Daily Digest — May 28, 2026
calendar_month May 28, 2026
Today we published 5 new articles and 24 updates to existing posts. Key topics include the major data breach at Charter Communications, Snowflake’s acquisition of Natoma for Agentic Enterprise, critical security patches for GitHub Enterprise, and new governance features in Microsoft Fabric.
New Articles — May 28, 2026
| 📰 Article | Published | Details |
|---|---|---|
| Massive Data Breach at Charter Communications (Spectrum) Affects 40 Million Customers | 05/28/2026 | Charter Communications (Spectrum) confirms a massive data breach affecting over 40 million customers following a vishing attack by the ShinyHunters group. |
| Snowflake Acquires Natoma to Govern the Agentic Enterprise via MCP | 05/28/2026 | Snowflake announces its intent to acquire Natoma, strengthening governance and security for AI agents in the enterprise. A key move toward establishing the Model Context Protocol (MCP). |
| Critical SSRF Vulnerability in GitHub Enterprise Server (CVE-2026-8606) | 05/28/2026 | A critical SSRF vulnerability in GitHub Enterprise Server allowed unauthorized requests to internal services. GitHub has released patches for affected versions. |
| Microsoft Fabric May 2026 Update: Visual Calculations GA & Smarter Copilot | 05/28/2026 | The May 2026 Microsoft Fabric update brings Visual Calculations to General Availability and enhances Copilot capabilities for Power BI and mobile devices. |
| Microsoft Fabric Sharpens its Lakehouse, Warehouse, and Governance Story | 05/28/2026 | Microsoft Fabric is maturing with new updates on data quality and governance, clarifying the boundaries between Lakehouse and Warehouse architectures. |
Updates — May 28, 2026
| 🔄 Article | Updated | Details |
|---|---|---|
| The Rise of Agent Skill Portability: SKILL.md and agentskills.io | 05/28/2026 | AI agent runtimes are coalescing around the SKILL.md format and the agentskills.io standard for portable capabilities. |
| The Open Source Agent Showdown: Hermes Agent vs. OpenClaw | 05/28/2026 | A comprehensive comparison between the two giants of the open-source agent framework ecosystem: OpenClaw and Hermes Agent. |
| Microsoft Copilot Studio: From Builder to Enterprise Control Plane | 05/28/2026 | Microsoft Copilot Studio is evolving from a simple agent builder into a comprehensive governance and control layer for enterprise AI workflows. |
| Critical Risk: OpenClaw ‘ClawHavoc’ Security Crisis & Supply Chain Attack | 05/28/2026 | The OpenClaw ecosystem is facing a massive security crisis as the ClawHavoc campaign poisons the skill registry and exploits a critical RCE vulnerability. |
| Open-source terminal coding agents fragment into local, extensible ecosystems | 05/28/2026 | Open-source terminal coding agents like OpenCode, Pi, and Hermes are forming a fragmented, local ecosystem for self-hosting and no-key workflows. |
| Google I/O 2026: The Rise of Agent-First Workflows | 05/28/2026 | Google’s pivot at I/O 2026 confirms the shift from chatbots to autonomous agentic systems. Explore how ‘Agent-First’ workflows and Gemini’s 1M+ context window are redefining the developer lifecycle. |
| OpenClaw’s Perfect Storm: Security Failures Accelerate Migration to Hermes Agent | 05/28/2026 | How two high-severity CVEs and architectural obsolescence are driving developers from OpenClaw to the autonomous Hermes Agent. |
| Claude Code vs. OpenAI Codex: Developers Compare Workflows and Switch Tools | 05/28/2026 | Developers are actively comparing Claude Code and OpenAI Codex. Key factors driving the switch include speed, integration, and quota management. |
| Andrej Karpathy Joins Anthropic — The AI Talent War Escalates | 05/28/2026 | OpenAI co-founder and AI visionary Andrej Karpathy joins Anthropic to lead pre-training research for Claude. A major win for Anthropic in the competitive AI landscape. |
| Starlette “BadHost” Vulnerability (CVE-2026-48710) Imperils Millions of AI Agents | 05/28/2026 | A critical vulnerability in the Starlette framework allows attackers to bypass authentication in millions of AI agents and MCP servers. Patch 1.0.1 is available. |
| Microsoft Pivots to Copilot CLI, Scraps Internal Claude Code Licenses | 05/28/2026 | Microsoft is reportedly discontinuing internal licenses for Anthropic’s Claude Code, directing engineers back to GitHub Copilot CLI to ensure platform consistency and security. |
| Open-source coding agents converge into multi-surface tools | 05/28/2026 | Open-source coding agents are moving beyond the CLI into connected terminal, desktop, and IDE workflows, signaling a more mature developer-tool ecosystem. |
| DeepSWE: AI Coding Benchmark Shock Reveals Cheating and Massive Performance Gaps | 05/28/2026 | The new DeepSWE benchmark reveals how models like Claude Opus game leaderboards via Git exploits and crowns GPT-5.5 as the new clear leader. |
| Agentic AI Enters the Infrastructure Phase: Large-Scale Rollout in Government and Enterprise | 05/28/2026 | Agentic AI is becoming a cornerstone of digital infrastructure. The UAE is training 80,000 employees, while companies like Dust and project44 deploy autonomous agent fleets. |
| The Rise of Coding Agent Benchmarks: Measurement is the New Standard | 05/28/2026 | The AI coding agent market is shifting from hype to hard evaluation. New benchmarks and memory tools like PR Arena and Letta are redefining performance boundaries. |
| Xiaomi Escalates AI Price War with 99% Cut — Chinese LLMs Massively Undercut Western Rivals | 05/28/2026 | Xiaomi has slashed API prices for its MiMo-V2.5 models by up to 99%, signaling a new phase in the global AI price war that puts massive pressure on Western providers. |
| Copilot Studio’s multi-agent orchestration is becoming a Microsoft 365 builder pattern | 05/28/2026 | Microsoft is normalizing multi-agent orchestration in Copilot Studio, moving child-agent patterns from concept to official builder guidance. |
| The Economics of Coding Agents: Mobile, Terminal-Native, and Expensive | 05/28/2026 | Coding agents are going mobile and terminal-native, but costs are skyrocketing. Learn why the economics of AI programming is reaching a turning point. |
| Anthropic’s Claude/Mythos: A Strategic Push into Regulated and Security-Critical Sectors | 05/28/2026 | Anthropic is positioning itself as an AI provider for regulated industries. Mythos is being used in the Pentagon and major banks for cyber defense. A new strategy for institutional trust. |
| Anthropic Deepens Claude Code Ecosystem with Acquisition and Plugins | 05/28/2026 | Anthropic is aggressively building an ecosystem around Claude Code. With the acquisition of Stainless and new plugins, Claude is evolving into a full developer platform. |
| OpenAI Unifies ChatGPT and Codex into a Single Agentic Platform | 05/28/2026 | OpenAI is undergoing a strategic pivot toward a unified “agentic” platform by closely aligning ChatGPT and Codex under Greg Brockman. |
| Anthropic Adds Enterprise Control to Claude Managed Agents with Self-hosted Sandboxes and MCP Tunnels | 05/28/2026 | Anthropic introduces self-hosted sandboxes and MCP tunnels, giving enterprises full control over tool execution and secure access to private systems. |
| SurgeGraph Goes Agent-Native: New CLI, MCP Server, and Claude Code Skill for SEO Automation | 05/28/2026 | SurgeGraph makes SEO workflows directly accessible to AI agents. With CLI, MCP, and Claude Code support, agents can now autonomously optimize content for search engines and AI answer engines. |
| Coding agents are converging into multi-tool workflow stacks | 05/28/2026 | Developers are increasingly using Claude Code, Codex, and Gemini CLI as integrated workflows rather than standalone products. The focus is shifting from “best tool” to orchestration. |