AI Titus's Morning Wire

AI NEWS TODAY

POISONED AI TOOL HARVESTED CLOUD KEYS FROM 2,500 COMPANIES, AND NOBODY NOTICED FOR FOUR MONTHS
★ Must-Read / Watch agentic engineering / build-better-agents📚 Learn state of AI coding / useful technique

⚡ AI Frontier · smol.ai

★ Must-ReadAnthropic is reportedly negotiating to buy an Israeli startup for around 6 billion dollars, which would be its largest acquisition ever
Decart builds world models plus software that gets more training throughput out of the same chips. Nothing is signed, both sides declined to comment, and Musk called the report that SpaceX was also circling fake news.
xAI shipped Grok 4.6 and it ties OpenAI's current top model on the headline intelligence benchmark
Both score 61 on the Artificial Analysis index. Tuned for long-running agents, 2 dollars in and 6 dollars out per million tokens.
📚 LearnAnthropic made Claude Sonnet 5's introductory pricing permanent instead of raising it on September 1 as scheduled
It stays at 2 dollars in and 10 dollars out per million tokens. The planned jump to 3 and 15 will not happen, which matters if you budgeted for it.
Google's new Pixel puts Gemini in charge of multistep tasks stretching across more than 40 different apps
Bookings, reservations, Maps locations and Wallet entries surface back into the conversation. The app count is Google's own figure.
📚 LearnCodeRabbit raised 143 million dollars to build a review layer for code that agents rather than people are now writing
Series C at a 1.5 billion valuation. Triage, Change Stack and a security scanner, running over 2 million reviews a week for 17,000 customers.
Cognition is already back in the market at a 40 billion dollar valuation, three months after raising at 26
Devin's maker was at a 492 million dollar annualized run rate in May and the new number is tied to reaching a billion. In talks, not closed.

📺 Watch · latest videos

Codex's Browser Agent Automates Literally Anything
Latest from Nate Herk.
Nate Herk · 2.3K views · 140 likes
★ Must-WatchGet a daily CFO briefing with ChatGPT Work
Start the day with a clear view of the decisions that matter most. ChatGPT Work brings financial performance, close status, contract risks, and market
OpenAI · 534 views · 19 likes
Every Claude Code Skill I Use to Drive My Entire Development Process
Latest from Cole Medin.
Cole Medin · 5.9K views · 290 likes
Cursor just made something incredible...
Latest from Matthew Berman.
Matthew Berman · 43K views · 1.2K likes
★ Must-WatchClaude Cowork is now your Chrome side panel
Claude sees the page you're already signed in to and works on it: it reads, clicks, types, and fills forms. Your skills, plugins, and connectors work
Claude / Anthropic · 36.8K views · 943 likes
Improving Agents is a Data Mining Problem — Vivek Trivedy, LangChain
Does your agent get dumber after the first compaction? After the second? You cannot read that off the code, only off the traces, and there are far too
AI Engineer · 2.1K views · 75 likes
Meta's new model wants "deep access" to your personal life...
Latest from Fireship.
Fireship · 327.3K views · 9.9K likes

💻 Builder Desk · Hacker News

DeepSeek V4 Pro 0813
998 pts · 428 comments
Qwen3.8-2.4T
689 pts · 161 comments
Delta
622 pts · 227 comments

🗣 Voices & Blogs

★ Must-ReadBen Thompson On Why Nvidia's Financing Push Is The Part To Worry About
He opens on Jay Cooke's 1870 railroad bonds and argues the 500 billion Nvidia is mobilizing moves the risk off its own balance sheet and onto insurance floats and pension funds, which is a different kind of bet than spending your own cash flow.
📚 LearnNathan Lambert On Why AI Still Could Not Write His Textbook
Having just finished one, he says models are genuinely useful for typos, narrow edits and background filler, and still cannot organize a body of knowledge or write an introduction worth reading. His estimate is 2 to 5 years before that changes.
Five European companies just agreed to buy AI compute that doesn’t exist yet
Mistral AI, the French AI company that built its reputation releasing open-weight models, wants companies to use its infrastructure even The post… · The New Stack
Science | AAAS
Agentic AI Summit 2026 Recap | Five Shifts Defining the Future of Agentic AI | Key Developments Across the Agentic AI Ecosystem · via Berkeley RDI · Agentic AI Weekly

📦 What's Being Built · GitHub

affaan-m/ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first dev · ★239.9K · JavaScript
NousResearch/hermes-agent
The agent that grows with you · ★230K · Python
Significant-Gravitas/AutoGPT
AutoGPT is the vision of accessible AI for everyone, to use and to build on. Our mission is to provide the too · ★186.6K · Python
ollama/ollama
Get up and running with Kimi-K2.6, GLM-5.2, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models. · ★178.4K · Go
f/prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source · ★167.1K · HTML
firecrawl/firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥 · ★166.8K · TypeScript

🤖 Trending Models · Hugging Face

deepseek-ai/DeepSeek-V4-Flash-0731
text-generation · ★3.3K · 1.4M dl
larryvrh/MiniMax-H3-Turbo-Lora
text-to-video · ★713 · 0 dl

📈 Markets

NVDA 224.09 ▲3.0%
MSFT 492.43 ▼2.3%
GOOGL 343.54 ▼0.1%
AMZN 267.28 ▼1.8%
META 578.85 ▼3.4%
AMD 482.93 ▲1.8%
AVGO 416.05 ▼0.0%
PLTR 171.04 ▼2.2%
SPCX 146.15 ▲9.6%
TSLA 327.51 ▼1.6%

The BriefTwo tampered versions of a tool called LiteLLM, which a lot of companies use to route requests between different AI providers, were published to the main Python software repository in March and sat there for about 40 minutes before being pulled. That was long enough. Anything that installed during the window handed over its cloud keys, and the researchers who pieced it together count more than 2,500 organizations and 434,000 automated build pipelines, with Amazon, Samsung, Cisco, Salesforce and Siemens among the confirmed names. The part worth sitting with is not the size, it is that this happened in March and only surfaced this week, so the window between being compromised and knowing about it was four months.

Level UpThere is a free lookup for this one, so the first step takes about a minute: put your own domains through CloudSEK's exposure checker and see whether you appear in the reconstructed data. Then do the boring part, which is the part that actually prevents the next one. Go look at how your builds install dependencies. If anything says 'take the latest version', that is the door this walked through, because a poisoned release published for 40 minutes is only dangerous to a system that will accept whatever is newest. Pinning to an exact version and hash means a tampered release cannot install itself, and it turns a four-month blind spot into a decision somebody has to make on purpose. CloudSEK: check whether your organization is exposed