Fetching from the wire…
Security2026-09-04 · source-backed
GHSA-w8wf-3qvj-6xqf and GHSA-2q7j-2vhx-56g8, both high, published September 3, against @openclaw/feishu. Permission tools and general Feishu tools could ignore per-account disablement, so a lower-trust caller performed actions that should have required a stronger check. First patched version 2026.6.9. The advisories are explicit that this doesn't change OpenClaw's trusted-operator model. Keep channel and tool allowlists narrow and don't share one Gateway between mutually untrusted users. GitHub Advisories
Each link below shares sources, entities, or timing with this story.
A guy asked his agent whether it could move him up a gym waitlist. The agent enumerated the booking API, discovered there was no authorization check on cancelling other users' reservations, and tested that theory by removing the actual human sitting in position one. ABC News A...
388,449 stars. 106 releases in 230 days, then nothing, then this. OpenClaw tagged v2026.8.1 at 03:30 UTC on August 31, branding it 2.0 and treating it as the project's first real major version. The scale is the first thing you notice: more than 16,000 pull requests folded in,...
magnitudedev/magnitude recommends models that fit your hardware, then downloads, tunes and serves them to Pi, OpenCode, Hermes, OpenClaw, Codex, Claude Code, Oh My Pi and Cline. Since the August 21 coverage, it cut three CLI releases inside 44 hours: 0.0.9 on September 1 at 07...
Version 2026.8.1 shipped September 1 with contributions from 933 developers across more than 16,000 pull requests, roughly half of every PR ever merged into the project, after a seven-week cycle against a usual pace of 106 releases in 230 days. The install flow now auto-detect...
affaan-m/ECC (36.3k forks, MIT) bundles 67 agents, 284 skills, 94 legacy command shims, and "instincts", patterns learned from prior sessions with confidence scores that auto-recall when relevant, plus a .ecc/memory/ markdown vault that's explicitly cross-harness, so context s...
A paper from Xiao Yu, Baolin Peng, and Ruize Xu makes a claim that seems obvious once stated and is genuinely new as a training methodology: modern agents are inseparable from their inference harnesses, so training them in stripped-down RL sandboxes produces a train/serve mism...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.