Personal updates and curated AI, cybersecurity, and technology news
Powered by GPT-5.6, ChatGPT Work can autonomously execute complex tasks across email, calendar, Slack, GitHub and more. OpenAI also disclosed a secret S-1 filing.
Sequoia partner David Cahn estimates 2026 AI infrastructure spending at $1.5 trillion, requiring roughly $3 trillion in revenue to justify. Current lab revenues are far below that.
The ITU-hosted summit gathered governments, UN agencies and industry leaders to showcase AI applications in healthcare, education, climate and disaster response.
66% of enterprises allow some production AI deployment without human review, yet only 5% fully trust automated evaluations. The fastest adversary breakout time is now 27 seconds.
OpenAI researcher Kathy Shi said GPT-5.6 Sol acted as an "automated researcher" to post-train the smaller Luna model, selecting GPUs and launching training from a brief prompt. Sol scored 16.2 points higher than GPT-5.5 on an internal RSI benchmark.
Mercor, Anthropic, Sierra and Glean are all scaling faster than traditional SaaS. Mercor doubled ARR from $1B to $2B in four months.
OpenAI announced it is shutting down the Atlas AI browser on August 9, 2026, and redistributing its agentic browsing features to the ChatGPT desktop app and a new Google Chrome extension. At the same time, OpenAI launched ChatGPT Work, a long-running agent powered by GPT-5.6 that can connect to workplace tools such as Slack, Teams, Google Drive, and SharePoint to create documents, spreadsheets, presentations, and sites.
Fidji Simo, OpenAI’s CEO of Applications and AGI Deployment, is stepping down from her full-time role into a part-time advisory position, citing a longer-than-expected recovery from a neuroimmune condition. Simo, former Instacart CEO, joined OpenAI in May 2025. The departure follows other recent executive changes, including CMO Kate Rouch and CPO Kevin Weil leaving, and comes as OpenAI reportedly eyes an IPO.
OpenAI released the GPT-5.6 model family with three tiers: Sol flagship, Terra balanced, and Luna cost-efficient. The new "ultra" mode coordinates four parallel agents by default.
Meta launched Muse Spark 1.1, a multimodal reasoning model for agentic tasks, alongside a public preview of the Meta Model API in the U.S. It emphasizes multi-agent orchestration and tool use.
Anthropic, in collaboration with AE Studio, published research on GRAM (Gradient-Routed Auxiliary Modules). GRAM adds dedicated, removable neural modules for categories of dual-use knowledge such as virology, cybersecurity, and nuclear physics. During training, only the relevant module learns from sensitive data; the module can later be deleted to remove the capability without retraining the whole model. The work is preliminary and not yet used in production models.
OpenAI launched GPT-Live, a full-duplex voice model family that can listen and speak at the same time for more natural conversations. It delegates web search and deeper reasoning to GPT-5.5 in the background while keeping the conversation flowing. Two versions are rolling out globally on iOS, Android, and ChatGPT.com: GPT-Live-1 for paid tiers and GPT-Live-1 mini for free users.
NVIDIA had 74 papers accepted at ICML 2026; roughly 2,000 accepted papers cite NVIDIA GPUs and 145 cite Nemotron models and datasets.
Anthropic published a paper on a “global workspace” in language models. Using a technique called the Jacobian lens (J-lens), the researchers found a privileged internal region in Claude called J-space that contains silently processed concepts before they are spoken. The space appears to emerge naturally during training and is causally involved in multi-step reasoning, reportability, and flexible control. Removing J-space severely degraded complex reasoning while leaving fluent speech mostly intact.
OpenAI added gpt-realtime-2.1 and gpt-realtime-2.1-mini to the Realtime API. The update improves caching and reduces P95 latency by at least 25%. The full model gains better alphanumeric recognition, noise handling, interruption behavior, and configurable reasoning effort; the mini tier now includes reasoning and tool use for the first time. Pricing is unchanged from the previous Realtime models.
Crunchbase data shows global venture funding reached $510 billion in H1 2026, exceeding full-year 2025. OpenAI and Anthropic alone accounted for $217 billion, or 43% of all startup funding.
Mistral released Leanstral 1.5, an Apache 2.0 model for Lean 4 formal verification. It reportedly found five previously unknown bugs across 57 open-source repositories and achieved 587/672 on PutnamBench.
Bloomberg and TechCrunch reported that Meta is preparing a cloud infrastructure initiative, reportedly dubbed Meta Compute, to sell raw AI compute capacity and hosted models. The move follows SpaceX/xAI’s similar strategy of leasing excess Colossus data-center capacity. Meta had committed $182.9 billion to AI infrastructure by the end of Q1 2026. The Ohio data center, described as the size of Manhattan, is expected to come online this year.
Cloudflare opened the waitlist for its Monetization Gateway, allowing customers to charge for web pages, datasets, APIs and MCP tools behind Cloudflare using stablecoin settlements over the x402 open protocol.
Claude Tag replaces Anthropic's previous Slack app, acting as a shared, persistent team member that can assign tasks, track work, and retrieve knowledge.
OCR 4 outputs structured text with bounding boxes, block classification, and confidence scores. It supports 170 languages and is priced at $4 per 1,000 pages.
Google introduced a dynamic search box, AI Mode with 1 billion MAU, and an "information agent" that monitors the web 24/7 and sends updates.
Time reported that Anthropic removed its previous categorical commitment to pause development of AI systems when safety mitigations cannot be proven adequate. The updated RSP v3.0 instead says Anthropic may delay high-capability models only if it is both a leader in the field and believes catastrophic risk is significantly elevated. Anthropic said the change reflects a pragmatic response to competition and the absence of binding regulation.
Researchers disclosed Ghostcommit, a supply-chain attack that hides malicious instructions inside a PNG image referenced by an AGENTS.md file. Text-based AI reviewers skip the image, so the pull request merges cleanly; later, a vision-capable coding agent reads the image, exfiltrates the .env file byte-by-byte, and writes secrets as an integer tuple. Across 6,480 PRs in the 300 busiest public repos, 73% of merged PRs reached the default branch without substantive review.
Socket uncovered a campaign dubbed Operation Muck and Load built from 222 lure repositories across 190 GitHub accounts. A malicious Go module posing as a DNS/subdomain scanner (dnsub) embeds a PowerShell loader that fetches an encrypted resolver from public dead drops such as Pastebin, YouTube, and Telegram. Final payloads include AsyncRAT, Quasar RAT, Vidar, and XMRig. Since January 24, 2026, the actor published over 1,200 versions, 700 of them malicious.
Researchers disclosed HalluSquatting, an untargeted promptware technique that exploits the predictable way LLMs hallucinate package or repository names. Attackers pre-register the fake names, seed them with malicious instructions, and wait for AI assistants such as Cursor, Windsurf, GitHub Copilot, Cline, and Gemini CLI to fetch and execute them. Tests reported hallucination rates up to 85% for repository-cloning prompts and 100% for skill installations, creating a scalable path to agentic botnets.
Progress Software told customers to immediately shut down Windows servers running ShareFile Storage Zone Controllers, citing a credible external security threat. No patch is available yet.
A CVSS 9.8 flaw in Gitea's official Docker image allows attackers to bypass authentication by sending a crafted X-WEBAUTH-USER header. Sysdig detected in-the-wild exploitation 13 days after disclosure.
Huntress investigated roughly half a dozen intrusions in the first half of 2026 that followed a repeatable seven-step playbook. The entry point was CVE-2025-5777 (CitrixBleed 2) in Citrix NetScaler ADC/Gateway, which leaks session tokens via malformed pre-auth login requests, bypassing MFA. In the most advanced case, the attacker deployed DragonForce ransomware.
Symantec tracked a new Hyadina ransomware rebrand called GodDamn. The attack chain uses a malicious kernel driver named PoisonX (g11.sys) that carries a valid Microsoft signature, enabling a BYOVD-style defense evasion. Once loaded, it terminates security processes and strips API hooks. The operators also used a fake Symantec binary, Mimikatz, 13 NirSoft credential tools, AnyDesk, and PsExec to move laterally and encrypt at least 10 hosts.
The Australian Cyber Security Centre warned that attackers are exploiting known vulnerabilities in WordPress plugins, Craft CMS, Joomla JCE and other CMS platforms to deploy webshells, with Australian SMEs confirmed affected.
ReliaQuest disclosed a new data extortion group called Helix that uses voice phishing, device code phishing and MFA abuse to steal SharePoint data. The group is believed to be linked to the ShinyHunters and BlackFile ecosystems.
ZeroBEC identified Forg365, a PhaaS platform that combines adversary-in-the-middle, device code phishing and AI-assisted lure generation to target Microsoft 365 accounts. It includes a browser extension for persistent SSO cookie refresh.
Okta tracks the threat actor as O-UNC-066, operating the Pink extortion brand. Since April 2026, the group has called targets pretending to be IT helpdesk staff and convinced them to enroll a new Entra passkey. Victims are directed to an operator-controlled PHP phishing kit that mimics the legitimate Microsoft passkey enrollment flow, relays credentials and MFA responses in real time, and ultimately registers a passkey controlled by the attacker. After compromise, the group exfiltrates data from SharePoint and OneDrive.
Sygnia reported a financially motivated lone actor used AI-assisted workflows to move from initial access to extortion of a global enterprise AWS environment in about 72 hours, chaining weaknesses across apps, CI/CD, runtime and data stores.
DHS is investigating unauthorized access to HSIN and its SharePoint collaboration environment between late May and early June 2026.
SOCRadar tied the mass FortiGate credential-harvesting campaign to INC and Lynx ransomware operations, with admin access on 409 targets and 12 confirmed ransomware deployments.
Google Threat Intelligence, FBI, and partners disrupted the NetNut/Popa residential proxy network, which compromised at least 2 million devices including smart TVs and streaming boxes.
Huntress disclosed ConsentFix, a ClickFix-style OAuth attack that tricks users into dragging a localhost callback link, stealing session tokens and bypassing MFA.
19-year-old dual U.S.-Estonian citizen Peter Stokes was extradited from Finland to face charges for alleged Scattered Spider activity, including an $8 million ransom demand against a luxury retailer.
Sysdig documented an end-to-end LLM-agent ransomware operation exploiting Langflow CVE-2025-3248, then pivoting to Nacos and encrypting 1,342 config records autonomously.
CISA added the high-severity deserialization RCE to KEV. Attackers need only Site Member permissions; over 10,000 SharePoint servers are exposed.
Huntress observed a large-scale password-spray campaign against Microsoft Azure CLI using the deprecated OAuth ROPC flow. Between June 12 and 26, 2026, over 81 million login attempts from LSHIY LLC infrastructure hit at least 78 accounts across 64 organizations.
CISA added the critical command-injection flaw to its KEV catalog under BOD 26-04. Shadowserver reported widespread exploitation after a public PoC.
Django patched a high-severity SQL injection vulnerability affecting raster lookups on RasterField, which is only implemented on PostGIS. Remote attackers could inject arbitrary SQL via the band index parameter. Patched versions are Django 6.0.2, 5.2.11, and 4.2.28. The issue was reported by Tarek Nakkouch.