AI news April 10, 2026: Cursor kills the IDE, Mythos is too dangerous
Alexandre
··
Reading time: 17 min
If you thought last week with Anthropic's two leaks and the $297 billion VC tsunami was the peak, this week immediately proves otherwise. Cursor just rewrote what a product is. OpenAI just matched Anthropic's pricing. And one AI model was officially deemed too dangerous to put in the hands of the public.
This week: Cursor 3 turns its IDE into an agent management console and pushes the code editor down to fallback status. OpenAI launches a $100-per-month tier to go straight at Claude Code, claiming 3 million weekly Codex users and 70% month-over-month growth. Anthropic suffers a second straight leak, this time the source code of Claude Code, and then announces Project Glasswing to tightly control access to Claude Mythos Preview. And OpenAI, Anthropic, and Google unite through the Frontier Model Forum to share intelligence against China, which is copying their models at scale.
For a solo dev building Livate with Claude Code every day, this week hits my tools, my dev costs, and the stability of the platforms I depend on. It is the kind of week where I checked my dependencies twice.
The week at a glance
Event
Date
Actor
Key figure
Source
Cursor 3 launch (agent console)
Apr. 5
Cursor
$2B ARR
The New Stack
Claude Code source code leak
~Apr. 1
Anthropic
512,000 TypeScript lines
Financial Times
Project Glasswing + Mythos Preview
Apr. 7
Anthropic
$100M credits, 40+ partners
VentureBeat
OpenAI launches $100/month Codex tier
Apr. 9
OpenAI
3M weekly Codex users
TechCrunch
FMF anti-distillation alliance vs China
Apr. 6
OpenAI + Anthropic + Google
Billions in estimated losses
Bloomberg
Mythos finds a 13-year-old ActiveMQ flaw
Apr. 10
Anthropic / Claude
Bug present since 2013
CSO Online
Sources: TechCrunch, Financial Times, VentureBeat, Bloomberg, The New Stack
Cursor 3: the IDE is pushed down to fallback status for AI agents
On April 5, 2026, Cursor released Cursor 3, a full rebuild of the product under the codename Glass. The main interface is no longer a code editor: it is an agent management console. The prompt box now sits where the file tree used to be. Cursor, which generates $2 billion in annualized revenue, is betting that developers will spend most of their time directing agents, not writing code line by line. The New Stack calls it a $2 billion bet.
The classic IDE still exists in Cursor 3. But it is treated as a secondary tool, a fallback. The signal is blunt: if the company with the fastest revenue growth in the sector says the code editor is no longer the center of the workflow, something fundamental has changed in how professional developers work.
Definition — Agent management console: an interface centered on supervising and coordinating multiple AI agents in parallel, as opposed to a traditional code editor where the developer writes the code themselves. In Cursor 3, the engineer dispatches agents, inspects their results, and decides which ones to merge. The editor becomes a verification tool rather than a production tool.
The context matters. Cursor 3 is not an incremental release. The New Stack describes the product as built from scratch, not redesigned, but fully rewritten. That level of investment, for a $2 billion ARR company, says a lot about how strongly they believe the era of the agentic IDE is only beginning.
Other signals point the same way this week. Forbes reports that agent registries are becoming the new battleground for cloud giants: AWS, Azure, and Google Cloud are fighting to become the marketplace where companies publish and consume specialized AI agents. And Microsoft, according to Forbes, is taking the opposite path from Cursor: an agent stack so complex that it confuses developers while rivals simplify.
My take as a solo dev
What strikes me is the brutality of the message. Cursor is not saying “we improve the IDE.” They are saying “the IDE is the secondary view.” That is a product statement, not an incremental improvement.
In my daily work on Livate, I have been using Claude Code in terminal mode for months. I describe what I want, the agent iterates, I review the diffs. I barely spend any time writing code character by character anymore. So the Cursor 3 model is already familiar to me. What changes with their release is that it is now officially the product direction of a $2 billion ARR company.
What changes concretely for me: the friction is no longer in writing code, it is in the precision of the request and the ability to spot when the agent goes off the rails. I have had Claude Code sessions where 40 minutes of work ended with a diff I had to reject entirely because I framed the context badly. The IDE would not have saved me. A better task prompt would have.
But while Cursor 3 changes the shape of work, OpenAI decided this week to change pricing so it does not fall behind.
Click to enlarge
OpenAI launches a $100/month tier to attack Claude Code head-on
On April 9, 2026, OpenAI announced a new ChatGPT subscription tier at $100 per month, explicitly positioned to compete with Anthropic's Claude Code. The plan includes 5x the usage limits of the $20 Plus tier and access to all Pro-tier features at $200, including ChatGPT 5.4 Pro and unlimited access to the Instant and Thinking models. OpenAI says Codex has 3 million weekly users, up 5x in three months, with 70% month-over-month growth. According to TechCrunch, the OpenAI spokesperson was blunt: “Compared to Claude Code, Codex delivers more coding capacity per dollar.”
The pricing structure is now:
Tier
Price / month
Codex limits
Included model
Go
$8 (with ads)
Basic
n/a
Plus
$20
1x
Standard
Pro (new)
$100
5x Plus
ChatGPT 5.4 Pro + Instant + Thinking
Pro Max
$200
20x Plus
Everything included
Source: TechCrunch, CNBC, April 9, 2026
What is strategically revealing is the implicit admission. OpenAI left Anthropic alone in the $100/month segment since the launch of Claude Code. That is exactly the segment of heavy developers: people doing vibe coding, automating entire pipelines, and needing tokens at scale. By filling that gap, OpenAI is acknowledging that Anthropic had captured that segment.
CNET ran the headline “OpenAI adds $100/month ChatGPT subscription because of vibe coding.” The heavy use of AI to generate code without fully knowing what you are doing has become mainstream enough to justify its own pricing tier. The term “vibe coding” comes from Andrej Karpathy (former OpenAI) and was all over X this week in reaction to the announcement.
One important nuance on the numbers: TechCrunch notes that the 5x limits are only guaranteed until May 31, 2026. After that, the caps will return to the standard schedule. Anyone signing up for the new tier and building a dependency on those limits should expect a possible downgrade in June.
My take as a solo dev
As someone who has been using Claude Code at $100 per month for months, this announcement comes late, but it clarifies something: the war over coding tools is now a war over pricing and capacity, not features.
What really interests me is Codex growth: 3 million weekly users, +70% month over month. That is huge. It means demand for high-volume AI coding tools is real and OpenAI is capturing it.
Is Codex worth the same price as Claude Code for a solo dev? Honestly, I am still on Claude Code for now. Its contextual understanding on large codebases, its handling of compilation errors, its ability to keep architectural consistency across dozens of files: that is what convinced me. But with Codex growing this fast, the pressure on Anthropic to ship the next version is real. And for users like us, that is exactly what we want.
Anthropic again: Claude Code source leak, then Project Glasswing
On April 1, 2026, Anthropic suffered its second leak in two weeks: a debug sourcemap accidentally included in Claude Code v2.1.88 exposed the agent's source code, according to the Financial Times. Anthropic said “human error” was responsible. A few days later, on April 7, the company announced Project Glasswing: restricted access to Claude Mythos Preview for a consortium of 40+ partners including Amazon, Apple, Microsoft, Google, Nvidia, CrowdStrike, and the Linux Foundation. The company committed $100 million in usage credits and $4 million in donations to open-source security groups.
The timeline since late March is telling:
Date
Event
What it reveals
~Mar. 28
Leaked blog draft reveals Claude Mythos
CMS process not strong enough for sensitive drafts
Apr. 1
Claude Code v2.1.88 sourcemap in production
Release pipeline lacks debug artifact validation
Apr. 6
Claude outage
Third technical incident in 10 days
Apr. 7
Project Glasswing + Mythos Preview announced
Fast product response despite operational turbulence
Source: Financial Times, TechRadar, Anthropic Blog
Definition — Sourcemap: a technical file generated during compilation that maps original source code to transformed or minified code. It helps debugging in production, but it exposes source code when accidentally shipped in a public deployment. Best practice: never include sourcemaps in a public production bundle.
What makes this leak especially sensitive is the context of the tool itself. Claude Code has access to my file system, environment variables, and API keys. When the source code of that kind of tool is out in the wild, the possible attack vectors become readable to anyone looking for vulnerabilities.
SecurityWeek also reported this week that Claude itself found a 13-year-old RCE (Remote Code Execution) bug in Apache ActiveMQ Classic, a flaw automated testing tools had not detected. That is not incidental: it is exactly the kind of capability Mythos Preview demonstrates, and exactly what Project Glasswing is trying to control.
My take as a solo dev who uses Claude Code every day
Two leaks in two weeks at Anthropic. I am not going to pretend that does not affect me.
The first reaction is practical: is my stack exposed? I checked my .gitignore, my environment variables, and Claude Code permissions on my machine again. Not because there is an immediate known threat, but because when the source code of your main tool is circulating on GitHub, the attack surface becomes public.
The second reaction is more nuanced. The leak triggered an involuntary community audit of Claude Code. Thousands of developers read that code in a few days. And overall, the architecture was praised. When your tool survives that kind of scrutiny without disaster, that is a positive signal about the quality of Anthropic's work.
What remains worrying is the pattern: two human-error leaks in two weeks, a major outage, and an announcement of a model too dangerous to publish. Anthropic is building some of the best models on the market right now, by many indicators. But their operational processes show cracks under pressure. It is the sign of a company scaling fast with guardrails that are not keeping up.
Click to enlarge
Claude Mythos: the model too dangerous to publish, and the Glasswing initiative
On April 7, 2026, Anthropic announced that Claude Mythos Preview would not be made public. In testing, the model discovered thousands of high-severity zero-day vulnerabilities, including some that had been dormant for decades: a bug in OpenBSD 27 years old, a flaw in FFmpeg 16 years old, and multiple Linux kernel chains that could escalate privileges all the way to full machine control. According to VentureBeat and Axios, Anthropic believes that releasing the model publicly would give adversaries an overwhelming offensive advantage. Project Glasswing brings together 40+ partners with $100 million in usage credits to use Mythos for defensive purposes only.
Definition — Zero-day: a security vulnerability unknown to the software vendor at the time it is discovered, so no patch is available. The term “zero-day” refers to the fact that defenders have zero days to prepare once the vulnerability is exploited. Mythos Preview autonomously found thousands of such vulnerabilities where classical tools missed them after millions of test runs.
The VentureBeat numbers are staggering. Mythos Preview autonomously identified thousands of high-severity vulnerabilities. In one cited example, automated testing tools had executed a specific line of code 5 million times without detecting the issue. Mythos found it. According to Anthropic, the model can chain vulnerabilities in the Linux kernel to escalate from basic user access to full machine control.
Project Glasswing partners include names that tell you everything about the initiative:
Category
Partners
Hyperscalers
Amazon, Microsoft, Google
Hardware
Apple, Nvidia, Broadcom, Cisco
Cybersecurity
CrowdStrike, Palo Alto Networks
Open source
Linux Foundation
Source: VentureBeat, Tech Times, Anthropic Blog, April 7, 2026
Axios reports that Anthropic is discussing Mythos with the U.S. government, including the Pentagon, which wants to use AI tools for identifying adversary infrastructure targets. Gizmodo put it bluntly: “Anthropic's New Model Is So Scarily Powerful It Won't Be Released.” On X and Reddit, the debate exploded: this is the first time a lab has publicly decided not to release a model because of its offensive capabilities.
VentureBeat quotes CrowdStrike's Williams: “Mythos makes one thing painfully clear. This is not a prioritization problem. It is an exposure window problem.” The exposure window is the delay between vulnerability discovery and patching. Mythos can find and potentially exploit thousands of flaws while human security teams are still handling dozens.
My take as a solo dev
This is the story of the week that really deserves attention.
An AI model that autonomously finds zero-day vulnerabilities in OpenBSD, a security-focused OS, that are 27 years old, and that classical tools missed after 5 million test runs. That is not a marginal improvement. That is a change in what AI can do in cybersecurity.
What bothers me in Anthropic's narrative is the implicit trust we are supposed to give to their 40 “vetted” partners. These companies (Amazon, Microsoft, Apple, Nvidia) are not exactly neutral government entities. They are commercial actors with business interests. Giving this consortium exclusive access to a vulnerability-exploitation tool at Mythos scale creates a massive information asymmetry. Defenders outside the circle do not have access to the same tool as potential state-level attackers who will build their own equivalent in the coming months.
Honestly, I do not know whether Anthropic is making the right choice. Release Mythos = risk weaponization by adversaries. Do not release it = create a security elite with access to capabilities others do not have. Both options are bad. The problem is that no “exposure window” disappears just because the model stays locked away with 40 partners.
And the discussions with the Pentagon about identifying “adversary infrastructure targets”: that is the kind of sentence you should read twice.
OpenAI, Anthropic, Google: the AI cartel against China
On April 6, 2026, Bloomberg revealed that OpenAI, Anthropic, and Google had joined forces through the Frontier Model Forum to share intelligence on Chinese entities' attempts to distill their models adversarially. Anthropic identified three Chinese labs (DeepSeek, Moonshot, and MiniMax) as illegally extracting capabilities from its models via distillation. U.S. government estimates put the annual losses for Silicon Valley labs in the billions. OpenAI had already sent Congress a memo accusing DeepSeek of free-riding on its capabilities.
Definition — Adversarial distillation: a technique where a smaller “student” AI model is trained using massive outputs from a larger “teacher” model, transferring capabilities without access to the teacher's weights or training data. When it violates a service's terms of use, U.S. labs describe it as a form of intellectual property theft.
Bloomberg says the three companies are sharing information through the Frontier Model Forum, a nonprofit founded in 2023 with Microsoft, to detect adversarial distillation patterns that violate their terms. The Los Angeles Times reports that U.S. officials estimate the practice costs billions of dollars in annual lost revenue.
The geopolitical signal is strong. OpenAI, Anthropic, and Google compete directly in the market. The fact that they coordinate on one issue, even if only by sharing information about a common threat, shows that China is now seen as an existential threat to the business model of American AI.
There is also a regulatory dimension to watch. Anthropic already blocked access for China-controlled entities last year. OpenAI sent a memo to Congress. That is the kind of lobbying that usually comes before legislation, potentially export restrictions on AI APIs similar to the controls already in place on Nvidia chips.
For independent developers outside the U.S. who use these APIs, the question becomes: how long before access to these models requires proof of nationality or location?
My take as a solo dev
What strikes me is the paradox of the American position. On one hand, OpenAI and Anthropic want to open global markets and maximize their user base. On the other hand, they want to restrict access to those who copy their technology. Those two goals are not compatible in a world without geopolitical friction.
DeepSeek did the industry an involuntary favor: it proved that you can distill very advanced capabilities from open-access models at far lower cost. The problem is not DeepSeek. The problem is that adversarial distillation is fundamentally hard to detect and block without restricting legitimate use.
For my part, I use Claude Code and Anthropic APIs from France. I do not think these measures will affect me directly in the short term. But if geopolitical pressure leads to strict export controls on LLM APIs, the business model for an indie dev relying on those services from Europe changes fundamentally. It is a risk variable I am watching, and one that any independent developer using LLMs should factor into stack decisions.
Other AI news this week
News
What happened
Why it matters
OWASP GenAI Matrix
On April 6, the OWASP GenAI Security Project published a tooling matrix to secure LLM agents against goal drift, prompt injection, and unsafe tool execution. (Dark Reading)
A de facto reference for securing AI agents in production. Free, open source. A bookmark.
Microsoft agent stack confusion
Forbes reports that Microsoft's agent stack (Azure AI Foundry, Semantic Kernel, Copilot Studio) is seen as too fragmented by developers, while Cursor and Anthropic simplify. (Forbes)
A signal on Microsoft execution despite massive investment.
Solo founder at $1.8B in 2 months
Viral X thread: a solo founder claims to have built a $1.8 billion company in two months with $20,000 and AI tools. Gary Marcus tore down the narrative. (Substack Marcus on AI)
The myth of the AI solo founder billionaire in two months deserves Marcus's debunking.
OpenAI slams Anthropic
CNBC reports that OpenAI sent an internal memo to shareholders attacking Anthropic on its commercial ambitions and safety posture. (CNBC)
The OpenAI/Anthropic rivalry goes beyond products. A signal on pressure and the next moves.
Cloud agent registries
AWS, Azure, and GCP launch registries to publish and discover AI agents. The new battleground of hyperscalers, according to Forbes. (Forbes)
The agent marketplace is the equivalent of the App Store for LLMs. The winning platform controls distribution.
Claude finds a 13-year-old ActiveMQ bug
Claude discovered a 2013-dormant RCE bug in Apache ActiveMQ Classic within minutes, missed by millions of automated test runs. (CSO Online)
A production preview of Mythos capabilities. Went viral on Reddit r/netsec.
What the week of April 10, 2026 changes for independent developers
1. The classic IDE is officially on the way out as the main interface
Cursor 3 does not say “we improve the IDE,” it says “the IDE is the fallback.” For devs building products solo or in small teams, the dominant workflow in 24 months will be agent dispatch + diff review, not line-by-line writing. Getting used to precise task framing and evaluating agent outputs is no longer optional.
2. The $100/month segment is now the entry point for serious coding tools
OpenAI and Anthropic both now have a $100 tier for intensive coding. That has become the standard price point for professional AI coding tools. For independents who put AI at the center of their workflow, this is a budget line item like any other professional SaaS.
3. The attack surface of our tools is now public
Claude Code source is circulating. Mythos capabilities are publicly documented. OWASP has published a threat matrix for LLM agents. If you let an AI agent access your file system, API keys, or database, you need an explicit security policy. Not “I’ll think about it later.”
4. Geopolitics is entering the technical stack
The OpenAI/Anthropic/Google alliance against Chinese distillation hints at API access restrictions based on nationality or location. For European devs, that is a risk variable to watch over the next 12 to 18 months. Diversifying model providers is no longer just about pricing.
5. The most powerful models will no longer be publicly available
Mythos will not be released. OpenAI is planning a staggered rollout of its equivalent, according to Axios. We are entering an era where the most capable frontier models are reserved for vetted consortia. Access to the best models will depend on belonging to partner programs.
Frequently asked questions about AI news April 10, 2026
What is Cursor 3 and why is it a turning point?
Cursor 3, launched on April 5, 2026 under the codename Glass, replaces the IDE's main interface with an agent management console. The prompt box now occupies the file tree area. The code editor remains available, but as a secondary tool. Cursor generates $2 billion in annualized revenue and is betting that developers will spend most of their time directing agents instead of writing code directly.
Why is OpenAI launching a $100/month tier now?
On April 9, 2026, OpenAI announced a $100-per-month tier explicitly aimed at Anthropic's Claude Code, which had owned that segment for months. The plan offers 5x the Codex limits of the $20 Plus tier. OpenAI says Codex has 3 million weekly users and 70% month-over-month growth. The 5x limits are only guaranteed until May 31, 2026.
What is Anthropic's Project Glasswing?
Project Glasswing is Anthropic's initiative launched on April 7, 2026 to control access to Claude Mythos Preview, its most powerful model. The model discovered thousands of zero-day vulnerabilities in testing (including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw) and is considered too risky for public release. Anthropic is limiting access to 40+ vetted partners including Amazon, Apple, Microsoft, and CrowdStrike, with $100 million in usage credits.
How are OpenAI, Anthropic, and Google cooperating against China?
According to Bloomberg on April 6, 2026, the three labs are sharing information through the Frontier Model Forum, a nonprofit founded in 2023 with Microsoft, to detect adversarial distillation attempts by Chinese entities. Anthropic identified DeepSeek, Moonshot, and MiniMax as illegally extracting its capabilities. U.S. government estimates put the practice at billions in annual losses.
What is adversarial distillation and why is it a problem?
Adversarial distillation means training a model using massive outputs from a more powerful model, transferring capabilities without access to weights or training data. DeepSeek showed in 2025 that you can get near-frontier performance from open-access models at much lower cost using this method. U.S. labs consider it a violation of terms of use and a threat to their business model.
Conclusion: the week the rules changed for developers
Cursor 3 says the IDE is the past. OpenAI says the pricing war is on. Anthropic says some models will never leave the lab. And the three biggest AI companies in the world are joining forces against adversaries they cannot control.
For building Livate from my solo-dev position, this week was dense. My tools are evolving faster than my work habits. My dev costs are becoming a real budget line. And the platforms I rely on are making geopolitical tradeoffs that could one day affect my access.
What sticks with me is one conviction: the skills that become more valuable in this new environment are not “I know how to write perfect code.” They are “I know how to clearly frame a problem, judge a solution, and decide when to ship.” That is what I have been trying to do with Claude Code on Livate for months. And apparently, Cursor agrees.
Alex
Key takeaways
Cursor 3, launched on April 5, 2026, turns its IDE into an agent management console (codename Glass). The code editor becomes the fallback. Cursor generates $2B ARR and bets the dominant workflow will be agent dispatch + review, not line-by-line writing.
OpenAI announces a $100/month tier on April 9 to compete with Anthropic's Claude Code. Codex claims 3 million weekly users, 5x in 3 months, +70% month over month. The 5x limits are only guaranteed until May 31, 2026.
Anthropic suffers its second major leak in two weeks: a Claude Code v2.1.88 sourcemap exposes the agent's source code (human error). Claude outage on April 6. The company is operating under heavy pressure despite remarkable product results.
Claude Mythos Preview discovers thousands of zero-days including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg flaw. Too dangerous for public release. Project Glasswing: access limited to 40+ vetted partners (Amazon, Apple, Microsoft, CrowdStrike), $100M in usage credits.
OpenAI, Anthropic, and Google cooperate through the Frontier Model Forum against adversarial distillation by DeepSeek, Moonshot, and MiniMax. Estimated losses reach several billion dollars per year. Risk of API access restrictions based on nationality in the next 12 to 18 months.