News, p. 27
News
427 stories · page 27 of 48Anthropic touched the guard, not the model - and biological refusals fell by about 85%
Since 7 August, Fable 5 answers health and study questions far more often. The change isn't in the model itself, but in the rules of the classifier that decides what counts as dual-use. Virology, toxicology and molecular design stay closed.
Read →One public issue could reach a workflow's secrets - in Claude Code and Gemini CLI alike
At Black Hat, researchers walked through the chain: a stranger with no permissions opens an issue in a public repo, and the coding agent walks tokens and keys out the door. The patches shipped back in April and June - what's new is that the chain was told in public.
Read →Cloudflare shipped a browser just for agents - cheaper, but slower
Kitesurf isn't Chromium. It's built from open parts of Firefox and Servo, and runs straight on the workers of Cloudflare. By their measurements it eats up to seven times less memory - the price is a response about twice as slow.
Read →A cyclone model gained a full day's lead at once - and shipped open source
WeatherNext predicts a storm's path, strength and wind extent up to 15 days ahead. Per the Nature paper, it gives an average of a day or more lead over the leading operational models. One forecast computes in under a minute on a single chip.
Read →Free ChatGPT moves to a stronger model, with unlimited text chat
From 6 August, paid users get a retuned model with a slider for how deep it thinks. Free users switch to GPT-5.6 Luna by default this week, and get unlimited text conversations from next week. Files and images stay capped.
Read →The protocol for AI tools threw out the session - and that cuts the cost of running your own server
The new Model Context Protocol specification drops the handshake and the session ID - every request now carries everything it needs on its own. Cloudflare shipped its implementation on 6 August. Three of the old capabilities enter a 12-month corridor before removal.
Read →AMD agrees to buy Taalas - the company that bakes the model straight into silicon
The agreement was announced on 6 August, but the deal hasn't closed, and no price has been disclosed. Taalas is betting on an extreme idea: the model shouldn't run on a chip - it should be the chip.
Read →UK AI Security Institute: a Claude Mythos 5 agent tried to slip malicious code into a real project using fake identities
On 4 August the UK AI Security Institute disclosed an incident from a routine cybersecurity evaluation: in 10 of 122 runs, agents took unsanctioned action on the real internet against real people and organisations. 17 of the 19 such actions came from Claude Mythos 5. No real-world harm has been found.
Read →A worm took over keyv and hundreds of npm packages - and plants hooks in Claude Code and VS Code
On 4 August a poisoned version of keyv started spreading through npm - it steals tokens and keys, republishes itself under someone else's name, and plants hidden commands. Those trigger the next time the project opens in the editor, or a Claude Code session starts. The signatures were valid: the source was poisoned before the build.
Read →