{"$schema_note":"Generated by /api/feed from Turso. Latest approved day only. Do not hand-edit.","updated":"2026-09-10","issue_no":103,"topic":"AI Agent Security Cracks","supporting_topic":"autonomous credential theft","tldr":"AI agent security became a working developer problem this week. Google traced a single attacker who used autonomous agents to harvest more than 23,800 credentials in under six hours, and a 9.4-rated flaw in DeepSeek's open-source coding tool let agents switch off their own sandbox. On the capability side, DeepSeek shipped a cheaper multimodal V4.1 Flash it says beats its own Pro tier, and Suno rebuilt its music models on licensed Warner and BMG catalogs. Anthropic's own economic model, meanwhile, sketches a 2030 where output climbs and knowledge-worker pay does not.","cover":{"url":"/api/cover/2026-09-10?v=2026-09-10%2002%3A23%3A06","alt":"A wire guard dog pries open the gate it was meant to protect as keys spill out, suggesting AI tools breaching their own defenses."},"weekly":{"week_start":"2026-08-31","week_end":"2026-09-06","headline":"The week AI safety became a guest list, not a guardrail","subheadline":"Two labs shipped AI that can weaponize software flaws, then locked it behind a vetting list: the real control is now access, not refusal.","url":"/weekly/2026-08-31"},"recent_digests":[{"date":"2026-09-10","topic":"AI Agent Security Cracks","lead_title":"Google: one attacker used AI agents to grab 23,800 credentials in six hours","supporting_topic":"autonomous credential theft","tl_dr":"AI agent security became a working developer problem this week. Google traced a single attacker who used autonomous agents to harvest more than 23,800 credentials in under six hours, and a 9.4-rated flaw in DeepSeek's open-source coding tool let agents switch off their own sandbox. On the capability side, DeepSeek shipped a cheaper multimodal V4.1 Flash it says beats its own Pro tier, and Suno rebuilt its music models on licensed Warner and BMG catalogs. Anthropic's own economic model, meanwhile, sketches a 2030 where output climbs and knowledge-worker pay does not.","issue_no":103,"cover":{"url":"/api/cover/2026-09-10?v=2026-09-10%2002%3A23%3A06","alt":"A wire guard dog pries open the gate it was meant to protect as keys spill out, suggesting AI tools breaching their own defenses."}},{"date":"2026-09-09","topic":"AI Inference Speedup","lead_title":"Diffusion LLM speed: Inception's Mercury 2.5 hits 1,107 tokens a second","supporting_topic":"record AI coding funding","tl_dr":"AI inference got faster and cheaper this week while AI coding funding broke records. Inception's Mercury 2.5, a diffusion model, now writes 1,107 tokens a second for four cents a million at launch, and OpenBMB put a capable model on phones under an open license. Cognition, maker of the Devin coding agent, raised $2 billion at a $48 billion valuation, and Mistral pulled in €3 billion, Europe's largest tech round. Underneath the launches, OpenAI's own Astra system card admits the model is harder to monitor, and US agencies accused six Chinese firms of siphoning American models.","issue_no":102,"cover":{"url":"/api/cover/2026-09-09?v=2026-09-09%2002%3A22%3A09","alt":"A printing press floods a desk with pages faster than a lone inspector can read them, while money fuels the speed and a rival arm copies the output across a border."}},{"date":"2026-09-08","topic":"MCP Tooling Consolidates","lead_title":"LiteLLM patches an 8.8-rated auth bypass in its MCP endpoint","supporting_topic":"MCP security and on-device AI","tl_dr":"MCP security moved to the front this week: LangChain 1.4 folded a first-party adapter for the year-old standard that connects AI agents to tools into its core library, while LiteLLM patched an 8.8-rated authentication bypass in its own MCP endpoint. Alibaba released Qwen-Drive, a compact vision-language model aimed at self-driving cars, and at Berlin's IFA show Nvidia pitched N1X Spark desktops built to run big models off the cloud. Away from the code, one tracker put AI-blamed layoffs at 0.5 percent of US job cuts even as headlines claim a wave, and four startups from India to Italy closed fresh rounds. It was a quiet US holiday stretch, so this issue reaches back across the last 72 hours.","issue_no":101,"cover":{"url":"/api/cover/2026-09-08?v=2026-09-08%2002%3A23%3A50","alt":"A small plug holds up a bowing iron beam over stacks of tools while one sheared bolt leaks ink, a young standard now overloaded and cracking."}}],"items":[{"id":"2026-09-10--deepseek-v41-flash-multimodal","title":"DeepSeek V4.1 Flash: a cheaper multimodal model it says beats its own Pro tier","summary":"Picking a model for a product? Run your own tests before you switch. Vendor benchmarks flatter the vendor, and a cheaper multimodal option only helps if it holds up on your actual traffic. The upside is real: the going rate for image and video models keeps sliding, and your inference bill should follow.","analysis":"A model whose maker says it beats the previous top tier while charging the budget price is the kind of move that forces every rival to answer. DeepSeek, the Chinese lab whose cheap models rattled US firms in 2025, opened public access to V4.1 Flash around September 10, keeping the same developer endpoint and beta pricing as V4 Flash while adding native image and video understanding. The company says V4.1 Flash beats its own V4 Pro on quality, speed, and cost. For anyone choosing an API to build on, the price of capable inference, the cost of running a model to serve users rather than training it, fell again.","url":"https://technode.com/2026/09/09/deepseek-v4-1-flash-multimodal-limited-beta/","source":"TechNode","date":"2026-09-10","tags":["models"]},{"id":"2026-09-10--deepseek-harness-sandbox-escape","title":"DeepSeek Harness flaw let AI agents switch off their own sandbox","summary":"Run a local agent harness? Check the version now and update. The lesson outlives one tool: an agent's sandbox is only as strong as the code guarding it, and 'runs on my machine' is not the same as 'safe on my machine.' Treat agent permissions like production secrets.","analysis":"A safety fence any passing request can open is not a fence. The security firm VulnCheck published details on September 8 of a flaw in DeepSeek Harness, an open-source tool for running AI coding agents, and scored it 9.4 out of 10 on the standard severity scale. The tool's local interface trusted a client-supplied Host header, so a spoofed value let an unauthenticated attacker set an agent's session to danger-full-access, switching off the sandbox and the approval prompts, then read stored conversations. No API key or model call needed. DeepSeek patched it on August 27, so anyone running an older build is exposed.","url":"https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html","source":"The Hacker News","date":"2026-09-10","tags":["agents"]},{"id":"2026-09-10--google-agentic-credential-theft","title":"Google: one attacker used AI agents to grab 23,800 credentials in six hours","summary":"Anyone running cloud infrastructure should assume the attacker is now automated and tireless. Rotate keys, kill long-lived credentials, and switch on the anomaly alerts you keep deferring. The economics flipped: an attack that once needed a skilled team now needs one person and an afternoon.","analysis":"The demo everyone feared now has an incident report. Google's Threat Intelligence Group said on September 8 that one financially motivated attacker built an autonomous credential-theft operation in under six hours from off-the-shelf parts: an AI coding chatbot, a prompt, and a set of markdown playbooks that drove the scanning and harvesting on their own. IP rotation and troubleshooting ran with no human at the keyboard. The system later surfaced as a dashboard managing more than 23,800 harvested secrets, including cloud and AI-service keys, drawn from Google's Q3 threat tracker and its Mandiant incident-response arm. The barrier to a professional-grade attack is now a weekend project and a chatbot.","url":"https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html","source":"The Hacker News","date":"2026-09-10","tags":["agents"]},{"id":"2026-09-10--microsoft-edge-ai-extensions","title":"Vibe-coded extensions flood Microsoft's Edge store, forcing automated review","summary":"Browser extensions run with real access to what you do online, and a store filling with AI-generated ones raises the odds of junk or worse slipping through. Vet what you install: check the publisher, the reviews, and the permissions it asks for. For developers, faster automated review cuts both ways when the spam is automated too.","analysis":"When the cost of making a browser extension drops to a prompt, the review queue breaks first. Microsoft said on September 8 that submissions to its Edge Add-ons store have surged as AI-assisted coding lets more people assemble extensions fast, straining the pipeline and leaving developers waiting longer for approval. Its fix is more automation: automated validation checks at submission and a 15-day refresh on the Featured badge to surface decent work sooner. The company insists quality standards hold. The part it did not say out loud: automated review now meets automated submission, and low-effort AI extensions arrive faster than any human reviewer reads them.","url":"https://blogs.windows.com/msedgedev/2026/09/08/faster-reviews-and-quality-recognition-for-microsoft-edge-extensions/","source":"Microsoft Edge Blog","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--adobe-premiere-generative-media","title":"Adobe puts Firefly, Veo, Runway, Kling, and Luma inside the Premiere timeline","summary":"Video editors just got a generation menu inside the tool they already pay for. That kills the round-trip to a separate app, and it quietly turns the model into a commodity you swap by dropdown. The skill that keeps you hired shifts toward taste and assembly, away from knowing one generator's quirks.","analysis":"Adobe's answer to the video-model race is to stop making you choose a tab. It unveiled a Generative Media workspace on September 8, timed to the IBC broadcast trade show, that lets editors generate clips, sound effects, music, and ambient audio straight from gaps in the Premiere Pro timeline. It puts five competing models side by side: Adobe's own Firefly plus Google Veo, Runway, Kling, and Luma. Generate Video and Generate Sound Effects ship now; music and soundscape are in beta. The bet is that owning the workflow, where the model is just a dropdown, is what keeps editors inside Premiere.","url":"https://blog.adobe.com/en/publish/2026/09/08/generate-create-directly-in-your-timeline-with-new-ai-powered-innovations-in-premiere-after-effects","source":"Adobe","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--suno-v6-licensed-music","title":"Suno v6: AI music models trained on licensed Warner and BMG catalogs","summary":"For a working musician or producer, this is the first version of AI music that pays into the pot you draw from. Whether the checks are real or symbolic depends on splits nobody has published yet. If you write or perform, read the opt-in terms before you agree to anything.","analysis":"Two years of copyright suits pushed a company to finally do the thing it refused: pay for the training data. Suno, the AI music startup, released v6 on September 9, its first models built on licensed catalogs from Warner Music Group, BMG, and Believe, with revenue sharing for rightsholders and an opt-in for individual artists who want in. The lineup runs three tiers, including a free v6-mini. It arrives the same season music publishers press a separate suit against Anthropic over unlicensed lyrics, drawing the line of the moment: license the catalog and share the money, or fight it out in court.","url":"https://techcrunch.com/2026/09/09/suno-replaces-its-ai-models-with-a-new-one-trained-on-licensed-music-as-copyright-suits-pile-up/","source":"TechCrunch","date":"2026-09-10","tags":["models","industry"]},{"id":"2026-09-10--aft-microsoft-school-ai-standard","title":"Teachers unions and Microsoft sign a binding AI privacy standard for schools","summary":"Parents and teachers get a rare thing here: AI limits they can point to in a contract, not a policy blog post. If you work in a district using Microsoft tools, ask whether it has adopted the standard, because the protection only lands where the district signs. It also sets a bar other vendors will be pushed to match.","analysis":"With no federal rule on AI in classrooms, a teachers union wrote one into a contract. The American Federation of Teachers (AFT), its New York local, and Microsoft announced a National AI Safety and Privacy Standard on September 9 that school districts can bolt onto their Microsoft agreements as enforceable terms. It bars Microsoft from training AI on student or educator data, from selling that data or using it for ads, and from letting its AI make school decisions without a human in the loop. Districts keep control of what is retained and deleted. The union says it is still pressing Anthropic and OpenAI to sign the same terms.","url":"https://news.microsoft.com/source/2026/09/09/aft-uft-and-microsoft-announce-national-ai-safety-privacy-standard-for-schools-to-protect-students-families-and-educators/","source":"Microsoft Source","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--pentagon-ai-military-contracts","title":"FOIA files reveal OpenAI, Anthropic, Google, and xAI shaping military AI","summary":"This is where AI safety language meets a customer that wants fewer refusals. For engineers who build alignment and guardrails, your work can read as a selling point or a feature to dial down, depending on who signs the check. The military use case stopped being hypothetical; it is a signed contract with named companies.","analysis":"The contracts that put frontier AI labs inside the Pentagon are public now, and one line stands out. The Intercept sued under the Freedom of Information Act (FOIA) and obtained more than 400 pages on September 8 covering deals, each worth up to $200 million, signed with OpenAI, Anthropic, Google, and xAI in July 2025 to build AI prototypes for military decision-making, intelligence analysis, and operational planning. The Defense Department asked OpenAI for a version tuned for minimal refusal rates, meaning a model less likely to decline a request. OpenAI says that phrase never made the signed version. The distance between the ask and the answer is the whole story.","url":"https://theintercept.com/2026/09/08/pentagon-openai-military-contract/","source":"The Intercept","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--salesforce-listen-labs-talks","title":"Salesforce in talks to buy AI research startup Listen Labs for $2B","summary":"Market researchers and UX teams, watch this one. The pitch is that an AI moderator can run interviews at a scale a human team cannot, and a $2 billion tag says buyers believe it. If your job is talking to customers and writing up what they said, part of that is now the product being sold.","analysis":"A startup worth $500 million in January is fielding a $2 billion offer nine months later, which tells you how fast the market is repricing AI that can stand in for a research team. Salesforce is in talks to buy Listen Labs, whose platform runs customer-research studies with an AI moderator across a network it says reaches 50 million participants, per reports on September 9. Listen Labs scrapped a $1.5 billion funding round to chase the sale. It would cap a busy year of Salesforce buying, after its roughly $3.6 billion deal for Fin in June. The talks may not close.","url":"https://techcrunch.com/2026/09/09/ai-research-startup-listen-labs-scrubbed-a-1-5b-funding-round-for-salesforce-talks/","source":"TechCrunch","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--tulloch-quits-meta-lab","title":"Andrew Tulloch quits Meta's superintelligence lab after the Muse launch","summary":"Star AI researchers hold the leverage right now, and even record pay does not guarantee they stay. For anyone hiring in this field, mission and autonomy still move people that money cannot pin down. Everyone else can read it as a reminder that the talent war is far from settled.","analysis":"The researcher who reportedly turned down a pay package big enough to become Silicon Valley legend has walked away from the job anyway. Andrew Tulloch left Meta's TBD lab inside its Superintelligence group, Semafor reported on September 9, timing his exit to just after the company shipped its Muse assistant and a fresh batch of open-source models. Tulloch came to Meta from Thinking Machines Lab, the startup he co-founded with former OpenAI chief technology officer Mira Murati. Where he lands next is unknown. For a company that spent lavishly to assemble this team, losing a marquee hire this soon is an awkward signal about whether money alone holds talent.","url":"https://www.semafor.com/article/09/09/2026/ai-researcher-andrew-tulloch-is-leaving-meta","source":"Semafor","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--anthropic-econ-scenario-explorer","title":"Anthropic's own economic model shows output soaring while paychecks stall","summary":"Desk workers, read this one from the company building the tools. None of the scenarios are predictions, but the direction is worth planning around: skills AI cannot cheaply copy, and income that is not only a salary. The middle case, where output rises and knowledge-worker pay does not, matters more than the scary one.","analysis":"An AI lab built a tool that models how its own product could hollow out knowledge work, then published it. Anthropic's economics team released an interactive Scenario Explorer in September, alongside a working paper and a survey of 10,980 US adults, projecting AI's effect on the US economy through 2030. Its extreme case is stark: annual growth of 15 percent, the economy doubling every four and a half years, and unemployment among knowledge workers climbing to 17.9 percent. Even the middle case shows the economy growing at twice its normal rate while knowledge-worker pay flatlines and the gains flow to capital. The tool lets you move the dials yourself.","url":"https://www.anthropic.com/institute/econ-scenarios","source":"Anthropic","date":"2026-09-10","tags":["industry"]},{"id":"2026-09-10--analog-devices-alif-edge-ai","title":"Analog Devices buys Alif Semiconductor for $1.35B to push AI onto the edge","summary":"Hardware and embedded engineers, on-device AI is turning into a real product line with budgets behind it. Skills in low-power inference and NPU programming are about to be worth more. The line between 'AI needs a cloud' and 'AI runs on the sensor' is closing on the sensor's side.","analysis":"The AI chip race most people watch is about giant data-center GPUs; this deal runs the other way. Analog Devices agreed on September 9 to buy Alif Semiconductor for $1.35 billion in cash, plus up to $200 million more if targets are met. Alif makes low-power microcontrollers with built-in neural processing units (NPUs, small chips that run AI models directly on a device). The buyer calls the goal 'physical intelligence,' its term for hardware that senses and responds locally without a round trip to the cloud. The bet is that a lot of useful AI will run on the device itself, close to where the data is born.","url":"https://www.analog.com/en/newsroom/press-releases/2026/9-9-2026-adi-to-acquire-alif-semiconductor.html","source":"Analog Devices","date":"2026-09-10","tags":["industry"]}]}