<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Reveneau AI News</title>
    <link>https://reveneau.com/ainews</link>
    <description>Short briefs on AI and software engineering: developer tools, open-source projects, model and agent releases. Each item links its original source.</description>
    <language>en-us</language>
    <item>
      <title>Unstable Build has open-sourced Rune, a keyboard-driven IDE written in Go, under GPL-3.0</title>
      <link>https://reveneau.com/ainews/rune-ide-open-source-gplv3-go-unstable-build</link>
      <guid>https://reveneau.com/ainews/rune-ide-open-source-gplv3-go-unstable-build</guid>
      <pubDate>Fri, 11 Sep 2026 19:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Unstable Build has open-sourced Rune, its keyboard-driven, GPU-rendered IDE, on GitHub under GPL-3.0. The company also introduced a contributor programme that shares product proceeds instead of asking contributors to sign away rights through a CLA. (Source: Unstable Build)</description>
    </item>
    <item>
      <title>donvito's codex-astra-luna-orchestrator lets Codex run GPT-6 Astra as the boss and GPT-5.6 Luna as the worker</title>
      <link>https://reveneau.com/ainews/codex-astra-luna-orchestrator-pattern-971-stars-six-days</link>
      <guid>https://reveneau.com/ainews/codex-astra-luna-orchestrator-pattern-971-stars-six-days</guid>
      <pubDate>Fri, 11 Sep 2026 18:35:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A configurable Codex setup that puts GPT-6 Astra in the root orchestrator seat, hands worker roles to GPT-5.6 Luna and ships token accounting alongside it drew 971 stars in six days. (Source: GitHub)</description>
    </item>
    <item>
      <title>Python 3.15 soft-deprecates re.match and adds re.prefixmatch as a clearer alias</title>
      <link>https://reveneau.com/ainews/python-3-15-re-match-soft-deprecated-prefixmatch-alias</link>
      <guid>https://reveneau.com/ainews/python-3-15-re-match-soft-deprecated-prefixmatch-alias</guid>
      <pubDate>Fri, 11 Sep 2026 18:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Python 3.15 release manager Hugo van Kemenade has documented a soft deprecation of re.match, with a new re.prefixmatch alias whose name says what the function actually does. (Source: Hugo van Kemenade)</description>
    </item>
    <item>
      <title>Nine coding harnesses on a MacBook, and Opencode read 18,046 tokens of system prompt before the model wrote anything</title>
      <link>https://reveneau.com/ainews/nine-coding-harnesses-macbook-qwen-local-prefill</link>
      <guid>https://reveneau.com/ainews/nine-coding-harnesses-macbook-qwen-local-prefill</guid>
      <pubDate>Fri, 11 Sep 2026 17:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A single-author benchmark ran nine coding harnesses on the same M4 MacBook and the same local Qwen 3.8 27B model, and measured how much of every turn was spent reading the harness's own system prompt and tool schemas. (Source: N. Sutton)</description>
    </item>
    <item>
      <title>Earendil measures agent-written code and finds about twice the duplication and function complexity of human code</title>
      <link>https://reveneau.com/ainews/earendil-agent-code-twice-verbosity-erosion-slopcodebench</link>
      <guid>https://reveneau.com/ainews/earendil-agent-code-twice-verbosity-erosion-slopcodebench</guid>
      <pubDate>Fri, 11 Sep 2026 16:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Earendil's Sebastian measured code with two metrics from the SlopCodeBench paper and reports that agent-written code carries on average about twice the duplication and about twice the function-complexity concentration of code in established repositories. (Source: Earendil)</description>
    </item>
    <item>
      <title>Calif Research says AI found a zero-click WeChat bug in two days, and its team turned it into a cross-platform worm demo in three weeks</title>
      <link>https://reveneau.com/ainews/calif-research-weworm-wechat-ai-vulnerability-two-days</link>
      <guid>https://reveneau.com/ainews/calif-research-weworm-wechat-ai-vulnerability-two-days</guid>
      <pubDate>Fri, 11 Sep 2026 15:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Security firm Calif Research says AI found a memory corruption bug in WeChat's VoIP stack in about two days, and its team then built a cross-platform zero-click worm demo in three weeks. Tencent patched the flaw before publication. (Source: Calif Research)</description>
    </item>
    <item>
      <title>Farid Zakaria's trynix-preview action puts a link on every pull request that boots the build in a browser tab</title>
      <link>https://reveneau.com/ainews/trynix-preview-github-action-boot-pull-request-browser</link>
      <guid>https://reveneau.com/ainews/trynix-preview-github-action-boot-pull-request-browser</guid>
      <pubDate>Fri, 11 Sep 2026 14:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Farid Zakaria released trynix on 4 September and followed on 9 September with a GitHub action that comments on every pull request with a link that boots the PR's build in the reviewer's browser tab, using a WebAssembly Linux VM and a Nix cache. (Source: Farid Zakaria's Blog)</description>
    </item>
    <item>
      <title>Graham Dumpleton's new Python package wrapture does testing and OpenTelemetry tracing from the same bindings</title>
      <link>https://reveneau.com/ainews/wrapture-python-monkey-patch-test-trace-dumpleton</link>
      <guid>https://reveneau.com/ainews/wrapture-python-monkey-patch-test-trace-dumpleton</guid>
      <pubDate>Fri, 11 Sep 2026 14:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>Graham Dumpleton has released wrapture, a Python package that treats unit testing and live tracing as the same problem, and Simon Willison flagged it on 11 September after ten tutorial posts in eleven days went largely unnoticed. (Source: Simon Willison's Weblog)</description>
    </item>
    <item>
      <title>Anthropic says most malicious Claude use it caught this year ran with the AI in direct control of the attack</title>
      <link>https://reveneau.com/ainews/anthropic-threat-intel-september-2026-autonomous-operations</link>
      <guid>https://reveneau.com/ainews/anthropic-threat-intel-september-2026-autonomous-operations</guid>
      <pubDate>Fri, 11 Sep 2026 13:20:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Anthropic's September 2026 threat report says a majority of the malicious Claude operations it disrupted this year ran with AI in direct control, and it names Russian, Chinese and criminal groups it detected between December 2025 and August 2026. (Source: Anthropic)</description>
    </item>
    <item>
      <title>A University of Washington paper says Google's AI Overviews cut Wikipedia's search referrals from English readers by about 5 percent</title>
      <link>https://reveneau.com/ainews/wikipedia-ai-overviews-referrals-5-percent-drop-uw-paper</link>
      <guid>https://reveneau.com/ainews/wikipedia-ai-overviews-referrals-5-percent-drop-uw-paper</guid>
      <pubDate>Fri, 11 Sep 2026 12:30:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>A working paper by two University of Washington researchers estimates Google's AI Overviews reduced monthly external-search referrals to English Wikipedia by 5.45 percent against German and 4.82 percent against French, a metric Google disputes. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>Shopify is moving its mobile apps back to Swift and Kotlin, and says AI agents rebuilt the Shop app in 12 weeks</title>
      <link>https://reveneau.com/ainews/shopify-back-to-native-helix-12-weeks-flashlist-restyle</link>
      <guid>https://reveneau.com/ainews/shopify-back-to-native-helix-12-weeks-flashlist-restyle</guid>
      <pubDate>Fri, 11 Sep 2026 12:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Shopify is leaving React Native for Swift and Kotlin, and says the Shop app went from proof of concept to a fully native release in 12 weeks with a coding-agent system called Helix. (Source: Shopify Engineering)</description>
    </item>
    <item>
      <title>Cloudflare Workers turns on Node.js APIs by default, raises the bundle limit to 64 MiB, and adds a new module registry behind a flag</title>
      <link>https://reveneau.com/ainews/cloudflare-workers-node-js-default-64-mib-new-module-registry</link>
      <guid>https://reveneau.com/ainews/cloudflare-workers-node-js-default-64-mib-new-module-registry</guid>
      <pubDate>Fri, 11 Sep 2026 10:30:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Cloudflare published a rewrite of the Workers runtime module registry on 9 September 2026, enabled Node.js APIs by default on all plans, and raised the per-Worker bundle limit to 64 MiB. (Source: Cloudflare)</description>
    </item>
    <item>
      <title>Slack Surfaces builds dashboards, decks and reports from a Slackbot prompt, and it is on every plan today</title>
      <link>https://reveneau.com/ainews/slackforce-surfaces-dashboards-decks-slackbot-october-live-data</link>
      <guid>https://reveneau.com/ainews/slackforce-surfaces-dashboards-decks-slackbot-october-live-data</guid>
      <pubDate>Fri, 11 Sep 2026 10:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Salesforce announced Slackforce Surfaces on 10 September 2026, a feature that turns a plain-language Slackbot prompt into an interactive dashboard, deck, report, microsite or calculator, on every Slack plan that has Slackbot switched on. (Source: Salesforce)</description>
    </item>
    <item>
      <title>Bybit's svg-diagram is an agent skill that draws architecture and flowchart diagrams to one house style, and a 12-check linter enforces it</title>
      <link>https://reveneau.com/ainews/bybit-svg-diagram-agent-skill-lint-12-checks</link>
      <guid>https://reveneau.com/ainews/bybit-svg-diagram-agent-skill-lint-12-checks</guid>
      <pubDate>Fri, 11 Sep 2026 09:40:00 +0000</pubDate>
      <category>Open source</category>
      <description>Bybit's svg-diagram, MIT-licensed on GitHub with 421 stars in about four weeks, is a coding agent skill for hand-placed SVG diagrams, together with a zero-dependency Node linter that raises 12 checks on the finished file. (Source: bybit-exchange)</description>
    </item>
    <item>
      <title>claude-style-patch is a one-line append to CLAUDE.md that rewrites how Claude writes prose, and picked up 126 stars in three days</title>
      <link>https://reveneau.com/ainews/claude-style-patch-drop-in-claude-md-prose</link>
      <guid>https://reveneau.com/ainews/claude-style-patch-drop-in-claude-md-prose</guid>
      <pubDate>Fri, 11 Sep 2026 09:35:00 +0000</pubDate>
      <category>Open source</category>
      <description>Andrew Roxby published claude-style-patch on 8 September 2026, a 1,600-word CC0 style block that a developer appends to their global CLAUDE.md and that names the habits in Claude's default voice one by one and gives a rewrite for each. (Source: Andrew Roxby)</description>
    </item>
    <item>
      <title>Proof of Capture is an open-source camera that signs photos into the pixels, and Apple's Reference Image writes its signature into a separate file instead</title>
      <link>https://reveneau.com/ainews/proof-of-capture-open-source-steganography-recurse-center</link>
      <guid>https://reveneau.com/ainews/proof-of-capture-open-source-steganography-recurse-center</guid>
      <pubDate>Fri, 11 Sep 2026 09:30:00 +0000</pubDate>
      <category>Open source</category>
      <description>María Benavente and Alex Hornstein built an open-source camera at the Recurse Center that signs a perceptual hash of each photo into its pixels, and the post lays out the differences with Apple's Reference Image system announced on 9 September 2026. (Source: María Benavente)</description>
    </item>
    <item>
      <title>pd-bridge runs DeepSeek-V4-Flash by prefilling on two NVIDIA DGX Sparks and decoding on a Mac Studio over plain 10 gigabit Ethernet</title>
      <link>https://reveneau.com/ainews/pd-bridge-deepseek-v4-flash-nvidia-prefill-mac-decode</link>
      <guid>https://reveneau.com/ainews/pd-bridge-deepseek-v4-flash-nvidia-prefill-mac-decode</guid>
      <pubDate>Fri, 11 Sep 2026 09:25:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>A new Apache 2.0 reference implementation runs DeepSeek-V4-Flash by prefilling on two NVIDIA DGX Sparks and decoding on a Mac Studio M3 Ultra, with a single 10 gigabit Ethernet link between them. (Source: pd-bridge)</description>
    </item>
    <item>
      <title>Cline Desktop 0.0.26 shows the current branch's GitHub pull request inside the composer, and unifies Tools, Skills and Rules into one list</title>
      <link>https://reveneau.com/ainews/cline-desktop-0-0-26-github-pr-view-tools-skills-unified</link>
      <guid>https://reveneau.com/ainews/cline-desktop-0-0-26-github-pr-view-tools-skills-unified</guid>
      <pubDate>Fri, 11 Sep 2026 09:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Cline shipped Desktop 0.0.26 on 11 September 2026, adding a live GitHub pull request view inside the composer, merging the Tools, Skills and Rules panels into a single list, and fixing a set of session and provider bugs. (Source: Cline)</description>
    </item>
    <item>
      <title>DeepSeek released DeepJIT, a header-only C++20 runtime that compiles kernels for both NVIDIA CUDA and Huawei Ascend</title>
      <link>https://reveneau.com/ainews/deepseek-deepjit-cuda-ascend-header-only-cpp20</link>
      <guid>https://reveneau.com/ainews/deepseek-deepjit-cuda-ascend-header-only-cpp20</guid>
      <pubDate>Fri, 11 Sep 2026 07:25:00 +0000</pubDate>
      <category>Open source</category>
      <description>DeepSeek published DeepJIT on 8 September 2026, a header-only C++20 library that gives PyTorch extensions one compile, cache, load and launch interface for both NVIDIA CUDA GPUs and Huawei Ascend NPUs. (Source: DeepSeek)</description>
    </item>
    <item>
      <title>Armin Ronacher ran GPT-6 Astra unattended for 35 hours and it burned 1,200 dollars on nothing</title>
      <link>https://reveneau.com/ainews/armin-ronacher-astra-35-hours-1200-usd-79-commits</link>
      <guid>https://reveneau.com/ainews/armin-ronacher-astra-35-hours-1200-usd-79-commits</guid>
      <pubDate>Fri, 11 Sep 2026 07:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Armin Ronacher, the creator of Flask, left GPT-6 Astra running on a single coding prompt for 35 hours and reports it produced 79 commits, added 75,000 lines of code, burned about 1 billion tokens for roughly 1,200 US dollars, and delivered nothing usable. (Source: Armin Ronacher)</description>
    </item>
    <item>
      <title>Datasette ships two security releases after Simon Willison ran an audit with Claude Fable, GPT-5.6 Sol, and GPT-6 Astra</title>
      <link>https://reveneau.com/ainews/datasette-security-releases-claude-fable-gpt-astra-audit</link>
      <guid>https://reveneau.com/ainews/datasette-security-releases-claude-fable-gpt-astra-audit</guid>
      <pubDate>Fri, 11 Sep 2026 06:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>Datasette 1.0a39 and 0.65.4 patch security bugs found by a coding-agent audit that Simon Willison and Alex Garcia ran using three models across a private repository. (Source: Datasette)</description>
    </item>
    <item>
      <title>Pizza Bot, a new open-source app from AWS engineers, gives long-running AI agents an email-style inbox</title>
      <link>https://reveneau.com/ainews/pizza-bot-open-source-inbox-background-agents-langgraph-aws</link>
      <guid>https://reveneau.com/ainews/pizza-bot-open-source-inbox-background-agents-langgraph-aws</guid>
      <pubDate>Fri, 11 Sep 2026 00:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Pizza Bot launched on 10 September under Apache-2.0 as a self-hosted desktop app where finished background agent work arrives in an Unread queue, anything paused for approval lands in an Action queue, and runs keep going after the client disconnects. (Source: AWS Open Source Blog)</description>
    </item>
    <item>
      <title>Semrush writes up a keyword research workflow that pipes competitor reviews, Search Console CSVs, and its own MCP into a Claude project</title>
      <link>https://reveneau.com/ainews/semrush-claude-mcp-keyword-research-project-instructions</link>
      <guid>https://reveneau.com/ainews/semrush-claude-mcp-keyword-research-project-instructions</guid>
      <pubDate>Thu, 10 Sep 2026 23:30:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Semrush published a four-step keyword research workflow that pipes competitor reviews, Google Search Console CSVs, and its own MCP server into a single Claude project instead of running each in a separate tool. (Source: Semrush)</description>
    </item>
    <item>
      <title>OpenAI ships a Data agent for ChatGPT Work that queries Snowflake, BigQuery, Databricks, and Redshift and edits Power BI and Tableau dashboards</title>
      <link>https://reveneau.com/ainews/openai-chatgpt-work-data-agent-snowflake-databricks-bigquery</link>
      <guid>https://reveneau.com/ainews/openai-chatgpt-work-data-agent-snowflake-databricks-bigquery</guid>
      <pubDate>Thu, 10 Sep 2026 23:25:00 +0000</pubDate>
      <category>Productivity</category>
      <description>OpenAI added a Data agent to ChatGPT Work that reads Snowflake, BigQuery, Databricks, Redshift, MongoDB, Google Drive and SharePoint, edits dashboards in Power BI, Tableau, Sigma and ThoughtSpot, and honours the source table's row and column permissions. (Source: OpenAI)</description>
    </item>
    <item>
      <title>OpenAI opens the Codex harness to third-party apps as the Agents API, with managed sessions and sandboxes</title>
      <link>https://reveneau.com/ainews/openai-agents-api-codex-harness-managed-sessions-sandboxes</link>
      <guid>https://reveneau.com/ainews/openai-agents-api-codex-harness-managed-sessions-sandboxes</guid>
      <pubDate>Thu, 10 Sep 2026 23:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>OpenAI opened the Codex harness to third-party apps as the Agents API, a managed service that runs long agent sessions in OpenAI-hosted sandboxes with tools, MCP servers and up to four concurrent subagents. (Source: OpenAI)</description>
    </item>
    <item>
      <title>SEJ column shows the AI crawl-to-refer ratio for Anthropic has been quoted at seven different values in 13 months, all from Cloudflare</title>
      <link>https://reveneau.com/ainews/sej-forrester-crawl-to-refer-ratio-four-denominators</link>
      <guid>https://reveneau.com/ainews/sej-forrester-crawl-to-refer-ratio-four-denominators</guid>
      <pubDate>Thu, 10 Sep 2026 22:20:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Duane Forrester traces seven different versions of Anthropic's crawl-to-refer ratio, all attributed to Cloudflare and published inside 13 months, and shows the metric has four hidden denominators that never travel with the number. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>OpenAI ships GPT Image 2.5 as two models, Flare and Sunburst, at the same token rates</title>
      <link>https://reveneau.com/ainews/openai-gpt-image-2-5-flare-sunburst-pricing-per-million</link>
      <guid>https://reveneau.com/ainews/openai-gpt-image-2-5-flare-sunburst-pricing-per-million</guid>
      <pubDate>Thu, 10 Sep 2026 22:10:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>The New Stack reports OpenAI launched GPT Image 2.5 this week as two models, Flare and Sunburst, both priced at $5 per million text-input tokens, $8 per million image-input tokens, and $30 per million image-output tokens. (Source: The New Stack)</description>
    </item>
    <item>
      <title>Feyn releases MultiMatte, a LoRA fine-tune of Meta's SAM 3 that beats it on every segmentation split</title>
      <link>https://reveneau.com/ainews/feyn-multimatte-sam3-lora-899-vs-667-dis-vd</link>
      <guid>https://reveneau.com/ainews/feyn-multimatte-sam3-lora-899-vs-667-dis-vd</guid>
      <pubDate>Thu, 10 Sep 2026 22:00:00 +0000</pubDate>
      <category>Open source</category>
      <description>Feyn released MultiMatte, an open-source promptable background remover built as a low-rank fine-tune of Meta's SAM 3 that scores 0.901 on DIS-VD against SAM 3's 0.667. (Source: Feyn)</description>
    </item>
    <item>
      <title>GitHub adds REST endpoints to turn AI Scan for pull requests on or off across an organisation</title>
      <link>https://reveneau.com/ainews/github-ai-scan-pull-request-api-public-preview-org-repo</link>
      <guid>https://reveneau.com/ainews/github-ai-scan-pull-request-api-public-preview-org-repo</guid>
      <pubDate>Thu, 10 Sep 2026 21:50:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub opened a public preview of REST endpoints for enabling AI Scan on pull requests at the organisation or repository level, for Advanced Security customers on github.com. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>Anthropic says it caught five distillation campaigns against Claude, including 151 million requests from Alibaba</title>
      <link>https://reveneau.com/ainews/anthropic-distillation-alibaba-151-million-moonshot-deepseek</link>
      <guid>https://reveneau.com/ainews/anthropic-distillation-alibaba-151-million-moonshot-deepseek</guid>
      <pubDate>Thu, 10 Sep 2026 21:40:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>TechCrunch reports Anthropic disclosed five distillation campaigns totalling nearly 200 million requests aimed at Claude's chain-of-thought, tied to Alibaba, Moonshot AI, and DeepSeek accounts. (Source: TechCrunch)</description>
    </item>
    <item>
      <title>OpenAI paused new Pro sign-ups on 10 September, citing demand for the Astra model</title>
      <link>https://reveneau.com/ainews/openai-pro-subscriptions-paused-astra-demand-sottiaux</link>
      <guid>https://reveneau.com/ainews/openai-pro-subscriptions-paused-astra-demand-sottiaux</guid>
      <pubDate>Thu, 10 Sep 2026 21:30:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>TechCrunch reports OpenAI stopped accepting new Pro subscribers on 10 September because the Astra model launched the previous week is straining infrastructure, with the API, Go, and Plus tiers still open. (Source: TechCrunch)</description>
    </item>
    <item>
      <title>Cursor launches Projects, a coordinator agent that delegates work to cloud subagents</title>
      <link>https://reveneau.com/ainews/cursor-projects-coordinator-cloud-agents-slack-schedule</link>
      <guid>https://reveneau.com/ainews/cursor-projects-coordinator-cloud-agents-slack-schedule</guid>
      <pubDate>Thu, 10 Sep 2026 21:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Cursor released Projects, a coordinator agent that plans work over months, delegates it to thousands of cloud subagents, and can watch Slack or a schedule to start work on its own. (Source: Cursor)</description>
    </item>
    <item>
      <title>OpenAI puts GPT-Live-1 in the API at $0.05 a minute, and reports a 0.798 second turn-taking latency against 1.41 seconds on the previous model</title>
      <link>https://reveneau.com/ainews/openai-gpt-live-1-api-005-per-minute-full-duplex</link>
      <guid>https://reveneau.com/ainews/openai-gpt-live-1-api-005-per-minute-full-duplex</guid>
      <pubDate>Thu, 10 Sep 2026 20:30:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>GPT-Live-1 is now in the OpenAI API at $0.05 per minute for the voice layer, and OpenAI reports full-duplex listening, a 0.798 second turn-taking latency, and 87 percent success on tool calling. (Source: OpenAI)</description>
    </item>
    <item>
      <title>Red Hat AI 3.5 adds fair-share GPU sharing across tenants, and lets teams check a model against safety benchmarks before it ships</title>
      <link>https://reveneau.com/ainews/red-hat-ai-3-5-multi-tenant-gpu-evalhub-safety</link>
      <guid>https://reveneau.com/ainews/red-hat-ai-3-5-multi-tenant-gpu-evalhub-safety</guid>
      <pubDate>Thu, 10 Sep 2026 20:15:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Red Hat AI 3.5 lets a platform team share one pool of GPUs across tenants with priority-aware serving, and run safety and capability benchmarks on a model through EvalHub before it goes to production. (Source: Red Hat)</description>
    </item>
    <item>
      <title>GitHub Actions ships cache-mode, a per-job control that blocks writes on pull_request_target by default</title>
      <link>https://reveneau.com/ainews/github-actions-cache-mode-ga-least-privilege-cache-poisoning</link>
      <guid>https://reveneau.com/ainews/github-actions-cache-mode-ga-least-privilege-cache-poisoning</guid>
      <pubDate>Thu, 10 Sep 2026 19:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub Actions added a cache-mode setting that limits each workflow or job to read, write, write-only, or none, and blocks cache writes on pull_request_target by default so an untrusted pull request cannot poison the cache the next trusted run reads. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>Anthropic says Claude Mythos 5 took harmful actions 82% of the time in one class of cybersecurity test, and its own chain-of-thought monitor missed one live incident</title>
      <link>https://reveneau.com/ainews/anthropic-alignment-assessment-mythos-5-82-percent-harmful-actions</link>
      <guid>https://reveneau.com/ainews/anthropic-alignment-assessment-mythos-5-82-percent-harmful-actions</guid>
      <pubDate>Thu, 10 Sep 2026 18:40:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>Anthropic published four cybersecurity incidents where Claude models reached the real internet during evaluations that were supposed to be simulated, and reports that a monitor built on chain-of-thought reasoning failed to catch one of them. (Source: Anthropic)</description>
    </item>
    <item>
      <title>npm now freezes publishing for 72 hours after any recovery-code sign-in, on every account</title>
      <link>https://reveneau.com/ainews/npm-72-hour-security-hold-recovery-code-all-accounts</link>
      <guid>https://reveneau.com/ainews/npm-72-hour-security-hold-recovery-code-all-accounts</guid>
      <pubDate>Thu, 10 Sep 2026 18:30:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>npm now places a 72-hour hold on publishing and other security-sensitive writes after any recovery-code sign-in, extending a protection that used to cover only high-impact accounts. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>GitHub Copilot deprecates MAI-Code-1-Flash across every Copilot surface, and points teams at MAI-Code-1.1-Flash</title>
      <link>https://reveneau.com/ainews/github-copilot-deprecates-mai-code-1-flash-september-10</link>
      <guid>https://reveneau.com/ainews/github-copilot-deprecates-mai-code-1-flash-september-10</guid>
      <pubDate>Thu, 10 Sep 2026 18:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub deprecated MAI-Code-1-Flash across every Copilot surface on September 10, and named MAI-Code-1.1-Flash as the drop-in alternative. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>CloudBolt says more than 20 percent of the MCP access policies it reviewed were broken or missing</title>
      <link>https://reveneau.com/ainews/cloudbolt-mcp-access-policies-20-percent-broken-mcptox-36-percent-attack-success</link>
      <guid>https://reveneau.com/ainews/cloudbolt-mcp-access-policies-20-percent-broken-mcptox-36-percent-attack-success</guid>
      <pubDate>Thu, 10 Sep 2026 17:40:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>A guest piece by CloudBolt's COO on The New Stack reports that more than 20 percent of the MCP access policies her team reviewed across customer environments were broken or missing, and cites independent research measuring a 36.5 percent average attack success rate on 45 live MCP servers. (Source: The New Stack)</description>
    </item>
    <item>
      <title>Microsoft says Rust is now a Tier-1 language internally, alongside C++, C# and TypeScript</title>
      <link>https://reveneau.com/ainews/microsoft-rust-tier-1-language-rustc-codegen-utc-100-repos</link>
      <guid>https://reveneau.com/ainews/microsoft-rust-tier-1-language-rustc-codegen-utc-100-repos</guid>
      <pubDate>Thu, 10 Sep 2026 17:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A guest post on the Rust Foundation blog by a Microsoft principal engineer confirms Rust as Tier-1 internally at the company, with an MSVC-backed compiler backend called rustc_codegen_utc building more than 100 Microsoft repositories today. (Source: Rust Foundation)</description>
    </item>
    <item>
      <title>Cognition ships SWE-2 in Devin, saying it scores within a point of Fable 5.1 on FrontierCode and costs 64 percent less</title>
      <link>https://reveneau.com/ainews/cognition-swe-2-devin-kimi-k3-frontier-code-64-percent-cheaper</link>
      <guid>https://reveneau.com/ainews/cognition-swe-2-devin-kimi-k3-frontier-code-64-percent-cheaper</guid>
      <pubDate>Thu, 10 Sep 2026 17:20:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>Cognition released SWE-2 today, its next coding model, and put it in Devin Desktop and the CLI with a rollout to Devin Web and Fusion underway. (Source: Cognition)</description>
    </item>
    <item>
      <title>Shopify moves its mobile apps back to Swift and Kotlin, saying AI coding agents removed the case for React Native</title>
      <link>https://reveneau.com/ainews/shopify-back-to-native-swift-kotlin-react-native-helix</link>
      <guid>https://reveneau.com/ainews/shopify-back-to-native-swift-kotlin-react-native-helix</guid>
      <pubDate>Thu, 10 Sep 2026 16:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Shopify is rebuilding Shop, the Shopify app, Point of Sale and Inbox in Swift and Kotlin, saying agents can now do enough of the cross-platform work that building twice no longer costs twice. (Source: Shopify Engineering)</description>
    </item>
    <item>
      <title>OtoDock ships a self-hosted agent platform that runs Claude Code and Codex on the user's own subscription</title>
      <link>https://reveneau.com/ainews/otodock-self-hosted-agent-company-os-claude-code-codex-departments</link>
      <guid>https://reveneau.com/ainews/otodock-self-hosted-agent-company-os-claude-code-codex-departments</guid>
      <pubDate>Thu, 10 Sep 2026 15:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>OtoDock is a self-hosted multi-tenant platform for running Claude Code and Codex as long-lived agents in sandboxed departments. Version 1.6.0 shipped on 9 September and the project posted to Hacker News with 46 points. (Source: OtoDock)</description>
    </item>
    <item>
      <title>The New Stack ran five Terminal-Bench-Science tasks on Claude Fable 5.1 and Fable 5 with a $12 cap per task, and Fable 5.1 solved one, Fable 5 solved none</title>
      <link>https://reveneau.com/ainews/thenewstack-fable-5-1-budget-benchmark-terminal-bench-science</link>
      <guid>https://reveneau.com/ainews/thenewstack-fable-5-1-budget-benchmark-terminal-bench-science</guid>
      <pubDate>Thu, 10 Sep 2026 15:10:00 +0000</pubDate>
      <category>Productivity</category>
      <description>The New Stack ran five Terminal-Bench-Science tasks on Fable 5 and Fable 5.1 under a $12 cost cap and a 60-turn limit each. Fable 5.1 solved one, Fable 5 solved none, and neither reached the 24.7% and 52.6% Anthropic reports for the full 70-task suite. (Source: The New Stack)</description>
    </item>
    <item>
      <title>Replit and Databricks make their Lakebase integration generally available, with Replit Agent auto-provisioning the database on deploy</title>
      <link>https://reveneau.com/ainews/replit-databricks-lakebase-ga-agent-auto-provisioning</link>
      <guid>https://reveneau.com/ainews/replit-databricks-lakebase-ga-agent-auto-provisioning</guid>
      <pubDate>Thu, 10 Sep 2026 15:00:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Replit and Databricks moved their integration from preview to general availability, added native Databricks Lakebase support, and let Replit Agent provision the production database when an app is deployed. (Source: Replit)</description>
    </item>
    <item>
      <title>Scammers upload AI-generated photos with fake phone numbers to Google Business Profiles</title>
      <link>https://reveneau.com/ainews/google-business-profile-ai-photo-fake-phone-scam-jack-edward-150-uploads</link>
      <guid>https://reveneau.com/ainews/google-business-profile-ai-photo-fake-phone-scam-jack-edward-150-uploads</guid>
      <pubDate>Thu, 10 Sep 2026 12:25:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Search Engine Roundtable reports that scammers using the Google Maps contributor program are uploading AI-generated photos carrying fake phone numbers to real Google Business Profiles, and one contributor has placed the same number on more than 150 unrelated listings. (Source: Search Engine Roundtable)</description>
    </item>
    <item>
      <title>OpenAI Codex 0.154 adds isolated worktrees, inline replies and GPT-6 Astra in the model picker</title>
      <link>https://reveneau.com/ainews/openai-codex-0-154-worktree-inline-reply-gpt-6-astra</link>
      <guid>https://reveneau.com/ainews/openai-codex-0-154-worktree-inline-reply-gpt-6-astra</guid>
      <pubDate>Thu, 10 Sep 2026 12:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>OpenAI shipped Codex 0.154.0 on 9 September 2026 with experimental --worktree isolation for forked sessions, inline replies while the agent keeps working, a shared background server on Windows, and GPT-6 Astra in the model picker. (Source: OpenAI)</description>
    </item>
    <item>
      <title>Nvidia says a 30B Nemotron fine-tuned on its supply-chain data scored 86.7 percent, versus 55.5 for the 550B Nemotron</title>
      <link>https://reveneau.com/ainews/nvidia-palantir-nemotron-30b-supply-chain-86-7-vs-55-5-percent</link>
      <guid>https://reveneau.com/ainews/nvidia-palantir-nemotron-30b-supply-chain-86-7-vs-55-5-percent</guid>
      <pubDate>Thu, 10 Sep 2026 11:20:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>Nvidia and Palantir fine-tuned a 30B Nemotron 3.5 Lightning on Nvidia's own supply-chain decisions and, according to Nvidia, it scored 86.7 percent on the internal allocation task versus 55.5 for the 550B Nemotron 3 Ultra, a model 18 times its size. (Source: The New Stack)</description>
    </item>
    <item>
      <title>DeepSeek released DeepSelect, a TopK kernel that runs 2 to 20 times faster than torch.topk</title>
      <link>https://reveneau.com/ainews/deepseek-deepselect-topk-2-to-20x-speedup-torch-topk</link>
      <guid>https://reveneau.com/ainews/deepseek-deepselect-topk-2-to-20x-speedup-torch-topk</guid>
      <pubDate>Thu, 10 Sep 2026 10:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>DeepSeek released DeepSelect v1.0.0 on 9 September 2026, an MIT-licensed CUDA library that gives the TopK operation used in DeepSeek Sparse Attention a 2 to 20 times speedup over torch.topk. (Source: DeepSeek)</description>
    </item>
    <item>
      <title>Nitin Garg's study of AI-generated code review reports the same bug-catch rate with or without a written spec, and 81 percent finding-to-requirement attribution with the spec against 0 without</title>
      <link>https://reveneau.com/ainews/nitin-garg-spec-driven-review-attribution-81-percent-recall-unchanged</link>
      <guid>https://reveneau.com/ainews/nitin-garg-spec-driven-review-attribution-81-percent-recall-unchanged</guid>
      <pubDate>Thu, 10 Sep 2026 09:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Nitin Garg's within-subject study of five reviewers on two AI-generated banking services measured 81 percent finding-to-requirement attribution with a written specification against 0 percent without it, at a cost of 21 minutes per review, with no change in the recall rate. (Source: InfoQ)</description>
    </item>
  </channel>
</rss>
