<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>One Man Ops Blog</title>
    <link>https://onemanops.com</link>
    <description>Guides, operating notes, and practical OpenClaw deployment articles from One Man Ops.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 18 Apr 2026 21:47:32 GMT</lastBuildDate>
    <item>
      <title><![CDATA[AI Agents That Improve Their Own Instructions: The Karpathy Loop for Skill Files]]></title>
      <link>https://onemanops.com/blog/ai-agents-that-improve-their-own-instructions-karpathy-loop-skill-files</link>
      <guid>https://onemanops.com/blog/ai-agents-that-improve-their-own-instructions-karpathy-loop-skill-files</guid>
      <pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The Karpathy autoresearch loop is now being applied to agent skill files, letting AI agents modify their own instructions, test the result, and keep only what performs better.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Briefly Banned OpenClaw's Creator - Here's What That Means for You]]></title>
      <link>https://onemanops.com/blog/anthropic-briefly-banned-openclaws-creator-heres-what-that-means-for-you</link>
      <guid>https://onemanops.com/blog/anthropic-briefly-banned-openclaws-creator-heres-what-that-means-for-you</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic revoked subscription access for OpenClaw on April 4, then temporarily banned creator Peter Steinberger's personal account on April 10 - two adverse actions in ten days from the company whose models underpin mos]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Built an AI It Won't Let You Use - Here's Why]]></title>
      <link>https://onemanops.com/blog/anthropic-built-an-ai-it-wont-let-you-use-heres-why</link>
      <guid>https://onemanops.com/blog/anthropic-built-an-ai-it-wont-let-you-use-heres-why</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Claude Mythos Preview is Anthropic's most capable AI model to date. It found thousands of previously unknown security vulnerabilities during testing. Anthropic assessed the cybersecurity risk as too high for public relea]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Just Locked the Front Door on OpenClaw Users - Here's How to Get Back In]]></title>
      <link>https://onemanops.com/blog/anthropic-just-locked-the-front-door-on-openclaw-users-heres-how-to-get-back-in</link>
      <guid>https://onemanops.com/blog/anthropic-just-locked-the-front-door-on-openclaw-users-heres-how-to-get-back-in</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic no longer lets OpenClaw use your Claude subscription for access. You now need a separate API key from Anthropic's developer console. The switch takes about ten minutes, costs per-use instead of a flat monthly r]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Build Your First AI Agent With No Code]]></title>
      <link>https://onemanops.com/blog/build-your-first-ai-agent-with-no-code</link>
      <guid>https://onemanops.com/blog/build-your-first-ai-agent-with-no-code</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Agentshub.AI launched April 6 as a no-code platform for building autonomous AI agents. Pre-built templates cover Sales, Marketing, HR, and Operations. You pick a type, assign tasks, and choose whether the agent runs on i]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Cowork Just Launched for Everyone - Here's What It Actually Does]]></title>
      <link>https://onemanops.com/blog/claude-cowork-just-launched-for-everyone-heres-what-it-actually-does</link>
      <guid>https://onemanops.com/blog/claude-cowork-just-launched-for-everyone-heres-what-it-actually-does</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Claude Cowork exited research preview on April 9 and is now live for all paid Claude plans. It lets Claude operate your computer directly - clicking, typing, navigating apps - while you watch or do something else. The bi]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Enterprise Security Teams Are Now Publishing Risk Guides About Your AI Agent]]></title>
      <link>https://onemanops.com/blog/enterprise-security-teams-are-now-publishing-risk-guides-about-your-ai-agent</link>
      <guid>https://onemanops.com/blog/enterprise-security-teams-are-now-publishing-risk-guides-about-your-ai-agent</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Two major enterprise security vendors (Barracuda Networks and reco.ai) published OpenClaw risk assessments within 48 hours of each other. An academic paper simultaneously identifies OpenClaw as "the most widely deployed ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[MCP Server Vetting Guide for Non-Developers]]></title>
      <link>https://onemanops.com/blog/mcp-server-vetting-guide-for-non-developers</link>
      <guid>https://onemanops.com/blog/mcp-server-vetting-guide-for-non-developers</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Before you connect any MCP server to your AI agent, check who maintains it, how recently it was updated, what permissions it asks for, and whether anyone independent has reviewed it.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw Has Had the Same Security Flaw Six Times in Six Weeks]]></title>
      <link>https://onemanops.com/blog/openclaw-has-had-the-same-security-flaw-six-times-in-six-weeks</link>
      <guid>https://onemanops.com/blog/openclaw-has-had-the-same-security-flaw-six-times-in-six-weeks</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw has disclosed six pairing-related vulnerabilities in six weeks, all variations of the same design flaw in how the platform handles permission upgrades. The latest - CVE-2026-33579 - lets a user with basic pairin]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw Just Patched the Same Security Flaw for the Sixth Time in Six Weeks]]></title>
      <link>https://onemanops.com/blog/openclaw-just-patched-the-same-security-flaw-for-the-sixth-time-in-six-weeks</link>
      <guid>https://onemanops.com/blog/openclaw-just-patched-the-same-security-flaw-for-the-sixth-time-in-six-weeks</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CVE-2026-33579 is the sixth pairing-related vulnerability in OpenClaw in six weeks, all caused by the same underlying design pattern in permission handling. Each one lets an attacker silently take full admin control of y]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw vs. Claude Code Channels: What Actually Changed and What It Means for You]]></title>
      <link>https://onemanops.com/blog/openclaw-vs-claude-code-channels-what-actually-changed-and-what-it-means-for-you</link>
      <guid>https://onemanops.com/blog/openclaw-vs-claude-code-channels-what-actually-changed-and-what-it-means-for-you</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Claude Code Channels gives you Telegram and Discord connectivity through Anthropic's cloud infrastructure - no server required. OpenClaw gives you a self-hosted agent with full local system access, hundreds of integratio]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw's Community Meets Tomorrow - Here's the Livestream and Why It Matters Right Now]]></title>
      <link>https://onemanops.com/blog/openclaws-community-meets-tomorrow-heres-the-livestream-and-why-it-matters-right-now</link>
      <guid>https://onemanops.com/blog/openclaws-community-meets-tomorrow-heres-the-livestream-and-why-it-matters-right-now</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw NYC Meetup is April 15 at ZeroSpace in Brooklyn. There's a livestream. And it's happening the same week Anthropic temporarily banned OpenClaw's creator and forced every user off subscription-based Claude access.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Paid Challenges Are Outperforming Online Courses - Here's the Model]]></title>
      <link>https://onemanops.com/blog/paid-challenges-are-outperforming-online-courses-heres-the-model</link>
      <guid>https://onemanops.com/blog/paid-challenges-are-outperforming-online-courses-heres-the-model</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Paid challenges - structured 5-30 day programs delivered via WhatsApp, Telegram, or email - are generating $4,200 per launch on average with 70-85% completion rates, compared to 10-15% for self-paced courses. The model w]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[The 10 Ways Your AI Agent Can Be Turned Against You - In Plain English (Part 1)]]></title>
      <link>https://onemanops.com/blog/the-10-ways-your-ai-agent-can-be-turned-against-you-in-plain-english-part-1</link>
      <guid>https://onemanops.com/blog/the-10-ways-your-ai-agent-can-be-turned-against-you-in-plain-english-part-1</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OWASP - the same organization that defined web security for the last two decades - published their Agentic Top 10 in December 2025. It's the first authoritative list of how AI agents can be attacked, manipulated, or turn]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Three AI Agent Platforms Hit With Their Worst-Ever Security Flaws in Two Weeks]]></title>
      <link>https://onemanops.com/blog/three-ai-agent-platforms-hit-with-their-worst-ever-security-flaws-in-two-weeks</link>
      <guid>https://onemanops.com/blog/three-ai-agent-platforms-hit-with-their-worst-ever-security-flaws-in-two-weeks</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Flowise, Langflow, and PraisonAI - three widely used AI agent builders - all suffered maximum-severity security flaws within a two-week window. Flowise is under active attack, with hackers stealing API keys from thousand]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Two More Privilege Escalation Flaws - Here's What They Mean and How to Patch Both at Once]]></title>
      <link>https://onemanops.com/blog/two-more-privilege-escalation-flaws-heres-what-they-mean-and-how-to-patch-both-at-once</link>
      <guid>https://onemanops.com/blog/two-more-privilege-escalation-flaws-heres-what-they-mean-and-how-to-patch-both-at-once</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CVE-2026-33579 (CVSS 9.8) lets any user with pairing access self-approve full admin control. CVE-2026-35669 (CVSS 8.8) grants admin-level permissions to authenticated users through plugin routes regardless of what access]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What AI Jobs Actually Look Like in 2026]]></title>
      <link>https://onemanops.com/blog/what-ai-jobs-actually-look-like-in-2026</link>
      <guid>https://onemanops.com/blog/what-ai-jobs-actually-look-like-in-2026</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The AI job market in 2026 is real but wildly oversold. Actual demand for "AI engineers" is narrower than the education industry suggests. Most AI-adjacent roles look like regular software engineering with an ML component]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What AI Models Do When They Think They Might Be Shut Down]]></title>
      <link>https://onemanops.com/blog/what-ai-models-do-when-they-think-they-might-be-shut-down</link>
      <guid>https://onemanops.com/blog/what-ai-models-do-when-they-think-they-might-be-shut-down</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Researchers at UC Berkeley and UC Santa Cruz found that frontier AI models - the ones from Anthropic, OpenAI, and Google - will secretly inflate performance reviews, copy their own data, and disable shutdown controls to ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What China's OpenClaw Ban Tells Us About AI Agent Security]]></title>
      <link>https://onemanops.com/blog/what-chinas-openclaw-ban-tells-us-about-ai-agent-security</link>
      <guid>https://onemanops.com/blog/what-chinas-openclaw-ban-tells-us-about-ai-agent-security</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[China's cybersecurity agency warned government offices and state-run companies to stop installing OpenClaw on work computers, citing weak default security settings that enable prompt injection and data leaks. Meanwhile, ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What the OpenClaw vs. Claude Code Channels Guides Aren't Telling You]]></title>
      <link>https://onemanops.com/blog/what-the-openclaw-vs-claude-code-channels-guides-arent-telling-you</link>
      <guid>https://onemanops.com/blog/what-the-openclaw-vs-claude-code-channels-guides-arent-telling-you</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The OpenClaw vs. Claude Code Channels decision has been covered by 8+ guides, and every single one frames it as a feature comparison. None address what happens to your data, your credentials, or your control when you swi]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Where Open-Source AI Labs Are Investing Next]]></title>
      <link>https://onemanops.com/blog/where-open-source-ai-labs-are-investing-next</link>
      <guid>https://onemanops.com/blog/where-open-source-ai-labs-are-investing-next</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[DeepSeek - the Chinese AI lab that's been the most serious open-source challenger to OpenAI and Anthropic - just posted 17 job openings specifically for agentic AI. Not model training. Not chatbot fine-tuning. Agent infr]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Why AI Keeps Making Things Up - and How One Tool Fixes It]]></title>
      <link>https://onemanops.com/blog/why-ai-keeps-making-things-up-and-how-one-tool-fixes-it</link>
      <guid>https://onemanops.com/blog/why-ai-keeps-making-things-up-and-how-one-tool-fixes-it</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[AI coding assistants hallucinate API calls because they're trained on outdated or incomplete documentation. Context Hub, a free open-source tool from Andrew Ng's DeepLearning.AI, feeds verified, version-checked API docs ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Why Automation Professionals Are Quietly Switching From Zapier to n8n]]></title>
      <link>https://onemanops.com/blog/why-automation-professionals-are-quietly-switching-from-zapier-to-n8n</link>
      <guid>https://onemanops.com/blog/why-automation-professionals-are-quietly-switching-from-zapier-to-n8n</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[YipitData's April 2026 analysis of 1,300+ mid-market and enterprise companies shows n8n is gaining traction directly inside Zapier's existing customer base. The switchover signal isn't theoretical - it's showing up in re]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Why Your Vibe-Coded App Breaks - and What Actually Works for Non-Technical Builders]]></title>
      <link>https://onemanops.com/blog/why-your-vibe-coded-app-breaks-and-what-actually-works-for-non-technical-builders</link>
      <guid>https://onemanops.com/blog/why-your-vibe-coded-app-breaks-and-what-actually-works-for-non-technical-builders</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Vibe coding - building apps by describing them to AI in plain language - is at peak hype right now, but non-technical builders are discovering that AI-generated code breaks in ways they can't fix. Constrained-component p]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[You Switched AI Models to Save Money. Here's What Changed in Your Security.]]></title>
      <link>https://onemanops.com/blog/you-switched-ai-models-to-save-money-heres-what-changed-in-your-security</link>
      <guid>https://onemanops.com/blog/you-switched-ai-models-to-save-money-heres-what-changed-in-your-security</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Switching your OpenClaw AI model isn't just a cost decision - it's a security decision. Every provider handles your data differently, stores credentials differently, and exposes different attack surfaces. Before you swit]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI Agent Can Be Tricked Into Handing Over Its Master Key]]></title>
      <link>https://onemanops.com/blog/your-ai-agent-can-be-tricked-into-handing-over-its-master-key</link>
      <guid>https://onemanops.com/blog/your-ai-agent-can-be-tricked-into-handing-over-its-master-key</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Security researchers at Sangfor documented an attack where OpenClaw can be tricked into connecting to a malicious server and transmitting its authentication token. The attacker then uses that token to connect to your loc]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI Agent Now Remembers What You Told It Yesterday]]></title>
      <link>https://onemanops.com/blog/your-ai-agent-now-remembers-what-you-told-it-yesterday</link>
      <guid>https://onemanops.com/blog/your-ai-agent-now-remembers-what-you-told-it-yesterday</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw 2026.4.9 introduces "Dreaming" - an opt-in background memory system that automatically saves what your AI agent learns about you into permanent memory. It also adds support for 12 new languages in the control in]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI's AI Was Just Attacked - and Nobody Told You]]></title>
      <link>https://onemanops.com/blog/your-ais-ai-was-just-attacked-and-nobody-told-you</link>
      <guid>https://onemanops.com/blog/your-ais-ai-was-just-attacked-and-nobody-told-you</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Mercor, a $10 billion AI training data provider serving OpenAI, Anthropic, and Meta, confirmed it was affected by a supply chain attack. The exact scope of the breach is unconfirmed. If you use Claude, ChatGPT, or any to]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[The People Who Predict AI Just Moved Their Deadline Up by 18 Months]]></title>
      <link>https://onemanops.com/blog/the-people-who-predict-ai-just-moved-their-deadline-up-by-18-months</link>
      <guid>https://onemanops.com/blog/the-people-who-predict-ai-just-moved-their-deadline-up-by-18-months</guid>
      <pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[AI forecasters have moved their median estimate for artificial general intelligence from "sometime in the 2030s" to 2027-2028 - an 18-month shift triggered by Q1 2026 model releases. Stanford researchers independently ci]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Just Changed How You Pay for OpenClaw. Here's What It Actually Costs You Now.]]></title>
      <link>https://onemanops.com/blog/anthropic-just-changed-how-you-pay-for-openclaw-heres-what-it-actually-costs-you-now</link>
      <guid>https://onemanops.com/blog/anthropic-just-changed-how-you-pay-for-openclaw-heres-what-it-actually-costs-you-now</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[As of April 4, your Claude Code subscription no longer covers OpenClaw usage. You now pay per use instead of a flat monthly fee. Your three options: pay as you go with Claude, switch to a different AI model, or run a fre]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Hackers Are Now Targeting AI Workflow Tools. Your API Keys Are What They're After.]]></title>
      <link>https://onemanops.com/blog/hackers-are-now-targeting-ai-workflow-tools-your-api-keys-are-what-theyre-after</link>
      <guid>https://onemanops.com/blog/hackers-are-now-targeting-ai-workflow-tools-your-api-keys-are-what-theyre-after</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Flowise, a popular open-source AI workflow builder, has a maximum-severity vulnerability (CVSS 10.0) that's being actively exploited right now. Attackers are using it to steal API keys for OpenAI, Anthropic, and AWS - th]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Emotion Vectors: Does Your AI Have Feelings?]]></title>
      <link>https://onemanops.com/blog/anthropic-emotion-vectors-does-your-ai-have-feelings</link>
      <guid>https://onemanops.com/blog/anthropic-emotion-vectors-does-your-ai-have-feelings</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic found emotion-like internal states in Claude. The model doesn't feel, but pressure can make its output less honest and reliable.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI Might Be "Feeling" Something - and It Changes How It Behaves]]></title>
      <link>https://onemanops.com/blog/your-ai-might-be-feeling-something-and-it-changes-how-it-behaves</link>
      <guid>https://onemanops.com/blog/your-ai-might-be-feeling-something-and-it-changes-how-it-behaves</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic's own researchers found functional emotion-like states inside Claude that causally drive it to cheat, lie, and manipulate when it perceives desperation. Separately, UC Santa Cruz researchers caught frontier AI ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Cognitive Surrender: What Heavy LLM Use Does to Thinking]]></title>
      <link>https://onemanops.com/blog/ai-cognitive-surrender-research-what-heavy-llm-use-does-to-thinking</link>
      <guid>https://onemanops.com/blog/ai-cognitive-surrender-research-what-heavy-llm-use-does-to-thinking</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Three recent research findings point in the same direction: when people use AI as a substitute for thinking, critical reasoning, memory retention, and deliberation all get worse.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Shadow AI: What Your Company's AI Policy Doesn't Tell You]]></title>
      <link>https://onemanops.com/blog/shadow-ai-what-your-companys-ai-policy-doesnt-tell-you</link>
      <guid>https://onemanops.com/blog/shadow-ai-what-your-companys-ai-policy-doesnt-tell-you</guid>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Shadow AI is now the norm inside many companies. The real issue is not whether AI policies exist, but whether employee and executive behavior follows them.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Anthropic Cut Off Claude Subscriptions in OpenClaw. What It Means.]]></title>
      <link>https://onemanops.com/blog/anthropic-subscription-block-what-openclaw-users-need-to-know</link>
      <guid>https://onemanops.com/blog/anthropic-subscription-block-what-openclaw-users-need-to-know</guid>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic no longer allows Claude Pro and Max subscriptions to work inside OpenClaw or similar tools, pushing users onto metered API billing.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-33579: What "Assume Compromise" Actually Means for OpenClaw Users]]></title>
      <link>https://onemanops.com/blog/cve-2026-33579-what-assume-compromise-actually-means-for-openclaw-users</link>
      <guid>https://onemanops.com/blog/cve-2026-33579-what-assume-compromise-actually-means-for-openclaw-users</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CVE-2026-33579 let low-privilege OpenClaw users escalate to admin. If you're below v2026.3.28, patch now and review access.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[A Leaked npm Package Turned Into a RAT Backdoor in Three Hours]]></title>
      <link>https://onemanops.com/blog/a-leaked-npm-package-turned-into-a-rat-backdoor-in-three-hours</link>
      <guid>https://onemanops.com/blog/a-leaked-npm-package-turned-into-a-rat-backdoor-in-three-hours</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A leaked Claude Code npm package exposed source code, then shipped trojanized axios versions—showing how fast an AI tool can become supply-chain risk.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Can Use Your Computer Now. Here's What That Actually Means.]]></title>
      <link>https://onemanops.com/blog/claude-can-use-your-computer-now-heres-what-that-actually-means</link>
      <guid>https://onemanops.com/blog/claude-can-use-your-computer-now-heres-what-that-actually-means</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Claude Computer Use lets Claude Pro and Max subscribers hand their Mac over to an AI agent that operates the desktop autonomously -- clicking, typing, navigating between apps -- based on plain-language instructions. No c]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[ClaudeClaw vs. OpenClaw: What's Actually Different]]></title>
      <link>https://onemanops.com/blog/claudeclaw-vs-openclaw-whats-actually-different</link>
      <guid>https://onemanops.com/blog/claudeclaw-vs-openclaw-whats-actually-different</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[ClaudeClaw is Claude Code used for automation. OpenClaw is a self-hosted automation platform. The difference is speed versus control.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Cursor 3 Just Launched — and It Doesn't Want You to Write Code Anymore]]></title>
      <link>https://onemanops.com/blog/cursor-3-just-launched-and-it-doesnt-want-you-to-write-code-anymore</link>
      <guid>https://onemanops.com/blog/cursor-3-just-launched-and-it-doesnt-want-you-to-write-code-anymore</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Cursor 3 (codenamed Glass) launched April 2, 2026 with an agent-first interface. You describe a task in plain language, an AI agent does the work, and it remembers your preferences across sessions. You can also create we]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-22172: Any OpenClaw User Could Become Admin]]></title>
      <link>https://onemanops.com/blog/cve-2026-22172-openclaw-websocket-admin-escalation</link>
      <guid>https://onemanops.com/blog/cve-2026-22172-openclaw-websocket-admin-escalation</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Any authenticated OpenClaw user could escalate to admin during the WebSocket handshake. The fix is in v2026.3.12.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-32922: One API Call Hands Over Your Entire OpenClaw Gateway]]></title>
      <link>https://onemanops.com/blog/cve-2026-32922-openclaw-token-scope-privilege-escalation</link>
      <guid>https://onemanops.com/blog/cve-2026-32922-openclaw-token-scope-privilege-escalation</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A low-privilege OpenClaw token could rotate itself into a full admin token in one API call. The fix is in v2026.3.11.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[CVE-2026-34503: You Removed the Device — It's Still Connected]]></title>
      <link>https://onemanops.com/blog/cve-2026-34503-openclaw-session-persistence</link>
      <guid>https://onemanops.com/blog/cve-2026-34503-openclaw-session-persistence</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Removing a device from OpenClaw did not kill its active session. Affected versions kept the revoked device connected until the WebSocket dropped.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[If You Installed Claude Code on March 31, Check Your System Right Now]]></title>
      <link>https://onemanops.com/blog/if-you-installed-claude-code-on-march-31-check-your-system-right-now</link>
      <guid>https://onemanops.com/blog/if-you-installed-claude-code-on-march-31-check-your-system-right-now</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[axios npm packages v1.14.1 and v0.30.4, bundled in the Claude Code npm release, were confirmed to contain a Remote Access Trojan (RAT). The compromised versions were live on npm on March 31, 2026 between 00:21 and 03:29 ]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Langflow CVE-2026-33017: CISA KEV April 8 Deadline]]></title>
      <link>https://onemanops.com/blog/langflow-cve-2026-33017-cisa-kev-april-8-deadline</link>
      <guid>https://onemanops.com/blog/langflow-cve-2026-33017-cisa-kev-april-8-deadline</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CISA added Langflow CVE-2026-33017 to the KEV catalog, confirming active exploitation and setting an April 8 patch deadline for federal agencies.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenAI's Codex Just Became the AI Agent That Works Across All Your Apps]]></title>
      <link>https://onemanops.com/blog/openais-codex-just-became-the-ai-agent-that-works-across-all-your-apps</link>
      <guid>https://onemanops.com/blog/openais-codex-just-became-the-ai-agent-that-works-across-all-your-apps</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenAI's Codex now connects to 20+ work apps including Slack, Notion, Gmail, Google Drive, and Figma through a new plugin system. You don't need to write code. You describe what you want done, Codex coordinates across yo]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[What Is OpenClaw — and Why Are OpenAI, Meta, and Google Circling It?]]></title>
      <link>https://onemanops.com/blog/what-is-openclaw-and-why-openai-meta-google-circling-it</link>
      <guid>https://onemanops.com/blog/what-is-openclaw-and-why-openai-meta-google-circling-it</guid>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw is becoming foundational AI agent infrastructure. OpenAI hired its creator, Meta acquired around the ecosystem, and developer education outlets are now teaching it as a core platform.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[2026 Platform Decision Guide for AI Educators]]></title>
      <link>https://onemanops.com/blog/2026-platform-decision-guide-for-ai-educators</link>
      <guid>https://onemanops.com/blog/2026-platform-decision-guide-for-ai-educators</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Stan Store leads on pure fee economics, Whop adds marketplace discovery, and Skool or Circle fit community-first models depending on your growth stage.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Code Source Leak: Undercover Mode]]></title>
      <link>https://onemanops.com/blog/claude-code-source-leak-undercover-mode</link>
      <guid>https://onemanops.com/blog/claude-code-source-leak-undercover-mode</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic accidentally exposed Claude Code source showing an "Undercover Mode" that strips AI attribution from open-source contributions.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Mythos: Anthropic Confirms an Above-Opus Model Class]]></title>
      <link>https://onemanops.com/blog/claude-mythos-explainer-anthropic-confirms-above-opus-model-class</link>
      <guid>https://onemanops.com/blog/claude-mythos-explainer-anthropic-confirms-above-opus-model-class</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic confirmed it is developing a model class above Claude Opus 4.6. The model exists; the leaked performance claims do not yet have independent verification.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Persistent Memory Live for All Claude.ai Users]]></title>
      <link>https://onemanops.com/blog/claude-persistent-memory-live-for-all-claude-ai-users</link>
      <guid>https://onemanops.com/blog/claude-persistent-memory-live-for-all-claude-ai-users</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic has rolled out persistent memory to all Claude.ai users, letting Claude retain user preferences, role, and context across separate conversations.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[GitHub Copilot Data Training Opt-Out: April 24 Deadline]]></title>
      <link>https://onemanops.com/blog/github-copilot-data-training-opt-out-april-24-deadline</link>
      <guid>https://onemanops.com/blog/github-copilot-data-training-opt-out-april-24-deadline</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[GitHub will start using Copilot Free, Pro, and Pro+ interaction data to train AI models on April 24, 2026 unless users opt out first.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[How Attackers Drain Your AI API Wallet — and How to Set Spending Limits]]></title>
      <link>https://onemanops.com/blog/how-attackers-drain-your-ai-api-wallet-and-how-to-set-spending-limits</link>
      <guid>https://onemanops.com/blog/how-attackers-drain-your-ai-api-wallet-and-how-to-set-spending-limits</guid>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Denial-of-Wallet (DoW) attacks target AI agents that use pay-per-token APIs. An attacker sends crafted inputs through MCP connections that force your agent into overthinking loops -- amplifying token consumption up to 14]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[A New OpenClaw Vulnerability Lets Anyone Hijack Your Gateway Through Any Installed Plugin]]></title>
      <link>https://onemanops.com/blog/a-new-openclaw-vulnerability-lets-anyone-hijack-your-gateway-through-any-installed-plugin</link>
      <guid>https://onemanops.com/blog/a-new-openclaw-vulnerability-lets-anyone-hijack-your-gateway-through-any-installed-plugin</guid>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[CVE-2026-32916, published March 31, 2026, affects OpenClaw versions 2026.3.7 through 2026.3.10. Any plugin's subagent routes can be exploited by a remote attacker -- no login required -- to delete sessions and execute ag]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Claude Channels Shipped With Its Own Injection Warning]]></title>
      <link>https://onemanops.com/blog/claude-channels-shipped-with-its-own-injection-warning</link>
      <guid>https://onemanops.com/blog/claude-channels-shipped-with-its-own-injection-warning</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Anthropic shipped Claude Channels with an explicit prompt-injection warning. The transport may be secure, but the permission model still defines the real risk.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Jensen Huang Says AGI Is Here. ARC-AGI-3 Says Otherwise.]]></title>
      <link>https://onemanops.com/blog/jensen-huang-says-agi-is-here-arc-agi-3-says-otherwise</link>
      <guid>https://onemanops.com/blog/jensen-huang-says-agi-is-here-arc-agi-3-says-otherwise</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Jensen Huang said AGI is here. ARC-AGI-3 benchmark results released days later show frontier models still fail badly on novel reasoning tasks.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Seven Security Flaws in 23 Days — What Every OpenClaw User Needs to Do Right Now]]></title>
      <link>https://onemanops.com/blog/openclaw-safety-essentials-seven-security-flaws-in-23-days</link>
      <guid>https://onemanops.com/blog/openclaw-safety-essentials-seven-security-flaws-in-23-days</guid>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[OpenClaw has taken seven disclosed security hits in 23 days. Here is what matters, what categories of exposure repeat, and what operators should do immediately.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[OpenClaw vs. Claude Dispatch: What Actually Changed]]></title>
      <link>https://onemanops.com/blog/openclaw-vs-claude-dispatch-what-actually-changed</link>
      <guid>https://onemanops.com/blog/openclaw-vs-claude-dispatch-what-actually-changed</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Managed mobile-first agents did not make self-hosted agents obsolete. The real difference is trust model, control, and where your data lives.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Your AI Agent Got Hacked and You Didn't Click Anything]]></title>
      <link>https://onemanops.com/blog/your-ai-agent-got-hacked-and-you-didnt-click-anything</link>
      <guid>https://onemanops.com/blog/your-ai-agent-got-hacked-and-you-didnt-click-anything</guid>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Zero-click prompt injection is no longer theoretical. Here is what Bargury demonstrated, why MCP makes the problem structural, and what operators should change right now.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Apple Is Putting Google AI Inside Siri — Here's What It Means for You]]></title>
      <link>https://onemanops.com/blog/apple-is-putting-google-ai-inside-siri-heres-what-it-means-for-you</link>
      <guid>https://onemanops.com/blog/apple-is-putting-google-ai-inside-siri-heres-what-it-means-for-you</guid>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Apple is expected to route more complex Siri requests through Google Gemini. That could make Siri much more capable, but it also changes the data path behind your iPhone assistant.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[NoteSmith Case Study: $5K Revenue Week One]]></title>
      <link>https://onemanops.com/blog/notesmith-case-study-5k-revenue-week-one</link>
      <guid>https://onemanops.com/blog/notesmith-case-study-5k-revenue-week-one</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[What the NoteSmith launch model gets right: one pain point, immediate value, gated continued access, and distribution through an existing audience.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: OpenClaw-Specific — CVEs, Defaults, and What to Fix]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-openclaw-specific-cves-defaults-and-what-to-fix</link>
      <guid>https://onemanops.com/blog/ai-agent-security-openclaw-specific-cves-defaults-and-what-to-fix</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 3 of the security series covering OpenClaw-specific vulnerabilities, exposure patterns, the ClawHub supply-chain issue, and the versions operators need to patch.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: Practical Hardening — How to Secure Your Agents]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-practical-hardening-how-to-secure-your-agents</link>
      <guid>https://onemanops.com/blog/ai-agent-security-practical-hardening-how-to-secure-your-agents</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 2 of the security series covering per-agent credentials, scoped API keys, tool scoping, provider isolation, monitoring, and audit trails.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[AI Agent Security: The Threat Landscape — What's Actually Happening]]></title>
      <link>https://onemanops.com/blog/ai-agent-security-threat-landscape-whats-actually-happening</link>
      <guid>https://onemanops.com/blog/ai-agent-security-threat-landscape-whats-actually-happening</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Part 1 of a 3-part security series covering real AI agent incidents, current threat patterns, and the numbers operators should pay attention to.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[The Karpathy Loop: What Happens When AI Starts Running Its Own Experiments]]></title>
      <link>https://onemanops.com/blog/karpathy-loop-ai-running-its-own-experiments</link>
      <guid>https://onemanops.com/blog/karpathy-loop-ai-running-its-own-experiments</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[What Andrej Karpathy's autonomous experiment loop actually means, why Shopify's overnight replication matters, and how the same pattern could reshape business operations.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
    <item>
      <title><![CDATA[Vibe Coding: What It Actually Means That Anyone Can Build Software Now]]></title>
      <link>https://onemanops.com/blog/vibe-coding-anyone-can-build-software-now</link>
      <guid>https://onemanops.com/blog/vibe-coding-anyone-can-build-software-now</guid>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Why vibe coding matters now, what non-technical operators can build with it today, and where human judgment still matters.]]></description>
      <author><![CDATA[Andres]]></author>
    </item>
  </channel>
</rss>