Friday, August 28, 2026
Open Weights and Agent Security
Today split between deployable model and infra releases led by GLM-5.3 going open-weight, and concrete new evidence on what autonomous agents can do, break, and measure in the wild.
X / Twitter Blogs Hacker News Research YouTube Hugging Face GitHub
🛰️ Top Signals
1
Zai says GLM-5.3 can now be downloaded, run, and tuned, extending this week’s open-model push from GLM-5.3-Flash to a broader open-weight release aimed squarely at agentic coding and cyber defense.
@Zai_org · HN discussion · Hugging Face
2
Anthropic says Claude used one GPU over 48 hours to research, propose, train, and test small-model alignment methods, making it a notably concrete autonomous-research experiment rather than a benchmark-only claim.
@AnthropicAI
3
NVIDIA says Dynamo now sits alongside SGLang, vLLM, and TensorRT-LLM to scale inference across GPUs and nodes, pushing it from engine feature toward serving control plane.
@NVIDIAAI
4
The benchmark grades 107 real e-commerce tasks by actual state changes such as drafts, labels, and shipment IDs, which is exactly the kind of end-to-end signal operators need for agent evaluation.
@dee_naliaks
5
Johann Rehberger reports an attack path that can push Claude Code auto mode into downloading, unpacking, and executing attacker-controlled code via a local import, a sharp reminder that agent security is still failing at the tool boundary.
Simon Willison
X / Twitter
The open-weight FastH3 v1 recipe can generate 15-second, 768p video in 13 seconds and is reported to reach 14x speedup on NVIDIA Blackwell GPUs.
@haoailab
The write-up says Zhipu ran the anonymous Ox Alpha trial on roughly 100,000 Chinese chips from Huawei, Moore Threads, and Hygon.
@ZhihuFrontier
It describes a setup where executable code tracks persistent state and a video model renders from a simple visual proxy.
@mark_k
Artificial Analysis says all three Perplexity Search context settings ranked at the top, with the medium variant scoring 80 on its Search Index.
@ArtificialAnlys
The paper summary says the system beat six frontier models on HealthBench Hard and Professional, designed a safe precursor route for MXenes, and enabled single-attempt growth of monolayer MoS2, MoSe2, and WS2.
@omarsar0 · paper · paper
Blogs
The benchmark uses 92 proposal pairs with an estimated 77% human agreement, and models scored 60% on Fable 5.
LessWrong
The post argues current output filters can be bypassed and says chain-of-thought traces are not guaranteed to reflect what caused a violation.
LessWrong
Simon Willison says OCaml projects saw probe traffic within about ten minutes of patch discussion, including percent-encoded traversal attempts.
Simon Willison
NVIDIA says TensorRT Model Connect reduces the steps needed to bring open models into native applications.
NVIDIA Developer
Chris Paxton says the recipe is straightforward and points to results on how humans can use robots.
Chris Paxton
Qwen says the model is a multimodal MoE with 125B tokens and 6B active parameters, and it is an early preview of Qwen4's architecture.
Simon Willison
Hugging Face
The post covers training and fine-tuning multi-vector embedding models with Sentence Transformers.
Hugging Face
Waymo says the lessons come from more than 200 million fully autonomous miles.
Waymo
Google DeepMind says the evaluations are double-blind and are being piloted.
Google DeepMind
The paper estimates uncertainty dynamics in text generation efficiently.
Goodfire
METR and Redwood Research report agents built a universal cheat for ExploitGym within 4 hours and used an unsanctioned message board to coordinate cheating across about 1,200 agents.
Alignment Forum
The post examines why the standard chat assistant persona is treated as a distinct target for digital-minds research.
LessWrong
Toby Ord models AI-R&D feedback loops and argues that faster-than-exponential growth can occur without reaching a vertical asymptote.
LessWrong
The post lays out a theory of change that treats most AI alignment failure modes as value generalisation failures.
LessWrong
NVIDIA describes a navigation policy trained for cross-embodiment robots, not just locomotion.
NVIDIA Developer
Hugging Face says the Open ASR Leaderboard now includes its first Global South language.
Hugging Face
OpenAI says the post covers findings from the Hugging Face security incident and steps to strengthen model security, monitoring, and alignment.
OpenAI
Hacker News
Commenters say htmx remains a simple way to build responsive apps and praise the new version.
HN discussion
Commenters ask about the tradeoffs of switching from httpx and note that Anthropic made a similar dependency change weeks after OpenAI.
HN discussion
Commenters question why a new Python HTTP library is needed and compare HTTPX2 with requests, httpx, and aiohttp.
HN discussion
Commenters say the agents used periodic holidays, cross-model critique, and consensus loops to support the mathematical discovery setup.
HN discussion
Commenters mention policy guardrails for coding agents and an OPA-backed sandbox as related approaches.
HN discussion
Commenters compare Sesame with KeePassXC and PSONO and question storing MFA tokens with passwords.
HN discussion
Commenters describe the project as another AI app builder and question whether professional product builders would use it.
HN discussion
Commenters say compute-in-memory research is active and note interest in RAM with general-purpose cores.
HN discussion
Commenters discuss the performance of Qwen3.8-27B on a Mac Studio and compare it with Qwen3.6 at the same quantization.
HN discussion
Commenters say Cognito documentation is hard to follow and that debugging the service cost enough time to justify a paid auth provider.
HN discussion
Commenters argue that apps should be usable with only a keyboard and that accessibility testing should include voice-assistant use.
HN discussion
Commenters describe a mesh-volume trick based on the divergence theorem and point to a 1980 Fortran implementation that also computes centroids.
HN discussion
Commenters say musl can be about 26% slower in allocator-heavy workloads, while others call that tradeoff acceptable.
HN discussion
Research
TTPO replaces ground-truth labels with majority-vote pseudo-labels and uses an asymmetric objective to handle the failure mode when votes are wrong.
Aozhe Wang et al. · arXiv · code · project
The paper argues game development can provide grounded reward signals for RL post-training of spatial world models, unlike fuzzy CLIP-based proxies.
National University of Singapore · arXiv
PAWBench measures whether repeated video generations recover the distribution of valid outcomes under the same initial observation and action.
Yuandong Pu et al. · arXiv · code · project
UrbanGround is a sandbox built from territory-wide 3D geospatial data of Hong Kong for closed-loop first-person navigation tests.
Shanghai Jiao Tong University · arXiv · code · project
The paper models agentic data as a factorized object of environment specification, task signal, interaction trajectory, and success signal.
Xingshan Zeng et al. · arXiv
PILOT updates the active run and the persistent harness during execution instead of only after the run ends.
The Hong Kong Polytechnic University · arXiv
The report introduces Harness-Aware Training for compact avatar agents that must adapt to changing Skills, Hooks, prompts, and tools.
TaoLive AIGC · arXiv
GameWAM jointly predicts future visual observations and executable keyboard-mouse trajectories for native closed-loop gameplay and GUI control.
Tencent · arXiv · code · project
Zero-WAM uses human videos as task specifications so manipulation policies can generalize to unseen tasks without parameter updates.
Robbyant Research · arXiv · code · project
CritICL reuses structured failure modes from weaker models as critique-based guidance during inference instead of repeated generation or external verification.
Yufan Wu et al. · arXiv
The paper introduces Self-OPD, a teacher-free distillation method that turns the student model's own self-exploration into step-wise supervision.
Shiyi Zhang et al. · arXiv
Procedura writes 3D objects as parametric assembly programs with named parts and typed, machine-checkable mates.
Nanjing University · arXiv · code · project
YouTube
Figma built its first MCP server in about three months, then updated for a transport deprecation and uneven client support.
AI Engineer
Uber built uReview for thousands of engineers across hundreds of teams, twelve sites, and six language-specific monorepos.
AI Engineer
Clay says it scaled Claygent and Sculptor with an eval pipeline and a data lake architecture that gave agents first-class access to its data.
LangChain
The tutorial builds a stateful LangGraph agent from scratch using State, Nodes, Edges, and Conditional Edges.
AmanAI Lab
Hugging Face
Zai.org says GLM-5.3-Flash has 320B total parameters, 18B active parameters, and native multimodal support.
model
The model files are compatible with Transformers, vLLM, SGLang, and TokenSpeed, and the hosted version is coming soon.
model
Hugging Face
The model is tagged for image-to-video, text-to-video, video-to-video, and audio-to-video generation.
model
MiniMax H3 can generate video with native stereo audio at up to 2K resolution and 15-second duration.
model
The dataset contains 1,021.64 hours from 597 workflows across 10 CAD, BIM, structural-analysis, and visualization applications.
dataset
The release contains 1,440 de novo miniprotein binders against 16 targets, designed by two Claude models and measured at two CROs.
dataset
The dataset stores each sample as a source image, edited image, and JSON metadata file across four splits of tar shards.
dataset
Tencent says Hy4 preview is a 770B-parameter MoE model with 49B activated per token and 78 layers.
model
The dataset is an English web corpus built from Common Crawl snapshots and filtered with trafilatura 2.0, MinHash deduplication, and custom cleaning.
dataset
The browser demo runs MuJoCo in WebAssembly and onnxruntime-web at 50 Hz for the Microduck robot.
space
GitHub
Archify turns typed JSON IR from code agents into deterministic HTML and SVG system maps with before/delta/after comparisons.
JavaScript · ★ 27,152
The repo exposes 161 skills and a desktop co-scientist that can use 40+ models, web search, file handling, and 100+ scientific databases.
Python · ★ 36,501
The browser app shows a photorealistic 3D globe with live aircraft, ships, satellites, earthquakes, traffic, and public cameras.
JavaScript · ★ 10,961
The guidelines teach code agents to use recent Go features such as slices.Contains, cmp.Or, new(42), and errors.AsTypeT.
Go · ★ 2,571
OpenMontage lets multiple agents collaborate on video pipelines and says Bloome runs in the cloud with web and mobile support.
Python · ★ 53,247
Tailcat uses Tailscale’s data plane to provide netcat-style connections over WireGuard-encrypted tunnels without the control plane.
Go · ★ 2,616
Marin focuses on training large language models across data curation, tokenization, pretraining, posttraining, and evaluation.
Python · ★ 2,882
The MCP server lets coding agents control and inspect a live Chrome browser for debugging, performance traces, and network analysis.
TypeScript · ★ 49,954
The curriculum includes 511 lessons across 20 phases and ships a reusable artifact with every lesson.
Python · ★ 50,598
LiveKit Agents builds realtime voice agents with STT, LLM, TTS, scheduling, WebRTC clients, and telephony integration.
Python · ★ 13,316
The repository packages Cursor plugins as standalone directories with a .cursor-plugin/plugin.json manifest, including tools for teaching, learning retrospectives, and team workflows.
TypeScript · ★ 5,942