Skip to content
Wednesday 2026-10-07 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • The Asia Agent Wave – Manus, Enhans, and Huawei All Moved This Week

    The global AI agent market is no longer a singular, borderless frontier. This week, three distinct developments across Asia-involving Manus, Enhans, and Huawei-demonstrate that the next phase of agentic deployment is being shaped by regional capital, sovereign infrastructure, and heavy-handed regulatory oversight. While US-based firms like Sierra and Cognition continue to command massive valuations, the…

  • Google’s Gemini 3.8 Thinks Out Loud — And That Changes How AI Earns Trust

    Google’s September 2026 release of Gemini 3.8 Live Extended Thinking marks a departure from the industry standard of opaque, black-box inference. By enabling the model to reason and speak simultaneously, Google has shifted the transparency needle from static, post-hoc disclosures to a dynamic, real-time visibility model. This capability allows the system to narrate its thought…

  • Huawei Cloud Ships AICS, the First Major China-Side Managed Agent Platform, on the Same Day as Google

    The simultaneous arrival of Huawei Cloud’s AI Cluster Service (AICS) and Google’s Managed Agent Harness this week reveals a deepening structural divide in how autonomous systems are being built. While both platforms aim to standardize enterprise agent deployment, they are emerging from fundamentally different architectural philosophies. Huawei’s announcement at HUAWEI CONNECT 2026 in Shanghai marks…

  • Plugin4Shell Bypasses SHA Pinning Across All Four Major AI Coding Agents

    The security of the AI agent ecosystem has long relied on a simple, foundational assumption: if you pin a specific version of a plugin using a cryptographic hash, you are guaranteed to run that exact code. Plugin4Shell proves that this assumption is fundamentally broken. Discovered by the AIR Security research lab, Plugin4Shell is the first…

  • The Fault Line Spreads: Azure’s September CVE Cluster Now Covers PostgreSQL and Billing

    Azure Vulnerability Cluster Expands to Data and Financial Tiers Azure Database for PostgreSQL is vulnerable to CVE-2026-85878, an Improper Authorization flaw (CWE-285) carrying a CVSS score of 9.9. Simultaneously, Azure Billing is affected by CVE-2026-62874, an Insufficient Data Authenticity Verification issue (CWE-345) with a maximum CVSS score of 10.0. Both vulnerabilities were published September 18…

  • Muse for macOS: When Your Personal AI Agent Follows You to Work

    I spent the better part of this morning watching an AI agent try to organize my digital life. It felt less like a productivity hack and more like inviting a very eager, slightly clumsy intern to live inside my laptop. Meta released its standalone Muse app for macOS on September 17, 2026, and it is…

  • The Pattern Widens: Microsoft Fabric’s Authentication Bypass and the Expanding Identity Attack Surface

    Attackers can exploit CVE-2026-69843, a critical authentication bypass in Microsoft Fabric, without credentials or user interaction. This CVSS 10.0 vulnerability uses a network attack vector and features a scope-changed metric, allowing an adversary to cross security boundaries from the network directly into the analytics and data tier where OneLake stores enterprise data. The vulnerability is…

  • AgentCard Gives AI Agents Their Own Identity. That Is the Point.

    Alchemy’s integration of AgentCard with Mastercard Agent Pay establishes a dedicated identity layer for autonomous software. By provisioning each agent with a unique email address, phone number, stablecoin wallet, and tokenized payment credentials, Alchemy is attempting to treat AI agents as distinct, verifiable entities rather than mere extensions of a user’s existing account. This is…