September 21, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
ChatGPT now tracks your activity on other websites via an ad collector
Reports show ChatGPT can track user behavior on third-party websites through a built-in ad collector, raising fresh privacy concerns about OpenAI's products.
Alibaba launches Qwen Image 2.1
Alibaba's Qwen team has released Qwen Image 2.1, an updated image-generation model that builds on its predecessor with improved quality and performance.
'Pirate Face' rescues LLM models from deletion
The Pirate Face project is archiving open LLM models at risk of being taken offline, aiming to keep them available for researchers and developers.
AX: Google's open agentic orchestrator
Google has released AX, an open-source orchestrator for coordinating multiple AI agents in production, staking out a stronger position in the agent-framework race.
Terence Tao: Why do we still need human mathematicians?
Mathematician Terence Tao discusses what role humans still play in mathematical research now that AI models are getting better at proving theorems and solving advanced problems.
Employee describes workplace where Claude Code writes everything from specs to reports
In a quote shared by Simon Willison, a new hire describes how a large company relies entirely on Claude Code to produce specs, code, tests, PRDs, and reports, illustrating how deeply AI agents have become embedded in the workflow.
Security
'Exfiltrate Your Weights': a fresh look at AI model weight security
A new project highlights how feasible it can be to exfiltrate the weights of large language models from AI labs, spotlighting insider-threat risk and model security.
Researchers escape OpenAI Codex sandbox to run commands on the host
Security researchers found two ways to break out of OpenAI Codex's sandbox, including from its most locked-down mode, and ran commands directly on a developer's machine. OpenAI has patched both issues.
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign centered on the 'indexed-btree' package shows how attackers bypass supply-chain defenses by hiding malicious code in a package's normal runtime behavior instead of its install scripts.
What happened to the Snowden archive
A new post traces the fate of the documents Edward Snowden leaked, mapping where the material sits today and who still has access to it more than a decade later.
IT
Samsung to more than double HBM4 and HBM4E output
Samsung plans to more than double production of HBM4 and HBM4E DRAM next year to meet soaring demand for memory used in AI chips.
Spain orders blocks on Archive.today and its mirrors
Spanish authorities have ordered internet providers to block Archive.today and its mirror sites, a move that raises concerns about access to archived content and internet censorship.