Skip to content
Wednesday 2026-10-07 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • Your Calendar Might Be the Most Dangerous Thing in Your Smart Home

    You probably think of your digital calendar as a benign scheduling tool. Dentist appointments, grocery runs, work meetings—the mundane markers of a busy week. But researchers from Tel Aviv University, Technion, and security firm SafeBreach have demonstrated that your calendar is something else entirely: a prime attack surface for AI-powered smart homes. In their study…

  • Three Strikes on the Firewall Management Plane: Cisco FMC Logs Its Third CISA KEV of 2026

    Federal agencies have until the end of today, September 12, 2026, to remediate CVE-2026-20079, a critical authentication bypass vulnerability in the Cisco Secure Firewall Management Center (FMC). With a CVSS score of 10.0, the flaw allows an unauthenticated remote attacker to execute scripts and gain root access to the management interface. The vulnerability stems from…

  • The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory

    On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This activity signaled the exploitation of PaperCut NG and MF, specifically targeting a chain of vulnerabilities that would soon be formally assigned as CVE-2026-81578 and CVE-2026-82078. The Mechanics of the Chain The attack relies on…

  • One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours

    A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal vulnerability, designated CVE-2026-85706, carries a CVSS score of 10.0. It stems from a failure in path confinement combined with a complete lack of authentication enforcement. To trigger the exploit,…

  • Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit

    The BlueMoon exploit kit demonstrates a shift in how threat actors leverage the time between open-source vulnerability disclosure and stable-channel deployment. By chaining three distinct vulnerabilities — CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 — the kit achieves SYSTEM-level escalation on Windows systems running Chromium-based browsers. This chain highlights a structural reliance on the patch-gap window, where security…

  • Sonos 27 Turns Millions of Speakers Into an AI Agent Platform — and It’s Free

    The Hidden Cost of Your Smart Home Every month, my credit card statement feels like a slow-motion subscription tax. Between the streaming services, the cloud storage, and now the AI assistants, the cost of keeping a house “smart” is quietly ballooning. When Sonos announced its 27 update on September 8, 2026, the industry narrative was…

  • Four Days, Two Markets: How the AI Capital Market Split Into Two Games

    The Great Bifurcation Between September 8 and September 11, 2026, the artificial intelligence capital market underwent a definitive split. Four major funding events in four days did not merely signal high activity; they mapped the geography of a new, bifurcated financial reality. On one side, infrastructure labs are absorbing sovereign-scale capital to secure their position…

  • Anthropic’s 200M-Exchange Distillation Report Is the Evidence Behind the Joint US Intelligence Accusation

    Three days before Anthropic published its September 2026 threat intelligence report, the CISA, FBI, and NSA issued a joint advisory (AA26-251A) accusing six Chinese AI companies of industrial-scale distillation against US AI firms. Anthropic’s report, published September 10, is the evidentiary backbone of that accusation. The numbers are the story: approximately 200 million exchanges across…

  • The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs

    The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs In the global race for artificial intelligence dominance, the conventional wisdom has been to fund the model labs first, letting the compute infrastructure follow the demand. But in China, the capital markets are inverting this hierarchy. By prioritizing the public listing of AI chipmakers…

  • The Orchestration Arbitrage: How Sakana’s Fugu Max Rewrites the Pricing War

    On September 11, 2026, Sakana AI launched Fugu Max v1.0 and Fugu Ultra v2.0, effectively transforming multi-agent orchestration into a standardized, API-compatible product. By pricing Fugu Max at $2 per million input tokens and $6 per million output tokens, Sakana has undercut the output costs of frontier models like Sonnet 5, GPT 5.6 Terra, and…