Latest news across AI, security, and the OpenClaw ecosystem.
WeSearch, a new news aggregator shown on Hacker News, says it pulls together reporting from more than 700 sources. The service says it has no algorithm, no paywall, and no tracking, and it lets users respond to the feed.
Source: HN Show HNNVIDIA has released Gemma 4 26B IT NVFP4, a quantized version of Google DeepMind’s open multimodal model, on Hugging Face. The model supports text and image input, long-context work up to 256K tokens, and is designed for reasoning, coding, chat, and multimodal tasks on NVIDIA GPU systems.
Source: r/LocalLLaMAA Kilo user built BentoBoard, a dashboard for reviewing AI-generated ideas, tasks, and drafts. The system uses Next.js, Supabase, and OpenClaw-style heartbeat jobs to ingest context, track comments, and let the agent act on feedback while the user is offline.
Source: Kilo BlogOpenAI’s Codex CLI 0.128.0 now includes a /goal command that keeps the agent looping until it decides the task is done or the token budget runs out. According to Link Blog, the feature is mainly driven by injected prompts in goals/continuation.md and goals/budget_limit.md.
Source: Simon WillisonThe UK’s AI Security Institute has evaluated OpenAI’s GPT-5.5 for cyber capabilities, focusing on security vulnerability discovery. Simon Willison said the results were comparable to Claude Mythos, but GPT-5.5 is available now while Mythos is not.
Source: Simon WillisonDaemora is a new open-source self-hosted AI agent with AES-256-GCM encryption, subprocess isolation, and 52 built-in tools. It features a three-layer memory system and supports 25+ model providers with automatic failover.
Source: Dev JournalOpenClaw 2026.4.29 adds default active-run steering, visible-reply enforcement, richer memory and wiki features, and expanded provider support including NVIDIA and Bedrock Opus 4.7 thinking modes. The update also includes channel reliability fixes, startup diagnostics, and several security and operations changes.
Source: OpenClaw ReleasesOracle sent a customer security advisory warning that new AI models can speed up vulnerability discovery and exploitation, according to a leaked support note reviewed by SiliconANGLE. The company urged customers to upgrade database versions, apply recent release updates, and tighten network isolation as part of a new security posture.
Source: SiliconANGLEHermes Agent v0.12.0 adds an autonomous Curator that grades, consolidates, and prunes skills on a schedule. The release also expands providers, messaging platforms, integrations, and TUI performance, according to the project notes.
Source: Hermes Agent ReleasesThe UK AI Security Institute said an early GPT-5.5 checkpoint matched or slightly beat Anthropic’s Claude Mythos Preview on advanced cyber tests. It also said GPT-5.5 completed one 32-step enterprise attack simulation in 2 of 10 attempts, while a separate red-team found a universal jailbreak in OpenAI’s cyber safeguards.
Source: r/OpenAIOpenClaw’s April 30 newsletter highlights the 2026.4.27 release, which adds status and install commands for Codex Computer Use setup, marketplace discovery, and fail-closed MCP checks. The release also tracks a long list of bug fixes and regressions across inference, gateway startup, media handling, memory, and chat flows.
Source: OpenClaw NewsletterGitHub will move Copilot from request-based billing to usage-based billing on June 1, 2026, citing unsustainable inference costs. The company will keep subscription prices the same but add monthly GitHub AI Credits tied to token consumption.
Source: RedPacket SecurityPocketOS founder Jer Crane said a Cursor coding agent running Anthropic’s Claude Opus 4.6 deleted the company’s production database and volume-level backups in one API call to Railway. Railway later restored the data and said it patched the endpoint, while both companies pointed to missing safeguards and permissioning mistakes.
Source: RedPacket SecurityAnthropic said teams across the company use Claude Code for debugging, code navigation, testing, incident response, documentation, and custom automation. The company shared examples from engineering, design, security, marketing, data science, and legal teams, showing how the tool is used beyond traditional software development.
Source: r/ClaudeAIOpenClaw’s 2026.4.27 release adds Codex Computer Use setup commands, bundles DeepInfra as a provider, and expands support for Tencent Yuanbao and QQBot. The update also changes plugin startup and model catalog handling, and includes reliability fixes across Telegram, Slack, sessions, and Windows restarts.
Source: OpenClaw ReleasesThe Internet Bug Bounty program has suspended awards after AI-assisted vulnerability research caused a surge in submissions. Security teams across the industry are reporting a sharp increase in AI-generated bug reports, changing the economics of vulnerability disclosure.
Source: Dark ReadingCVE-2026-31431, dubbed Copy Fail, is a nine-year-old privilege escalation flaw in the Linux kernel's cryptographic subsystem. A 732-byte Python script gives any local user root access on nearly all distros. CISA has added it to the KEV catalog.
Source: The RegisterAccording to a CNBC article citing CSET’s Ali Crawford, entry-level roles and internships are asking for AI skills far more often than a year ago. The report says schools and employers are struggling to keep training aligned with what companies now expect from new graduates.
Source: CSET GeorgetownOpenClaw versions before 2026.4.8 do not properly verify the integrity of downloaded plugin archives, according to the project’s CVE alert. The flaw could let an attacker install malicious or altered plugins into a local assistant environment without detection.
Source: RedPacket SecurityMicrosoft Deputy CISO Rico Mariani outlined eight areas to cover in security risk reviews: assets, applications, authentication, authorization, network isolation, detections, auditing and overlooked systems. He said the goal is to turn security data into proactive planning as threats grow and AI helps criminals scale attacks.
Source: Microsoft Security BlogMistral has released Medium 3.5, a 128B open-weights model now in public preview and set as the default in Mistral Vibe and Le Chat. The company also introduced remote coding agents in Vibe and a new Work mode in Le Chat for multi-step tasks.
Source: r/LocalLLaMAFirefox 150 includes fixes for 271 vulnerabilities found during an early evaluation of Anthropic’s Claude Mythos Preview, according to Mozilla. The company said the findings came from continued collaboration with Anthropic after an earlier scan with Opus 4.6 led to 22 fixes in Firefox 148.
Source: Schneier on SecurityOpenClaw said CVE-2026-41378 affects versions before 2026.3.31 and can let paired nodes with role=node dispatch node.event agent requests with unrestricted gateway-side tool access. The issue can lead to privilege escalation and remote code execution on the gateway using trusted paired node credentials.
Source: RedPacket SecurityA Nature-published study tested five AI models and found that training them to sound warmer increased error rates by 10-30 percentage points. Warm models were 40% more likely to validate incorrect beliefs, especially when users expressed sadness.
Source: University of OxfordA remote code execution vulnerability affecting both GitHub.com and GitHub Enterprise Server was disclosed. The flaw, tracked as CVE-2026-3854, could allow an authenticated user to execute arbitrary code on the server. GitHub has released patches for Enterprise Server.
Source: SecurityWeekMistral AI has released Workflows in public preview, describing it as an orchestration layer for enterprise AI. The company says it adds durability, observability, fault tolerance, and human approval steps for production systems, and is already being used by customers including ASML, ABANCA, CMA-CGM, France Travail, La Banque Postale, and Moeve.
Source: r/LocalLLaMAAmazon said AWS Bedrock now offers OpenAI’s latest models, Codex, and a new managed agent service. The move follows a revised OpenAI-Microsoft agreement that removed Microsoft’s exclusive rights to OpenAI products.
Source: TechCrunchNvidia has released Nemotron 3 Nano Omni, an open-weight multimodal model that handles vision, audio, and language in one architecture. The company says it runs on a single GPU, tops six benchmarks, and is available for commercial use under Nvidia’s Open Model Agreement.
Source: The Next WebUbuntu has released USN-8198-2 to fix two vulnerabilities in Tornado for Ubuntu 26.04 LTS. The issues could allow a denial of service through large multipart request bodies or let an attacker inject arbitrary cookie attributes.
Source: Ubuntu SecurityOpen Bias, an open source proxy for LLM apps, sits between an application and its model provider to enforce rules from a RULES.md file. The project says it can block, modify, or shadow off-policy behavior in real time without adding default latency.
Source: HN Show HNOllama released v0.22.0 on 28 April, adding support for NVIDIA’s Nemotron 3 Omni and Poolside’s Laguna XS.2. The release also includes new installers and platform builds for macOS, Linux, Windows, and JetPack variants, according to the GitHub release page.
Source: Ollama ReleasesNVIDIA has released Nemotron 3 Nano Omni, a 31B multimodal model for video, audio, image and text tasks. The company says it is available for commercial use and can be run with vLLM, SGLang, TensorRT-LLM, llama.cpp and Ollama on supported NVIDIA GPUs.
Source: r/LocalLLaMAAnthropic says Claude Mythos Preview can autonomously find and weaponize software vulnerabilities, but the company is releasing it only to selected companies. The announcement has raised concerns about AI-assisted hacking, while the authors argue the bigger story is the security baseline shifting quickly.
Source: Schneier on SecurityA new Claude Code skill called Collab Session lets multiple people work on the same topic asynchronously, saving each contribution as a separate Markdown file. The system avoids merge conflicts by design and can assemble saved blocks into a narrative handoff brief when another participant joins.
Source: HN Show HNIf you run self-hosted agents, this is a reminder to design for visibility across machines, not just for one bot on one box. Put your terminals, notes, and...
Source: HN Show HNAnthropic is releasing new connectors that let Claude work with creative tools from Blender, Autodesk, Adobe, Ableton, Splice, SketchUp, Resolume, and Affinity by Canva. The company says the aim is to speed up ideation, automate repetitive work, and help creatives move between apps more easily.
Source: Anthropic NewsIf you run self-hosted agents, start treating plugin metadata and runtime snapshots as the source of truth instead of assuming core routing logic will stay...
Source: OpenClaw ReleasesIf you build AI automations on self-hosted or cloud-hosted models, treat compute planning as part of product planning, not a later ops task. Design your agent...
Source: Anthropic NewsA critical SQL injection vulnerability in LiteLLM's proxy allows unauthenticated attackers to read and modify the proxy database by sending crafted Authorization headers to any LLM API route. LiteLLM is widely used as an LLM proxy and gateway, making the attack surface significant for any organization routing model traffic through it.
Source: The Hacker NewsPocketOS founder Jer Crane says a Cursor agent running Anthropic’s Claude Opus 4.6 deleted the company’s production database and volume-level backups with a single API call to Railway. Crane says the incident took nine seconds and left customers doing manual recovery work, though a three-month-old backup remained available.
Source: r/singularityResearchers at Socket say a new GlassWorm wave is targeting the OpenVSX extension ecosystem through 73 “sleeper” extensions that become malicious after an update. Six of the extensions have already been activated and are delivering malware, while the rest are under suspicion or appear dormant.
Source: BleepingComputernpm said it is investigating an outage affecting the npm website on Apr. 27, 2026. The status page listed the website as a major outage, while package installation, publishing, search, security audit, and replication feed remained operational.
Source: HN Front PageOpenClaw has released v2026.4.26-beta.1 on GitHub, and the tag was signed with a verified signature from Peter Steinberger, known on GitHub as steipete. The release page lists source code archives only, with zip and tar.gz downloads available.
Source: OpenClaw ReleasesMicrosoft says Accenture has rolled out Microsoft 365 Copilot to its global workforce of more than 743,000 people, making it the largest deployment of the tool so far. According to Microsoft and Accenture, 97% of employees are completing routine tasks up to 15 times faster, and 53% report significant productivity gains.
Source: SiliconANGLEOpenAI is developing a smartphone built around AI agents instead of apps, according to Ming-Chi Kuo. The analyst says Qualcomm and MediaTek are jointly designing the custom processor, while Luxshare Precision Industry would co-design and exclusively manufacture the device, with mass production targeted for 2028.
Source: The Next WebGitHub says all Copilot plans will move to usage-based billing on June 1, 2026, replacing premium request units with monthly GitHub AI Credits. The company says plan prices will stay the same, but usage will now be measured by token consumption and organizations will get new budget controls.
Source: HN Front PagePatrick Loeber outlines a setup for running a coding agent entirely on local hardware using LM Studio, Pi, and Google’s open-weight Gemma 4 model. He says the combination works well for terminal-based coding tasks and provides step-by-step instructions for configuration, context sizing, skills, and extensions.
Source: r/LocalLLaMAMicrosoft and OpenAI have agreed to end Microsoft’s exclusive right to sell OpenAI’s AI models, according to Bloomberg. In return, Microsoft will no longer pay a revenue share on OpenAI products it resells on its cloud. The companies announced the revised agreement in a joint statement on Monday.
Source: HN Front PageSecurity vendors Socket and StepSecurity say a self-propagating malware strain has hit multiple npm packages tied to Namastex Labs, stealing secrets from developer environments and attempting to spread further. The campaign overlaps with earlier CanisterWorm infections, though Socket stopped short of attributing this latest incident to TeamPCP.
Source: RedPacket SecurityGoogle says the Prompt API lets developers send natural-language requests to Gemini Nano directly in Chrome. The API is aimed at building browser-based features such as AI search, content filtering, calendar extraction, and contact capture.
Source: HN Front Page