August 27, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Z.ai releases GLM-5.3-Flash
Z.ai has shipped GLM-5.3-Flash, a new open-weight language model that quickly shot to the top of Hacker News. It's the latest in a wave of faster, cheaper open models from Chinese AI labs.
Alibaba releases Qwen3.8-Flash-Next as a preview of Qwen4
Alibaba has released the weights for Qwen3.8-Flash-Next, a multimodal MoE model that serves as an early preview of the upcoming Qwen4 architecture. It's a big model — 125 billion parameters total but only about 6 billion active per run — and NVIDIA has already published a guide for running it on GB300 NVL72 for agentic coding.
Nvidia agrees to acquire Hugging Face for $13 billion
Nvidia has agreed to buy Hugging Face for roughly $13 billion, according to Business Insider. The deal would give Nvidia direct control over one of the most central hubs for sharing open AI models.
NVIDIA launches NVLink Fusion with NVHBM for next-gen AI infrastructure
NVIDIA is introducing NVLink Fusion with NVHBM to meet the ever-growing compute demands of AI factories running large models and complex reasoning workloads. The technology aims to make it easier to build data centers that scale alongside future AI workloads.
Security
OpenAI addresses the Hugging Face incident and the road ahead
OpenAI has published a rundown of a security incident at Hugging Face and the measures now being rolled out across the open-model ecosystem. The post lands just as Nvidia's planned acquisition of Hugging Face puts the platform's security even more in the spotlight.
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now going after a chain of two Microsoft SharePoint vulnerabilities that together allow arbitrary code execution on unpatched servers, according to threat intelligence firm Defused. Organizations that haven't patched their SharePoint servers should prioritize it immediately.
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation. It shows that hardware protections alone aren't enough to stop memory-based attacks on GPUs.
Dev
Tailcat: like netcat, but over Tailscale's data plane
Tailscale has released Tailcat, a tool that works like netcat but routes traffic over Tailscale's own data plane instead of the regular network. The project got a warm reception on Hacker News as a handy tool for developers and ops.
Anthropic's Compliance API exits beta and covers more products
The session endpoints in Anthropic's Compliance API are now out of beta for Cowork and Claude Code sessions, and the same endpoints now also return transcripts from Claude Science sessions and Claude for Microsoft 365 in Excel, PowerPoint, Word, and Outlook, currently in beta for Enterprise customers.
Admin API now available in the ant CLI and more SDKs
Anthropic's Admin API is now available in the ant CLI and in the Python, TypeScript, C#, Go, Java, PHP, and Ruby SDKs under client.beta.organization. It covers organization info, members, invites, workspaces, API keys, rate limits, service accounts, and workload identity federation.
Other
AWS acquires DuckLabs
Amazon Web Services has agreed to acquire startup DuckLabs, a deal that topped Hacker News' front page. Terms of the deal and plans for the product haven't been disclosed yet.
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to roughly $18 billion with a bipartisan coalition of 52 state attorneys general, over allegations that Facebook and Instagram were deliberately designed to drive compulsive use among children and teens. It's one of the largest settlements to date over social media's harms to minors.