AI News Briefing — Google pauses open source bug bounty over AI submissions
Google pauses its open source bug bounty after a surge of mostly invalid AI-written reports. New Claude Cowork tasks on Pro and Max run in the cloud from October 6, and Cantina releases an open-weights vulnerability research model.
Model releases
-
[2026-10-01] Cantina Security and Yeta Labs released apex-flash-1, a 321B-parameter reinforcement-learning fine-tune of GLM-5.3-Flash for vulnerability research, under the MIT license on Hugging Face. It solved 40 of Cantina’s 60 held-out bug tasks (66.7%), against 60.0% for the base model and 71.7% for Claude Opus 5 High, at an estimated $2.38 for the whole set. An abliterated variant with fewer refusals ships alongside it. (official)
Sixty tasks written by the vendor is a small test, so treat the gap to Opus as a hint rather than a ranking. Cantina pitches it as a worker under a larger agent, run inside the Codex harness.
For Security Engineers: At an estimated $2.38 for all 60 tasks, it is cheap enough to run as a first-pass worker under your existing agent, with its findings checked by a stronger model or a person before any report goes out. The abliterated variant drops refusals you may prefer to keep.
Coding agents
-
[2026-09-30] From October 6, new Claude Cowork tasks on Pro and Max plans run on Anthropic’s servers, and the “Only on your computer” option in Settings > General goes away. Tasks already started locally finish there. Scheduled tasks move to the cloud as well; those that use local files need the desktop app open. Anthropic points anyone whose work must stay on one machine to Claude Code. (official)
Folders stay on the laptop, but each file a cloud task needs is copied up for that session, which is the part to check against a client’s data rules.
For Engineering Managers / Tech Leads: Teams that chose “Only on your computer” for client work lose that setting on October 6, and only tasks already running stay local. Those workflows need a move to Claude Code before then, and anyone with scheduled tasks on local files needs the desktop app left open.
-
[2026-10-03] DeepSeek Harness v0.2.1-alpha.1 adds an experimental compatibility layer for Claude Code Mods. DeepSeek says the goal for now is to confirm the Mods API is broadly a subset of what Harness plugins can do, not to run real mods end to end. (official)
AI-assisted SDLC
-
[2026-10-01] Google pauses its open source bug bounty, the Open Source Software Vulnerability Rewards Program, citing “a significant rise in automated submissions, the vast majority of which are not valid.” Maintainers had been buried in AI-written reports with hallucinated details. New product reports for Go, Angular, Bazel, Protocol Buffers, Fuchsia and other covered projects are closed from October 1; supply-chain reports, the Patch Rewards Program, the Cloud VRP and reports filed before the pause still go through. An update is promised for the first quarter of 2027. (source, source)
curl ended its HackerOne bounty in January for the same reason and Intel dropped rewards in mid-September. A paid bounty is becoming an unreliable way to reach a maintainer, and a report written with an agent now needs a working reproduction to be read at all.
Practice & craft
-
[2026-10-04] Writing in The New Stack, Arjun Iyer argues that agents have made CI the bottleneck and that faster pipelines fix the wrong layer. He cites Anthropic’s CI job volume growing 25x in six months and Linear’s test suite nearly quadrupling since January. Agent sandboxes and CI both test one repository against mocks, while distributed-system failures sit at service boundaries, so he wants agents verifying against the running system before a pull request exists. (source)
A renamed response field passes every test in its own repository and breaks the first consumer that reads it. No amount of pipeline speed catches that.
Watch list
-
Reflection’s first open-weight model: Axios reports it is due soon, expected to trail the top US models but match the best Chinese open weights. Reflection has given no name or date and has not commented. (source) (unconfirmed)
Should it ship as described, teams barred from Chinese-origin weights would get an open model near the best of them; a name, a license and a download link are what to wait for.
-
Step 5 Preview’s weights: not uploaded; due October 15.
-
Gemini 4 Argon for paid API users: Fairwind cohort only; no date.
-
Dropped until there’s news: OpenAI’s Decisions API, with no price or wider access since September 30, and Apple’s Full Disk Access change, with no macOS version since October 2.