October 1, 2026
Today's top tech stories, deduped across the newsletters I read and briefly summarized. Click a source to open the original article.
AI
Google launches Gemini 4 Argon
Google has announced Gemini 4 Argon on its AI blog. The launch drew more than 1,000 points on Hacker News.
Anthropic deprecates Claude Sonnet 4.5
The claude-sonnet-4-5-20250929 model retires on the Claude API on November 30, 2026. Anthropic recommends migrating to Claude Sonnet 5.5.
GPT 6.1 Sol: near-Astra intelligence for a fifth of the price
Simon Willison comments on the launch of GPT 6.1 Sol, pitched as delivering near-Astra intelligence at a fifth of the price. The discussion took place on Hacker News.
NVIDIA NeMo Relay traces agent harness behavior
NVIDIA shows how NeMo Relay traces how AI agents complete tasks. It exposes inefficient paths, such as a failed search triggering another search.
Security
Anthropic: GLM-5.3 can hijack control flow in some trials
Anthropic's Frontier Red Team tested GLM-5.3 on 100 randomly selected tasks from its internal Binary Exploitation benchmark. The model developed full control flow hijacks in 4% of trials.
Researcher could have accessed 17 trillion Microsoft records
A security researcher describes how he could have accessed 17 trillion Microsoft records. The post earned more than 260 points on Hacker News.
Cisco warns of actively exploited SD-WAN Manager zero-day
Cisco released security updates for a critical zero-day in Catalyst SD-WAN Manager (CVE-2026-76504). Attackers are actively exploiting it to gain admin privileges.
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a critical MikroTik RouterOS vulnerability. It can allow remote code execution without authentication, or a denial-of-service condition.
DIVD: two Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure says attackers breached its network by chaining two zero-day vulnerabilities in the open-source Zammad ticketing system. It describes the breach as AI-driven.
Over 543,000 valid credentials exposed in public GitHub repos
More than 543,000 credentials in public GitHub repositories were still valid in July. That held despite the platform's measures to prevent accidental leaks.
Russian state hackers use new RedFlick technique
The Russian state actor Star Blizzard uses a new installation method called RedFlick to deploy its CosmicPulse backdoor.
Web
Netlify: 5x faster Edge Functions with Firecracker MicroVMs
Netlify moved Edge Functions from V8 isolates to Firecracker MicroVMs and reports five times faster performance.