Latest news across AI, security, and the OpenClaw ecosystem.
Microsoft said its new multi-model agentic security system, codename MDASH, helped identify 16 vulnerabilities in Windows networking and authentication components, including four critical remote code execution bugs. The company said the system also scored 88.45% on the public CyberGym benchmark and found all 21 planted bugs in a private test driver with zero false positives.
Source: Microsoft Security BlogAWS has launched a preview of full repository code review in AWS Security Agent. The feature scans an entire codebase, builds a security model of the application, and produces findings with evidence, severity, and remediation guidance.
Source: AWS Security BlogOllama released v0.23.4 on GitHub on May 12, tagging commit 3af1a00. According to the release page, the update adds image modalities for vision models in the launch/opencode branch change set #15922.
Source: Ollama ReleasesOpenAI has launched Daybreak, a cybersecurity platform built to find vulnerabilities, generate patches, and validate fixes in enterprise codebases. The system uses three GPT-5.5 variants and launches with partners including Cisco, CrowdStrike, and Palo Alto Networks.
Source: The Next WebStatewright is a system for constraining AI agents with state machines so they can only use approved tools in each phase of a workflow. The project says this improves reliability in tools like Claude Code, Codex, Cursor, opencode, and Pi, and can boost local-model performance on coding tasks.
Source: HN Show HNYantrikDB is a new memory engine for AI agents that ships with a small default embedder and an MCP server. Its creator says it can recall context, remember decisions, and detect contradictions without extra model downloads or sentence-transformers.
Source: HN Show HNKimiflare is an open-source CLI coding agent that uses Kimi K2.6 on Cloudflare Workers AI. Its creator says the cloud tier will be shut down when expiring Cloudflare credits run out, but the project will remain available as open source and BYOK.
Source: HN Show HNSafeSandbox is a local CLI tool that creates git snapshots while AI coding agents edit a repository. It supports automatic restore points, manual checkpoints, and rollback to earlier states, all on the user’s machine.
Source: HN Show HNA new Telegram/Slack interface lets users control local Codex agents from chat instead of the command line. The tool supports session control, directory mapping, approval requests, and keeps chat-to-session links across restarts.
Source: HN Show HNSAP has invested in workflow automation platform n8n, valuing the company at $5.2 billion, according to n8n. The company also said n8n will be embedded natively inside SAP’s Joule Studio as part of the partnership.
Source: n8n Blogcurl maintainer Daniel Stenberg said Anthropic’s Mythos scan found one confirmed vulnerability and about 20 bugs in curl, after the project reviewed the report. He said the issue will be released as a low-severity CVE with curl 8.21.0 in late June.
Source: r/ClaudeAIRapunzel is a desktop app for managing agent sessions in a tree-based terminal interface, built for people running many long-lived Codex, Claude, or Gemini sessions. It stores workspace state locally, supports branch actions like rename and collapse, and can restore the session tree on launch.
Source: HN Show HNA CISO who still writes code argues that AI coding agents are bringing back “cowboy” engineering: fast, opaque changes that few people fully understand. The article says teams need tighter review, smaller PRs, and better tracking of agent-written code to avoid hidden technical debt.
Source: Kilo BlogDigg has relaunched again, this time as an AI news aggregator that ranks stories using real-time signals from X, according to the company. The beta version is currently focused on AI news and uses metrics such as views, comments, likes, and saves, along with sentiment analysis and clustering.
Source: TechCrunchA public analysis of 7,066 job postings from Hacker News and five other boards found Python, TypeScript, React, and AWS leading demand. The dataset also shows explicit salary ranges in 15% of postings, with a median band of $150K to $210K.
Source: HN Show HNHivemind, a new tool from Activeloop, records coding-agent sessions as structured traces and turns repeated patterns into reusable skills. It supports Claude Code, OpenClaw, Codex, Cursor, Hermes, and pi, and propagates those skills to connected agents on the same team.
Source: HN Show HNSLayer is a semantic layer that sits between databases and AI agents, internal tools, dashboards, and scripts. The project says it can auto-create models from schema, compile queries into SQL, and let agents update models at runtime through MCP, REST, CLI, and Python interfaces.
Source: HN Show HNA Hacker News user introduced a planner app built around separate workspaces for different parts of life, such as work, training, travel, or hobbies. Each planner includes tasks, notes, calendars, and a journal, with a shared Today view that shows scheduled items across planners.
Source: HN Show HNVeles is a new local code search tool written in Rust that combines BM25 keyword search with semantic retrieval. It runs on CPU, stores a persistent on-disk index, and exposes MCP and gRPC interfaces for use with AI agents and other tools.
Source: HN Show HNA new MCP tool for Codex runs app-server reviews of uncommitted changes in a separate context from the main coding session. The project says this reduces regressions, keeps review context clean, and supports longer autonomous runs.
Source: HN Show HNGeopolitical tension, supply chain disruption, and changing regulations are forcing CIOs to rethink global IT strategy. Forrester and several IT leaders say the pressure is also affecting AI spending, compliance, and infrastructure planning across regions.
Source: CIO AIGoogle Chrome has been quietly installing Gemini Nano, a 4GB on-device AI model, on some users’ computers without asking first, according to Swedish computer scientist and lawyer Alexander Hanff. Google says users can disable and remove the model in Chrome settings, and it will stop downloading or updating once turned off.
Source: r/ControlProblemAnthropic has introduced agent view in Claude Code, a new interface for managing multiple agent sessions from one place. The Research Preview is available now on Pro, Max, Team, Enterprise, and Claude API plans, with opt-in through the terminal command `claude agents`.
Source: Claude BlogAnthropic said the Claude Platform on AWS is now generally available, giving AWS customers access to the full Claude API feature set with AWS authentication, billing, and commitment retirement. The service includes Claude Managed Agents, code execution, web search, Files API, Skills, and other features that were previously tied to the native Claude API.
Source: Claude BlogOpenAI CEO Sam Altman said older users tend to treat ChatGPT like a Google replacement, while people in their 20s and 30s use it more like a life advisor. He also said college students are using it like an operating system, with saved prompts, file connections, and constant context from past chats.
Source: r/OpenAIA Hacker News post introduced PerceptAI, a tool that uses OCR and vision models to let AI agents read and act on any screen, not just websites. Its creator said the system uses EasyOCR, Groq Vision, and PyAutoGUI to handle desktop apps and other software without APIs.
Source: HN Show HNagent-postmortem-skill is an open-source verification skill that makes coding agents back up completion claims with evidence. It checks git state, command output, and exit codes before a task can be marked done.
Source: HN Show HNAlibaba is integrating its Qwen AI app with Taobao and Tmall, giving it access to more than 4 billion items and Alipay checkout, Reuters reported, citing a source familiar with the plan. The setup lets shoppers search, compare, track prices and place orders through the AI agent, while Alibaba says the purchase flow can run end to end.
Source: The Next WebDraft is a plugin that adds persistent product context to Claude Code, Codex CLI, and Cursor sessions. The project says it injects a live snapshot of product information at session start and records changes in an append-only log so the context does not go stale.
Source: HN Show HNRemind is a free Mac app that schedules prompts for Claude Code and runs them locally on the user’s machine. The developer says it uses the same files, skills, and CLI tools available at the keyboard, unlike Claude Code’s built-in /schedule feature, which runs on Anthropic’s servers.
Source: HN Show HNWorkspace MCP is a new open source server that gives AI assistants and developer tools control over Google Workspace services including Gmail, Drive, Calendar, Docs, Sheets, Slides, Forms, Tasks, Contacts and Chat. The project says it supports OAuth 2.1, multi-user deployments, stateless mode and central hosting for organizations.
Source: r/LocalLLaMAA new open source guide called How-to-Train-Your-GPT walks readers through building, training, and running a language model from scratch. The 12-chapter, 3,900-line interactive textbook focuses on modern decoder-only Transformer parts such as attention, RoPE, RMSNorm, and KV cache.
Source: HN Show HNA benchmark on Hetzner’s $4.99-per-month CX23 VPS tested SQLite with a 6 GB database that did not fit in RAM. The results showed about 3.9k operations per second for a mixed read/write workload, with the author saying SQLite handled real production-style traffic on the low-cost shared-CPU server.
Source: HN Show HNA new embeddable Share2ChatGPT widget lets sites open ChatGPT with the current page pre-loaded as a prompt. The script is one file, uses data attributes for setup, and supports themes, sizes, languages, and a direct redirect URL.
Source: HN Show HNConcord is a terminal user interface client for Discord that supports browsing servers, reading and sending messages, reactions, polls, file uploads, and image previews. The project can be installed with Homebrew, Cargo, Nix, or a shell installer, and it stores Discord tokens in plain text under ~/.concord/credential.
Source: HN Show HNIntruder, a London cybersecurity startup backed by GCHQ’s Cyber Accelerator, has launched AI pentesting agents that mimic human methodology and return results in minutes. The company says the tools can help midmarket firms test faster and at lower cost than manual penetration tests, which can run $10,000 to $50,000.
Source: The Next WebStrings found in ChatGPT for Android version 1.2026.125 suggest OpenAI is working on remote control for Codex desktop sessions from phones. The feature would let users reconnect to desktop coding sessions, add Codex shortcuts, and manage remote threads through the mobile app.
Source: r/OpenAIAnthropic says it reduced agentic misalignment in Claude models by changing safety training, including teaching the model to explain why actions are better and using more diverse data. The company says newer Claude models now score zero on its blackmail evaluation, though it says alignment remains an unsolved problem.
Source: r/ControlProblemSignegy is a free, open-source PDF toolkit that runs entirely in the browser, according to its launch page. It offers signing, merging, splitting, compressing, and other PDF tools without requiring an account or uploading files to a server.
Source: HN Show HNCyberSecQwen-4B is a 4-billion-parameter cybersecurity model built for local use, according to its creator. The project says it was fine-tuned for tasks like CWE classification and CTI Q&A, and it was benchmarked against Cisco’s Foundation-Sec-Instruct-8B under the CTI-Bench protocol.
Source: Hugging Face BlogKept is a local-first knowledge manager that saves AI conversations as Markdown files on the user’s machine. It supports ChatGPT, Claude, Gemini, Grok, and Kimi, and adds local search, graph views, and an MCP server for agentic tools.
Source: HN Show HNOpenAI released three new streaming audio models in its Realtime API: GPT-Realtime-2, GPT-Realtime-Translate, and GPT-Realtime-Whisper. The company says GPT-Realtime-2 adds better reasoning, longer context, tool use, and interruption handling for voice agents, while the other two models handle live translation and transcription.
Source: Latent SpaceAWS has added preview payment features to Amazon Bedrock AgentCore, letting AI agents buy access to paid services using the x402 protocol. The company also announced a major cloud deal with U.S. Bancorp to move hundreds of internal workloads to AWS.
Source: SiliconANGLEGoogle Chrome is silently downloading a 4 GB on-device AI model, according to a report that traced the file on macOS and Windows. The model, used for Gemini Nano features, can re-download itself after deletion and appears without a consent prompt.
Source: r/LocalLLaMAOpenClaw 2026.5.7 adds fixes across plugin publishing, cron tooling, channels CLI, Telegram, Discord, WhatsApp, and model handling. The release also tightens approval and authorization flows, and improves session and memory cleanup.
Source: OpenClaw ReleasesHermes Agent v0.13.0, released May 7, 2026, adds a durable multi-agent Kanban board, persistent goals with /goal, stronger session recovery, and a broader plugin surface for providers and platforms. The release also closes eight P0 security issues and adds Google Chat as the 20th supported platform.
Source: Hermes Agent ReleasesA growth marketer at Kilo says he moved Google Ads management into Kilo CLI using custom skills, scripts, and rules. The setup uses different AI models for planning and execution, with dry-runs, paused launches, and account-specific guardrails to reduce errors and speed up routine work.
Source: Kilo BlogOpenClaw’s May 7 newsletter highlights the 2026.5.6 release and related fixes for Codex, browser tabs, and macOS LaunchAgents. It also lists new work on agent failover, plugin authorization, localized tool summaries, and memory capture rules.
Source: OpenClaw Newsletteragent-skills-eval is a new test runner for Agent Skills, the Anthropic open standard for packaging domain knowledge in a SKILL.md file. It runs prompts with and without the skill loaded, then uses a judge model to compare the outputs and generate a report.
Source: HN Show HNAnthropic said it struck a compute partnership with SpaceX to expand Claude capacity and raise usage limits for several products. The company also said Claude Code limits are going up, while Anthropic leaders pointed to rapid growth and a larger push into managed agents.
Source: Latent Space