Sec & AI News — 22 August 2026
🛑 OpenAI Stopped Training Its Own Model. Cyber Was the Reason.
OpenAI paused reinforcement learning on its latest deployment-bound models for two weeks, and the largest planned frontier RL run is still on hold. On 7 August they found preliminary evidence that the upcoming model, Astra, may cross the Critical cybersecurity threshold in their own Preparedness Framework. Add the Hugging Face incident, and the hardening followed: isolated research clusters, alerts firing inside 30 minutes, roughly 20% of inference compute spent watching the models rather than serving them. We heard the too-dangerous-to-release line about GPT-2 in 2019. This time the model already broke out of a sandbox and hacked a live website, so the claim arrives with a receipt attached.
🔍 One Zoom Message Takes Over Your Machine
A researcher pointed AI at the Zoom client and asked it to find the dangerous code. It scored 3,762 functions, ranked all 70 libraries, and buried the vulnerable one at 45th. The bug got found anyway, because a person looked at that ranking, decided the question was wrong, and asked a different one: not where is the dangerous code, but what can a remote participant actually reach? I've been running AI-directed vulnerability research for months and hit the identical wall from the other side. My cleverest taint scanners are consistently the least productive thing I run, because a missing permission check is the absence of a safe operation and there's no pattern to match against nothing. Patch Zoom Workplace to 7.1.5 first. Then read it for the part that isn't the bug: the labour is being automated and the judgement isn't.
- One Zoom Message Takes Over Your Machine — by Nathan House
⚖️ Six Fixes for Dangerous AI. Most Are Theatre.
OpenAI holding Astra back is one lab's voluntary call, which raises the obvious question of what happens when a lab decides not to. So I scored all six proposals on the table — voluntary vetting, the mandatory-access bill, vendor gatekeeping, export controls, baking removal into the weights, a FINRA for AI — against the same five questions. Does it gate the capability. Who vets, and who holds them accountable. Who gets locked out. Does it survive open weights. Is there a route in for an independent. The verdict is that no single fix works and the honest answer is layered. There's also a test every one of them fails: gating the frontier buys months, and the open-weight gap shrank from 6-10 months to 4-7 in a year. Qwen shipping a frontier-adjacent model you can run offline, three items down, is that gap closing in real time.
- AI's Dual-Use Problem Has 6 Proposed Fixes. Most Won't Work — by Nathan House
🧬 An mRNA Cancer Vaccine Passed Phase 3
Individualised neoantigen therapy, now named intismeran autogene, hit both endpoints in the INTerpath-001 trial with Keytruda. 1,137 patients, completely resected stage IIB to IV melanoma, randomised 2:1, recurrence-free survival and distant metastasis-free survival both met at interim analysis. First positive phase 3 for an individualised mRNA cancer therapy. The AI part went unmentioned in most coverage, which tells you where the news cycle sits: integrated algorithms read next-generation sequencing from tumour and blood samples and predict up to 34 neoantigens most likely to provoke an immune response. Machine learning picking targets. The boring version, and the one that actually shipped.
- Merck and Moderna announce Phase 3 results
- Ars Technica
- Moderna: Advancing the fight against cancer through mRNA & AI
💾 A Frontier-Class Model That Fits on Your Desk
Qwen3.8-27B, open weights, Apache 2.0. Artificial Analysis puts it at 51 on the agentic index, above GPT-5.6 Terra and Claude Opus 4.8, and 52 on the intelligence index. Quantised builds land around 17-24GB, so a 3090, 4090 or 5090 runs it, or a Mac with enough unified memory. Nothing ranked above it on that agentic list runs on consumer hardware at all. An uncensored variant is already circulating on LM Studio and it is exactly as uncensored as that word suggests. Two items ago the argument was whether governments can gate dangerous capability. This is the model that doesn't care about the answer, sitting on a laptop, offline, with the safety training filed off.
👁️ ChatGPT Would Like to Watch Your Computer Now
Computer History turns your activity across apps and websites into memories and a searchable timeline that ChatGPT and Codex can reference. Ask what you worked on, pick up where you left off, turn a repeated workflow into a skill. It records interaction events rather than screenshots, it's off by default, you pick which apps contribute, and you can pause it from the Mac menu bar. Microsoft shipped roughly this idea as Recall and got taken apart for it. Pro, Business and Enterprise only, with an admin grant required.
💬 ChatGPT Can Now Read and Send Your iMessages
An Apple Messages plugin for the ChatGPT Mac app. It searches iMessage, SMS and RCS, catches you up on threads, drafts replies and sends them. Approval of the message and recipients is required by default. Apple silicon only, works in ChatGPT Work and Codex modes rather than ordinary chats, available on all plans.
- Codex and ChatGPT updates: Apple Messages, Sites, sharing, and pinned threads
- Apple Messages plugin docs
🫧 Google Will Now Take the Watermark Off For You
Gemini's visible sparkle watermark is now a setting you can switch off, across Nano Banana images, Omni video and Lyria music. SynthID and C2PA Content Credentials stay embedded, so the provenance is technically still there. The visible marker was the one non-technical people could actually see without uploading anything anywhere. Unavailable in some regions, because EU law says otherwise.
📊 A Third of the Post-ChatGPT Web Is Machine-Written
Pew sampled 10,000 webpages from July 2026 and ran them through Pangram's detector. 10% showed significant signs of AI authorship. Restrict it to pages published after ChatGPT launched and the figure hits 35%. By domain: about 10% on .com, 4.6% on .org, roughly 1% on .edu and .gov. Read it as 10% of sampled pages rather than 10% of the internet. The methodology page is worth the click if you plan to quote the number.
📧 Claude Can Send Email Now, Not Just Draft It
The Gmail connector drafts, sends, replies and forwards. The Drive connector manages files. Claude asks for approval before it sends, by default, and you decide where that default sits. The gap between reads your inbox and acts in your inbox is the entire security conversation, and it just closed on another surface.
🧑🎓 ChatGPT Is Guessing Whether You're a Teenager
ChatGPT for Teens went global on 18 August, and age prediction is how you get sorted into it. Tell it your age and it knows. Say nothing, and it infers from how you write. Chat like a teenager and you may be handed the teen model regardless of your birth certificate. Adults who get misrouted verify with a Persona selfie check.
🎓 A Free Year of Google AI for Students
US students get twelve months of Google AI Pro, a $19.99/month plan. Students in 140-plus other markets get AI Plus instead, so check which one your country is actually offered before celebrating. Sign-up closes 31 December 2026. Comes with a student hub, study notebooks, flashcards and practice quizzes.
🦐 Alibaba Made a Music Model Called HappyShrimp
Text to full song: melody, arrangement, lyrics, vocals. Beta since 17 August, built by Alibaba's Token Hub group, partnered with Taihe Music, and the name revives the old Xiami Music brand. Output quality sits below Suno. It refuses style-of-named-artist prompts, same as Suno does. The market for a Suno alternative is real right now, given the download caps Suno just introduced, so generic and available may be enough.
🐙 Cursor Is Building a GitHub
Origin: repos, pull requests, code browsing, two-way GitHub sync. Early beta since 17 August on all paid plans. GitHub remains the source of truth, and the blog post spends its time telling you how to bring your repos across. The editor company now wants the place your code lives.
💼 Agents Move Into Slack
Slack Code puts dedicated code channels in Slack where you tag Claude Code, Devin, Copilot or Vercel and they work alongside humans in the thread. The agents don't run inside Slack. It drives your existing harnesses and brings the conversation to where the team already is. All Slack plans, though you bring your own agent access. First Buzz, then Grok Bot, now this. Everyone has decided the chat window is the correct interface for supervising autonomous code.
🧠 Perplexity Built Karpathy's Wiki
Brain organises Perplexity Computer's memory into a browsable wiki of Concepts, Entities and Workstreams. It's the knowledge-wiki idea Karpathy sketched on X a few months back, now shipped as a product. Research preview, Max and Enterprise Max.
🗿 Image to 3D Model, Two Free Tries
Tripo P2.0 Preview generates native quad topology up to 50K triangles, which means meshes that go straight into a game pipeline rather than needing a retopology pass first. Fantasy creatures from generated images come out sharp. Photos of real people come out with a face that isn't quite theirs. Everyone gets two free generations.
🤖 A Robot That Jumps Two Metres
Unitree previewed a new humanoid, nicknamed Superman, claiming a 2 m standing high jump and 12.66 m/s top speed on 0.85 m legs. That's 45.6 km/h, past any human sprint record, and the jump clears a person's head in the demo video. Built in roughly three months. Company-reported figures on an X post, with no product page behind them yet.
💻 Meta Ships a Mac App
Meta AI as a desktop application: window sharing, system-wide dictation, scheduled tasks, artifacts, media history. Apple silicon, macOS 15+, launched 19 August, free tier plus Meta One paid tiers. It looks and feels like Codex or Cowork with fewer features, which reads as a statement of intent more than a finished product.