September 17, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Anthropic tests 'Claude Money' to analyze bank accounts
Anthropic is piloting a personal finance feature that lets Claude connect directly to users' bank accounts to 'understand your money.' The feature raises privacy and security questions about financial data flowing into an AI chatbot.
Claude Cowork and Claude chat become a single product
Anthropic is merging Cowork and the standard Claude chat interface into one unified app, cutting the confusion between Cowork, Claude, and Claude Code. The move folds agentic workflows directly into Claude's core product.
Google launches Gemini 3.8 Live with extended reasoning for voice
Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking, bringing deeper reasoning to real-time voice conversations. Simon Willison built a standalone tool to test the new audio API.
Training a 4B model to produce 81% faster query plans than Postgres
A developer trained a 4-billion-parameter model with reinforcement learning to generate query plans 81% faster than PostgreSQL's built-in planner. The project shows how small, specialized models can challenge traditional database engines on narrow tasks.
Security
Hackers got inside a Flock surveillance camera
Security researchers showed how Flock's network of automatic license-plate cameras can be compromised, exposing how the system collects and shares surveillance data. The findings renew privacy concerns about the widespread police camera network.
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies warn that Iranian state-linked hackers are using a Windows malware strain called CHOSEN BRICK to surveil dissidents, activists, and journalists worldwide. The campaign underscores how state-backed actors keep targeting civil society.
Malware bypasses browser checks to force-install Chrome, Edge extensions
A banking-malware operation active since mid-2025 uses a toolkit called KREMLIN to bypass browser security checks and force-install malicious Chrome and Edge extensions. The extensions steal credentials, session tokens, and other sensitive data.
Spain's data protection agency gets first report of an AI-powered data breach
Spain's AEPD was notified of an attack allegedly carried out by an AI agent built on a known large language model. The case could become one of the first officially logged breaches where an AI agent is the alleged attacker.
Dev
NVIDIA brings native Rust support to CUDA GPU programming
NVIDIA introduced two tracks for writing GPU kernels in Rust and used agentic AI to translate CUDA tile operations from Python into safe, idiomatic Rust via cuTile Rust. The move extends Rust's ownership model to GPU programming without going through C++.
Datasette ships security fix for private-row leak
Datasette 0.65.5 and 1.0a40 patch a vulnerability where a trailing newline in a requested table name could bypass access controls and expose private rows. The 1.0a40 release also adds new features, including letting plugins launch and manage their own processes.
IT
AWS says it can't restore some data from Middle East facilities hit by Iranian strikes
Amazon says it cannot fully recover data from certain Middle East data centers after the facilities were struck amid Iranian attacks. The incident highlights how exposed cloud infrastructure is to geopolitical conflict and physical warfare.
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the KB5124008 security update for Windows 11 breaks domain trust relationships on some enterprise systems, locking users out even with valid domain credentials. It's the latest in a string of troublesome updates from Microsoft.