Skip to content
Friday 2026-09-25 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours

    A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal vulnerability, designated CVE-2026-85706, carries a CVSS score of 10.0. It stems from a failure in path confinement combined with a complete lack of authentication enforcement. To trigger the exploit,…

  • Anthropic’s 200M-Exchange Distillation Report Is the Evidence Behind the Joint US Intelligence Accusation

    Three days before Anthropic published its September 2026 threat intelligence report, the CISA, FBI, and NSA issued a joint advisory (AA26-251A) accusing six Chinese AI companies of industrial-scale distillation against US AI firms. Anthropic’s report, published September 10, is the evidentiary backbone of that accusation. The numbers are the story: approximately 200 million exchanges across…

  • The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs

    The Hardware Sovereign: Why China is Listing Chipmakers Before Model Labs In the global race for artificial intelligence dominance, the conventional wisdom has been to fund the model labs first, letting the compute infrastructure follow the demand. But in China, the capital markets are inverting this hierarchy. By prioritizing the public listing of AI chipmakers…

  • Weekly Lab Notes: The Week the Compute Landlord Thesis Went Global

    The compute landlord thesis has officially outgrown its domestic borders. What began as a race to secure domestic data center capacity has evolved into a global scramble for energy sovereignty, vertical distribution control, and the architectural bypass of a fractured supply chain. This week’s activity reveals a landscape where the physical constraints of AI —…

  • KYA Solves Agent Identity. It Doesn’t Solve Consumer Trust.

    The Know Your Agent framework announced by Ant International, Visa, and Mastercard on September 10, 2026, addressed the identity layer of autonomous commerce. It did not address the trust layer. For the three payment networks and every merchant hoping to participate in the projected $3-5 trillion agentic commerce market, the distinction matters more than the…

  • Three Bills, Three Theories – A Fourth Theory Emerges from Florida

    Florida Attorney General James Uthmeier has introduced a legislative proposal that fundamentally alters the risk profile for the agent economy. By seeking to apply an existing aider-and-abettor statute to the developers and deployers of autonomous systems, the state is bypassing the ongoing federal debate over technical standards. This proposal, introduced on September 8, 2026, signals…

  • What Agent Commerce Needs From Product Data: Lessons From the W3C/GS1 Workshop

    An AI agent can navigate the entire digital funnel – searching, comparing, checking out, and executing payments – yet still fail at the point of purchase. This is the “last meter” problem, a structural friction point where the digital intent of an agent meets the physical reality of a product. If an agent cannot definitively…

  • OpenAI Endorses California Safety Bills – The ‘Reverse Federalism’ Regulatory Moat

    On September 9, 2026, OpenAI formally endorsed four specific California AI safety bills currently awaiting action from Governor Gavin Newsom. This legislative package includes SB 813, which mandates independent AI risk assessments; AB 1405, establishing rigorous standards for AI auditors; SB 1119, focused on child safety and parental controls; and AB 1864, which introduces safeguards…