Skip to content
Saturday 2026-09-12 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory

    On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This activity signaled the exploitation of PaperCut NG and MF, specifically targeting a chain of vulnerabilities that would soon be formally assigned as CVE-2026-81578 and CVE-2026-82078. The Mechanics of the Chain The attack relies on…

  • One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours

    A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal vulnerability, designated CVE-2026-85706, carries a CVSS score of 10.0. It stems from a failure in path confinement combined with a complete lack of authentication enforcement. To trigger the exploit,…

  • Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit

    The BlueMoon exploit kit demonstrates a shift in how threat actors leverage the time between open-source vulnerability disclosure and stable-channel deployment. By chaining three distinct vulnerabilities — CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 — the kit achieves SYSTEM-level escalation on Windows systems running Chromium-based browsers. This chain highlights a structural reliance on the patch-gap window, where security…

  • Sonos 27 Turns Millions of Speakers Into an AI Agent Platform — and It’s Free

    The Hidden Cost of Your Smart Home Every month, my credit card statement feels like a slow-motion subscription tax. Between the streaming services, the cloud storage, and now the AI assistants, the cost of keeping a house “smart” is quietly ballooning. When Sonos announced its 27 update on September 8, 2026, the industry narrative was…

  • Four Days, Two Markets: How the AI Capital Market Split Into Two Games

    The Great Bifurcation Between September 8 and September 11, 2026, the artificial intelligence capital market underwent a definitive split. Four major funding events in four days did not merely signal high activity; they mapped the geography of a new, bifurcated financial reality. On one side, infrastructure labs are absorbing sovereign-scale capital to secure their position…

  • Anthropic’s 200M-Exchange Distillation Report Is the Evidence Behind the Joint US Intelligence Accusation

    Three days before Anthropic published its September 2026 threat intelligence report, the CISA, FBI, and NSA issued a joint advisory (AA26-251A) accusing six Chinese AI companies of industrial-scale distillation against US AI firms. Anthropic’s report, published September 10, is the evidentiary backbone of that accusation. The numbers are the story: approximately 200 million exchanges across…

  • The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs

    The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs In the global race for artificial intelligence dominance, the conventional wisdom has been to fund the model labs first, letting the compute infrastructure follow the demand. But in China, the capital markets are inverting this hierarchy. By prioritizing the public listing of AI chipmakers…

  • The Orchestration Arbitrage: How Sakana’s Fugu Max Rewrites the Pricing War

    On September 11, 2026, Sakana AI launched Fugu Max v1.0 and Fugu Ultra v2.0, effectively transforming multi-agent orchestration into a standardized, API-compatible product. By pricing Fugu Max at $2 per million input tokens and $6 per million output tokens, Sakana has undercut the output costs of frontier models like Sonnet 5, GPT 5.6 Terra, and…

  • When Agents Shop on Specs, the Brand Premium Becomes the Margin at Risk

    With only four days remaining until Dreamforce 2026 and NRF Europe converge on September 15-17, the transition to the agentic enterprise has become the primary focus for platform providers like Salesforce, who are positioning merchant readiness as the next frontier of digital retail. Yet, as the hype cycle accelerates, a quiet disconnect persists between the…

  • Four Weeks, Four Critical CVEs: AI Inference Infrastructure Is Now a Regular Target

    On September 11, 2026, the disclosure of CVE-2026-86793 in the SGLang open-source LLM inference framework extended the authentication gap into a layer it had not yet reached: the inference server itself. The vulnerability, discovered by VicOne researcher Reuel Magistrado, stems from a SafeUnpickler bypass where an overly broad allowlist for Python builtins, combined with an…