Apr 27, 2026 update

Archik stores architecture diagrams in YAML for Claude Code

If you build agent workflows or self-hosted tooling, treat your architecture map as a first-class file in the repo, not a separate drawing. Put a validation...

Source: HN Show HN
Apr 27, 2026 update

Klutch MCP lets Claude manage credit card rules in plain English

If you build self-hosted agents, this is a good example of separating the chat layer from the policy engine. Keep the model as the interface, but make sure the...

Source: HN Show HN
Apr 26, 2026 update

Dillo 3.3.0 Adds Remote Control and OAuth Fixes

Dillo 3.3.0, released on 2026-04-26, adds a new command-line control tool, page actions, and several bug fixes. According to the release notes, it also introduces experimental FLTK 1.4 support and a change that fixes OAuth logins by allowing cookies from main-page redirects.

Source: HN Front Page
Apr 25, 2026 update

OpenClaw v2026.4.25 Ships Full TTS Upgrade With Azure Speech and OpenTelemetry

OpenClaw v2026.4.25 delivers a major TTS overhaul with per-agent voice overrides, Azure Speech as a bundled provider alongside Xiaomi, Inworld, Volcengine, and ElevenLabs v3. The release also adds OpenTelemetry coverage across model calls, token usage, and tool loops, and moves the plugin registry to a cold persisted path for faster startup.

Source: OpenClaw Releases
Apr 25, 2026 security

EU Regulators Warn of Escalating AI-Driven Cyber Attacks Across Europe

European regulators warned that AI is enabling faster, more complex cyber attacks, with threat actors using AI to automate reconnaissance, craft social engineering attacks, and find vulnerabilities at machine speed. New regulatory proceedings against X under the Digital Services Act were announced alongside.

Source: The News / European regulators
Apr 24, 2026 security

OpenClaw Surges on GitHub as Self-Hosted AI Agent Gateway

OpenClaw, a self-hosted AI agent gateway written in TypeScript, has become GitHub’s most-starred non-aggregator software project after reaching 355,000 stars in about five months. According to the source article, the project runs on developer-owned hardware, connects to more than 50 messaging platforms, and can execute shell commands, file operations, and API calls.

Source: AIThinkerLab
Apr 24, 2026 update

Anthropic Details Claude Code Quality Problems in Postmortem

Anthropic says recent complaints about Claude Code quality were caused by three separate issues in the product’s harness, not by the underlying models. In one example, a bug made Claude repeatedly clear older thinking in idle sessions, which made it seem forgetful and repetitive, according to the company’s postmortem.

Source: Simon Willison
Apr 24, 2026 update

Docker Friction Deep-Dive — Permissions, WSL2, and Gateway Access

An analysis documenting the three main pain points with Docker deployments: file permissions, WSL2 UID/GID conflicts, and gateway access from outside the container. Community consensus: Docker is the wrong abstraction for many operators.

Source: Kilo
Apr 24, 2026 community

DeepSeek Releases V4 Flash and V4 Pro — Open-Source With 1M Context

DeepSeek's latest open-source models claim a 1-million-token context window with improved agentic capabilities and a new Hybrid Attention Architecture. Performance is competitive with US frontier models at dramatically lower cost.

Source: Wall Street Journal
Apr 24, 2026 security

CVE-2026-41297 — SSRF Vulnerability in OpenClaw Marketplace Plugin Downloads (CVSS 7.6)

The marketplace.ts module failed to restrict redirect destinations during archive downloads, allowing server-side request forgery. Attackers could redirect plugin downloads to malicious payloads.

Source: RedPacket Security
Apr 24, 2026 security

MCP remote code execution flaw disclosed - Anthropic says works as designed

Security researchers disclosed that MCP's StdioServerParameters allow arbitrary command execution on servers, as commands and arguments passed to create local instances are executed in a server-side shell without input sanitization. Anthropic responded that there is no design flaw and that developers are responsible for input sanitization.

Source: Hackaday
Apr 24, 2026 security

MCP remote code execution flaw documented as by-design risk

OX Security documented how MCP's StdioServerParameters allow arbitrary command execution on servers. The parameters passed to create local instances can contain any command and arguments, executed in a server-side shell without input sanitization. Anthropic responded that this is not a design flaw and that input sanitization is the developer's responsibility. Researchers warn that thousands of MCP deployments are effectively running RCE-as-a-Service.

Source: Hackaday
Apr 24, 2026 release

OpenClaw v2026.4.24 Adds Azure as Officially Documented Deployment Target

Azure joins DigitalOcean, Docker, GCP, Hetzner, and others as a documented deployment target with official install instructions. Previously, Azure deployment required adapting guides from other platforms.

Source: OpenClaw
Apr 24, 2026 release

OpenClaw v2026.4.24 Ships Voice Calls, DeepSeek V4, and Azure Speech TTS

The biggest release of the month adds full-agent voice calls, DeepSeek V4 Flash and Pro models, Azure Speech as a bundled TTS provider, and the Crestodian first-run TUI helper for smoother CLI onboarding.

Source: Multiple
Apr 23, 2026 community

Canonical ships Ubuntu 26.04 LTS with AI and security upgrades

Canonical released Ubuntu 26.04 LTS, codenamed Resolute Raccoon, on April 23, 2026. The update adds native support for NVIDIA CUDA and AMD ROCm, expanded memory-safe components, TPM-backed full-disk encryption, and new hardware support across servers, desktops, and cloud deployments.

Source: Canonical Blog
Apr 23, 2026 community

OpenAI launches GPT-5.5 for coding, work, and research

OpenAI introduced GPT-5.5 on April 23, 2026, describing it as its smartest and most intuitive model yet. The company said it is rolling out to ChatGPT and Codex users, with GPT-5.5 Pro also available for higher-tier users, and that the API release is coming soon.

Source: OpenAI News
Apr 23, 2026 update

OpenAI adds scheduled automations to Codex

OpenAI says Codex can now run tasks automatically on schedules and triggers, making the coding assistant more proactive. The company says the feature can handle recurring work such as morning briefs, weekly reviews, status updates, and data cleanup.

Source: OpenAI News
Apr 23, 2026 update

Ubuntu 26.04 LTS Released — Wayland-Only Desktop and Mandatory cgroup v2

Canonical released Ubuntu 26.04 LTS "Resolute Raccoon" with GNOME 50, Linux kernel 7.0, and the first Ubuntu LTS to ship without an Xorg session. The release drops cgroup v1 support entirely via systemd 259, adds TPM-backed full disk encryption, and includes native support for NVIDIA CUDA and AMD ROCm.

Source: Canonical
Apr 23, 2026 community

OpenAI Releases GPT-5.5 "Spud" — Agentic Coding Focus, 900M Weekly Users

OpenAI's most capable model dropped just one week after Opus 4.7, with a 1M context window, agentic coding focus, and efficiency gains over GPT-5.4. ChatGPT now has 900M weekly active users and 50M subscribers. API at $5/1M input, $30/1M output.

Source: OpenAI
Apr 23, 2026 release

OpenClaw v2026.4.23 Integrates GPT-5.5 and Adds Forked-Context Subagents

GPT-5.5 support arrives within days of OpenAI's release, alongside image generation and editing via Codex OAuth. The new forked-context subagent architecture lets agents spin off independent sub-tasks without polluting the main conversation.

Source: Blockchain News
Apr 22, 2026 community

Qwen says Qwen3.6-27B matches flagship coding models

Qwen says its new open-weight Qwen3.6-27B model delivers flagship-level agentic coding performance and beats its previous open-source flagship, Qwen3.5-397B-A17B, across major coding benchmarks. The new model is far smaller too: 55.6GB on Hugging Face, compared with 807GB for Qwen3.5-397B-A17B.

Source: Simon Willison
Apr 22, 2026 update

Claude Opus 4.7 Beats Kimi K2.6 on Workflow Spec Test

A test of two models on the same FlowGraph workflow orchestration spec found Claude Opus 4.7 scored 91/100 and Kimi K2.6 scored 68/100. Reviewers found one real bug in Claude’s build and six confirmed issues in Kimi’s, mostly around lease handling, scheduling, and streaming.

Source: Kilo Blog
Apr 22, 2026 community

GitHub Copilot tightens Individual plan limits and pauses signups

GitHub has announced changes to Copilot Individual plans, including tighter usage limits, a pause on new individual signups, and a shift of Claude Opus 4.7 to the $39-per-month Pro+ tier. The company said the update reflects rising compute demand from agentic workflows and the need to keep service reliable.

Source: Simon Willison
Apr 22, 2026 security

NIST NVD backlog and Claude Mythos reshape vulnerability defense

NIST says it will no longer enrich most vulnerabilities in the National Vulnerability Database because the backlog has grown too large. At the same time, the Cloud Security Alliance and the U.K.’s AI Security Institute say Anthropic’s Claude Mythos Preview can autonomously find and exploit vulnerabilities at a level that changes attacker economics.

Source: Kiteworks
Apr 22, 2026 community

Cursor reportedly agrees to deal with SpaceX and xAI

Cursor reportedly agreed to a deal with SpaceX that could value the coding tool at $60 billion, with SpaceX also already owning xAI. The report says the move could push Cursor users toward models tied to Elon Musk’s AI strategy, while raising concerns about access to third-party models such as Anthropic’s Claude.

Source: Kilo Blog
Apr 22, 2026 community

OpenAI Introduces Workspace Agents in ChatGPT for Team Workflows

OpenAI launched workspace agents in ChatGPT, letting teams create shared Codex-powered agents that handle complex tasks across ChatGPT and Slack with organizational controls, approvals, and memory. The feature is in research preview for Business, Enterprise, and Edu plans, free until May 6 before switching to credit-based pricing.

Source: OpenAI
Apr 22, 2026 release

OpenClaw v2026.4.22 Blocks Cross-Bot Token Replay on Teams

Shared Bot Framework audience tokens must now name the configured app via verified appid or azp claim. Prevents lateral movement between bots in enterprise Teams deployments.

Source: GitHub
Apr 22, 2026 release

OpenClaw v2026.4.22 Hardens Android Intents — Auto-Send Blocked for Injected Prompts

External Android apps can no longer auto-dispatch prompts to OpenClaw via ASK_OPENCLAW intents. Actions now only prefill the draft, requiring user confirmation before sending.

Source: GitHub
Apr 21, 2026 update

OpenClaw's April Release Cadence Described as "Obsessed With Operator Visibility"

Community analysts noted a deliberate shift from novelty features toward inspectable, truthful agent infrastructure with honest cost accounting and built-in diagnostics.

Source: OpenClaw Community
Apr 21, 2026 community

OpenAI launches Codex Labs for enterprise rollout

OpenAI said Codex now has more than 4 million weekly developers and is being used by enterprises across software development and operations. The company is launching Codex Labs and working with global systems integrators to help organizations move Codex from pilots to production.

Source: OpenAI News
Apr 21, 2026 release

OpenClaw v2026.4.21 Upgrades Default Image Model and Tightens Permissions

Default image model switches to gpt-image-2, command permissions are tightened to owner-only, and Slack thread aliasing is fixed. Security hardening continues as a theme across April releases.

Source: Gaoxiaoma
Apr 20, 2026 update

Moonshot releases open-weight Kimi K2.6 for agentic workflows

Moonshot AI has released Kimi K2.6, an open-weight model aimed at agentic coding and long-context tasks. Kilo Code says it is already integrated into Kilo CLI, VS Code and JetBrains extensions, Hermes, and KiloClaw.

Source: Kilo Blog
Apr 20, 2026 update

ClariSortAi Launches openclaw-manager-plugin for Claude Code

An interactive onboarding wizard that handles OpenClaw installation, channel configuration, and security hardening through conversation in Claude Code. Setup via chat instead of docs.

Source: GitHub
Apr 20, 2026 update

Composio Ships OpenClaw + Ollama MCP Integration (SOC 2 Compliant)

Composio's MCP server plugs directly into OpenClaw agents with OAuth and credential management handled externally. SOC 2 Type 2 compliant for enterprise use.

Source: Composio
Apr 20, 2026 update

Peter Steinberger's "Two Sides of OpenClaw" Talk Highlights Security vs. Growth Tension

Steinberger's talk contrasted OpenClaw's inspiring open-source narrative with the serious engineering challenges around security and scaling. A candid assessment from the creator before his departure to OpenAI.

Source: Radical Data Science
Apr 20, 2026 update

SwarmClaw Launches as Multi-Agent Runtime for OpenClaw Operators

Supports 23 built-in providers including Ollama, Claude, GPT, Gemini, and DeepSeek. Enables delegation to Claude Code, Codex, and Gemini CLI with per-agent gateway profiles.

Source: GitHub
Apr 20, 2026 community

Kimi K2.6 Launches as Open-Weight Agentic Model With 300-Agent Swarm Orchestration

Moonshot AI released Kimi K2.6, a 1-trillion-parameter open-weight model with 32 billion active parameters per token, scoring 58.6 on SWE-Bench Pro at roughly a quarter of Claude Opus's API cost. The model can orchestrate up to 300 concurrent sub-agents and is available on Ollama, Hugging Face, and Cloudflare Workers AI with day-one OpenClaw integration.

Source: Moonshot AI
Apr 20, 2026 release

OpenClaw v2026.4.20 Fixes Session Management and Cost Tracking Duplication

A "house-repair release" focused on operator reliability — fixing session pruning, cost tracking duplication, and default session management. No new features, just making existing ones work correctly.

Source: Gaoxiaoma
Apr 19, 2026 security

Anthropic updates Claude Opus 4.7 system prompt and tool handling

Anthropic published changes to the Claude Opus 4.7 system prompt, continuing its unusual practice of releasing prompt archives for user-facing chat systems. The update adds stronger child-safety rules, new guidance on tool use and ambiguity handling, and shifts the model’s knowledge cutoff language to January 2026.

Source: Simon Willison
Apr 19, 2026 community

Spotify shares its agentic-first development approach - real patterns from a large engineering team

A New Stack article describes how Spotify is dogfooding AI agents internally, structuring agent workflows at scale, and integrating AI into their engineering platform. The piece provides real-world patterns from a large team rather than theoretical architecture.

Source: The New Stack
Apr 18, 2026 security

Claude system prompts become easier to track in Git

Simon Willison describes a Git-based way to explore Anthropic’s published Claude system prompts. The approach breaks the Markdown source into separate files and timestamped commits so researchers can use standard Git tools to track changes over time.

Source: Simon Willison
Apr 18, 2026 update

Ollama Ships Native `ollama launch openclaw` Command

One command now handles onboarding, provider config, gateway daemon install, model selection, and bundled web search. Dramatically simplifies local AI agent setup for new users.

Source: Ollama
Apr 18, 2026 update

OpenClaw Moves to Node 24 as Recommended Default Runtime

Node 22.14+ remains supported via LTS, but Node 24 is now the default for fresh installs, CI, and release workflows. Existing installs on Node 22 keep working.

Source: OpenClaw
Apr 18, 2026 update

OpenClaw Ships Docker Sandbox Mode for Agent Tool Execution

When sandbox mode is enabled, the gateway runs agent tools inside isolated Docker containers while the gateway stays on the host. Hard walls around untrusted sessions.

Source: OpenClaw
Apr 18, 2026 update

"Orchestrator-Agent-Worker" Pattern Emerges as 2026 Best Practice

A deep-dive architecture piece proposes n8n managing the "what" and "when" while OpenClaw agents handle the "how" and "why." Includes async agent calls and agent pooling behind load balancers.

Source: Kollox Limited
Apr 18, 2026 update

OSS Installer Projects Emerge — OutClaw, Linux Wizard, Lobster Cage

Three community projects aim to simplify OpenClaw deployment for non-DevOps users: OutClaw (GUI installer), OpenClaw Linux Installation Wizard, and Lobster Cage (hardened Docker Compose for Raspberry Pi).

Source: Kilo
Apr 18, 2026 update

Warning — Don't Use /v1 URL With Remote Ollama

Using the OpenAI-compatible /v1 endpoint with Ollama breaks tool calling, causing models to output raw JSON as plain text instead of executing tools. The native Ollama API URL is required.

Source: OpenClaw GitHub
Apr 18, 2026 security

Pawel Huryn's "Agent One" Highlights OpenClaw's Architectural Security Gap vs n8n

Analysis shows n8n's Docker isolation and tool approval system provide "hard architectural boundaries" that prompt injection cannot override, unlike OpenClaw's prompt-instruction-based security model. The comparison highlights a fundamental design gap.

Source: xCloud
Apr 17, 2026 community

Cursor nears $2 billion round at $50 billion valuation

Cursor is reportedly close to raising at least $2 billion in new funding at a $50 billion valuation, according to four sources familiar with the deal. The company’s revenue has climbed quickly, and it expects to end 2026 with an annualized revenue run rate above $6 billion, the sources said.

Source: TechCrunch
Apr 17, 2026 update

AI token budgets are inflating code output, not productivity

New data from developer analytics firms suggests AI coding tools are increasing code volume, but not necessarily useful output. Companies such as Waydev, GitClear, Faros AI, and Jellyfish say engineers are approving more AI-generated code while also spending more time revising it later.

Source: TechCrunch