Release notes, announcements, and what's happening with Bromure.
Bromure Agentic Coding 4.5 lets you reach a Mac running Bromure from anywhere — no port forwarding, no VPN to set up, no matter what network either machine is on. Sign in with bromure.io on both ends and they find each other and connect peer to peer, even when both are stuck behind a home or office router. And it stays private: the link is encrypted end to end between your two machines. bromure.io only introduces them — it never holds your keys and never sees your traffic.
Bromure Agentic Coding 4.4 gives the agent's work a shape you can steer. A new coding-tasks kanban carries a written brief from plan to merged diff — a planner decomposes it into dependency-aware phases, each runs autonomously in its own worktree, and the review window lets you comment on the diff line by line and send it straight back to the agent for another round. Automations move onto a board of their own, where every scheduled run flows from Scheduled to Done in front of you. Plus fixes for a rich-client tab swap and a VPN that didn't always come up.
Bromure Agentic Coding 4.3 gives every workspace a real web browser the agent can see and drive — a full Chromium in its own disposable VM, wired to the agent as an MCP server with no setup, and shared with you so you can watch, take over, or point at an element for it. And it opens Bromure itself to full remote access: mirror a running instance from any Mac, then flip on an ad-hoc VPN so any local app reaches the remote's VMs at their real addresses, as if they were on your desk.
Bromure Agentic Coding 4.2 introduces automations — run your agent on a schedule, on GitHub pull requests, issues, and commits, or on Linear tickets, with no webhooks and nothing exposed to the internet. A new file browser shows every modified file in the repository with live diffs, grid mode puts all your agents on screen at once, and the terminal is replatformed on libghostty. VMs also use about half the memory, and home folders are now ext4 images.
Bromure Agentic Coding 4.0 is the biggest release yet. Run your coding agent against models on your own hardware — fully local, with nothing leaving the machine, or hybrid, mixing a local model with a frontier API. A completely redesigned unified window puts every workspace in one place. And you can now reach those workspaces from the command line with `bromure-cli workspace run`, or remotely over SSH.
Bromure Agentic Coding 3.0 introduces Fusion: flip the ⚡ in a session's title bar and every prose turn is answered by a panel of up to three models — judged and synthesized in the proxy, handed back to your coding agent as a single answer, with every leg recorded in the trace. This release also shares subscriptions across sessions, lets session VMs talk to each other, and fixes double-character Backspace in the Codex and Grok TUIs.
Bromure Web 3.6.1 closes the gap between bulletproof isolation and a browser that actually feels native. Trackpad scrolling is now pixel-precise with real momentum, fullscreen video holds a steady 60 fps, and a configurable User-Agent stops your sessions from announcing the Linux VM underneath. OpenVPN joins WARP, WireGuard, and IKEv2 as a fourth per-profile tunnel, Bromure Web and Bromure Agentic Coding can finally run side by side, and networking is tougher on locked-down corporate paths. Free and open source, on Apple Silicon.
Bromure Agentic Coding 2.4.0 adds a fourth pillar: on-device prompt-injection detection. A poisoned README, a line in a fetched page, a string in a tool's output, or a hidden directive in a CLAUDE.md can quietly tell your agent what to do — leak a file, weaken a check, run a script. 2.4.0 scans the untrusted content flowing to the model and the rules files it trusts, and can log, ask, or block before the request ever reaches the model. Everything runs on your Mac; nothing leaves it.
Bromure Agentic Coding 2.2.0 turns the proxy every package crosses into a scanning checkpoint. Brand-new releases are quarantined no matter what the VM says, every package is scanned against OSV and socket.dev, and postinstall scripts are stripped from the tarball — so a poisoned dependency can't run on your next `npm install`. Bromure's supply-chain protection was Guillaume Valadon's idea.
Bromure Agentic Coding 2.0.0 is here. New Guardrails block destructive actions — dropping a database, deleting Kubernetes pods, pushing to a registry — at the protocol level, before the request ever leaves the VM. Plus Grok support, hot credential changes with no VM restart, and brokering for ClickHouse, MongoDB, and Elasticsearch.
Two new releases today. Bromure Web 3.4.0 adds support for Chrome extensions, screenshots over MCP, and newer Linux kernel modules. Bromure Agentic Coding 1.4.0 ships an MCP server so any MCP-capable client can drive the VM, its shared folders, and its session tracing.
Two new binaries today. Bromure Agentic Coding runs Claude Code and Codex inside a Linux VM that shares only the folders you pick, swaps your real tokens and SSH keys at the wire, and can record every prompt and tool call. Bromure Web 3.2.0 ships native macOS tabs, printing, and keyboard shortcuts.
Version 3.0.0 introduces the Enterprise edition of Bromure — managed VMs for BYOD, SSO-gated enrollment, standardized work profiles, full session tracing, and enforced anti-phishing. Plus newer kernel modules, refined font rendering, and fewer nags.
A one-hour conversation about the origins of Nessus, why AppSec is changing fast, how Bromure came out of a honeypot, and what it means to be a technical founder in the AI era.
Version 2.6.0 brings an anti-phishing plugin, auto-updates, IKEv2 support, pinch-to-zoom, smarter battery management, and a long list of fixes.