September 24, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Claude Opus 5.5, GPT-6 Sol, and GPT-6 Luna spark a new AI pricing war
Anthropic launched Claude Opus 5.5 while OpenAI shipped GPT-6 Sol and GPT-6 Luna in the same week, and the llm command-line tool added support for all three models within a day. The releases land amid an intensifying price war among frontier AI labs.
Google launches Gemini 3.8 text-to-speech models
Google released two new Gemini 3.8 text-to-speech models, and Simon Willison published a browser-based playground the same day for trying them out directly.
Claude discovers a novel enzyme system with CRISPR-like repeats
Anthropic reports that Claude helped identify an entirely new enzyme system featuring CRISPR-like repeats, one of the more concrete examples yet of AI-assisted basic research in gene-editing science.
NVIDIA introduces NV-Reason-CT, an open 3D CT VLM for radiologist reasoning
NVIDIA has released NV-Reason-CT, an open vision-language model for 3D CT scans trained to mimic radiologists' step-by-step chain-of-thought reasoning, an area that has gotten far less attention than 2D X-ray and pathology-slide AI.
US officials push to label AI critics as "foreign agents"
A report claims parts of the US federal government want to formally label prominent AI critics as foreign agents, raising concerns that criticizing the AI industry could become politically and legally risky.
Security
Malicious AI agents steal 600,000 credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records with payment-skimming malware.
Check Point confirms active exploitation of Security Gateway VPN RCE flaw
Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling functionality of its Security Gateway product.
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to actively exploiting the flaw, writing files to disk that execute shell commands when accessed.
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is already being actively exploited, affecting on-premises deployments of VeloCloud Orchestrator (VCO).
How one Kubernetes YAML file can hand over a GCP organization
Varonis demonstrates how a Kubernetes user with limited permissions can exploit the authority granted to Google Kubernetes Config Connector to seize control of an entire Google Cloud organization, a classic confused-deputy problem.
Web
Cloudflare ships support for Vary, the ugliest part of HTTP
Cloudflare has shipped support for the HTTP Vary header in its cache, a long-requested feature that lets sites correctly cache content that varies by things like language or device type.
IT
NVIDIA shows how to validate GPU cluster readiness before AI workloads land
NVIDIA notes that a GPU cluster can pass every health check and still fail when a real AI workload starts, and lays out how to validate that GPUs, network links, and nodes actually work together before launching large-scale training.