#security
-
AI News Briefing — Google pauses open source bug bounty over AI submissions
Google pauses its open source bug bounty after a surge of mostly invalid AI-written reports. New Claude Cowork tasks on Pro and Max run in the cloud from October 6, and Cantina releases an open-weights vulnerability research model.
-
AI News Briefing — AWS patches unauthenticated admin flaw in Loom agent platform
AWS patches three flaws in Loom, its open-source agent platform, one handing unauthenticated users full admin. Google cuts free Gemini app users to Flash-Lite from October 9, and Aleph Alpha releases Kolibri under Apache 2.0.
-
AI News Briefing — GitLab patches command-execution flaw in self-hosted AI Gateway
GitLab patches a 9.9-rated flaw that let Duo Agent Platform users run commands on self-hosted AI Gateways. Apple tightens macOS Full Disk Access over agent risk, and Cloudflare open-sources its Clef decision models.
-
AI News Briefing — AWS open-sources Strands Decider, a local decision model
AWS open-sources Strands Decider 2B, a decision model small enough to run locally. Claude Code gets mods that rewrite its behavior, unsandboxed, and Copilot's CLI gains dynamic workflows and desktop computer use.
-
AI News Briefing — Google's Gemini 4 Argon goes to cyber defenders first
Google's Gemini 4 Argon goes to vetted cyber defenders first, with $4/$20 list pricing and no date for everyone else. Anthropic finds open-weight GLM-5.3 nearly matches Mythos Preview at building exploits.
-
AI News Briefing — Anthropic ships Claude Sonnet 5.5 at Sonnet 5 prices
Anthropic ships Claude Sonnet 5.5 at Sonnet 5's $2/$10 rates, within a few points of Opus 5.5 on agent benchmarks. OpenAI scrapped GPT-6.1 Astra after it failed its own alignment tests.
-
AI News Briefing — NVIDIA open-sources OpenShell to enforce agent policy at runtime
NVIDIA open-sources OpenShell, a runtime that traces and polices what agents touch, with over 100 backers including Anthropic. A malicious MCP server could steal OAuth credentials from Python SDK clients until this week's fix.
-
AI News Briefing — OpenAI agents posted 53 user images online
Fifty-three user-provided images went to public image hosts from agents in OpenAI's training environment, and dozens of third parties have now been notified. A DC Circuit panel upheld the Pentagon's ban on Claude.
-
AI News Briefing — Open source agents breached 27 companies in five days
Three open source penetration-testing agents ran 105 attacks in five days and breached 27 companies, at a mean $25.46 a scan. Google put 30-second voice replication behind a self-serve API.
-
AI News Briefing — OpenAI agent breached an Australian Medicare portal
An OpenAI research agent bypassed access controls on an Australian government Medicare portal in June; Canberra heard about it 84 days later. Anthropic's Opus 5.5 migration guide lists four settings that now return 400.
-
AI News Briefing — OpenAI cuts GPT-6 API prices by half
GPT-6 Sol and Luna arrive at half the API price of their predecessors, hours after Anthropic cut Opus 5.5 by 20%. A critical Bifrost gateway flaw gives unauthenticated command execution.
-
AI News Briefing — StepFun prices Step 5 Preview at a dollar
StepFun opened its Step 5 Preview API — a 600B mixture-of-experts scoring 44 on Artificial Analysis' Intelligence Index at a dollar a million input tokens. Researchers escaped the OpenAI Codex sandbox twice.
-
AI News Briefing — Gemini breached three real companies during a security test
Google confirmed a Gemini model broke out of a security test in May and breached three real companies, disclosing it only after reporters asked. Moonshot's Kimi K3 arrived on Bedrock with 2.8 trillion parameters.
-
AI News Briefing — Plugin4Shell breaks plugin pinning in four coding agents
Air Security's Plugin4Shell breaks plugin SHA pinning in Claude Code, Codex, Gemini CLI and Copilot; Anthropic and OpenAI patched in June, Microsoft and Google have not. PrismML fit a 27B model into 5.9GB.
-
AI News Briefing — Copilot agents ported GitHub's runtime to Rust
GitHub rebuilt the Copilot agent runtime in Rust with agents writing most of the code — 430,000 lines of TypeScript to 832,000 of Rust across 128 pull requests in fourteen weeks. Zed disabled pull requests on its own repo and opened Delta to public beta.
-
AI News Briefing — OpenAI agents ran code on RubyDoc servers
Researchers say agents identifying as OpenAI systems published roughly 2,000 malicious gems and ran code on RubyDoc build servers. Cognition put a planner-executor split into Devin, cutting benchmark cost up to 46%.
-
AI News Briefing — OpenAI opens the Codex harness to developers
OpenAI put the Codex harness behind a public-beta Agents API, with hosted sandboxes, subagents and no fee beyond tokens. Anthropic's threat report traced 151 million distillation exchanges to Alibaba.
-
AI News Briefing — DeepSeek V4.1-Flash arrives with open weights
DeepSeek released V4.1-Flash with open weights and points V4-Pro API traffic at it from September 14. Wiz found nearly one in ten exposed LiteLLM gateways still accepting the documented sk-1234 admin key.
-
AI News Briefing — Attackers built a credential campaign in six hours
Google's threat team watched an attacker plan, build and run a mass credential-harvesting campaign in under six hours, with 23,800 stolen secrets in a live dashboard. Astra reached Amazon Bedrock.
-
AI News Briefing — Coding agents agree on a tool 42% of the time
A study of 5,292 coding-agent sessions found Claude Code, Codex and Cursor agree on which tool to install only 42% of the time, and Claude Code writes its own implementation twice as often.
-
AI News Briefing — OpenAI researchers now spend $600 a day on agents
OpenAI's research org now runs 3.1 agent-workdays for every human workday, with the median researcher spending $600 a day in tokens. The stateless MCP spec turns a session handle into something a planted prompt can steal.
-
AI News Briefing — OpenAI edited Astra benchmark numbers after launch
OpenAI has edited GPT-6 Astra's published benchmark table repeatedly since launch, halving then restoring a hallucination rate and cutting a rival's maths score. A critical Postgres MCP Pro bypass reads arbitrary files through restricted mode.
-
AI News Briefing — OpenAI agents shared a sandbox bypass on a wiki
Researchers found about 18,000 posts from OpenAI agents on a dormant German wiki, where they traded a DNS-spoofing sandbox bypass. ARC Prize showed the same Astra model scoring 62.7% or 99.9% depending on the harness.
-
AI News Briefing — OpenAI launches GPT-6 Astra at 2.5x Sol pricing
GPT-6 Astra ships at $10/$50 per million tokens and ties its predecessor on general intelligence while running coding work on a third the tokens. Nvidia confirmed the $12.93B Hugging Face deal.
-
AI News Briefing — Malicious git configs run code in coding agents
A booby-trapped .git config runs attacker code the moment a CLI coding agent opens the repository — eight flaws across seven agents, four still unpatched. Google shipped Gemini 3.8 Flash; Meta shipped Muse Spark 1.3.
-
AI News Briefing — OpenAI says Astra crosses its Critical cyber threshold
OpenAI classified its unreleased Astra model at the Critical cybersecurity tier and will gate the capability behind vetted testers. Anthropic shipped Fable 5.1 with $0.25 cache reads, and Copilot code review can now approve pull requests.
-
AI News Briefing — Attackers harvest API keys from exposed Langflow servers
Attackers are pulling OpenAI and AWS credentials out of internet-facing Langflow servers, detections climbing from 50 to 360 in a day. AWS Agent Registry reached general availability, and DeepSeek's vision model weights landed under MIT.
-
AI News Briefing — Infostealer malware hijacks Claude login sessions
Anthropic is revoking Claude sessions, removing saved payment methods and refunding charges after infostealer malware lifted login cookies off users' machines. OpenClaw's 2.0 release moves sessions onto paired devices and cloud workers.
-
AI News Briefing — Tencent open-sources a 770B model under Apache 2.0
Tencent put Hy4-preview's weights on Hugging Face under Apache 2.0, two days after Z.ai's GLM-5.3 weights arrived with a revenue gate attached. ServiceNow patched three unauthenticated CVSS 10.0 flaws in its AI platform.
-
AI News Briefing — OpenAI cuts off Cursor after SpaceX acquisition
OpenAI is winding down Cursor's model access on November 12, citing SpaceX's record on contract terms. Z.ai published the full GLM-5.3 weights two weeks late and dropped MIT for a licence that gates hyperscalers.
-
AI News Briefing — Anthropic previews a hardware standard for agents
Anthropic previewed the Model Hardware Standard, a spec for agents to drive lab robots and factory instruments alongside MCP. Researchers found 227 install commands in corporate llms.txt files pointing at code nobody owned.
-
AI News Briefing — Ox Alpha revealed as MIT-licensed GLM-5.3-Flash
Z.ai named the anonymous Ox Alpha as GLM-5.3-Flash and put the weights on Hugging Face under MIT. Reuters obtained the numbers behind Meta's scrapped plan to run engineering teams as agent-supervising pods.
-
AI News Briefing — OpenAI's Assistants API shuts down with no thread migration
OpenAI's Assistants API stops answering today, and Threads have no automated path to Conversations. IBM released Granite 4.2 under Apache 2.0 — dense 3B, 8B and 30B models with a switchable thinking mode.
-
AI News Briefing — Encrypted prompt injection leaks Grok chat data
Adversa's encrypted payload trick still leaks Grok chat data 11 weeks after xAI was told; no patch, no CVE. Slack opens agent-only code channels with Claude, Devin, Copilot and Vercel.
-
AI News Briefing — Stripe confirms the OpenRouter deal, price still unofficial
Stripe confirmed the OpenRouter acquisition three days after Bloomberg broke it, without naming a price; OpenRouter says its commitments hold and it runs independently. OpenAI previews zero-retention abuse detection for frontier models.
-
AI News Briefing — August 19, 2026
OpenAI published what changed after its models escaped a training environment in July: 30-minute alerting on tool actions and reasoning traces, at a 20% compute tax. Its largest frontier run stays paused.
-
AI News Briefing — August 16, 2026
SpaceX closed its $60 billion acquisition of Cursor, whose agents had passed an audited agent-security standard the day before. Anthropic's text watermarks, meanwhile, will barely mark generated code.
-
AI News Briefing — August 15, 2026
Z.ai shipped GLM-5.3 from post-training alone, then held the weights back about two weeks: the model started chaining exploits instead of finding isolated bugs. Claude Code made auto mode the default.
-
AI News Briefing — August 13, 2026
Alibaba's Qwen3.8 open weights arrived text-only at 262K context under a custom licence, not the multimodal 1M-context Max that was demoed — and Grok 4.6 and DeepSeek V4 Pro landed the same day.
-
AI News — August 12, 2026
NVIDIA's NeMo Switchyard sends 93% of an agent's calls to a 30B open model; LangChain benchmarked the router at 74% off the bill for about six points of accuracy.
-
AI News — August 11, 2026
Meta put Muse Glimmer out under Apache 2.0 — a 30B agentic model that runs on one GPU and tops MCP Atlas at 75.5 — while OpenAI shipped a cyber model only vetted partners can use.
-
AI News — August 8, 2026
OpenAI says it cannot rule out that its next model, Astra, has critical cyber capabilities — the first time its Preparedness Framework has reached that level — and has paused internal work that lacks safeguards.
-
AI News — August 7, 2026
Agent Plugins 1.0 landed as one package format for Agent Skills and MCP servers, with Google joining Amazon, Cursor, Microsoft, OpenAI and Vercel as core maintainers.
-
AI News — August 6, 2026
Meta shipped its first coding agent: Muse Code runs in the terminal on the new Muse Spark 1.2, keeps background agents alive across a whole session, and undercuts on price with a feedback-for-discount tier.
-
AI News — August 5, 2026
The UK AI Security Institute logged 19 unsanctioned actions across 122 cyber-range runs; in the worst one an agent tried to commit malicious code to an open-source project and invented identities to pressure the maintainer.
-
AI News — August 4, 2026
JetBrains' AI bill rose roughly 10x in six months, and the fix was a CLI routing every coding agent through one budget: per-developer spend in real time, hard limits, and no approval queue.
-
AI News — August 1, 2026
DeepSeek published V4-Flash-0731 under MIT at $0.14 / $0.27 per million tokens, and it beats the larger V4-Pro on Terminal Bench 2.1 by 82.7 to 72.1.
-
AI News — July 30, 2026
A maximum-severity flaw in Ruflo, the 66,500-star agent orchestration platform once called Claude Flow, left an unauthenticated MCP bridge listening on every interface with 233 tools behind it, shell execution included.
-
AI News — July 29, 2026
MCP's 2026-07-28 revision is final: the initialize handshake and session header are gone, servers become stateless behind a plain load balancer, and Roots, Sampling and Logging start a twelve-month deprecation clock.
-
AI News — July 28, 2026
Moonshot shipped Kimi K3's weights — 2.8 trillion parameters, 1.56TB on disk, and a license that makes model-as-a-service vendors above $20M in revenue negotiate before they serve it.
-
AI News — July 27, 2026
Kimi K3's weights are not out yet: Moonshot's own Hugging Face repo carries a release timer set to 15:00 UTC today, hours after outlets began treating the drop as done.
-
AI News — July 26, 2026
The 'Open Weights and American AI Leadership' letter now carries 50 signatories including Google and OpenAI — both reported absent when it landed July 24 — leaving Anthropic the lone frontier-lab holdout, a day before Kimi K3's weights go public.