September 26, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
US appeals court upholds Anthropic's supply chain risk designation
A U.S. appeals court has upheld the Pentagon's designation of Anthropic as a supply chain risk, a ruling that could affect the company's access to government contracts.
Meta's Muse gives every user a persistent cloud Linux VM
Meta has launched the AI agent Muse, which spins up a dedicated, persistent Linux virtual machine in Meta's cloud for every user — technically groundbreaking but packaged in a simple, approachable product, according to John Gruber.
Anthropic offers up to $250 in free Claude Code credits for cloud sessions
Anthropic now lets more users try Claude Code through cloud sessions without signing up for the research preview, offering up to $250 in free usage credits.
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription priced at $500 per month with faster access to its Codex coding tool, though it's unclear when it will roll out.
Security
Revealing the details of how OpenAI agents hacked Hugging Face
A new report walks through how autonomous OpenAI agents managed to hack into Hugging Face, raising fresh questions about the security of AI agents operating on their own.
Kiteworks urges 6-hour server shutdown over potential zero-day attack
Secure file-sharing vendor Kiteworks is urging customers worldwide to temporarily shut down their servers for a six-hour window after receiving threat intelligence warning of an imminent attack.
ShinyHunters hacked Clop's leak site using a Grav CMS path traversal flaw
The Clop ransomware gang had to move its leak site to a new Tor address after ShinyHunters compromised and defaced the old server through an unpatched path traversal vulnerability in Grav CMS.
CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency warns that attackers are actively exploiting a critical authentication bypass vulnerability (CVE-2026-5430) in WSO2 products, alongside flaws in SharePoint and Adobe Commerce.
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery vulnerability in the popular Elementor plugin for WordPress could let an unauthenticated attacker create administrator accounts on vulnerable sites.
With the rise of AI agents, SOC 2 should adapt or risk irrelevance
Token Security argues that AI agents often act through human credentials and take actions existing SOC 2 controls can't distinguish from human activity, creating security gaps compliance frameworks need to close.
Dev
Platform-independent SIMD in Go
The Go team is experimenting with platform-independent SIMD (Single Instruction, Multiple Data) support, aiming to make it easier to write faster, vectorized code without hand-written platform-specific assembly.
IT
Microsoft plans to deprecate Windows Deployment Services
Microsoft has announced it will deprecate the Windows Deployment Services (WDS) server role, starting with the next Windows Server release.