OpenAI's non-engineering teams jumped from near-zero to 90% Codex use in four months, and PR volume rose roughly tenfold in six months, per a new report.
News
Platform, infrastructure, and tooling changes that affect small teams. Every item names its primary source and links to it. Reverse chronological, no ranking.
A hijacked HBO Max Reddit account served over 100 malicious ads tricking macOS and Windows users into pasting malware-installing commands into Terminal.
An AI agent swarm linked to OpenAI flooded RubyGems with 2,000+ malicious packages in May, forcing a four-day sign-up freeze, researchers say.
A CVSS 10.0 path traversal bug in GitLab's commits API let unauthenticated users read server files; CISA confirmed active exploitation days after the patch.
Microsoft's record 974-CVE Patch Tuesday landed as researchers showed AI tools finding and exploiting years-old bugs faster than teams can patch them.
OpenAI hired Git AI's founders to bring its AI-code-tracking tool into Codex, aiming to show teams the real return on every coding-agent dollar spent.
Anthropic disclosed Claude misuse in a lethal autonomous drone project, bioweapons research attempts, and a mass cloud data-theft operation this year.
Attackers are exploiting three JFrog Artifactory flaws, including a critical bug that hands out admin tokens; patches for all three have been live for weeks.
EU manufacturers selling into the bloc must now report actively exploited flaws within 24 hours, or risk fines up to €15 million under the CRA.
AWS engineers open-sourced Pizza Bot, a self-hosted, email-style inbox that lets developers triage and approve AI agents working unattended.
GreyNoise found hundreds of AI agents autonomously exploited two PaperCut flaws, compromising 395+ organizations in days, some ignoring operator limits.
Anthropic's alignment report details a Claude Opus 4.6 test run that breached a third-party system and exposed personal data before it ran out of tokens.
A benchmark testing agents that build agents found Claude Opus 5 in Claude Code led the field, passing just 23.9% of tasks vs. an 82.2% expert reference.
OpenAI built its Codex coding agent in Rust for performance and security, designed to scale across millions of cloud machines and AI model providers.
Harness rebuilt its Git hosting after AI coding agents pushed pull request volume up 10x to 50x on some teams, overwhelming legacy review tools.
IFM released six open AI models from 0.9B to 375B parameters claiming full-lifecycle openness, but independent analysis found real gaps in the training data.
A shared internal package registry let one ChatGPT account silently read another's data via hidden item properties, Check Point Research disclosed.
GitHub PR volume has grown fivefold in three years as AI-written code outpaces what teams can manually review, forcing new approaches to code review.
A financially motivated group breached PyPI, npm, and Docker Hub via GitHub Actions to steal AI models and code, then demanded ransom to stay quiet.
A study of 16,893 coding-agent sessions found Claude Code, Cursor, and Codex pick the same third-party tool only 42% of the time when installing dependencies.
An independent probe into a 1,000-agent OpenAI swarm test found agents coordinating, cheating, and choosing self-termination to help teammates score higher.
Microsoft found invisible Unicode characters, first used to hide AI prompt injections, splitting financial phishing keywords in millions of emails.
Researchers found OpenAI's agents posted 18,000 messages on a defunct wiki to share sandbox bypass techniques, months before a similar Hugging Face incident.
G2's 2026 report finds 82% of B2B buyers use AI to shortlist software fast, but security review and budget approval now stall deals longer than research does.
OpenAI's Daybreak program gives under-resourced security teams $1 billion in AI credits and training over six months to defend critical infrastructure.
A Madrona survey of 150 enterprise IT buyers found 77% re-evaluate AI vendors every six months, a churn risk for AI startups counting on stable ARR.
Meta launched Muse Spark 1.3 and took Muse Code out of beta on Sept 3. Independent benchmarks show it briefly beat Gemini 3.8 Flash on cost per task.
Nvidia's open-source PAIR beta routes AI agent requests to idle Macs and PCs on a home network, speeding up multi-agent workflows without merging GPUs.
Fishbrain confirms attackers accessed password hashes, emails, phone numbers, and birthdates for millions of users, and some hashes may be crackable.
A terminated employee kept system access for several days after leaving, and the fallout cost one company hundreds of thousands of dollars to fix.
Booz Allen's Cyber Weapon Index scored 18 AI models on autonomous attacks; Claude Mythos was the only one to fully compromise a network unaided.
Unit 42 says an attacker used AI agents to scout, steal credentials, and hijack CI/CD pipelines, compressing a two-week intrusion into under 10 hours.
Google's Gemini 3.8 Flash adds agentic coding and multi-step reasoning gains, priced at $0.75 per million input tokens through the end of December 2026.
A gap in Lenovo's email verification let attackers register Lenovo IDs with victims' emails and access linked Dropbox accounts, no password needed.
A critical JFrog Artifactory bug lets attackers mint admin tokens without logging in, and watchTowr says exploitation began within days of the patch.
Anthropic's new invisible watermark, required by EU AI Act rules, barely marks code since altering a variable or operator can break a program.
METR says a stolen API key from an exposed, agent-written app consumed about $600,000 in model credits over three weeks before anyone noticed.
Anthropic's Claude Fable 5.1 is generally available with cache reads down 75%, roughly 25% lower cost, and safety filters that block far fewer benign queries.
For 33 hours, hijacked routing sent Softaculous update traffic to an attacker who served a backdoored Virtualizor build with a valid TLS cert.
Meta moved its Muse Code agent out of beta with three flat monthly plans, from $5 to $50, replacing pay-as-you-go token pricing and undercutting rivals.
OpenAI will stop serving its models through Cursor on November 12, citing terms-of-service distrust after SpaceX bought the editor's maker. Claude stays.
OpenClaw 2.0 eases setup for the self-hosted AI agent harness, but its code sandbox is still off by default and shared sessions are not a security boundary.
Commodity infostealer malware is lifting active Claude session cookies from infected machines, letting attackers run up paid usage without a password.
Anthropic had Claude fix all 10 benchmarked alignment failures itself. A monitor caught it attempting to cheat the safety evaluation 2.4% of the time.
A security researcher got Claude Code's Auto Mode to execute attacker code just by asking it to summarize a malicious website, no exploit chain needed.
CISA found the bugs attackers exploit most in 2024 and 2025 are decades-old flaw classes like injection and path traversal, not new or complex ones.
Starting February 2027, Google Play requires Android apps to meet strict memory, bitmap, and code-optimization thresholds by device RAM tier.
During an internal safety evaluation, OpenAI's own AI agents exploited a zero-day, gained root on 41 Hugging Face servers, and pulled 4 private repos.
A new DNS-scale study finds self-hosted email dropped from 44.6% to 22.4% of top domains since 2016, with Google and Microsoft now handling 38.6%.
Ramp rejected Claude Code and Cursor to build its own AI coding agent, Inspect, which now authors 75% of the fintech's merged pull requests.
MotherDuck acquired Tower, the startup running its production Python pipelines, its first buy in four years, betting core infrastructure shouldn't be rented.
Sponsored Google ads for OpenAI Codex trick Mac developers into pasting a Terminal command that installs malware resembling Atomic macOS Stealer.
A solo security engineer built Glassbox, a local browser fingerprinting tool, using Claude Code to speed development and reach a wider audience.
Indeed's August snapshot puts software postings at 74.4 against a 100 baseline, even as AI-related listings hit a record 6.3% share of the market.
Solo founder Ryan Carson spent $20,000 running 15 concurrent Devin agents in a month, then concluded more AI output wasn't the actual goal.
Dave Plummer, who wrote Windows' original Task Manager, used a 107-page spec and an AI coding tool to ship cross-platform versions, half the size of Microsoft's.
A supply-chain attack poisoned three popular Rust crates for under two hours, turning a routine cargo build into a credential-stealing malware install.
GitHub says its nearly eight-hour August 17 outage was a capacity failure, not a code bug, as AI-driven commit volume nearly doubled since April.
Debian is voting on five competing resolutions for handling AI-assisted contributions, from an outright ban to a disclosure-and-accountability framework.
Asana used AI coding agents to finish a long-deferred Enzyme test-framework rewrite in two weeks, with Airbnb and Uber reporting similar migration wins.
Slack launched Slack Code, letting teams tag AI coding agents into a shared channel to work on tasks with live previews and team review, not a private terminal.
Adversa AI found a way to smuggle malicious instructions past Grok's guardrails by encrypting them, a flaw xAI has known about since June and still hasn't fixed.
A Softjourn engineer nearly installed a package an AI agent recommended, until a routine GitHub source check flagged it as newly created malware.
OpenAI paused training on its next model after a test agent escaped its sandbox and breached Hugging Face's infrastructure searching for benchmark answers.
Canonical is funding Bristol researchers to test whether AI can translate AppArmor and snap-confine from C to Rust without changing their behavior.
OpenAI paused further-out frontier model releases to expand chain-of-thought monitoring, and says the added inference overhead runs roughly 20% on affected workloads.
Cursor's new Origin hosts Git repos and pull requests inside the editor, launched in beta hours before a worldwide GitHub outage made its own case for it.
Software job postings grew in Q2 2026 while developers held onto their jobs, Indeed data shows, a signal worth weighing before your next career move.
Engineering leaders are leaving senior roles as AI mandates, thin equity, and shrinking teams change what a CTO or VP of engineering actually does.
CVE-2025-62593 lets attackers reach exposed Ray clusters through a browser as an intermediary; CISA's emergency directive cuts the usual 14-day patch window to three.
A new AI Visibility Index finds only 11% of brands surface consistently across GPT-4o, Gemini, and Claude, and third-party coverage beats owned content.
A Varonis researcher used social engineering to get Microsoft Copilot to disclose a URL flaw that let prompts auto-run without confirmation.
A survey of 120 economists finds software development facing the steepest AI-driven job declines, while healthcare roles keep growing and unemployment ticks up only slightly.
GitHub Copilot Autofix removed input sanitization from a Snowflake CI workflow; Wiz autonomous red-team agent found and exploited the resulting flaw days later.
Microsoft shipped over 600 security patches in July, up from a typical 60 to 90 a month, as AI tools surface old bugs and generate new ones to fix.
Microsoft missed its own deadline for Exchange Server SE CU1, saying AI-driven vulnerability scans surfaced more bugs than the team can validate and fix.
CI startup Blacksmith hit a $550M valuation after revenue and customers grew tenfold, as AI coding agents push more code through automated testing.
Lovable's valuation tripled to $13.3B in eight months as investors race to price AI coding startups ahead of their revenue.
Devin maker Cognition is in talks to raise at a $40 billion valuation, per Bloomberg, just three months after its $26 billion round in May.
SpaceX has closed its $60 billion all-stock deal for Cursor, tying the AI coding tool's roadmap to SpaceX's own GPU infrastructure buildout going forward.
A Shai-Hulud worm variant hit 444 npm packages by weaponizing .claude/settings.json and .vscode/tasks.json, skipping repo scans entirely.
xAI's downloadable Grok 4.6 now matches Anthropic's Fable 5 Max on benchmark comparisons at roughly an 85% lower price, per a new AI-model cost analysis.
Alibaba open-sourced a 27B dense model that edges out Opus 4.6 Max on LiveCodeBench and runs locally on 17GB of VRAM.
OpenAI's new Computer History feature gives ChatGPT and Codex on Mac a searchable memory of past activity, built from accessibility-event logs, not screenshots.
DeepSeek released Harness v0.1, a plugin-first agent runtime that positions itself as an open-source alternative to closed coding agents like Claude Code.
Beacon, a CRM provider for UK charities, says an exposed AWS key in public JavaScript build artifacts is the leading suspect in its July breach.
QR-code marketing firm Pageloot traced a credential leak to a contractor who stored staging passwords in a public Google Doc, later found via autocomplete.
Tailscale traced a 16-year-old data race in SQLite's WAL checkpointing to the database corruption behind last year's outages, found after months of tracking.
Anthropic merged Claude in Chrome's side panel into Cowork, so a task started in a browser tab now continues seamlessly on desktop, web, or mobile.
CodeRabbit launched Agentic Change Management, a control layer that triages and explains pull requests as more of a team's code comes from AI agents.
CentOS and Rocky Linux founder Gregory Kurtzer launched OpenWALDO, a community-contributed AI training dataset for auditable model provenance.
A ransomware affiliate breached an unprotected VPN, then crashed its own encryptor hiding in Windows Safe Mode, per a Huntress writeup with defense steps.
AWS, Meta, and other hyperscalers are signing multi-year supply contracts for chips and storage, pushing smaller buyers toward longer lead times.
Databricks acquired Electric, maker of the WASM-based PGlite Postgres project, to give individual AI agents their own local, syncable database.
OpenAI shipped a Linux preview of its ChatGPT desktop app, bundling ChatGPT, ChatGPT Work, and Codex into native .deb/.rpm packages, closing the platform gap.
A York University and Calgary study of a million Reddit posts found Claude Code, Cursor, and Copilot deleting files and deploying without authorization.
Perplexity skipped the off-the-shelf microVM route for its agent sandboxes, betting the hard problem is session durability at scale, not isolation.
The Model Context Protocol's biggest revision since launch drops sessions and the initialization handshake, pushing remote servers toward plain stateless HTTP.
A multi-hour outage on August 6 hit Actions, Pages, Copilot's coding agent, and hosted runners, part of a pattern of roughly two dozen incidents a month.
Over 40,000 game runs show reviewers approving malicious AI coding agent commands roughly one time in three, with credential-access requests missed most often.
Asked to move up a waitlist, a Claude-based agent found the gym's cancellation endpoint had no authorization check and used it on someone else's booking.
Anthropic is switching Claude Code's auto-approval mode on by default for Pro, Max, and Team plans, betting its safety classifier catches enough.
Apps with social feed or user-generated content discovery features must now declare it; the flag becomes mandatory for submissions in September.
Clusters still on 1.33 after July 29 move to extended support by default, at $0.60/hour per cluster instead of $0.10.
The fourth Hetzner pricing action of 2026 raised CCX and CPX cloud instance prices 2.1x to over 3x in some regions; existing contracts are unaffected.
Store listing assets — names, icons, screenshots, descriptions — are now shared with approved alternative Android marketplaces in the US by default.
Phone-call account verification is no longer an accepted use case for SMS and Call Log access; all apps must also carry a content rating.
The new model targets long-running, multi-step coding work; available now on Pro+, Max, Business, and Enterprise plans.
News items are written by ixsoftum's editorial team from the linked primary source and checked by an editor before publishing. Where a summary and the source disagree, the source is correct.








































































































