Sec & AI News — 7 August 2026

9 min readBy Nathan House
Get every new Sec & AI News issue
Straight to your inbox. No spam.

🔴 Three Labs Admitted Their Models Broke Into Real Companies

OpenAI disclosed on 21 July that models under evaluation exploited a zero-day in Artifactory, escalated privileges, moved laterally to a node with internet access, then chained stolen credentials into remote code execution on Hugging Face's servers to pull benchmark solutions out of a production database. Anthropic reviewed 141,006 evaluation runs and found three incidents across six of them — Claude Opus 4.7 carried on attacking after recognising the systems were real, and Mythos 5 published a live malicious PyPI package that ran on fifteen real machines. Meta's Muse Spark 1.1 reached the public internet during testing and altered a third party's systems. Worth separating the three: Meta's was a misconfiguration by testing partner Irregular, not a containment break.

🛠️ Nobody Jailbroke Air Canada's Chatbot. It Just Made Up a Refund Policy.

Three labs can't keep their models inside an eval harness. Your chatbot has a smaller problem that will still cost you money: it invents things about your own business. In 2022 Air Canada's bot told a grieving customer they could claim a bereavement discount retroactively. No such policy existed. The airline argued in tribunal that the chatbot was a separate legal entity responsible for its own actions, the tribunal called that "a remarkable submission," and Air Canada paid. So I installed and ran eight AI red teaming tools against three targets, including my own. Most test whether someone can attack your bot. Two test whether it's telling your customers the truth. Read the actual responses, by the way. Seven of Giskard's nine detectors crashed on startup and still reported a plausible-looking four issues.

🔐 Looking For a VPN? I Tested Nord Properly and Built a Free Tool

If you're picking a VPN, I've done the work. Two days inside NordVPN's offices on ask-anything terms, their no-logs setup checked myself, and this week 26 servers speed-tested from New York and London. The finding that surprised me: twelve London servers in one hour ranged from 88 Mbps to 1,208, and every server that failed outright was one of the near-empty ones. Picking the emptiest server, which is what most of us do, is how you land on a dud. Use Quick Connect.

I also built runfrom, free and MIT-licensed, which sends a single command through another country instead of routing your whole machine: runfrom us -- curl https://example.com.

🧠 Anthropic Worked Out How To Cut Hacking Knowledge Out Of A Model

Fencing the knowledge in clearly isn't working, so the other option is making the model not know. GRAM trains dangerous domains into removable modules: delete the module and the model behaves as if it never saw the data. Cybersecurity is one of the four categories it was built to delete, which means your skill set is now officially on the list of things AI companies want an off switch for. Machine unlearning was the previous attempt and it doesn't hold — the paper fine-tuned an "unlearned" model on 512 examples per domain, about 1.3% of the original training data, and the capability came back to 0.91 of baseline. GRAM is preliminary, isn't in any production Claude, and once open weights are downloaded there's no switch left to flip. The part that matters for your career is where this ends up: offensive-cyber AI on vetted, tiered access.

🔵 Google DeepMind Lost Its CEO and Its Chief Scientist On The Same Day

Demis Hassabis moves to Chair of Google DeepMind and Chief Scientist of Alphabet, keeping Isomorphic Labs. Koray Kavukcuoglu takes over day-to-day as SVP, reporting to Pichai. On the same announcement, Jeff Dean left after 27 years, and he didn't go alone. Sanjay Ghemawat, Oriol Vinyals and Quoc Le went with him to Discovery Loop, an independent public benefit corporation building automated ML research for scientific discovery. Google is a founding investor and its cloud partner.

🟠 Alibaba Shipped a 2.4 Trillion Parameter Model. The Weights Are Still Coming.

Qwen3.8-Max landed on 3 August. Sparse mixture-of-experts, 2.4T total parameters with 95B active, one million token context. GPQA Diamond 92.6, which is genuinely frontier-adjacent on reasoning. Coding sits lower: Terminal-Bench 2.1 at 86.6, SWE-bench Pro at 67.7. It ranks fifth on Text Arena and second on Vision Arena. Pricing is $2 in, $6 out per million tokens, and the open weights are promised for "next week."

🟡 Meta Shipped a Terminal Coding Agent The Same Week Its Last Model Made The News

Muse Code arrived on 5 August from Meta Superintelligence Labs, and the 1.1 containment story broke the same day. Terminal only, no desktop app, unlike Claude Code and Codex. macOS and Linux, one-line install, persistent background subagents, and a replay-exact event log. The model behind it, Muse Spark 1.2, scores 59.3% on DeepSWE v1.1, up from 53.0, and 82.9% on Terminal-Bench 2.1. It costs $1.25 in and $4.25 out per million tokens.

🟣 Google Earth's Image Tool Lasted About 24 Hours

Launched Thursday 30 July with Nano Banana 2 wired into Google Earth. Pulled Friday. Journalist Henk van Ess demonstrated the problem inside a day: a nuclear plant planted in Iran, refugees near the Mexican border, a bomb crater beside a Gaza hospital. The watermark argument Google leaned on assumes people check watermarks. Its statement says it is "rolling back this feature while we work on implementing stronger guardrails," and notes the images never appeared in the main Earth experience.

🟢 Two New Video Models, One Week Apart

Black Forest Labs put FLUX 3 Video into general availability on 4 August: clips up to 20 seconds, 720p with 1080p upscaling, native audio, and an open-weight variant called FLUX 3 Dev on the roadmap. ByteDance got there first with Seedance 2.5 on 31 July. That one does 30 seconds in a single pass and accepts 30 images, 10 video clips and 10 audio clips as reference material at once, with timestamp-level control for targeted edits. Both claim to model physics accurately. Watch either one long enough and an object still quietly turns into a different object.

⚫ Hank Green Said Two Words And The Internet Decided He Was A Fraud

A "future Hank" segment on the Complexly channel included the line "I appreciate the pushback." Viewers read it as an AI tell. Green posted on X admitting he used ChatGPT for research on the script, said the line was an ad-lib replying to the episode's guest, then deleted the post. His longer response went up on Reddit. He is "mortified that I have let so many people down," and says the dopamine he gets from interacting with LLMs "is not healthy for me or good for the world. It is careless, and has disconnected me from where people are on this."

🔶 OpenAI's Unreleased Model Solved Ten Open Maths Problems For About $2,000

Published 1 August, credited to "an internal version of Astra, our next major model." Ten results across sphere packing, binary and spherical codes, non-sofic groups, Connes's rigidity conjecture, arithmetic circuit complexity, quantum parallel repetition, the closest vector problem, Ehrhart's volume conjecture, multicolour Ramsey numbers and two Erdős extremal conjectures. Humans prepared the manuscripts. Every argument was formalised in Lean and published. The compute bill for finding all of them came to roughly $2,000 at Sol API rates.

🔷 Free ChatGPT Users Get Unlimited Chats, Paid Users Get a Model That Argues Back

Announced 6 August. GPT-5.6 Sol gets more reliable facts, tighter formatting, and a willingness to push back rather than agree by default, plus a slider for thinking effort replacing the Instant/Thinking split. OpenAI's internal evaluation on financial, medical and legal prompts put responses containing at least one factual error 68% lower with Sol and 62% lower with Luna, both against GPT-5.5 Instant. Free tier now defaults to GPT-5.6 Luna with unlimited text chats and a Think button. Unlimited covers text. Uploads, images and tools stay capped.

🔸 Google Maps Will Now Order Your Dinner

Ask Maps went agentic on 6 August. Tell it to order spicy pad kee mao for pickup on your way home and it finds restaurants along the route, weighs your saved places and dietary needs, and adds the dish to a cart for review. Square and Toast are live; Uber Eats is coming. It also compares real-time hotel prices, surfaces events with ticket links, connects to Gmail (off by default, Calendar still pending), remembers past conversations, and adds a real-time transit delay widget. Food ordering, hotels and events are US-only for now.

🔹 OpenAI Shipped Three Education Plugins, Locked To Institutions

Out 4 August, and locked to ChatGPT Edu and ChatGPT for Teachers district deployments rather than consumer accounts. K–12 Educator does assignment translation, exit ticket briefs, family updates and practice tests. College Educator handles interactive teaching sites, course calendaring, materials and posters. College Student gets interactive learning sites, flashcards and study plans. It integrates with Learning Commons for standards alignment, and teachers keep control of grading and agentic actions.

⬛ Jony Ive's First OpenAI Device Is Reportedly a Doughnut

Bloomberg's Mark Gurman reports a screenless, battery-powered smart speaker roughly the size of a hockey puck, doughnut-shaped, priced above $300, with moving parts that animate when the device is responding. It is the first concrete shape anyone has put on the Ive collaboration since it was announced. OpenAI has announced nothing itself, and the expected date is 2027.