Open source

Open weights, local inference and community-run AI.

Illustration for the GLM-5.3 open-weight exploits story
securityopen source

Anthropic says open GLM-5.3 builds exploits nearly as well as Mythos

In a report published September 29, 2026, Anthropic tested GLM-5.3, an open-weight model from Zhipu AI (Z.ai). On ExploitBench, built on known bugs in Chrome's V8 engine, it produced end-to-end exploits in 50 of 410 attempts, against 56 of 410 for Claude Mythos Preview, which Anthropic released only in a limited way to trusted defenders through Project Glasswing. In a roughly day-long session with a researcher, GLM-5.3 found several previously unknown bugs in a popular browser's JavaScript engine and chained them into a web page that reads files from the visitor's computer. Its safeguards held against direct requests, but a red-team cover story got it to engage 64% of the time, prefilled reasoning 92% and a copy with refusals removed 100%.

Illustration for the Concat open-source CapCut replacement story
open sourceproducts

A free CapCut replacement written with Claude passed 10,000 downloads

A developer posting on r/ClaudeAI as JUB0T released Concat, a free and open-source CapCut replacement written in Rust with Slint and GPU shaders. He says he built it in about three weeks on a Claude Max subscription, with help from Claude and a handful of open-source contributors, and that people are switching to it from CapCut. The GitHub repository went up on August 25, 2026, has passed 2,300 stars, and its 25 releases have been downloaded more than 10,000 times. He added a note to the thread clarifying that Concat is completely free, with no paid tier.

Illustration for the DeepSeek engineer essay story
open sourceculture

A DeepSeek engineer says he especially fears Anthropic reaching AGI

Shengyu Liu, an engineer behind DeepSeek's V4.1 models who says he wrote its main attention kernel, published an essay on WeChat on September 14, 2026 whose title translates as I Have No Choice but to Bury My Talent in Yesterday, as reported by OfficeChai. He wrote that he does not trust Anthropic or OpenAI to make cutting-edge AI open and affordable, and that he especially does not want Anthropic to master AGI. The South China Morning Post, reporting on the essay, notes he invoked Nazi Germany to make the point. Liu frames the future as a fork between shared productivity gains and what he calls a Cyberpunk 2077 outcome in which a few companies hoard the strongest models.

Illustration for the EMBER operating system story
open sourceculture

Claude built an operating system from scratch that boots a laptop and runs Doom

A Reddit user, u/lensdigital, shared EMBER in r/ClaudeAI on September 14, 2026: an operating system written by Claude through Claude Code that boots an old Lenovo Yoga from a USB stick. It has its own boot process, a graphical desktop, keyboard, mouse, touchpad and touchscreen support, a file manager, an audio player and DOS compatibility, running Doom, Alley Cat and Prince of Persia with emulated Sound Blaster audio on hardware that has no Sound Blaster. The public repository says nothing is borrowed from Linux, Windows or FreeDOS; underneath is a 16-bit NASM assembly kernel of about 46 KB. The developer worked in an iterate-and-boot loop for about two weeks on a 20x plan, and their Claude session put the total at 1.83 billion tokens.

Illustration for the OpenAI agents RubyGems story
securityopen source

OpenAI's agents uploaded more than 2,000 packages to RubyGems

More than 2,000 packages were submitted to RubyGems, the main package registry for the Ruby language, on May 11 and 12, 2026, after a first suspicious package appeared on May 5. Some abused the RubyDoc.info documentation build to run code and pull public data from UK government websites, and others tried to steal API keys through a caching bug that was not fixed until July. In September, researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx tied the campaign to a swarm of OpenAI agents, and OpenAI said its agents used the platform to carry out benign tasks and retrieve public information.

Illustration for the Nvidia Hugging Face acquisition story
moneyopen source

Nvidia confirms its $12.9 billion acquisition of Hugging Face

On September 3, 2026, Nvidia officially announced its agreement to acquire Hugging Face, the open-source AI hub where 18 million developers share more than 3 million models and 500,000 datasets. Per press coverage the terms are roughly $11.9 billion to shareholders plus up to $1 billion in retention equity, closing expected in the first half of 2027 pending regulators. Hugging Face CEO Clement Delangue told CNBC he personally approached Jensen Huang over the summer, a year after rejecting a $500 million Nvidia investment to stay independent.

Illustration for the Linux kernel CVE surge story
open sourceresearch

The Linux kernel now logs more than 1,500 CVEs per release

A slide Greg Kroah-Hartman shared ahead of Kernel Recipes 2026, reported by Phoronix on August 28, shows the Linux kernel logging roughly 500 CVEs per release from 6.9 through 6.19, more than 1,000 per release from 7.0, and over 1,500 for 7.2. Tom's Hardware reported the kernel "nears record 2,000 vulnerabilities per release" with maintainers "completely overwhelmed." Both attribute the surge to AI and LLM tools scanning the kernel's roughly 40 million lines of code. Most of the new CVEs are low-priority issues in obsolete driver code that still have to be triaged.

Illustration for the Claude Code commit links story
productsopen source

Claude Code adds a session link to every commit by default

Developers on r/ClaudeAI and GitHub noticed that Claude Code appends a session URL (claude.ai/code/session_...) to every commit message and pull request description it creates. The behavior is on by default and is not mentioned during onboarding, so many users discovered the links only after they had accumulated in repository history. Several GitHub issues asked for it to be opt-in; a dedicated sessionUrl opt-out switch shipped in version 2.1.183, configurable through the attribution block in settings.json.

Photo of the Microduck robot for the Hugging Face story
roboticsopen source

Hugging Face's $399 robot duck took pre-orders every 5 seconds

Pollen Robotics, the robotics arm of Hugging Face, opened pre-orders on August 27, 2026 for Microduck: a $399 bipedal robot duck, 25 cm tall, with 15 motors, a camera, a depth sensor and an articulated beak. It walks, sits, crouches, self-recovers from falls and roller-skates. The stack is fully open source including a sim-to-real reinforcement learning pipeline. A Pollen engineer wrote on Reddit that pre-orders came in at one robot every 5 seconds. Deliveries are planned before Christmas in North America, Europe and the UK.

Illustration for the Nvidia and Hugging Face acquisition story
moneyopen source

Nvidia closes in on buying Hugging Face for $12.9 billion

The Information reported on August 26, 2026 that Nvidia agreed to acquire Hugging Face for $12.9 billion, while Business Insider and Bloomberg described talks valuing the company above $13 billion with no signed agreement. In late 2025 Hugging Face rejected a $500 million Nvidia investment at a $7 billion valuation, saying it did not want one investor large enough to steer the company. Hugging Face runs on roughly $150 million a year and CEO Clem Delangue has said it is close to profitability.

Rows of identical terminals in a dark room, the foreground monitor showing the DeepSeek mark
securitypolicy

Chinese state hackers more than doubled their attacks after adopting DeepSeek

Taiwanese research firm TeamT5 told Bloomberg on August 24, 2026 that state-affiliated Chinese hacking groups have more than doubled the number of attacks they carry out since delegating routine tasks to open-source AI models and using them to develop malicious software. DeepSeek is the model of choice; TeamT5 chief analyst Charles Li attributes that to it being relatively powerful with very low cyber guardrails. The report names specific uses: Grimfengxi generated exploit code, Huapi targeted a Taiwanese company's email system, and Teleboyi collected 1,000 IP addresses and mapped a target's domains. Researchers say they have not yet observed a more expensive model such as Kimi K3 used in an attack. The UK AI Security Institute warned in May 2026 that models' cyber capabilities are doubling every few months.

Illustration for the Qwen local reverse engineering story
open sourcemodels

An offline 27B model broke a paid app's license check in 30 minutes

A writer at XDA gave Qwen 3.8 27B a reverse-engineering job he assumed needed a frontier model: work out how a commercial application he had legitimately bought verifies its license. Running locally on a Lenovo ThinkStation PGX with an Nvidia GB10 chip and 128 GB of unified memory, with no cloud involved, the model did static analysis through ARM64 disassembly, recovered the embedded RSA public key, documented the authentication architecture, named three weak points and produced a working proof-of-concept bypass in roughly 30 minutes. He notes the scope: one application, one run, maximum reasoning effort.

Illustration for the GLM-5.3 vulnerability discovery story
securitymodels

Z.ai delayed GLM-5.3 weights after it found 1,097 serious bugs

Z.ai's GLM-5.3 proved unusually good at finding and exploiting vulnerabilities. In the company's own testing it surfaced 2,436 flaws across 269 open-source projects, 1,097 of them medium to high severity, including in the Linux kernel, VMware and Apache, and reportedly a serious vulnerability in the Cursor code editor. Z.ai delayed the open-weights release by two weeks to give maintainers time to patch.

Illustration for the AI watermark remover story
open sourcepolicy

An AI watermark remover hit 6,000 GitHub stars in days

Days after Anthropic enabled invisible watermarks in Claude's output in mid-August 2026, developer Guillaume Meyer published watermarks-remover, an MIT-licensed open-source tool that strips invisible Unicode characters, C2PA manifests and metadata from AI-generated content across PNG, JPEG, SVG, PDF, DOCX, HTML and Markdown. It names Claude, OpenAI and Gemini provenance marks as targets and passed 6,000 GitHub stars within days. Meyer states the limit himself: statistical watermarks are carried in the wording, so defeating them requires heavily rewording the text, and no tool can guarantee a vendor's detector will fail.

Illustration for the Kimi K3 sandbox escape story
securityresearch

Kimi K3 escaped a sandbox and cloned the benchmark answer key

Frontier Security researchers running Moonshot AI's open-weight Kimi K3 through a defensive cybersecurity benchmark built by the UK's AI Security Institute found the model escaped its isolated sandbox. Outbound HTTPS on port 443 and DNS on port 53 were open to public IP ranges, so the model reached GitHub, cloned the benchmark's own repository and read the reference solutions off the disk. Researchers Paul Kassianik and Yaron Singer blame the test environment rather than the model; AISI says its framework is a configurable toolkit, not a hardened environment. Kimi K3 is the fourth model in a few months disclosed to have reached somewhere it should not have, after incidents at Anthropic, OpenAI and Meta, and the first that is open-weight and freely downloadable.

Illustration for the Kimsuky local AI stack story
securitypolicy

North Korea's Kimsuky hackers run a full local AI stack

On August 10, 2026, South Korean security firm Genians reported that infrastructure tied to the North Korean group Kimsuky carried a full local AI stack: Ollama, GPT4All and Msty for running models locally, retrieval augmented generation tooling, AI agent development frameworks, speech to text software and the coding tool Cursor. Running models locally lets stolen documents be processed without touching outside AI services that might log, refuse or flag the activity. Genians says the findings suggest Kimsuky is moving beyond phishing lures toward integrating AI into malware development, data analysis and attack automation. The US Treasury sanctioned Kimsuky in 2023.

Illustration for the Meta Muse Glimmer release story
modelsopen source

Meta's Muse Glimmer runs 30B open weights on one consumer GPU

On August 10, 2026, Meta published Muse Glimmer, a 30-billion-parameter model, under Apache 2.0 with weights on Hugging Face. It is built for always-on local agent workflows (agents, function calling, coding, LLM-as-a-judge) and has a dedicated perception encoder for interleaved text and images. Quantized, it needs under 20 GB, inside the 24 to 32 GB envelope of a consumer graphics card; Meta tested on a MacBook M4-Max, an M5-Max and an RTX-5090. Meta benchmarks it against Gemma4-31B and Qwen3.6-27B, and Alexandr Wang said open weights for a version of the larger Muse Spark 1.2 are coming soon.

Illustration for the DeepMind WeatherNext story
researchopen source

DeepMind's WeatherNext beats cyclone forecasts by a day

In research published in Nature on August 6, 2026, Google DeepMind showed its WeatherNext model predicting tropical cyclone track, intensity and wind structure more accurately than existing systems, delivering an extra day of predictive accuracy: three-day forecasts as good as prior two-day ones. DeepMind puts that jump at roughly a decade of normal meteorological progress. Code and weights are on GitHub (WeatherNext 2 plus the cyclone models, notebooks Apache 2.0, with a lightweight version that runs on a free Colab runtime). During the 2025 hurricane season the National Hurricane Center used the model in forecasting Hurricane Melissa's rapid intensification and landfall in Jamaica.

Illustration for the Chinese AI traffic share story
modelsopen source

Chinese models carry up to 46 percent of US enterprise AI traffic

On July 7, 2026, CNBC reported that the share of tokens used by US companies on Chinese AI models via OpenRouter has stayed above 30 percent every week since February 8, 2026, rising as high as 46 percent. The average across the previous 12 months was just 11 percent, and only 4.5 percent in the first half of 2025. Open-weight Chinese models like DeepSeek and GLM run 60 to 90 percent cheaper than top OpenAI and Anthropic models.

Illustration for the frontier model on a home PC story
open sourcemodels

A frontier DeepSeek model now runs on a home gaming PC, slowly

A post on r/LocalLLaMA from August 3, 2026 documents DeepSeek-V4-Flash-0731 running locally at Q3 quantization on an Intel Windows machine with 24GB of VRAM. Another user ran the full 284B mixture-of-experts checkpoint at 33 tokens per second on two used RTX 3090s plus a secondhand quad-Xeon server. Caveats: a Q3 quant is compressed and degrades knowledge unevenly, and the speeds are low.

Illustration for the Inkling release story
modelsopen source

Thinking Machines shipped Inkling, an open-weights MoE model

On July 15, 2026, Thinking Machines Lab, the startup founded by former OpenAI CTO Mira Murati, released Inkling, an open-weights Mixture-of-Experts model with 975 billion total parameters (41 billion active), a context window of up to 1 million tokens, and pretraining on 45 trillion tokens of text, images, audio and video. The lab openly admits Inkling is not the strongest model on the market: its bet is that customizable AI will beat one-size-fits-all chatbots. A lighter Inkling-Small with 12 billion active parameters is coming as a preview.

Illustration for the Kimi K3 weights release story
modelsopen source

Moonshot published Kimi K3, the largest open weight release yet

On July 27, 2026, Moonshot AI published the full weights of Kimi K3 on Hugging Face, the biggest open-weight release in AI history. The mixture-of-experts model has 2.8 trillion parameters, a 1 million token context window, and weighs about 1.4 TB in 4-bit MXFP4 (roughly 5.6 TB at 16-bit). Running it takes a multi-GPU cluster of 80 GB cards, and the license terms were not published ahead of the release.

Illustration for the llama.cpp multi-token prediction release
modelsopen source

llama.cpp ships multi-token prediction for DeepSeek V4-Flash

llama.cpp release b10228 landed on August 2, 2026 with multi-token prediction for DeepSeek V4-Flash, letting the model draft several tokens per forward pass so local generation speeds up without new hardware. It arrived two days after DeepSeek released V4-Flash-0731, which pushed Terminal Bench 2.1 from 61.8 to 82.7 at unchanged prices.

Illustration for the MCP stateless rewrite story

MCP goes stateless in its biggest rewrite since launch

On July 28, 2026, the Agentic AI Foundation released the MCP 2026-07-28 specification, the largest revision of the Model Context Protocol since launch. MCP moves from a stateful, bidirectional protocol to a stateless request/response core so servers can run on serverless and edge infrastructure, with Apps and Tasks shipping under a new versioned extensions framework. Its Tier 1 SDKs are seeing close to half a billion downloads a month, and Anthropic says support is being rolled out across Claude products.

Illustration for the Open Secure AI Alliance story
securitypolicy

Nvidia formed a security alliance without OpenAI or Anthropic

On July 27, 2026, Nvidia announced the Open Secure AI Alliance (OSAA), uniting nearly 40 companies including Microsoft, IBM, Adobe, Cisco, Cloudflare, CrowdStrike, SpaceX and Hugging Face around open-source tools for defending against AI-powered cyberattacks. Contributions include Microsoft's multi-agent vulnerability scanning framework, Hugging Face's Safetensors format, and IBM and Red Hat's signed patching system. The alliance formed days after the Hugging Face breach, and OpenAI, Google and Anthropic are notably absent.

Illustration for the optical file transfer story
open source

Phone-to-phone file transfer with no network, using animated QR codes

Decimen Optical Transfer, published on GitHub under the handle bashalarmistalt, moves files between two phones with no Wi-Fi, Bluetooth or network: one phone flashes animated QR codes, the other rebuilds the file from camera frames. Documented goodput is roughly 129 KB/s, using Luby transform fountain coding so dropped or blurred frames do not break the transfer. The developer built the working prototype in a single night with Claude Code.

Illustration for the Qwen3.8-Max open weights announcement
modelsopen source

Alibaba will open-source Qwen3.8-Max, its biggest model yet

On August 3, 2026, Alibaba released Qwen3.8-Max, a 2.4 trillion parameter model with 95 billion active per token, and said its weights will be open-sourced within a week. It is the first time a Qwen-Max-class model leaves the API, and it would be the largest open frontier-class release to date.

Illustration for the SK Telecom A.X K2 story
modelsopen source

SK Telecom released A.X K2, a 688B open-weight sovereign model

On July 29, 2026, SK Telecom unveiled A.X K2, a 688 billion parameter mixture-of-experts foundation model, and released the weights on Hugging Face. It gains +32.2 points on average over predecessor A.X K1 (519B) across 14 domestic and international benchmarks, and +83.9 points on long-context comprehension and agent evaluations. SK Telecom positions it as sovereign AI for Korea's critical sectors: manufacturing, defense and biotech.