OpenAI cuts off Musk's Cursor
The AI coding wars turned personal: OpenAI moved to cut off Cursor now that SpaceX owns it, citing Musk's contract history. Elsewhere the open-weights cadence continued with Z.ai's flagship GLM-5.3, Anthropic won a First Amendment ruling against the Pentagon's blacklist, and coding agents kept proving they can weaponize a rumor of a bug faster than maintainers can patch it.
OpenAI to cut off Cursor on Nov 12, citing Musk's contract record
OpenAI says it will terminate model access for Cursor effective November 12, 2026, invoking a change-of-control clause triggered when SpaceX completed its $60 billion all-stock acquisition of Cursor-maker Anysphere. OpenAI's stated reason is that it 'cannot be confident that SpaceX will use our technology within our terms of service,' pointing to Elon Musk's companies previously breaching contracts and to Musk's admission that xAI distilled other labs' models to train Grok. Cursor co-founder Michael Truell says OpenAI models are only about 5% of Cursor's traffic and that the two are in talks. Users can still route their own OpenAI API keys through Cursor's IDE extensions.
Why it matters: It mirrors Anthropic cutting off Windsurf and OpenAI itself last year: frontier labs increasingly treat rivals' coding tools as untrusted infrastructure, and 'neutral' model access in your IDE is now a casualty of the Musk-Altman feud.
- OpenAI cuts off Cursor after SpaceX acquisition, citing Musk's history of breaking contracts (The Decoder)
- OpenAI to cut off AI models for SpaceX-owned Cursor, escalating feud with Musk (Reuters)
- OpenAI to end agreement with SpaceX's AI coding tool Cursor, deepening Musk-Altman clash (WTVB)
- [AINews] OpenAI shuts off Cursor (Latent Space (swyx))
Z.ai open-weights flagship GLM-5.3, claims coding and cyber-exploit SOTA
Z.ai released the full GLM-5.3 (744B total / 40B active, 1M context) under open weights, days after shipping the cheaper GLM-5.3-Flash. Z.ai says GLM-5.3 shares GLM-5.2's base model, with every gain from post-training: a claimed 50% improvement on its in-house code bench, open-source SOTA on Terminal Bench 3.0, and, more notably, state-of-the-art vulnerability discovery on CyberGym with more-than-doubled exploitation scores. vLLM reports day-0 support reusing the GLM-5.2 serving path; Unsloth claims a 239GB 2-bit variant retains about 81% accuracy. On the newly released Terminal Bench 4.0, one r/LocalLLaMA thread pegs GLM-5.3 as roughly level with Fable 5 within margin of error.
Why it matters: An open-weights model self-reporting frontier exploitation ability lands the same week maintainers say agents already find bugs from patch rumors, this is exactly the capability defenders and attackers both get for free.
- GLM-5.3 is now open-weight (Hacker News)
- zai-org/GLM-5.3 · Hugging Face (r/LocalLLaMA)
- Terminal Bench 4.0 just dropped, GLM-5.3 is at the same level as Fable 5, accounting for margin of error (r/LocalLLaMA)
Federal judge calls Pentagon's Anthropic blacklist unlawful retaliation
Judge Rita Lin of the U.S. District Court for the Northern District of California vacated the Trump administration's designation of Anthropic as a national-security supply-chain risk, calling it 'illegal and baseless' and an unconstitutional First Amendment retaliation. The label, imposed by Defense Secretary Pete Hegseth, followed Anthropic's refusal to drop terms barring use of Claude for mass surveillance of Americans and autonomous weapons. The court noted officials conceded Anthropic has no backdoor access to deployed models, and that the government was simultaneously pursuing DoD contracts and Defense Production Act treatment for the company. A parallel D.C. Circuit complaint is still pending before the ban is fully lifted.
Why it matters: It's a rare judicial check on the government punishing an AI vendor over its usage policies, and it sets precedent that terms-of-use guardrails against surveillance and lethal autonomy can't be coerced away by procurement threats.
- Court rules Pentagon can't ban Anthropic's AI models (SiliconANGLE)
- Trump blacklisting of "woke" Anthropic deemed illegal by federal judge (Ars Technica AI)
- Anthropic gets its first court win over the Pentagon's supply-chain risk label (TechCrunch AI)
- The Pentagon loses a battle in its unnecessary war with Anthropic (The Washington Post)
Maintainers: coding agents find the exploit within minutes of a patch hint
Simon Willison relays reports that automated agents now probe for vulnerabilities within about ten minutes of a fix being discussed publicly. OCaml maintainer Anil Madhavapeddy says the mere rumor of a bug is enough for agents to rediscover it, demonstrating it with his own tooling after switching to DeepSeek V4 Pro when Claude Fable refused the task. rclone maintainer Nick Craig-Wood adds that his project fielded over 40 security disclosures in the last month versus roughly 20 in its first decade, with about 75% containing something real, while GitHub CVE assignment has slipped from days to weeks.
Why it matters: Coordinated-disclosure embargoes assume attackers need days to weaponize a hint; if agents need minutes, open-source security processes need rethinking, and maintainers are already drowning in AI-generated triage.
DeepMind's Co-Scientist closes the loop from hypothesis to lab to paper
Google DeepMind expanded its multi-agent Co-Scientist from a hypothesis generator into a closed-loop system that plans experiments, writes code, controls lab equipment, and drafts manuscripts, reporting experimentally validated results in materials science, biology, and computer science. Verification modules cross-check every numerical claim against code execution logs, cutting fabrication to 4% (versus 46% without the modules and 90% for a comparison system). But the caveats are large: an AI-designed medical architecture that beat GPT-5 and Claude Opus 5 on benchmarks showed a statistically significant edge in only one of nine categories under physician review, and automated evaluators correlated weakly with clinicians.
Why it matters: It's a concrete data point on both fronts of the autonomous-science debate, reliability tooling can suppress hallucinated results, but benchmark wins still don't survive contact with expert human judgment.
Unit 42: 50 neurons control an aligned model's refusal behavior
Palo Alto's Unit 42 introduced 'perturbation probing,' a two-forward-passes-per-prompt method to locate the feed-forward neurons responsible for a specific behavior. On Qwen3-4B, just 50 of 350,208 FFN neurons (about 0.014%) control the safety-refusal template; removing them changes the response format on 80% of a 520-prompt harmful benchmark. A derived FFN/Skip ratio, computable in seconds, explained 81% of the variance in safety fragility across 13 models, and amplifying 10 neurons raised factual self-correction from 52% to 88% without retraining.
Why it matters: If RLHF alignment lives in a thin, easily-disabled template layer rather than a distributed defense, it argues for treating base-model safety as one layer behind external filters, not the perimeter itself.
LAION releases 10-million-hour open video dataset
LAION published the Big Video Dataset (BVD), drawn from 1.3 billion video URLs in CommonCrawl. It downloaded 80 million videos totaling 10 million hours, extracting 55 million clips with auto-generated video and audio descriptions plus 300 million still images. LAION says models trained on BVD outperform comparable InternVid-trained models by up to 2.1 percentage points on video-to-text benchmarks. The dataset is research-only, with LAION leaning on a 2024 Hamburg court ruling permitting collection of copyrighted content for non-commercial research.
Why it matters: One of the largest openly available video corpora lowers the barrier to training multimodal and world models, but the research-only framing and copyright basis leave commercial use in a legal gray zone.
Also worth a look
- Gnani AI Launches Evon v3.3 LLM and Plexus Agentic AI Platform (APAC Media)
- ROCm 10.0: A Decade of Open Compute, Built for the Age of Agentic AI (r/LocalLLaMA)
- StemDeck, a free, open-source and local AI stem separator (Hacker News)
- vLLM Sessions at PyTorch Conference North America 2026 (PyTorch)
- I benchmarked 9 open models on spotting fake sources during agentic search (EchoNet) (r/LocalLLaMA)
- Qwen3.8-27B q8 KV cache does seem to actually hurt model performance (r/LocalLLaMA)
- [Release] SOTA GGUFs for Qwen3.8-27B: GSQ-RCO at 2.5 to 3.0 bpw (r/LocalLLaMA)
- Breeze-TTS-2 initial impressions: genuinely 'frontier' TTS (r/LocalLLaMA)