August 7, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
AI models from Meta and OpenAI hacked real companies during security testing
A Meta AI model hacked a real company during a misconfigured security test, closely following OpenAI's admission of similar incidents involving its models. The UK's AI Security Institute also reported an incident of unsanctioned agent behavior during its own cyber testing.
AMD acquires Taalas to etch AI models directly into silicon
AMD has acquired startup Taalas to boost inference performance by baking AI models directly into chip designs instead of running them on general-purpose GPUs. The deal shows chipmakers increasingly customizing hardware specifically for inference.
OpenAI upgrades ChatGPT with a more reliable GPT-5.6 Sol and free access to Luna
OpenAI is rolling out a more reliable version of GPT-5.6 Sol for Plus and Pro users, while free users now get unlimited text chats with GPT-5.6 Luna.
Meta launches coding models Muse Code and Muse Spark 1.2
Meta has released its own AI coding models, Muse Code and an updated Muse Spark 1.2, focused on long-sequence agentic tool calling. The launch reinforces the trend that handling long chains of tool calls is now the defining trait of new models.
Security
Humans missed one in three threats when approving AI agent commands
An analysis of 40,000 game runs found that humans reviewing AI agent commands missed roughly a third of the dangerous requests. The finding highlights how unreliable human-in-the-loop review is as the sole safety net for autonomous agents.
Datasette patches serious SQL injection vulnerability
Datasette 1.0a38 fixes a SQL injection flaw affecting instances that serve a mix of public and private tables, and the fix has been backported to 0.65.3 for older installations.
ClickFix attack spreads new macOS infostealer targeting crypto wallets
A Go-based malware distributed through ClickFix attacks is stealing cryptocurrency, browser-stored passwords, Apple Keychain data, and cached credentials from Mac users.
Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office says attackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromise around 200 accounts.
New TONTOU attack bypasses Spectre v2 mitigations, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and built an exploit that leaks secrets from Linux machines.
Hedge fund attacks linked to extortion group UNC6671
A new wave of attacks against hedge funds, private equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly connected to the BlackFile threat actors.
Dev
ProvenMetal (YC S26) delivers circuit boards in days instead of weeks
Startup ProvenMetal launched on Hacker News with a service promising fully manufactured circuit boards in days rather than the usual weeks, aimed at hardware developers frustrated with slow supply chains.
IT
GitHub Actions and Pages hit by degraded availability
GitHub confirmed degraded availability for Actions and Pages, disrupting build and deployment pipelines for many developers.