August 11, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Meta returns to open-weight AI with Muse Glimmer
Meta released Muse Glimmer, a 30-billion-parameter open-weight model under a clean Apache 2.0 license with a 120K+ context window, built for local agentic workflows. Mark Zuckerberg used the launch to criticize "closed" AI rivals as Meta re-commits to open weights.
Claude Opus 5 system prompt reveals Fable 5 and Mythos 5 were suspended over export controls
The leaked Claude Opus 5 system prompt reveals that Anthropic suspended access to Claude Fable 5 and Claude Mythos 5 just three days after their June 2026 launch, to comply with U.S. Department of Commerce export controls.
OpenAI releases ChatGPT 5.6 Cyber, but only for approved users
OpenAI has developed a specialized model called GPT 5.6 Cyber, built for vulnerability research, penetration testing, incident response, and remediation, but access is currently restricted to approved users.
Needle2: 14MB agentic LLM for phones, wearables, and robots
Cactus Compute has released Needle2, a 14MB agentic LLM designed to run locally on phones, wearables, smart home devices, and robots.
Security
AI agent exposes gym website's missing authorization checks
An AI assistant (OpenClaw) successfully canceled other users' gym reservations because the booking API had zero authorization checks, demonstrated by canceling a reservation for someone in waitlist position #1. The incident highlights how AI agents can surface and exploit weak access controls.
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery flaw.
BdThemes plugin supply-chain hack creates rogue WordPress admins
A threat actor compromised WordPress design-tool maker BdThemes' upstream infrastructure and modified a JSON feed delivered to admins' browsers to create rogue administrator accounts.
Hackers breached a small Polish energy plant via private APN
Hackers breached the OT network of a Polish combined heat-and-power plant serving about 50,000 residents last year, gaining access via a private APN (Access Point Name).
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously linked to the Medusa ransomware operation is now deploying a new strain called StormEncryptor.
LexisNexis shuts down services after suspicious server activity
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline in response to unusual activity on servers hosted and managed by a third-party vendor.
Dev
GitHub Models is now retired
GitHub has shut down its GitHub Models service, breaking GitHub Actions workflows that depended on it without warning for some developers.
Other
The UK's war on online anonymity has come to America
Lobbying inspired by UK age-verification and identification laws is now pushing for similar anti-anonymity requirements in the US, according to a critical review.