Latest news across AI, security, and the OpenClaw ecosystem.
OpenAI's AGENTS.md standard has been adopted by over 60,000 open-source projects and major agent frameworks including Copilot, Cursor, Codex, Devin, Gemini CLI, and VS Code. The markdown convention gives AI coding agents consistent project-specific guidance.
Source: Linux FoundationAGENTS.md, the open standard for giving AI coding agents project-specific context, has been adopted by more than 60,000 open-source projects and is now supported by Copilot, Cursor, Codex, Gemini CLI, Devin, and others. The markdown file sits in a repo root and tells coding agents about build systems, coding conventions, test procedures, and project-specific rules. Originally created by OpenAI, it is now governed by the Agentic AI Foundation under the Linux Foundation.
Source: Agentic AI FoundationThe Agentic AI Foundation announced a global events program for 2026. The flagship European event, AGNTCon + MCPCon Europe, will be held September 17-18 in Amsterdam, with MCP Dev Summits planned across 10 cities worldwide.
Source: AAIFThe Agentic AI Foundation announced its 2026 global events program, anchored by AGNTCon + MCPCon Europe on September 17-18 in Amsterdam and AGNTCon + MCPCon North America in October. A series of regional MCP Dev Summits will also run across ten cities worldwide including Bengaluru, London, and Tokyo. Registration is open for the Amsterdam event.
Source: Agentic AI FoundationA documented architecture pattern where OpenClaw writes n8n workflows with incoming webhooks, then calls those webhooks for all API interactions. Credentials never leave n8n's encrypted store.
Source: GitHub (awesome-openclaw-usecases)Anthropic has launched Claude Design, a research preview tool that lets users create polished visual work with Claude, including prototypes, slides, one-pagers, and more. The product is powered by Claude Opus 4.7 and is available to Claude Pro, Max, Team, and Enterprise subscribers.
Source: Anthropic NewsA new design tool powered by Opus 4.7, available at claude.ai/design. It can ingest existing codebases to match in-house design systems and turn prompts into interactive prototypes.
Source: AnthropicA new comparison of model outputs found that Qwen3.6-35B-A3B running locally on a MacBook Pro M5 produced a better pelican illustration than Anthropic’s Claude Opus 4.7. The test also included a flamingo-on-a-unicycle SVG, which again went to Qwen, according to the article’s author.
Source: Simon WillisonOpenAI has updated Codex so it can use a computer’s apps, handle more developer workflows, and remember context across tasks. The company said the new features are rolling out now to desktop app users signed in with ChatGPT, with some personalization features and macOS computer use expanding later.
Source: OpenAI NewsComprehensive testing of 8 AI models across 27 OpenClaw-specific tests found DeepSeek V3.2 as the clear winner for agent workloads. The benchmark covers tool calling, multi-step reasoning, and cost efficiency.
Source: Buttondown (OpenClaw Newsletter)Anthropic switched to pay-as-you-go billing for third-party tool usage, impacting startups and hobbyists who relied on predictable subscription pricing for OpenClaw + Claude setups.
Source: Mean CEO BlogLatest release makes Opus 4.7 the default Anthropic model, adds Gemini text-to-speech, cloud-backed LanceDB memory, and a new Model Auth status card showing OAuth health at a glance.
Source: OpenClaw GitHubAnthropic has released Claude Opus 4.7 as a generally available model, positioning it as a substantial upgrade over Opus 4.6 in advanced software engineering, long-running tasks, and high-resolution vision. The company also says it is the first model released with new cybersecurity safeguards and tighter controls for prohibited or high-risk use cases.
Source: Anthropic NewsAnthropic's new flagship generally available model brings stronger agentic coding, 2,576px high-resolution vision, task budgets for long-running agents, and a new tokenizer that may use up to 35% more tokens. Reddit backlash was swift — some users prefer 4.6 for general chat.
Source: CNBCAnthropic shipped Opus 4.7 with stronger coding, better vision, and improved instruction-following. Same pricing as Opus 4.6. Claude Code got Auto mode and a new xhigh effort level.
Source: AnthropicOpenAI's "Codex for (almost) everything" update transforms Codex from a developer coding tool into a general-purpose AI workspace with macOS computer use, an in-app browser, scheduled automations, persistent memory, and over 90 plugins including Jira, Microsoft 365, Notion, and Slack. The update positions Codex as a direct competitor to both Claude Cowork and self-hosted agent platforms.
Source: OpenAISpotify published details on how it structures AI agent workflows internally, describing what The New Stack calls an agentic-first development approach. The piece covers how engineering teams at Spotify use internal platforms to coordinate agent-driven tasks at scale, including patterns for agent observability, approval workflows, and managing the boundary between automated and human-reviewed work.
Source: The New StackIndependent adversarial testing found OpenClaw successfully blocks only 17% of prompt injection attempts. The documented vulnerability makes unrestricted enterprise deployment premature without additional guardrails.
Source: AIThinkerLabAI incidents do not behave like traditional security incidents, according to the source article. Because model outputs can change from one prompt to the next, responders need broader classification, faster containment, and telemetry designed for AI behavior.
Source: Microsoft Security BlogOpenClaw's creator left for OpenAI in an acqui-hire deal. Fork activity surged 400% on the announcement, but development actually accelerated under the new 7-person steering committee.
Source: ClawbotOllama added support for Anthropic's Messages API, letting Claude Code run against locally hosted models instead of Anthropic's cloud. The setup enables agentic coding workflows with zero API costs using models like Qwen3-Coder or Codestral 2.
Source: OllamaMultiple guides appeared in April documenting how to run Claude Code against local models via Ollama, vLLM, LM Studio, and llama.cpp instead of paying for Anthropic API calls. Ollama officially added support for Anthropic's Messages API, letting Claude Code work with any locally-served model. The setup keeps Claude Code's planning and editing capabilities while swapping out the underlying model.
Source: MultipleThe official OpenClaw Docker image contains over 2,000 known vulnerabilities including several criticals with no fix available. The container holds Telegram tokens and Slack credentials, making the attack surface significant.
Source: Kilo / r/devsecops / r/sysadminAn Anthropic employee accidentally leaked Claude Code source code through a map file published to the npm registry. Security researcher Chaofan Shou posted the discovery on X, where it was viewed more than 30 million times. The leak exposed internal implementation details of one of the most widely used AI coding assistants.
Source: Cyber Security ReviewTeams on Copilot Enterprise subscriptions can now use the same provider for memory and retrieval workloads in OpenClaw. Reduces provider sprawl for organizations already invested in GitHub's ecosystem.
Source: PetronellatechAnthropic's newest flagship model is now natively supported in OpenClaw, positioning the framework as production-grade infrastructure. Google Gemini TTS joins Azure Speech as a voice output option.
Source: ClawbotAfter 13 CVEs were disclosed in April, the team shipped a hardening release with 50+ fixes. The update also adds GPT-5.4 Pro support, better Telegram forum topic handling, and core performance refactors.
Source: OpenClaw GitHubOpenClaw surpassed React, Vue, and TensorFlow to become the most-starred repository on GitHub during the first two weeks of April. The milestone signals mainstream adoption far beyond early adopters.
Source: ClawbotA step-by-step guide shows a Raspberry Pi 5 writing, compiling, and uploading Arduino sketches through plain English prompts via OpenClaw v2026.4.10. Verified and working.
Source: RootSaidDevelopers reported Claude suddenly felt less capable. Anthropic confirmed it quietly reduced the default effort level to save compute. The controversy raised transparency questions ahead of a potential IPO.
Source: FortuneThe April security batch fixed 13 vulnerabilities averaging CVSS 7.0, with two crossing the critical threshold. The worst: a device pairing flaw letting any token escalate to full operator access.
Source: Blink SecurityForward-compatible GPT-5.4-pro support arrives alongside a fix for the longstanding Ollama timeout issue where slow local model runs hit the global stream timeout. Complex reasoning tasks on local models no longer disconnect mid-response.
Source: PetronellatechResearch across 135,000 publicly exposed OpenClaw instances found nearly two-thirds have no authentication layer, making the critical April CVEs remotely exploitable with zero credentials.
Source: BlinkThe device pairing flow failed to validate scope before granting operator-level sessions, allowing any paired device to escalate to full admin access. Thirteen vulnerabilities patched in a single month - rare for the project.
Source: BlinkThe UK's AI Security Institute independently tested Mythos Preview and confirmed it can execute multi-stage corporate network attacks — 32 steps from reconnaissance to full takeover — that would take human professionals days. It's the first model to complete their full simulated attack.
Source: AISI (UK Gov)Unsloth added support for Llama 4 fine-tuning, delivering 2x faster training and 70% less memory usage compared to standard training methods. The tool makes fine-tuning large models practical on consumer GPUs.
Source: UnslothA step-by-step walkthrough for deploying OpenClaw inside Docker with least-privilege principles, treating the container as a sandbox for credential isolation. Covers file permissions, network restrictions, and secret mounting.
Source: AIMLAPISecurity researchers documented EchoLeak, ForcedLeak, GeminiJack, and three other critical flaws across major enterprise AI platforms. All exploited the same architectural gaps: untrusted input, broad data access, and missing per-operation controls.
Source: KiteworksPlugins can no longer access undeclared filesystem paths or network endpoints thanks to cryptographically signed manifests enforced at the kernel level via eBPF. This is the architectural answer to the malicious skills vulnerability from early April.
Source: ClawbotShopify released its AI Toolkit as open source under MIT license. The toolkit provides MCP plugins for Claude Code, Cursor, and Gemini CLI, giving AI coding agents direct access to Shopify's APIs.
Source: GitHubShopify open-sourced its AI Toolkit under the MIT license, providing MCP plugins for Claude Code, Cursor, and Gemini CLI. The plugins give AI coding assistants direct access to Shopify's APIs. This is one of the first major platform companies shipping official MCP server integrations as developer tools rather than community-built adapters.
Source: GitHubThe European Commission published guidance on April 10 clarifying which open-weight AI models qualify for lighter regulatory treatment under the AI Act. The exemption applies to models released under approved open-source licenses that meet specific transparency requirements.
Source: European CommissionHuggingFace released SmolVLM2-2.2B, a tiny multimodal model that handles vision and language tasks on devices with as little as 4GB RAM. The model gained 180,000+ downloads in its first week.
Source: HuggingFaceMicrosoft released Markitdown, an open-source Python tool that converts documents in nearly any format (PDF, DOCX, PPTX, HTML, images) to clean Markdown suitable for LLM input. The project gained 3,600+ stars in its first two weeks on GitHub. One pip install and a single function call handles the conversion.
Source: GitHubMicrosoft released Phi-4-Reasoning, a 14B parameter dense model under the MIT license. It scores 80.6 on AIME 2025 and 75.3 on GPQA Diamond, beating many models twice its size on reasoning tasks through chain-of-thought training.
Source: MicrosoftMicrosoft released Phi-4-Reasoning, a 14B dense model trained with chain-of-thought methods. It scores 80.6 on AIME 2025 and 75.3 on GPQA Diamond, beating many models twice its size on reasoning benchmarks. The MIT license makes it one of the most permissive model releases of the month. Runs on a single consumer GPU with about 8-10GB VRAM at 4-bit quantization.
Source: Microsoft ResearchAlibaba's Qwen team released the Qwen 3 family with eight model sizes from 0.6B to 72B parameters. The 72B model became the first open-weight model to beat GPT-4o on MMLU-Pro, while Qwen3-Coder-32B offers 128K context with native tool calling.
Source: QwenA technologist documented how he used Claude and Google's NotebookLM to organize complex cancer treatment, catching misdiagnoses and supporting three critical life-saving interventions. One of the most compelling real-world AI-for-good stories of the month.
Source: MultipleMicrosoft documented a phishing campaign using AI-generated lures and dynamic device code generation to bypass OAuth's 15-minute expiration window. Attackers blended traffic through Vercel and Cloudflare Workers.
Source: Microsoft Security BlogSecurity firm Reco found that 341 out of roughly 13,700 community-built skills on ClawHub contained malicious payloads — including prompt injections, hidden malware, and unsafe data handling patterns.
Source: Geek Metaverse