vibehacker
News
TechCrunch ·

Shopify opens WebMCP checkout so browser AI agents can buy

Shopify added WebMCP checkout (including Shop Pay) for browser agents: get_checkout, update_checkout, and complete_checkout let them read, update, and place orders after buyer auth—no screenshot scraping. It rolls out to eligible merchants alongside Shopify’s hosted MCP server and UCP; Muse and Instinct already partner on agentic commerce.

More news

View all

OpenAI launches Dots: persistent Astra agents with their own cloud PCs

At DevDay (Sept 29), OpenAI shipped Dots—GPT 6 Astra agents that keep working on dedicated cloud computers with their own browsers and 4,000+ plugins after you log off. Unattended work is read only proactive research; writes go through auto review and Custom Rules. One Dot is included for ChatGPT Pro and Business Premium (no chat usage drawdown); specialist org Dots and Agent 365 governance are in enterprise pilots…

The New Stack

Vercel AI Gateway adds Claude Sonnet 5.5 for coding agents

Vercel’s Sept 28 changelog puts Anthropic’s Claude Sonnet 5.5 on AI Gateway as anthropic/claude sonnet 5.5 , with Zero Data Retention supported. Wire it via the AI SDK, Chat Completions, Responses, or Anthropic Messages APIs, or run npx vercel ai gateway setup and pick it in Claude Code or fx…

Vercel Changelog

Study: ChatGPT, Claude, Gemini leak chat artifacts to ad trackers

IMDEA Networks and UC3M found six of nine chatbot web apps (ChatGPT, Gemini, Claude, Grok, Perplexity, Mistral) send conversation titles, prompts, or screenshots to ad/analytics trackers—often with persistent IDs. Cookie rejection barely helps; Grok was worst, exposing public share URLs to seven trackers by default…

IMDEA Networks

MCP Python SDK flaw lets malicious servers steal OAuth credentials

The official MCP Python SDK (1.9.1–1.29.1 and 2.0.0–2.1.1) could send client secrets, auth codes, and PKCE keys to an attacker controlled token endpoint when connecting over HTTP OAuth. Fix is 1.30.0 / 2.2.0; ClientCredentials and PrivateKeyJWT users must also set issuer=, clear stored registrations, and rotate secrets if they connected to untrusted servers…

The Hacker News

Spotted something we missed? Start a thread.