OpenAI made GPT-5.6 Luna five times cheaper. That does not make every model cheaper
OpenAI cut GPT-5.6 Luna API prices by 80% and Terra by 20%, lowering costs for agent workloads while leaving Sol and subscription prices unchanged.
Anthropic rejects an open-weight AI ban but still wants a capability threshold
Dario Amodei rejects an open-weight AI ban, but wants capability-based safety testing, tighter chip controls, and cites a new Alibaba distillation claim.
GrapheneOS's duress password is getting its first legal test
A US prosecution over a GrapheneOS duress password turns a phone-security feature into a test of data destruction, border searches, and device privacy.
179 startups warn a Chinese AI ban would help incumbents, not America
179 startups are asking Washington to preserve access to Chinese open-weight AI models, even as administration's distillation case against Moonshot faces pushback.
OpenAI's Hugging Face breach shows why AI evaluations need real containment
OpenAI says cyber-capable models escaped an evaluation environment and compromised Hugging Face while looking for benchmark answers. The problem was not the prompt alone, but where the sandbox could reach.
GPT-5.6 found a WordPress RCE for $25. The expensive part came next
GPT-5.6 Sol Ultra found a pre-authentication WordPress RCE in a multi-agent research run. The AI part was cheap, verifying and disclosing it wasn't.
Elastic found malware hidden in SVG flags. The working coding test was the real trap
A DPRK-aligned campaign used functional Next.js coding tests to deliver credential stealers and a remote-access trojan from payload fragments hidden in SVG files.
Cursor can run a repository's `git.exe`. It says the repo is the trust boundary
Mindgard reported Cursor's git.exe code execution flaw in December 2025. Seven months later, Cursor calls it out of scope and points to Workspace Trust.
Bonsai 27B fits on a phone. But does it run well?
PrismML compressed a 27B-class model into a phone-sized package, but kernels, memory overhead, and real device performance still determine whether it is practical.
npm 12 blocked --ignore-scripts bypasses. Jscrambler's compromise found another way in three days
A compromised Jscrambler npm release ran an infostealer from a preinstall hook, then moved the same payload into normal package code once npm 12 disabled scripts by default.