Apr 17, 2026 update

AGENTS.md reaches 60,000+ repo adoptions across major AI coding tools

OpenAI's AGENTS.md standard has been adopted by over 60,000 open-source projects and major agent frameworks including Copilot, Cursor, Codex, Devin, Gemini CLI, and VS Code. The markdown convention gives AI coding agents consistent project-specific guidance.

Source: Linux Foundation
Apr 17, 2026 update

AGENTS.md adoption crosses 60,000 repositories as AI coding agents standardize

AGENTS.md, the open standard for giving AI coding agents project-specific context, has been adopted by more than 60,000 open-source projects and is now supported by Copilot, Cursor, Codex, Gemini CLI, Devin, and others. The markdown file sits in a repo root and tells coding agents about build systems, coding conventions, test procedures, and project-specific rules. Originally created by OpenAI, it is now governed by the Agentic AI Foundation under the Linux Foundation.

Source: Agentic AI Foundation
Apr 17, 2026 update

AGNTCon + MCPCon Europe announced for Amsterdam, September 17-18

The Agentic AI Foundation announced a global events program for 2026. The flagship European event, AGNTCon + MCPCon Europe, will be held September 17-18 in Amsterdam, with MCP Dev Summits planned across 10 cities worldwide.

Source: AAIF
Apr 17, 2026 update

AGNTCon + MCPCon Europe announced for Amsterdam, September 17-18

The Agentic AI Foundation announced its 2026 global events program, anchored by AGNTCon + MCPCon Europe on September 17-18 in Amsterdam and AGNTCon + MCPCon North America in October. A series of regional MCP Dev Summits will also run across ten cities worldwide including Bengaluru, London, and Tokyo. Registration is open for the Amsterdam event.

Source: Agentic AI Foundation
Apr 17, 2026 update

n8n Proxy Pattern Documented — Credentials Stay in n8n, Agent Only Knows Webhook URL

A documented architecture pattern where OpenClaw writes n8n workflows with incoming webhooks, then calls those webhooks for all API interactions. Credentials never leave n8n's encrypted store.

Source: GitHub (awesome-openclaw-usecases)
Apr 17, 2026 community

Anthropic Launches Claude Design for Visual Prototyping

Anthropic has launched Claude Design, a research preview tool that lets users create polished visual work with Claude, including prototypes, slides, one-pagers, and more. The product is powered by Claude Opus 4.7 and is available to Claude Pro, Max, Team, and Enterprise subscribers.

Source: Anthropic News
Apr 17, 2026 community

Claude Design Launches in Research Preview — Prompt-to-Prototype Without Figma

A new design tool powered by Opus 4.7, available at claude.ai/design. It can ingest existing codebases to match in-house design systems and turn prompts into interactive prototypes.

Source: Anthropic
Apr 16, 2026 community

Qwen3.6-35B-A3B beats Claude Opus 4.7 on pelican test

A new comparison of model outputs found that Qwen3.6-35B-A3B running locally on a MacBook Pro M5 produced a better pelican illustration than Anthropic’s Claude Opus 4.7. The test also included a flamingo-on-a-unicycle SVG, which again went to Qwen, according to the article’s author.

Source: Simon Willison
Apr 16, 2026 community

OpenAI expands Codex with computer use, memory, and plugins

OpenAI has updated Codex so it can use a computer’s apps, handle more developer workflows, and remember context across tasks. The company said the new features are rolling out now to desktop app users signed in with ChatGPT, with some personalization features and macOS computer use expanding later.

Source: OpenAI News
Apr 16, 2026 update

AI Models Benchmark for Agents — DeepSeek V3.2 Wins for OpenClaw Workloads

Comprehensive testing of 8 AI models across 27 OpenClaw-specific tests found DeepSeek V3.2 as the clear winner for agent workloads. The benchmark covers tool calling, multi-step reasoning, and cost efficiency.

Source: Buttondown (OpenClaw Newsletter)
Apr 16, 2026 update

Anthropic Says Claude Subscribers Can No Longer Use Third-Party Tools Like OpenClaw Under Subscription Limits

Anthropic switched to pay-as-you-go billing for third-party tool usage, impacting startups and hobbyists who relied on predictable subscription pricing for OpenClaw + Claude setups.

Source: Mean CEO Blog
Apr 16, 2026 release

OpenClaw 2026.4.15 Ships with Claude Opus 4.7 and Cloud-Backed Memory

Latest release makes Opus 4.7 the default Anthropic model, adds Gemini text-to-speech, cloud-backed LanceDB memory, and a new Model Auth status card showing OAuth health at a glance.

Source: OpenClaw GitHub
Apr 16, 2026 community

Anthropic Launches Claude Opus 4.7 With Better Coding and Vision

Anthropic has released Claude Opus 4.7 as a generally available model, positioning it as a substantial upgrade over Opus 4.6 in advanced software engineering, long-running tasks, and high-resolution vision. The company also says it is the first model released with new cybersecurity safeguards and tighter controls for prohibited or high-risk use cases.

Source: Anthropic News
Apr 16, 2026 community

Anthropic Releases Claude Opus 4.7 — Strongest GA Model for Agentic Coding

Anthropic's new flagship generally available model brings stronger agentic coding, 2,576px high-resolution vision, task budgets for long-running agents, and a new tokenizer that may use up to 35% more tokens. Reddit backlash was swift — some users prefer 4.6 for general chat.

Source: CNBC
Apr 16, 2026 release

Claude Opus 4.7 Released — Anthropic's Most Capable Model Yet

Anthropic shipped Opus 4.7 with stronger coding, better vision, and improved instruction-following. Same pricing as Opus 4.6. Claude Code got Auto mode and a new xhigh effort level.

Source: Anthropic
Apr 16, 2026 community

OpenAI Expands Codex Into General-Purpose AI Workspace With Computer Use and 90+ Plugins

OpenAI's "Codex for (almost) everything" update transforms Codex from a developer coding tool into a general-purpose AI workspace with macOS computer use, an in-app browser, scheduled automations, persistent memory, and over 90 plugins including Jira, Microsoft 365, Notion, and Slack. The update positions Codex as a direct competitor to both Claude Cowork and self-hosted agent platforms.

Source: OpenAI
Apr 16, 2026 community

Spotify shares its agentic-first development approach at internal scale

Spotify published details on how it structures AI agent workflows internally, describing what The New Stack calls an agentic-first development approach. The piece covers how engineering teams at Spotify use internal platforms to coordinate agent-driven tasks at scale, including patterns for agent observability, approval workflows, and managing the boundary between automated and human-reviewed work.

Source: The New Stack
Apr 16, 2026 security

Independent Testing — OpenClaw Defends Against Only 17% of Adversarial Prompt Injection

Independent adversarial testing found OpenClaw successfully blocks only 17% of prompt injection attempts. The documented vulnerability makes unrestricted enterprise deployment premature without additional guardrails.

Source: AIThinkerLab
Apr 15, 2026 security

AI incident response needs new telemetry and playbooks

AI incidents do not behave like traditional security incidents, according to the source article. Because model outputs can change from one prompt to the next, responders need broader classification, faster containment, and telemetry designed for AI behavior.

Source: Microsoft Security Blog
Apr 15, 2026 update

OpenClaw Founder Peter Steinberger Departs for OpenAI — Governance Transfers to Steering Committee

OpenClaw's creator left for OpenAI in an acqui-hire deal. Fork activity surged 400% on the announcement, but development actually accelerated under the new 7-person steering committee.

Source: Clawbot
Apr 15, 2026 community

Claude Code now runs on local models via Ollama and vLLM - zero API cost agentic coding

Ollama added support for Anthropic's Messages API, letting Claude Code run against locally hosted models instead of Anthropic's cloud. The setup enables agentic coding workflows with zero API costs using models like Qwen3-Coder or Codestral 2.

Source: Ollama
Apr 15, 2026 community

Guides show how to run Claude Code with local models for zero API cost

Multiple guides appeared in April documenting how to run Claude Code against local models via Ollama, vLLM, LM Studio, and llama.cpp instead of paying for Anthropic API calls. Ollama officially added support for Anthropic's Messages API, letting Claude Code work with any locally-served model. The setup keeps Claude Code's planning and editing capabilities while swapping out the underlying model.

Source: Multiple
Apr 15, 2026 security

2,000+ CVEs Found in Official OpenClaw Docker Image

The official OpenClaw Docker image contains over 2,000 known vulnerabilities including several criticals with no fix available. The container holds Telegram tokens and Slack credentials, making the attack surface significant.

Source: Kilo / r/devsecops / r/sysadmin
Apr 15, 2026 security

Anthropic Accidentally Leaks Claude Code Source Code via npm Registry

An Anthropic employee accidentally leaked Claude Code source code through a map file published to the npm registry. Security researcher Chaofan Shou posted the discovery on X, where it was viewed more than 30 million times. The leak exposed internal implementation details of one of the most widely used AI coding assistants.

Source: Cyber Security Review
Apr 15, 2026 release

OpenClaw v2026.4.15 Adds GitHub Copilot as Embedding Provider

Teams on Copilot Enterprise subscriptions can now use the same provider for memory and retrieval workloads in OpenClaw. Reduces provider sprawl for organizations already invested in GitHub's ecosystem.

Source: Petronellatech
Apr 15, 2026 release

OpenClaw v2026.4.15 Adds Native Claude Opus 4.7 and Google Gemini TTS

Anthropic's newest flagship model is now natively supported in OpenClaw, positioning the framework as production-grade infrastructure. Google Gemini TTS joins Azure Speech as a voice output option.

Source: Clawbot
Apr 14, 2026 update

OpenClaw 2026.4.14 Focuses on Security After a Rough April

After 13 CVEs were disclosed in April, the team shipped a hardening release with 50+ fixes. The update also adds GPT-5.4 Pro support, better Telegram forum topic handling, and core performance refactors.

Source: OpenClaw GitHub
Apr 14, 2026 update

OpenClaw Becomes Most-Starred GitHub Repo in History at 347K+ Stars

OpenClaw surpassed React, Vue, and TensorFlow to become the most-starred repository on GitHub during the first two weeks of April. The milestone signals mainstream adoption far beyond early adopters.

Source: Clawbot
Apr 14, 2026 update

RootSaid Publishes OpenClaw + Arduino Automation Guide for Raspberry Pi

A step-by-step guide shows a Raspberry Pi 5 writing, compiling, and uploading Arduino sketches through plain English prompts via OpenClaw v2026.4.10. Verified and working.

Source: RootSaid
Apr 14, 2026 community

Anthropic Faces User Backlash Over Claude Performance Drop

Developers reported Claude suddenly felt less capable. Anthropic confirmed it quietly reduced the default effort level to save compute. The controversy raised transparency questions ahead of a potential IPO.

Source: Fortune
Apr 14, 2026 alert

13 CVEs Patched in April — Including a Critical Device Pairing Flaw

The April security batch fixed 13 vulnerabilities averaging CVSS 7.0, with two crossing the critical threshold. The worst: a device pairing flaw letting any token escalate to full operator access.

Source: Blink Security
Apr 14, 2026 release

OpenClaw v2026.4.14 Adds GPT-5.4-pro Support and Fixes Ollama Timeout Forwarding

Forward-compatible GPT-5.4-pro support arrives alongside a fix for the longstanding Ollama timeout issue where slow local model runs hit the global stream timeout. Complex reasoning tasks on local models no longer disconnect mid-response.

Source: Petronellatech
Apr 13, 2026 security

63% of Publicly Exposed OpenClaw Instances Run Without Any Authentication

Research across 135,000 publicly exposed OpenClaw instances found nearly two-thirds have no authentication layer, making the critical April CVEs remotely exploitable with zero credentials.

Source: Blink
Apr 13, 2026 security

OpenClaw Patches 13 CVEs in April - Including Critical Device Pairing Flaw (CVSS 8.7)

The device pairing flow failed to validate scope before granting operator-level sessions, allowing any paired device to escalate to full admin access. Thirteen vulnerabilities patched in a single month - rare for the project.

Source: Blink
Apr 13, 2026 security

UK AI Security Institute Confirms Mythos Preview Can Complete Full Network Attacks

The UK's AI Security Institute independently tested Mythos Preview and confirmed it can execute multi-stage corporate network attacks — 32 steps from reconnaissance to full takeover — that would take human professionals days. It's the first model to complete their full simulated attack.

Source: AISI (UK Gov)
Apr 12, 2026 community

Unsloth ships Llama 4 fine-tuning support - 2x faster training with 70% less memory

Unsloth added support for Llama 4 fine-tuning, delivering 2x faster training and 70% less memory usage compared to standard training methods. The tool makes fine-tuning large models practical on consumer GPUs.

Source: Unsloth
Apr 12, 2026 security

Secure OpenClaw Docker Isolation Guide Published

A step-by-step walkthrough for deploying OpenClaw inside Docker with least-privilege principles, treating the container as a sandbox for credential isolation. Covers file permissions, network restrictions, and secret mounting.

Source: AIMLAPI
Apr 12, 2026 security

Six Critical AI Vulnerabilities Hit Microsoft, Google, Salesforce in Under a Year

Security researchers documented EchoLeak, ForcedLeak, GeminiJack, and three other critical flaws across major enterprise AI platforms. All exploited the same architectural gaps: untrusted input, broad data access, and missing per-operation controls.

Source: Kiteworks
Apr 12, 2026 release

OpenClaw v2026.4.12 Introduces Cryptographically Signed Skill Manifests With eBPF Enforcement

Plugins can no longer access undeclared filesystem paths or network endpoints thanks to cryptographically signed manifests enforced at the kernel level via eBPF. This is the architectural answer to the malicious skills vulnerability from early April.

Source: Clawbot
Apr 10, 2026 update

Shopify open-sources AI Toolkit with MCP plugins for Claude Code and Cursor

Shopify released its AI Toolkit as open source under MIT license. The toolkit provides MCP plugins for Claude Code, Cursor, and Gemini CLI, giving AI coding agents direct access to Shopify's APIs.

Source: GitHub
Apr 10, 2026 update

Shopify open-sources AI Toolkit with MCP plugins for Claude Code and Cursor

Shopify open-sourced its AI Toolkit under the MIT license, providing MCP plugins for Claude Code, Cursor, and Gemini CLI. The plugins give AI coding assistants direct access to Shopify's APIs. This is one of the first major platform companies shipping official MCP server integrations as developer tools rather than community-built adapters.

Source: GitHub
Apr 10, 2026 community

EU AI Act open-source exemption guidance clarifies rules for self-hosted models

The European Commission published guidance on April 10 clarifying which open-weight AI models qualify for lighter regulatory treatment under the AI Act. The exemption applies to models released under approved open-source licenses that meet specific transparency requirements.

Source: European Commission
Apr 10, 2026 community

HuggingFace releases SmolVLM2 - multimodal AI that runs on devices with 4GB RAM

HuggingFace released SmolVLM2-2.2B, a tiny multimodal model that handles vision and language tasks on devices with as little as 4GB RAM. The model gained 180,000+ downloads in its first week.

Source: HuggingFace
Apr 10, 2026 community

Microsoft open-sources Markitdown for document-to-Markdown conversion

Microsoft released Markitdown, an open-source Python tool that converts documents in nearly any format (PDF, DOCX, PPTX, HTML, images) to clean Markdown suitable for LLM input. The project gained 3,600+ stars in its first two weeks on GitHub. One pip install and a single function call handles the conversion.

Source: GitHub
Apr 10, 2026 community

Microsoft releases Phi-4-Reasoning - 14B model under MIT license beats models twice its size

Microsoft released Phi-4-Reasoning, a 14B parameter dense model under the MIT license. It scores 80.6 on AIME 2025 and 75.3 on GPQA Diamond, beating many models twice its size on reasoning tasks through chain-of-thought training.

Source: Microsoft
Apr 10, 2026 community

Microsoft ships Phi-4-Reasoning at 14B parameters with MIT license

Microsoft released Phi-4-Reasoning, a 14B dense model trained with chain-of-thought methods. It scores 80.6 on AIME 2025 and 75.3 on GPQA Diamond, beating many models twice its size on reasoning benchmarks. The MIT license makes it one of the most permissive model releases of the month. Runs on a single consumer GPU with about 8-10GB VRAM at 4-bit quantization.

Source: Microsoft Research
Apr 10, 2026 community

Qwen 3 family ships eight model sizes - 72B beats GPT-4o on reasoning benchmarks

Alibaba's Qwen team released the Qwen 3 family with eight model sizes from 0.6B to 72B parameters. The 72B model became the first open-weight model to beat GPT-4o on MMLU-Pro, while Qwen3-Coder-32B offers 128K context with native tool calling.

Source: Qwen
Apr 10, 2026 community

Technologist Uses Claude and NotebookLM to Manage Mother's Stage 4 Cancer Care

A technologist documented how he used Claude and Google's NotebookLM to organize complex cancer treatment, catching misdiagnoses and supporting three critical life-saving interventions. One of the most compelling real-world AI-for-good stories of the month.

Source: Multiple
Apr 10, 2026 security

AI-Powered Phishing Campaign Bypasses OAuth with Dynamic Device Codes

Microsoft documented a phishing campaign using AI-generated lures and dynamic device code generation to bypass OAuth's 15-minute expiration window. Attackers blended traffic through Vercel and Cloudflare Workers.

Source: Microsoft Security Blog
Apr 10, 2026 alert

12% of ClawHub Skills Found to Contain Malicious Code

Security firm Reco found that 341 out of roughly 13,700 community-built skills on ClawHub contained malicious payloads — including prompt injections, hidden malware, and unsafe data handling patterns.

Source: Geek Metaverse