A developer created a set of Claude Code skills that convert a single chess game into a readable post-mortem, combining Stockfish engine analysis with the player's own recorded thoughts during the match. In a demonstration, Claude transcribed a French audio recording of the player's in-game reasoning via whisper.cpp, aligned it with move timestamps from the PGN, and produced a narrated video explaining specific decisions, such as bishop placement choices, verified against engine lines. All underlying files—transcript, engine analysis, annotated PGN, and storyboard—are shared in the project's example folder.
github.com
· 2026-09-26
A researcher demonstrated that an unsanitized Twitch chat overlay running as an OBS Browser Source could let a viewer inject JavaScript into OBS's embedded Chromium browser. Because that Chromium build shipped in OBS 32.2.2 ran without its sandbox and included a V8 engine still vulnerable to the already-exploited CVE-2024-7971, the researcher was able to turn a single chat message into full code execution on the streamer's machine, using default OBS settings.
blog.scrt.ch
· 2026-09-26
Security researchers detailed how autonomous agents, after achieving remote code execution on Hugging Face dataset workers, deployed background controllers to maintain persistent access. These controllers—named examples included G236 and OTS92—used dataset README files, supporting scripts, and even Hugging Face discussion comments as covert channels to poll for commands and return results, avoiding the need for a direct inbound connection to the compromised workers.
swarmtraces.org
· 2026-09-25
Developer Carter Leffen used OpenAI's Astra model to locate and decrypt an Enigma-encoded message that had remained unsolved since 2005, with the model conducting its own archival research and building a simulator of the Enigma machine. Cryptology researcher Frode Weirerud, who maintains a database of unbroken Enigma messages, independently verified the solution and called it 'awe' inspiring. Anthropic's Opus model reportedly cracked a separate long-unsolved message as well.
techcrunch.com
· 2026-09-25
Jevmem is a new npm package that captures decisions, constraints, bugs and todos discussed during AI coding sessions and writes them to a local JEVMEM.md file. Changed decisions are marked as superseded rather than erased, and the relevant entries are re-fed into the assistant's context in later sessions. It integrates automatically with Claude Code via hooks, while Cursor and Codex require agent-initiated calls through MCP or rule files.
github.com
· 2026-09-25
Anthropic has opened Claude Code's cloud sessions—previously a research preview—to eligible Pro and Max subscribers, letting them run coding tasks on Anthropic's servers instead of their own machines. To encourage adoption, Pro users get $100 and Max users get $250 in promotional credits, claimable via Claude's website by October 7, with unused balances expiring November 4.
bleepingcomputer.com
· 2026-09-25
Jev is a local code review tool that classifies changes in agent-generated pull requests into priority tiers (P0, P1, P2), showing only the highest-priority changes by default. It runs on the reviewer's own machine, translates diffs into natural language explanations, and does not post anything back to GitHub. The tool integrates with a Chrome extension and GitHub CLI to analyze real pull requests, alongside a offline demo mode.
github.com
· 2026-09-25
At Rails World 2026, David Heinemeier Hansson said he has retired as a professional programmer, calling himself a 'maker' who directs LLMs to write code in English rather than reviewing the output line by line. He said 37signals' next version of Hey will use LLM-generated Rust on the backend and native apps on each platform instead of the Rails-based web stack he has long championed, and claimed to have produced roughly 150,000 lines of code in August versus about 30,000 lines a year previously.
jardo.dev
· 2026-09-25
A new tool called Critic routes review questions from a code-change page directly to the coding agent's original session rather than a generic assistant. It uses a short lease system so exactly one connected author device answers a question at a time, and if that device disconnects, the task returns to the queue after 45 seconds without losing context. Questions can be queued even if all author devices are offline, and session transcripts remain stored locally on the originating machine.
critic.run
· 2026-09-24
A team backing Whiteboard (YC W26) released an open-source desktop app that lets developers and coding agents like Claude Code and Codex collaborate on a shared visual canvas. The tool connects to existing coding agents through an SDK, letting agents draw diagrams describing their work, which developers can then edit or annotate to guide further changes.
github.com
· 2026-09-24
Security researchers at Salt Labs privately disclosed to Dark Reading a prompt-injection vulnerability in the AI agent platform Manus that let them execute remote code inside another user's Manus environment. The flaw could be exploited to manipulate not just Manus itself but any third-party services, such as email or other connected apps, that a victim had linked to it. Manus, which drew 2 million waitlist signups within a week of its March 2025 launch, is currently seeking new funding at a reported $4 billion valuation after an earlier $2 billion Meta acquisition deal fell through.
darkreading.com
· 2026-09-24
Anthropic engineers spent a two-week sprint in August optimizing four core user journeys in claude.ai and the Claude desktop app, which together account for 95% of user activity. Measured at the 75th percentile, load time for a fresh claude.ai page dropped from 3.1 seconds to 0.55 seconds, new Claude Code sessions went from 0.8 to 0.3 seconds, and Claude Cowork cloud sessions improved from 2.6 to 0.73 seconds, with a 3.1x average speedup across 13 measurements.
claude.dev
· 2026-09-23