vibehacker
News
Hush Security ·

Hush: 12% of public MCP config credential slots hardcode secrets

Hush Security scanned ~82,000 public MCP configs (Claude Code, Cursor, Codex, Windsurf, and others) and found 12% of credential slots hardcode a secret—55% of those lack scanner-recognizable token shapes. Among secrets with a defined expiry policy, 80% never expire by default.

More news

View all

Arc Studio: Circle's onchain coding agent for Claude Code, Codex, Cursor

Circle's Arc launched Arc Studio (Sept 17): an AI coding agent that turns natural language prompts into full stack onchain apps—frontend, backend, and smart contracts—with native Circle stack (CCTP, wallets, Gateway) and protocol hooks for Aave, Morpho, and Uniswap. It runs on the web or as a subagent in Claude Code, Codex, and Cursor across nine chains; Studio does not deploy, sign, or fund mainnet transactions for you…

Arc

accessiBe Code Agent: WCAG 2.2 AA reviews inside GitHub PRs

accessiBe launched Code Agent (Sept 17), a beta for accessFlow customers that reviews GitHub PRs against WCAG 2.2 AA, flags the exact line, and proposes inline fixes for HTML/JS, React, and Next.js. Teams can gate merges on it like tests or lint; developers accept or reject every suggestion…

PR Newswire

OpenRouter stealth Union Alpha unmasked as unbiased.ai Pareto 26.9

OpenRouter’s anonymous Union Alpha (listed Sept 16) was identified as unbiased.ai’s Pareto 26.9, a blended model that keeps the best answer across engines; free trial ended after one day under 1B tokens/min load, with paid rates at $2.50/$7.50 per million input/output tokens. Unbiased says an official release is planned for Oct 10 after the stealth stress test…

GIGAZINE

OpenAI launches Astra for Law with legal search index and firm Trusted Access

OpenAI shipped Astra for Law (Sept 17): GPT 6 Astra plus a U.S. legal search index (230M+ URLs, with Free Law Project case law) and legal writing instructions, initially for selected firms via Trusted Access in ChatGPT and Codex, with API access coming for builders like Harvey and Legora. On Vals AI’s Legal Research Bench it scored 54.0% overall correctness vs 38.7% for Astra with web search alone…

OpenAI

Spotted something we missed? Start a thread.