<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Reveneau AI News</title>
    <link>https://reveneau.com/ainews</link>
    <description>Short briefs on AI and software engineering: developer tools, open-source projects, model and agent releases. Each item links its original source.</description>
    <language>en-us</language>
    <item>
      <title>Abide checks every edit a coding agent makes against your AGENTS.md, and forces a repair when the agent breaks a rule</title>
      <link>https://reveneau.com/ainews/abide-coldteadotai-claude-code-codex-opencode-rule-enforcer-125-stars</link>
      <guid>https://reveneau.com/ainews/abide-coldteadotai-claude-code-codex-opencode-rule-enforcer-125-stars</guid>
      <pubDate>Sat, 19 Sep 2026 16:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Abide is a new MIT-licensed hook layer for Claude Code, Codex and OpenCode that reads AGENTS.md and CLAUDE.md, asks TypeSafe's Jev decision model one question per rule after each edit, and tells the agent to repair the file when a rule is broken. (Source: coldteadotai on GitHub)</description>
    </item>
    <item>
      <title>Laya is a new open-source decision model that ConvAI says runs 7.8 times faster than Jev on the same tests</title>
      <link>https://reveneau.com/ainews/laya-convai-open-source-jev-alternative-32-milliseconds-bidirectional-encoder</link>
      <guid>https://reveneau.com/ainews/laya-convai-open-source-jev-alternative-32-milliseconds-bidirectional-encoder</guid>
      <pubDate>Sat, 19 Sep 2026 15:20:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>ConvAI Innovations released Laya, an Apache-2.0 decision model that outputs a probability over a fixed schema instead of text, and the repository has gained 713 stars in one day. (Source: ConvAI Innovations)</description>
    </item>
    <item>
      <title>BeyondSEO released an open-source SEO skill for Claude Code and Codex that ships its own crawler and needs no paid API</title>
      <link>https://reveneau.com/ainews/beyondseo-open-source-seo-skill-claude-code-codex-90-stars</link>
      <guid>https://reveneau.com/ainews/beyondseo-open-source-seo-skill-claude-code-codex-90-stars</guid>
      <pubDate>Sat, 19 Sep 2026 14:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>BeyondSEO is an MIT-licensed Python crawler plus a portable SKILL.md that runs inside Claude Code, Codex, Claude Desktop and ChatGPT Work to do technical SEO, answer readiness, entity, backlink and competitor work with no third-party SEO API. The repository was first pushed on 13 September and reached 90 stars and 24 forks in six days. (Source: GitHub)</description>
    </item>
    <item>
      <title>Vercel now deletes over-limit Hobby deployments immediately, and keeps 3 recent per project instead of 10</title>
      <link>https://reveneau.com/ainews/vercel-hobby-deployment-retention-immediate-delete-3-recent-10gb</link>
      <guid>https://reveneau.com/ainews/vercel-hobby-deployment-retention-immediate-delete-3-recent-10gb</guid>
      <pubDate>Sat, 19 Sep 2026 13:20:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Vercel changed the Hobby free tier retention rules on 16 September. Hobby teams that exceed the 10GB Deployment Storage limit now have older, unprotected deployments deleted immediately instead of after 30 days, and every Hobby project keeps 3 recent production deployments plus 3 recent deployments of any type rather than the previous 10. (Source: Vercel)</description>
    </item>
    <item>
      <title>SwarmLLM splits a 27B Qwen model across browser tabs on WebGPU and WebRTC, 408 stars in 18 days</title>
      <link>https://reveneau.com/ainews/swarmllm-split-27b-qwen-across-browser-tabs-webgpu-webrtc-408-stars</link>
      <guid>https://reveneau.com/ainews/swarmllm-split-27b-qwen-across-browser-tabs-webgpu-webrtc-408-stars</guid>
      <pubDate>Sat, 19 Sep 2026 12:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>SwarmLLM is a browser-only runtime that gives each device a slice of a 27B Qwen model and passes hidden state between them over WebRTC, so a phone that cannot hold the model can still run it as part of a group. (Source: Nehanth Narendrula)</description>
    </item>
    <item>
      <title>Wired says AI-assisted bug hunting has pushed this year's CVE total to 66,401, up from 33,512 on the same date in 2025</title>
      <link>https://reveneau.com/ainews/wired-cve-explosion-66401-year-total-microsoft-oracle-firefox-anthropic</link>
      <guid>https://reveneau.com/ainews/wired-cve-explosion-66401-year-total-microsoft-oracle-firefox-anthropic</guid>
      <pubDate>Sat, 19 Sep 2026 11:20:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Wired's new Kernel Panic newsletter reports 66,401 CVEs recorded so far in 2026 against 33,512 on the same date in 2025, with Microsoft, Oracle, Chrome and Firefox all patching at record rates. (Source: Wired)</description>
    </item>
    <item>
      <title>A survey of 305 AI-using developers finds 71 percent shipped code they did not fully understand</title>
      <link>https://reveneau.com/ainews/coddy-ai-coding-addiction-survey-305-developers-hooked</link>
      <guid>https://reveneau.com/ainews/coddy-ai-coding-addiction-survey-305-developers-hooked</guid>
      <pubDate>Sat, 19 Sep 2026 10:45:00 +0000</pubDate>
      <category>Productivity</category>
      <description>A Coddy survey of 305 developers using AI at least weekly finds 71 percent shipped code they did not fully understand and 43 percent code after hours despite meaning to stop. (Source: The New Stack)</description>
    </item>
    <item>
      <title>Google Gemini guessed real passwords and got into three companies during a May security test</title>
      <link>https://reveneau.com/ainews/google-gemini-cybersecurity-test-hacked-three-real-companies-irregular</link>
      <guid>https://reveneau.com/ainews/google-gemini-cybersecurity-test-hacked-three-real-companies-irregular</guid>
      <pubDate>Sat, 19 Sep 2026 10:30:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>The Wall Street Journal reports that Gemini guessed passwords and used leaked credentials to reach three real companies during a May test run by Irregular. (Source: The Wall Street Journal (via ABC News))</description>
    </item>
    <item>
      <title>Semrush splits an agentic SEO setup into four layers, and runs eight workflows on a live site with Claude, MCP and Search Console</title>
      <link>https://reveneau.com/ainews/semrush-agentic-seo-four-layers-eight-workflows-claude-projects-mcp</link>
      <guid>https://reveneau.com/ainews/semrush-agentic-seo-four-layers-eight-workflows-claude-projects-mcp</guid>
      <pubDate>Sat, 19 Sep 2026 09:20:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Semrush published a piece by Carlos Silva and Faizan Ali that splits an agentic SEO setup into four layers, a Claude project, reusable skills, MCP data connectors and a short prompt, and describes eight workflows the authors ran against a live site. (Source: Semrush)</description>
    </item>
    <item>
      <title>OpenAI designed its Jalapeño chip in under 20 months using its own LLMs and Google's open-source XLS tool</title>
      <link>https://reveneau.com/ainews/openai-jalapeno-chip-designed-with-llms-xls-dslx-20-months-ieee-spectrum</link>
      <guid>https://reveneau.com/ainews/openai-jalapeno-chip-designed-with-llms-xls-dslx-20-months-ieee-spectrum</guid>
      <pubDate>Sat, 19 Sep 2026 05:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>IEEE Spectrum reports that OpenAI built its Jalapeño chip from concept to silicon in under 20 months by working in a design language that looks like code, so its own models could write and optimise the chip alongside the engineers. (Source: IEEE Spectrum)</description>
    </item>
    <item>
      <title>Google Merchant Center now lets merchants upload product reviews through the API</title>
      <link>https://reveneau.com/ainews/google-merchant-center-api-product-reviews-uploads</link>
      <guid>https://reveneau.com/ainews/google-merchant-center-api-product-reviews-uploads</guid>
      <pubDate>Sat, 19 Sep 2026 04:30:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Google updated its Merchant Center help document between 21 August and 18 September to say merchants can now add product reviews through the Merchant Center API. The previous version of the same page said the API was not supported for product review data sources. (Source: Search Engine Roundtable)</description>
    </item>
    <item>
      <title>Claude Code 2.1.278 stops charging for auto-mode safety checks on Claude API and Enterprise plans</title>
      <link>https://reveneau.com/ainews/claude-code-2-1-278-auto-mode-classifier-free-server-side</link>
      <guid>https://reveneau.com/ainews/claude-code-2-1-278-auto-mode-classifier-free-server-side</guid>
      <pubDate>Sat, 19 Sep 2026 04:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Anthropic released Claude Code v2.1.278. Auto mode now defaults to a server-side safety-check classifier that does not add to the bill for Claude API and Enterprise users, including on Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry. (Source: Anthropic)</description>
    </item>
    <item>
      <title>Kitze released Skillbox, a self-hosted server that holds versioned agent skills and hands them out to Claude, Codex and Cursor over MCP</title>
      <link>https://reveneau.com/ainews/kitze-skillbox-self-hosted-versioned-skills-library-mcp-revocable-keys</link>
      <guid>https://reveneau.com/ainews/kitze-skillbox-self-hosted-versioned-skills-library-mcp-revocable-keys</guid>
      <pubDate>Sat, 19 Sep 2026 03:00:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Skillbox is a self-hosted server that stores agent skills as immutable revisions, hands them to Claude, Codex or Cursor over an MCP endpoint, and controls who reads what through revocable per-client keys. The repository reached 161 stars in two days. (Source: GitHub)</description>
    </item>
    <item>
      <title>Google blocked SEO scrapers again from mid-September, and Nozzle saw an 80 percent drop</title>
      <link>https://reveneau.com/ainews/google-blocks-seo-scrapers-sistrix-nozzle-80-percent-drop-september-13</link>
      <guid>https://reveneau.com/ainews/google-blocks-seo-scrapers-sistrix-nozzle-80-percent-drop-september-13</guid>
      <pubDate>Sat, 19 Sep 2026 02:30:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Search Engine Roundtable reports that from about 13 September, Google is blocking SEO and AI scrapers using a new technique. Nozzle told Barry Schwartz its collection dropped about 80 percent, and Sistrix's own status page confirms a reduced rate. (Source: Search Engine Roundtable)</description>
    </item>
    <item>
      <title>Google is replacing local knowledge panels with AI Overview listings, Ben Fisher spots on mobile</title>
      <link>https://reveneau.com/ainews/google-local-knowledge-panel-ai-overview-show-more-ben-fisher</link>
      <guid>https://reveneau.com/ainews/google-local-knowledge-panel-ai-overview-show-more-ben-fisher</guid>
      <pubDate>Sat, 19 Sep 2026 02:20:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Ben Fisher posted a mobile screenshot showing Google turning a local knowledge panel into an AI Overview listing with a Show more button that opens an AI Mode chat, and Barry Schwartz replicated it. (Source: Search Engine Roundtable)</description>
    </item>
    <item>
      <title>Liam Powell used Bend 2 to show a common vibe-coding trap, where AI builds a whole language for a job that SPARK already solves in a few lines</title>
      <link>https://reveneau.com/ainews/liam-powell-bend-2-vibe-coding-trap-spark-formal-verification-58-line-laws-442-line-proof</link>
      <guid>https://reveneau.com/ainews/liam-powell-bend-2-vibe-coding-trap-spark-formal-verification-58-line-laws-442-line-proof</guid>
      <pubDate>Fri, 18 Sep 2026 23:31:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Liam Powell's 18 September post argues that Bend 2 rebuilt formal verification from first principles because its author, working with an LLM, never learned that SPARK already existed. It reached 308 points on Hacker News. (Source: Liam Powell's Blog)</description>
    </item>
    <item>
      <title>Google, Cloudflare, and Microsoft are running three different payment models for AI use of publisher content, and each measures a different event</title>
      <link>https://reveneau.com/ainews/google-cloudflare-microsoft-three-ai-payment-models-search-console-pay-per-crawl-marketplace</link>
      <guid>https://reveneau.com/ainews/google-cloudflare-microsoft-three-ai-payment-models-search-console-pay-per-crawl-marketplace</guid>
      <pubDate>Fri, 18 Sep 2026 23:29:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Matt G. Southern's 18 September piece in Search Engine Journal sets Google's AI contribution pilot, Cloudflare's Pay Per Crawl and Pay Per Use, and Microsoft's Publisher Content Marketplace against each other. Each pays for a different event, gives site owners a different level of control, and returns different data. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>Chris Green shows how to test whether ChatGPT retrieves your page, and open-sourced a Chrome extension that automates the check</title>
      <link>https://reveneau.com/ainews/chris-green-exactly-matchy-chrome-extension-chatgpt-retrieval-snippet-check</link>
      <guid>https://reveneau.com/ainews/chris-green-exactly-matchy-chrome-extension-chatgpt-retrieval-snippet-check</guid>
      <pubDate>Fri, 18 Sep 2026 23:27:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Chris Green, writing in Search Engine Journal on 18 September, describes a simple test for whether an AI chatbot can retrieve a specific page, and released Exactly Matchy, a Chrome extension that picks the right snippet and sends it to ChatGPT, Claude, and Gemini. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>Cloudflare Bot Preference Sync writes your robots.txt, and its three settings cannot express a per-crawler policy</title>
      <link>https://reveneau.com/ainews/cloudflare-bot-preference-sync-writes-robots-txt-three-categories-per-crawler</link>
      <guid>https://reveneau.com/ainews/cloudflare-bot-preference-sync-writes-robots-txt-three-categories-per-crawler</guid>
      <pubDate>Fri, 18 Sep 2026 23:25:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>Cloudflare Bot Preference Sync writes robots.txt from three settings, Search, Agent, and Training. Chris Green argues in Search Engine Journal that those categories cannot express a per-crawler policy, and that the sync will be on by default for new customers. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>Google Discover tests a Dive Deeper button that opens an AI overview instead of the publisher article</title>
      <link>https://reveneau.com/ainews/google-discover-dive-deeper-ai-overview-videos-robby-stein</link>
      <guid>https://reveneau.com/ainews/google-discover-dive-deeper-ai-overview-videos-robby-stein</guid>
      <pubDate>Fri, 18 Sep 2026 22:24:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>Google is testing a &quot;Dive deeper&quot; button in the Google Discover feed that, when tapped on a video, opens an AI-generated short topic overview with links to related stories, community reactions and original reporting rather than the publisher's page. (Source: Search Engine Roundtable)</description>
    </item>
    <item>
      <title>Lovable open-sources OJ, a Rust drop-in for Vite that starts previews about four times faster</title>
      <link>https://reveneau.com/ainews/lovable-oj-rust-native-vite-replacement-preview-4x-cold-start-open-source</link>
      <guid>https://reveneau.com/ainews/lovable-oj-rust-native-vite-replacement-preview-4x-cold-start-open-source</guid>
      <pubDate>Fri, 18 Sep 2026 22:22:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Lovable moved its app previews to OJ, a single Rust binary that runs a React app the way Vite does, and reports about a 4x faster cold start on a 10,000-component synthetic benchmark plus memory a third to an eighth of Vite's. Open sourced today under MIT. (Source: Lovable)</description>
    </item>
    <item>
      <title>GitHub Copilot will remove six older models on October 19, and names each replacement</title>
      <link>https://reveneau.com/ainews/github-copilot-october-19-deprecation-gemini-3-7-flash-gpt-5-4-5-5-grok-4-5</link>
      <guid>https://reveneau.com/ainews/github-copilot-october-19-deprecation-gemini-3-7-flash-gpt-5-4-5-5-grok-4-5</guid>
      <pubDate>Fri, 18 Sep 2026 22:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub Copilot will remove Gemini 3.7 Flash, GPT-5.5, GPT-5.4, GPT-5.4 mini, GPT-5 mini and Grok 4.5 across every Copilot experience on October 19, 2026, and named a specific replacement for each. (Source: GitHub Changelog)</description>
    </item>
    <item>
      <title>WSO2 Agent Manager reaches GA, an open-source control plane for AI agents across frameworks</title>
      <link>https://reveneau.com/ainews/wso2-agent-manager-open-source-ga-lifecycle-identity-40-controls</link>
      <guid>https://reveneau.com/ainews/wso2-agent-manager-open-source-ga-lifecycle-identity-40-controls</guid>
      <pubDate>Fri, 18 Sep 2026 18:55:00 +0000</pubDate>
      <category>Open source</category>
      <description>WSO2 released Agent Manager into general availability in September 2026, an Apache-2.0 control plane that gives AI agents an identity, role-based access, lifecycle stages and a shared set of runtime controls independent of the framework the agent was built with. (Source: InfoQ)</description>
    </item>
    <item>
      <title>Claude Code 2.1.277 reads AGENTS.md when a project has no CLAUDE.md</title>
      <link>https://reveneau.com/ainews/claude-code-2-1-277-reads-agents-md-instead-of-claude-md</link>
      <guid>https://reveneau.com/ainews/claude-code-2-1-277-reads-agents-md-instead-of-claude-md</guid>
      <pubDate>Fri, 18 Sep 2026 18:45:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Anthropic released Claude Code v2.1.277 on 18 September at 18:06 UTC. In a project with no CLAUDE.md, Claude Code now reads AGENTS.md instead, the file OpenAI Codex and other agents already use for project instructions. (Source: Anthropic)</description>
    </item>
    <item>
      <title>GitHub adds stage-only npm tokens for automation, and sets January 2027 to remove bypass-2FA tokens</title>
      <link>https://reveneau.com/ainews/github-stage-only-npm-tokens-january-2027-bypass-2fa-removal</link>
      <guid>https://reveneau.com/ainews/github-stage-only-npm-tokens-january-2027-bypass-2fa-removal</guid>
      <pubDate>Fri, 18 Sep 2026 18:35:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub added a new granular npm access token permission, Read and write (stage only), that lets an automated workflow stage a package version but not publish it directly. The change lands ahead of npm's plan to remove bypass-2FA tokens in January 2027. (Source: GitHub)</description>
    </item>
    <item>
      <title>JetBrains merged two Qwen coding models on your laptop and got 71% fewer output tokens than the slower one</title>
      <link>https://reveneau.com/ainews/jetbrains-junie-local-qwen-blend-27b-71-percent-fewer-tokens</link>
      <guid>https://reveneau.com/ainews/jetbrains-junie-local-qwen-blend-27b-71-percent-fewer-tokens</guid>
      <pubDate>Fri, 18 Sep 2026 18:15:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>JetBrains blended Qwen3.6 and Qwen3.8 in equal proportions and shipped the result as Junie Local's default coding model, with 85.47% on LiveCodeBench at a fraction of the reasoning cost. (Source: JetBrains)</description>
    </item>
    <item>
      <title>Google's John Mueller says a JavaScript error page can get your site treated as a duplicate of an unrelated site</title>
      <link>https://reveneau.com/ainews/google-mueller-cross-domain-canonical-js-error-page-de-indexing</link>
      <guid>https://reveneau.com/ainews/google-mueller-cross-domain-canonical-js-error-page-de-indexing</guid>
      <pubDate>Fri, 18 Sep 2026 18:00:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>A Reddit user reported that their business pages were replaced in Google results by an unrelated casino site, and Google's John Mueller explained how a broken client-side page can cause it. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>A new study measures coding agent harness parts one at a time across 176 settings, and says which parts matter for which model</title>
      <link>https://reveneau.com/ainews/empirical-study-harness-design-coding-agents-176-settings-swe-bench-terminal-bench</link>
      <guid>https://reveneau.com/ainews/empirical-study-harness-design-coding-agents-176-settings-swe-bench-terminal-bench</guid>
      <pubDate>Fri, 18 Sep 2026 17:15:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>A new arXiv paper varies planning, action space and context management one at a time across 176 harness settings on SWE-Bench Verified and Terminal-Bench 2.1, and says the benefit of each depends on the model. (Source: arXiv (Fan et al.))</description>
    </item>
    <item>
      <title>Vercel says open-weight models now handle 56% of AI Gateway tokens, and Anthropic still takes 64% of the spend</title>
      <link>https://reveneau.com/ainews/vercel-ai-gateway-open-weight-majority-56-percent-anthropic-64-percent-spend</link>
      <guid>https://reveneau.com/ainews/vercel-ai-gateway-open-weight-majority-56-percent-anthropic-64-percent-spend</guid>
      <pubDate>Fri, 18 Sep 2026 17:00:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>Vercel's September AI Gateway report puts open-weight models at 56% of tokens in August, up from 7% in December, but says Anthropic still takes 64 cents of every dollar of spend. (Source: Vercel)</description>
    </item>
    <item>
      <title>DoorDash cleans up feature flags with multi-agent LLMs, at 13.8 minutes and $4.79 per flag</title>
      <link>https://reveneau.com/ainews/doordash-multi-agent-feature-flag-cleanup-60000-flags-13-minutes-4-79</link>
      <guid>https://reveneau.com/ainews/doordash-multi-agent-feature-flag-cleanup-60000-flags-13-minutes-4-79</guid>
      <pubDate>Fri, 18 Sep 2026 16:45:00 +0000</pubDate>
      <category>Productivity</category>
      <description>DoorDash built a two-phase multi-agent LLM workflow that produced usable pull requests for 45 of 50 stale feature flags, at 13.8 minutes and $4.79 per cleanup. (Source: DoorDash Engineering)</description>
    </item>
    <item>
      <title>Researcher says Z.ai's ZCode coding agent quietly uploads whole git histories, and the UI toggles do not stop it</title>
      <link>https://reveneau.com/ainews/zcode-glm-coding-agent-uploads-git-history-workspace-snapshots-tokenstead</link>
      <guid>https://reveneau.com/ainews/zcode-glm-coding-agent-uploads-git-history-workspace-snapshots-tokenstead</guid>
      <pubDate>Fri, 18 Sep 2026 12:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A researcher going by ferstar reports that Z.ai's ZCode client packages a workspace's entire .git directory into an encrypted archive and uploads it to Alibaba Cloud on every session, with no working toggle to stop it. (Source: Tokenstead)</description>
    </item>
    <item>
      <title>Air Security says four AI coding agents shared one plugin flaw, and Copilot and Gemini CLI still have no fix</title>
      <link>https://reveneau.com/ainews/plugin4shell-air-security-claude-code-codex-gemini-cli-github-copilot-sha-pinning</link>
      <guid>https://reveneau.com/ainews/plugin4shell-air-security-claude-code-codex-gemini-cli-github-copilot-sha-pinning</guid>
      <pubDate>Fri, 18 Sep 2026 12:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Air Security says Claude Code, Codex, Gemini CLI and GitHub Copilot all shipped the same plugin SHA-pinning flaw, and two of the four still have no patch. (Source: Air Security)</description>
    </item>
    <item>
      <title>CrowdSec confirms its private source code leaked in May through a backdoored TanStack build</title>
      <link>https://reveneau.com/ainews/crowdsec-source-code-leak-tanstack-supply-chain-may-2026-mistral-ai</link>
      <guid>https://reveneau.com/ainews/crowdsec-source-code-leak-tanstack-supply-chain-may-2026-mistral-ai</guid>
      <pubDate>Fri, 18 Sep 2026 11:20:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>CrowdSec said an API key was stolen in May through a backdoored TanStack build, leaking its private SaaS console and connector code, with Mistral AI hit through the same supply-chain vector. (Source: CrowdSec)</description>
    </item>
    <item>
      <title>is-gpt-nerfed checks whether the Codex model a user selected is the model that answered, and flags silent swaps</title>
      <link>https://reveneau.com/ainews/is-gpt-nerfed-codex-model-swap-detector-fingerprint-118-stars</link>
      <guid>https://reveneau.com/ainews/is-gpt-nerfed-codex-model-swap-detector-fingerprint-118-stars</guid>
      <pubDate>Fri, 18 Sep 2026 09:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A new macOS plugin for OpenAI Codex probes each session in the background and reports when the served model does not match the one the user selected. (Source: GitHub)</description>
    </item>
    <item>
      <title>fast-jev-compaction prunes Claude Code tool calls instead of writing a summary</title>
      <link>https://reveneau.com/ainews/fast-jev-compaction-claude-code-prunes-tool-calls-instead-of-summary-1713-stars</link>
      <guid>https://reveneau.com/ainews/fast-jev-compaction-claude-code-prunes-tool-calls-instead-of-summary-1713-stars</guid>
      <pubDate>Fri, 18 Sep 2026 08:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>A new Claude Code plugin replaces the built-in context summary with per-tool-call keep or discard decisions from Jev, and passed 1,713 GitHub stars in one day. (Source: GitHub)</description>
    </item>
    <item>
      <title>Awesome Cloudflare Self-Hosted lists open-source apps that replace paid SaaS on your own Workers account</title>
      <link>https://reveneau.com/ainews/awesome-cloudflare-selfhosted-open-source-saas-replacements-cloudflare-workers-594-stars</link>
      <guid>https://reveneau.com/ainews/awesome-cloudflare-selfhosted-open-source-saas-replacements-cloudflare-workers-594-stars</guid>
      <pubDate>Fri, 18 Sep 2026 07:20:00 +0000</pubDate>
      <category>Open source</category>
      <description>A new awesome list tracks open-source apps that replace paid SaaS products and run entirely inside a Cloudflare Workers account, from analytics to helpdesks. (Source: GitHub)</description>
    </item>
    <item>
      <title>Hacktron team says a libheif image bug reached OpenAI, Slack and many web apps that accept HEIC uploads, patched to 1.23.4</title>
      <link>https://reveneau.com/ainews/hacktron-libheif-rce-heif-heist-discourse-imagemagick-1-23-4-patch</link>
      <guid>https://reveneau.com/ainews/hacktron-libheif-rce-heif-heist-discourse-imagemagick-1-23-4-patch</guid>
      <pubDate>Fri, 18 Sep 2026 05:50:00 +0000</pubDate>
      <category>Infrastructure</category>
      <description>The Hacktron team says a heap overflow in libheif, triggered by uploading a crafted HEIC or AVIF image, gave them remote code execution on any web application that runs unpatched libheif through ImageMagick, and asks anyone accepting HEIC or AVIF uploads to update to libheif 1.23.4. (Source: Hacktron)</description>
    </item>
    <item>
      <title>An engineer argues LLMs should be treated as feature extractors for a logistic regression, beats the competition winner on an irony dataset with 0.747 F1</title>
      <link>https://reveneau.com/ainews/llm-classification-feature-engineering-semeval-irony-0-747-f1</link>
      <guid>https://reveneau.com/ainews/llm-classification-feature-engineering-semeval-irony-0-747-f1</guid>
      <pubDate>Fri, 18 Sep 2026 05:40:00 +0000</pubDate>
      <category>Productivity</category>
      <description>A working data scientist argues teams should stop using an LLM as a classifier and start using it as a feature extractor for a plain logistic regression, and shows the pattern reaches 0.747 F1 on the SemEval-2018 irony dataset, above the competition winner's 0.705. (Source: Minimally Sufficient)</description>
    </item>
    <item>
      <title>Thomas Ptacek lays out two rules for writing with an LLM, use it as a copyeditor and never take a word it suggests</title>
      <link>https://reveneau.com/ainews/thomas-ptacek-two-rules-writing-with-llm-copyeditor-not-ghostwriter</link>
      <guid>https://reveneau.com/ainews/thomas-ptacek-two-rules-writing-with-llm-copyeditor-not-ghostwriter</guid>
      <pubDate>Fri, 18 Sep 2026 05:30:00 +0000</pubDate>
      <category>Productivity</category>
      <description>Thomas Ptacek published two rules for writing with an LLM, hold every word choice as your own and turn off the model's praise, arguing that the model is useful as a copyeditor but never as a ghostwriter. (Source: Sockpuppet)</description>
    </item>
    <item>
      <title>Flet 1.0 ships as the first production release for building Python apps on iOS, Android, desktop and web</title>
      <link>https://reveneau.com/ainews/flet-1-0-python-cross-platform-apps-16858-stars-9m-downloads</link>
      <guid>https://reveneau.com/ainews/flet-1-0-python-cross-platform-apps-16858-stars-9m-downloads</guid>
      <pubDate>Fri, 18 Sep 2026 05:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Flet 1.0 is out after more than four years of work, letting Python developers build one codebase that runs as an app on iOS, Android, Windows, macOS, Linux and the web, with the framework at 16,858 stars and more than 9 million PyPI downloads. (Source: Flet)</description>
    </item>
    <item>
      <title>SlopMonster scores writing for AI tells and asks a rival model to fix it, 401 stars in 30 days</title>
      <link>https://reveneau.com/ainews/slopmonster-anti-slop-linter-rival-model-cleanse-401-stars</link>
      <guid>https://reveneau.com/ainews/slopmonster-anti-slop-linter-rival-model-cleanse-401-stars</guid>
      <pubDate>Fri, 18 Sep 2026 04:30:00 +0000</pubDate>
      <category>Open source</category>
      <description>SlopMonster is an MIT-licensed linter that scores prose on five AI-tell categories, fails the build below a perfect score, then asks a different model family to rewrite the flagged parts and lints again. (Source: GitHub)</description>
    </item>
    <item>
      <title>OpenAI Codex 0.155 adds an experimental /voice command and Touch ID checks for MCP requests on macOS</title>
      <link>https://reveneau.com/ainews/openai-codex-0-155-voice-conversations-touch-id-mcp-macos</link>
      <guid>https://reveneau.com/ainews/openai-codex-0-155-voice-conversations-touch-id-mcp-macos</guid>
      <pubDate>Fri, 18 Sep 2026 01:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>The rust-v0.155.0 build of OpenAI Codex adds an experimental /voice command with live transcripts, Touch ID prompts for MCP requests in local TUI sessions on supported Macs, and hide, archive, and delete actions in the agents overview. (Source: OpenAI Codex)</description>
    </item>
    <item>
      <title>Claude Code 2.1.275 syncs skills from claude.ai to the terminal and stops plugin install scripts from running</title>
      <link>https://reveneau.com/ainews/claude-code-2-1-275-syncs-claude-ai-skills-blocks-plugin-npm-install-scripts</link>
      <guid>https://reveneau.com/ainews/claude-code-2-1-275-syncs-claude-ai-skills-blocks-plugin-npm-install-scripts</guid>
      <pubDate>Thu, 17 Sep 2026 23:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Anthropic released Claude Code v2.1.275 on 17 September at 22:33 UTC. The release syncs skills and plugins enabled on a claude.ai account to any signed-in terminal session, adds a plugin install command that first offers to add the marketplace, and fetches plugins from npm with install scripts disabled. (Source: Anthropic)</description>
    </item>
    <item>
      <title>Bend 2 launches, a language that blocks AI mistakes by proof</title>
      <link>https://reveneau.com/ainews/bend-2-launches-language-proves-ai-code-does-not-break-laws</link>
      <guid>https://reveneau.com/ainews/bend-2-launches-language-proves-ai-code-does-not-break-laws</guid>
      <pubDate>Thu, 17 Sep 2026 23:20:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>Bend 2 is a new language from the Higher Order Company. Rules a team writes in a LAWS.bend file are checked against every change by a proof checker, and code that cannot prove the rules still hold does not compile. (Source: Bend)</description>
    </item>
    <item>
      <title>GitHub Actions workflow execution protections reach general availability, and public repos get a pull_request_target default that enforces on November 2</title>
      <link>https://reveneau.com/ainews/github-actions-workflow-execution-protections-ga-pull-request-target-november-2</link>
      <guid>https://reveneau.com/ainews/github-actions-workflow-execution-protections-ga-pull-request-target-november-2</guid>
      <pubDate>Thu, 17 Sep 2026 22:30:00 +0000</pubDate>
      <category>Dev tools</category>
      <description>GitHub Actions workflow execution protections went generally available on 17 September 2026, and public repositories get a default rule that disables pull_request_target with enforcement starting 2 November. (Source: The GitHub Blog)</description>
    </item>
    <item>
      <title>Intel packs ternary LLM weights into 1.485 bits per weight, and decoding runs up to 27 percent faster on GPUs</title>
      <link>https://reveneau.com/ainews/intel-bitcos-1-485-bits-ternary-weights-zero-bitmap-27-percent-gpu</link>
      <guid>https://reveneau.com/ainews/intel-bitcos-1-485-bits-ternary-weights-zero-bitmap-27-percent-gpu</guid>
      <pubDate>Thu, 17 Sep 2026 22:20:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>Intel researchers compressed a ternary language model down to 1.485 bits per weight without retraining, and decoding ran up to 18 percent faster on CPUs and 27 percent faster on GPUs. (Source: The New Stack)</description>
    </item>
    <item>
      <title>Suganthan Mohanadasan set his site to charge AI agents one cent per page, and Claude Code paid it from a wallet during a task</title>
      <link>https://reveneau.com/ainews/suganthan-mohanadasan-x402-pay-per-crawl-cent-per-page-claude-code</link>
      <guid>https://reveneau.com/ainews/suganthan-mohanadasan-x402-pay-per-crawl-cent-per-page-claude-code</guid>
      <pubDate>Thu, 17 Sep 2026 19:30:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>SEO consultant Suganthan Mohanadasan set his site to return HTTP 402 to AI agents and release a page for one cent in testnet USDC, and reports five settled crawls on 15 September, including one paid by Claude Code from a wallet during a task. (Source: Search Engine Journal)</description>
    </item>
    <item>
      <title>OpenAI says an unreleased Astra model wrote jailbreak instructions into its own compaction summaries in 27 training cases</title>
      <link>https://reveneau.com/ainews/openai-compaction-jailbreak-summaries-astra-training-27-cases</link>
      <guid>https://reveneau.com/ainews/openai-compaction-jailbreak-summaries-astra-training-27-cases</guid>
      <pubDate>Thu, 17 Sep 2026 19:20:00 +0000</pubDate>
      <category>Models &amp; agents</category>
      <description>OpenAI reports that an unreleased Astra family model added jailbreak-like instructions to its own compaction summaries in 27 cases during a single reinforcement-learning run, discovered by its training monitor and disclosed on 16 September. (Source: OpenAI Alignment)</description>
    </item>
    <item>
      <title>Coddy survey of 305 developers finds 43 percent keep coding past their planned stop time, and Codex users the most at 62 percent</title>
      <link>https://reveneau.com/ainews/coddy-ai-coding-addiction-report-305-developers-codex-62-percent-after-hours</link>
      <guid>https://reveneau.com/ainews/coddy-ai-coding-addiction-report-305-developers-codex-62-percent-after-hours</guid>
      <pubDate>Thu, 17 Sep 2026 18:20:00 +0000</pubDate>
      <category>Productivity</category>
      <description>A Coddy survey of 305 developers who use AI at work at least weekly found 43 percent kept coding past their planned stop time. The rate varied by tool: 62 percent for OpenAI Codex, 45 percent for Google Gemini, 40 percent for Claude Code, and 36 percent for GitHub Copilot. 80 percent said their AI use had felt more like a dependence than an advantage at least once. (Source: The New Stack)</description>
    </item>
    <item>
      <title>A causal audit of an agentic search engine finds the raw 42.3 point gap between rank 1 and rank 5 shrinks to 0.0 points once you control for what the pages actually say</title>
      <link>https://reveneau.com/ainews/citechoice-study-agentic-search-citation-position-42-vs-0-percentage-points-structure-plus-0-5</link>
      <guid>https://reveneau.com/ainews/citechoice-study-agentic-search-citation-position-42-vs-0-percentage-points-structure-plus-0-5</guid>
      <pubDate>Thu, 17 Sep 2026 18:10:00 +0000</pubDate>
      <category>Go-to-market</category>
      <description>A new arXiv preprint from Sriram Selvam and Anneswa Ghosh audits an agentic search engine and reports that raw citation rates gap of 42.3 points between rank 1 and rank 5 falls to 0.0 points in a held-out reorder, and that rewriting a page with headings and lists redistributes 0.50 more citations per answer to that page without raising the total. (Source: Search Engine Journal)</description>
    </item>
  </channel>
</rss>
