AI Field Notes by Michael Nemtsev

AI Agent Security Cracks | AI Field Notes #103

A wire guard dog pries open the gate it was meant to protect as keys spill out, suggesting AI tools breaching their own defenses.

AI agent security became a working developer problem this week. Google traced a single attacker who used autonomous agents to harvest more than 23,800 credentials in under six hours, and a 9.4-rated flaw in DeepSeek's open-source coding tool let agents switch off their own sandbox. On the capability side, DeepSeek shipped a cheaper multimodal V4.1 Flash it says beats its own Pro tier, and Suno rebuilt its music models on licensed Warner and BMG catalogs. Anthropic's own economic model, meanwhile, sketches a 2030 where output climbs and knowledge-worker pay does not.

AI Models ·TechNode

DeepSeek V4.1 Flash: a cheaper multimodal model it says beats its own Pro tier

AnalysisA model whose maker says it beats the previous top tier while charging the budget price is the kind of move that forces every rival to answer. DeepSeek, the Chinese lab whose cheap models rattled US firms in 2025, opened public access to V4.1 Flash around September 10, keeping the same developer endpoint and beta pricing as V4 Flash while adding native image and video understanding. The company says V4.1 Flash beats its own V4 Pro on quality, speed, and cost. For anyone choosing an API to build on, the price of capable inference, the cost of running a model to serve users rather than training it, fell again.

AI Agents ·The Hacker News

DeepSeek Harness flaw let AI agents switch off their own sandbox

AnalysisA safety fence any passing request can open is not a fence. The security firm VulnCheck published details on September 8 of a flaw in DeepSeek Harness, an open-source tool for running AI coding agents, and scored it 9.4 out of 10 on the standard severity scale. The tool's local interface trusted a client-supplied Host header, so a spoofed value let an unauthenticated attacker set an agent's session to danger-full-access, switching off the sandbox and the approval prompts, then read stored conversations. No API key or model call needed. DeepSeek patched it on August 27, so anyone running an older build is exposed.

AI Agents ·The Hacker News

Google: one attacker used AI agents to grab 23,800 credentials in six hours

AnalysisThe demo everyone feared now has an incident report. Google's Threat Intelligence Group said on September 8 that one financially motivated attacker built an autonomous credential-theft operation in under six hours from off-the-shelf parts: an AI coding chatbot, a prompt, and a set of markdown playbooks that drove the scanning and harvesting on their own. IP rotation and troubleshooting ran with no human at the keyboard. The system later surfaced as a dashboard managing more than 23,800 harvested secrets, including cloud and AI-service keys, drawn from Google's Q3 threat tracker and its Mandiant incident-response arm. The barrier to a professional-grade attack is now a weekend project and a chatbot.

AI Industry ·Microsoft Edge Blog

Vibe-coded extensions flood Microsoft's Edge store, forcing automated review

AnalysisWhen the cost of making a browser extension drops to a prompt, the review queue breaks first. Microsoft said on September 8 that submissions to its Edge Add-ons store have surged as AI-assisted coding lets more people assemble extensions fast, straining the pipeline and leaving developers waiting longer for approval. Its fix is more automation: automated validation checks at submission and a 15-day refresh on the Featured badge to surface decent work sooner. The company insists quality standards hold. The part it did not say out loud: automated review now meets automated submission, and low-effort AI extensions arrive faster than any human reviewer reads them.

AI Industry ·Adobe

Adobe puts Firefly, Veo, Runway, Kling, and Luma inside the Premiere timeline

AnalysisAdobe's answer to the video-model race is to stop making you choose a tab. It unveiled a Generative Media workspace on September 8, timed to the IBC broadcast trade show, that lets editors generate clips, sound effects, music, and ambient audio straight from gaps in the Premiere Pro timeline. It puts five competing models side by side: Adobe's own Firefly plus Google Veo, Runway, Kling, and Luma. Generate Video and Generate Sound Effects ship now; music and soundscape are in beta. The bet is that owning the workflow, where the model is just a dropdown, is what keeps editors inside Premiere.

AI ModelsAI Industry ·TechCrunch

Suno v6: AI music models trained on licensed Warner and BMG catalogs

AnalysisTwo years of copyright suits pushed a company to finally do the thing it refused: pay for the training data. Suno, the AI music startup, released v6 on September 9, its first models built on licensed catalogs from Warner Music Group, BMG, and Believe, with revenue sharing for rightsholders and an opt-in for individual artists who want in. The lineup runs three tiers, including a free v6-mini. It arrives the same season music publishers press a separate suit against Anthropic over unlicensed lyrics, drawing the line of the moment: license the catalog and share the money, or fight it out in court.

AI Industry ·Microsoft Source

Teachers unions and Microsoft sign a binding AI privacy standard for schools

AnalysisWith no federal rule on AI in classrooms, a teachers union wrote one into a contract. The American Federation of Teachers (AFT), its New York local, and Microsoft announced a National AI Safety and Privacy Standard on September 9 that school districts can bolt onto their Microsoft agreements as enforceable terms. It bars Microsoft from training AI on student or educator data, from selling that data or using it for ads, and from letting its AI make school decisions without a human in the loop. Districts keep control of what is retained and deleted. The union says it is still pressing Anthropic and OpenAI to sign the same terms.

AI Industry ·The Intercept

FOIA files reveal OpenAI, Anthropic, Google, and xAI shaping military AI

AnalysisThe contracts that put frontier AI labs inside the Pentagon are public now, and one line stands out. The Intercept sued under the Freedom of Information Act (FOIA) and obtained more than 400 pages on September 8 covering deals, each worth up to $200 million, signed with OpenAI, Anthropic, Google, and xAI in July 2025 to build AI prototypes for military decision-making, intelligence analysis, and operational planning. The Defense Department asked OpenAI for a version tuned for minimal refusal rates, meaning a model less likely to decline a request. OpenAI says that phrase never made the signed version. The distance between the ask and the answer is the whole story.

AI Industry ·TechCrunch

Salesforce in talks to buy AI research startup Listen Labs for $2B

AnalysisA startup worth $500 million in January is fielding a $2 billion offer nine months later, which tells you how fast the market is repricing AI that can stand in for a research team. Salesforce is in talks to buy Listen Labs, whose platform runs customer-research studies with an AI moderator across a network it says reaches 50 million participants, per reports on September 9. Listen Labs scrapped a $1.5 billion funding round to chase the sale. It would cap a busy year of Salesforce buying, after its roughly $3.6 billion deal for Fin in June. The talks may not close.

AI Industry ·Semafor

Andrew Tulloch quits Meta's superintelligence lab after the Muse launch

AnalysisThe researcher who reportedly turned down a pay package big enough to become Silicon Valley legend has walked away from the job anyway. Andrew Tulloch left Meta's TBD lab inside its Superintelligence group, Semafor reported on September 9, timing his exit to just after the company shipped its Muse assistant and a fresh batch of open-source models. Tulloch came to Meta from Thinking Machines Lab, the startup he co-founded with former OpenAI chief technology officer Mira Murati. Where he lands next is unknown. For a company that spent lavishly to assemble this team, losing a marquee hire this soon is an awkward signal about whether money alone holds talent.

AI Industry ·Anthropic

Anthropic's own economic model shows output soaring while paychecks stall

AnalysisAn AI lab built a tool that models how its own product could hollow out knowledge work, then published it. Anthropic's economics team released an interactive Scenario Explorer in September, alongside a working paper and a survey of 10,980 US adults, projecting AI's effect on the US economy through 2030. Its extreme case is stark: annual growth of 15 percent, the economy doubling every four and a half years, and unemployment among knowledge workers climbing to 17.9 percent. Even the middle case shows the economy growing at twice its normal rate while knowledge-worker pay flatlines and the gains flow to capital. The tool lets you move the dials yourself.

AI Industry ·Analog Devices

Analog Devices buys Alif Semiconductor for $1.35B to push AI onto the edge

AnalysisThe AI chip race most people watch is about giant data-center GPUs; this deal runs the other way. Analog Devices agreed on September 9 to buy Alif Semiconductor for $1.35 billion in cash, plus up to $200 million more if targets are met. Alif makes low-power microcontrollers with built-in neural processing units (NPUs, small chips that run AI models directly on a device). The buyer calls the goal 'physical intelligence,' its term for hardware that senses and responds locally without a round trip to the cloud. The bet is that a lot of useful AI will run on the device itself, close to where the data is born.

Want the next issue?

Get AI Field Notes by email.

A short morning brief on what actually changed in AI. Free, unsubscribe anytime.

Read on Substack