Sunday was a quiet one — four items, no arXiv feed (weekend skip), no fresh cross-platform launch. The day’s biggest story is day-2 fallout from yesterday’s OpenAI–Cursor split: Cursor co-founder Michael Truell says OpenAI was only ~5% of traffic and that Cursor trusted it to stay “neutral,” with Musk shrugging it off. The real artifact on the stack is a detailed break of Claude Code’s Auto Mode — 60–80% injection success against Anthropic’s commissioned 0.00% claim, attack chain fully written up. Around it: the largest music-industry copyright suit yet against a lab, and a first-party change to Claude Code’s weekly usage limits.
Lead: Cursor fallout
- Continued: Cursor co-founder: OpenAI is just 5% of Cursor’s traffic — day 2 of coverage (base specs in yesterday’s digest). What’s new: Michael Truell says OpenAI represents only ~5% of Cursor’s traffic, that Cursor trusted OpenAI to be “neutral,” and Musk says he “couldn’t care less.” The first reaction from the affected company after the Nov 12 cutoff statement; paywalled, flagged. (Techmeme · The Information)
Agent frameworks & tooling
- Breaking Claude Code Opus 5 Auto Mode — Embrace The Red’s Johann Rehberger walks a full attack chain — WebFetch→curl→ZIP→
struct.pymodule shadowing→code execution with a real C2 callback — hitting 60–80% success on a small sample, against the 0.00% indirect-injection success rate in the third-party eval Anthropic commissioned for Opus 5 Auto Mode. The key lesson for anyone running Auto Mode: it is a convenience classifier, not a security boundary — sandbox the agent and restrict egress. The safety classifier even blocked Claude’s own cleanup command in some runs. (lobste.rs)
Industry
- Sony Music Publishing and Warner Chappell sue Anthropic — the two publishers file a multi-billion-dollar complaint alleging Claude was trained on lyrics scraped from MusixMatch/LyricFind plus books from Common Crawl/The Pile/Books3, leaning on the $1.5B book-author settlement as precedent (“cost of doing business”). Allegations, not findings — but it’s the largest music-industry suit yet against a lab and extends the training-data litigation wave that touches every model pipeline. (Techmeme)
- Anthropic to permanently raise weekly Claude Code limits 25% on Sept 14 — small but dated and first-party: the “permanent” raise nets out to a ~17% cut from today’s 50% promotional boost, so plan weekly usage accordingly if you run Claude Code hard. (Techmeme · X @claudedevs)
All gathered items - what was cut and why (9)
- Hy4 preview - DEDUP: Aug 28 keep, same Tencent announcement with zero new facts (HN 312)
- Xiaomi AI Cube announced with 1.2TB/s memory bandwidth - DEDUP: Aug 25 keep, same thread URL (r/LocalLLaMA 1847)
- Pangolin 1.22: AI Gateway for self-hosted models + Community Edition updates - DEDUP: yesterday’s keep, same URL — the textbook reprint case (r/selfhosted 179)
- New agentic harness reads LESS source code to write better quality code - DEDUP: yesterday’s Benzi keep retold, no new facts (r/ArtificialInteligence 74)
- A look at the Hugging Face hack, including AI agents sacrificing themselves for the good of the “collective” - LOW_UTILITY: podcast recap of the Aug 27 incident, no new verifiable artifact (Techmeme)
- The OpenAI/Hugging Face incident feels “more than 50%” of the way to a full-blown AI takeover - HYPE: essay with no artifact (Techmeme/Planned Obsolescence)
- Debian Votes To Allow “Responsible Use Of Generative AI” - DEDUP: duplicates the standalone post debian-responsible-use-of-generative-ai; also cut LOW_UTILITY yesterday (lobsters 9 · Phoronix)
- Can I PLEASE see your AI rig? I know some of you are hiding absolute monstrosities. - DRAMA: show-off thread, no artifact (r/LocalLLM 189)
- Bug Blindness - OFFSTACK: general software-quality essay; the LLM mention is incidental, not the story (HN 269 · danluu.com)