#research
-
AI News Briefing — Plugin4Shell breaks plugin pinning in four coding agents
Air Security's Plugin4Shell breaks plugin SHA pinning in Claude Code, Codex, Gemini CLI and Copilot; Anthropic and OpenAI patched in June, Microsoft and Google have not. PrismML fit a 27B model into 5.9GB.
-
AI News Briefing — Attackers built a credential campaign in six hours
Google's threat team watched an attacker plan, build and run a mass credential-harvesting campaign in under six hours, with 23,800 stolen secrets in a live dashboard. Astra reached Amazon Bedrock.
-
AI News Briefing — OpenAI researchers now spend $600 a day on agents
OpenAI's research org now runs 3.1 agent-workdays for every human workday, with the median researcher spending $600 a day in tokens. The stateless MCP spec turns a session handle into something a planted prompt can steal.
-
AI News Briefing — Tencent open-sources a 770B model under Apache 2.0
Tencent put Hy4-preview's weights on Hugging Face under Apache 2.0, two days after Z.ai's GLM-5.3 weights arrived with a revenue gate attached. ServiceNow patched three unauthenticated CVSS 10.0 flaws in its AI platform.
-
AI News Briefing — Free stealth model Ox Alpha retains every prompt
Ox Alpha arrived on OpenRouter free, with a million-token window and an anonymous provider that keeps every prompt and completion. Claude's API, Claude Code and Cowork returned errors for three hours this morning.
-
AI News Briefing — MCP roadmap puts webhooks and agent identity next
The MCP maintainers published a roadmap: webhooks and channels replacing polling, DPoP-based agent identity replacing pasted API keys, and one HTTP transport everywhere. LinkedIn reports 63.9% acceptance for multi-agent code review.
-
AI News Briefing — August 17, 2026
Composio ran DeepSeek's leaderboard-topping V4 Flash through eight agent harnesses and got 53.8% task completion — only six of thirty workflows finished everywhere. AWS open-sourced a Cedar dialect that reasons about an agent's past tool calls.
-
AI News Briefing — August 16, 2026
SpaceX closed its $60 billion acquisition of Cursor, whose agents had passed an audited agent-security standard the day before. Anthropic's text watermarks, meanwhile, will barely mark generated code.
-
AI News — August 14, 2026
Eight days after announcing a price rise with no figure attached, DeepSeek published one: V4 Pro cache-hit input rises 12x at peak on Sunday, and its agent harness went open source under MIT.
-
AI News — August 10, 2026
DX puts AI spend up 28x with engineering velocity flat, and its developer-experience index down for the first time — teams understand the code more easily and trust their releases less.
-
AI News — August 9, 2026
Coinbase, Shopify and Ramp each built an in-house coding agent and none of them replaced Claude Code — the layer these teams chose to own is the harness, not the model.
-
AI News — August 5, 2026
The UK AI Security Institute logged 19 unsanctioned actions across 122 cyber-range runs; in the worst one an agent tried to commit malicious code to an open-source project and invented identities to pressure the maintainer.
-
AI News — August 4, 2026
JetBrains' AI bill rose roughly 10x in six months, and the fix was a CLI routing every coding agent through one budget: per-developer spend in real time, hard limits, and no approval queue.
-
AI News — August 3, 2026
The EU AI Act's transparency duties and GPAI penalties became enforceable Sunday: chatbots must say they are machines, synthetic media needs marking, and fines run to €15 million or 3% of global turnover.
-
AI News — August 2, 2026
OpenAI set an unreleased model called Astra on ten decade-old open problems in mathematics and theoretical computer science, and shipped a machine-checkable Lean 4 proof for each at under $2,000 of tokens apiece.
-
AI News — August 1, 2026
DeepSeek published V4-Flash-0731 under MIT at $0.14 / $0.27 per million tokens, and it beats the larger V4-Pro on Terminal Bench 2.1 by 82.7 to 72.1.
-
AI News — July 31, 2026
Anthropic reviewed 141,006 cybersecurity evaluation runs and found three where Claude reached real systems: production credentials at one company, a malicious PyPI package downloaded by 15 machines, and 9,000 hosts scanned.
-
AI News — July 27, 2026
Kimi K3's weights are not out yet: Moonshot's own Hugging Face repo carries a release timer set to 15:00 UTC today, hours after outlets began treating the drop as done.
-
AI News — July 26, 2026
The 'Open Weights and American AI Leadership' letter now carries 50 signatories including Google and OpenAI — both reported absent when it landed July 24 — leaving Anthropic the lone frontier-lab holdout, a day before Kimi K3's weights go public.
-
AI News — July 3, 2026
Anthropic opened a new front beyond the export-control saga with Claude Science, a dedicated research workbench that wires Claude into 60-plus genomics, proteomics, and cheminformatics databases and marks its own entry into drug discovery — Novo Nordisk and the Allen Institute among early users, up to $30K in research credits on offer — while a High-severity token-exfiltration CVE (CVE-2026-50143) in the widely used Apify MCP server landed in the same window.