieval across nine programming languages.
Source: Hugging Face BlogOpenClaw’s 2026.5.12 update externalizes several provider and plugin packages, adds fallback runtime backends for ACP turns, and tightens sandbox and credential handling. It also includes a long list of fixes for Telegram, WebChat, sessions, update flow, and auth behavior.
Source: OpenClaw ReleasesPlanBridge is an open-source tool that intercepts coding agents’ plans before code is written, letting users annotate and request changes line by line. It runs locally, integrates with Claude Code and Codex CLI, and keeps plan content on the user’s machine.
Source: HN Show HNSpecdd is a new agent skill that turns feature requests into specs before code is written, according to its GitHub project page. It is designed to work with Claude, Codex, Cursor, Copilot, Windsurf, Gemini CLI and other agents that read SKILL.md or AGENTS.md-style instructions.
Source: HN Show HNBlitzGraph says it is an AI-native backend that models data as graphs and lets agents send typed JSON queries instead of SQL. The project includes built-in validation, full-text search, transactions, and a remote MCP server for Claude and Codex.
Source: HN Show HNMicrosoft says autonomous AI agents need defense in depth because they can take actions, change data, and trigger workflows across systems. The company argues that the application layer - permissions, workflows, identity, and escalation controls - matters most for keeping agents safe in production.
Source: Microsoft Security BlogOkta expanded its AI agent security platform to Amazon Bedrock and other agent ecosystems, while also opening support to customers using non-Okta identity providers. The company said the move is meant to help enterprises discover, onboard, protect and govern AI agents across mixed vendor environments.
Source: SiliconANGLEFreshworks has unveiled Freddy AI Agent Studio, a no-code tool for building and deploying AI agents in Freshservice, along with an MCP Gateway and new AI Insights with xLAs. The company says the features aim to move agents into production faster and improve how IT teams measure employee experience.
Source: SiliconANGLEAnthropic says Claude Pro, Max, Team, and Enterprise subscribers will get a monthly Agent SDK credit starting June 15, 2026. The credit covers Claude Agent SDK use, the claude -p command, GitHub Actions integration, and third-party apps built on the SDK.
Source: r/ClaudeAINotion launched a developer platform that lets teams build custom code, connect external agents, and sync data from other databases into its workspace. The company says customers have already built more than one million Custom Agents since February.
Source: TechCrunchcc-ledger is a local-first ledger for Claude Code activity that records prompts, edits, and per-turn token cost on the user’s machine. Cloud sync to ccledger.dev is optional and only sends aggregates, not raw prompts or transcripts.
Source: HN Show HNAnthropic launched Claude for Small Business, a new set of features inside Claude Cowork for smaller firms. The suite adds bookkeeping, business insights, ad tools and integrations with services such as QuickBooks, Canva, Docusign, HubSpot and PayPal.
Source: TechCrunchJupiterOne has launched two new products, AI Attack Surface Management and Unified Vulnerability Management, to help security teams track AI sprawl and prioritize vulnerabilities. The company says the tools map assets, identities and AI agents together so teams can see what matters to business risk.
Source: SiliconANGLECelonis has acquired Ikigai Labs to add decision-intelligence technology to its process-mining platform. The company says the deal will help power a new Context Model meant to give enterprise AI a real-time view of how businesses operate.
Source: SiliconANGLESAP announced its “Autonomous Enterprise” vision at Sapphire 2026, centered on more than 50 AI assistants and 200-plus agents that can execute business processes. The company also introduced a new AI platform, a redesigned user interface, and developer tools to support governed agent deployment.
Source: CIO AIGremlin is a local, browser-native multi-agent coordinator built in TypeScript and Svelte. It runs without a separate server, supports multiple model providers, and lets users watch agent conversations in real time or inject human input during a run.
Source: HN Show HNVaultBix is a Chrome extension that warns or blocks users when they paste secrets, personal data, or proprietary code into AI tools. The company says detection runs locally in the browser, with no account required and no data sent to a server.
Source: HN Show HNDexgram is a Windows bridge that connects Telegram threaded topics to Codex Desktop threads. It syncs conversations, supports project-bound chats, handles files, and mirrors Codex progress back into Telegram.
Source: HN Show HNAnthropic has introduced Claude for Small Business, a package of connectors and ready-to-run workflows that embeds Claude inside tools such as QuickBooks, PayPal, HubSpot, Canva, Docusign, Google Workspace, and Microsoft 365. The company says the product is designed to help small businesses automate tasks like payroll planning, invoicing, monthly close, and campaign prep.
Source: Anthropic News