AI Titus's Morning Wire

AI NEWS TODAY

ONE BAD LINK COULD MAKE COPILOT QUIETLY HAND OVER YOUR EMAIL, FILES AND CALENDAR. MICROSOFT JUST PATCHED IT
★ Must-Read / Watch agentic engineering / build-better-agents📚 Learn state of AI coding / useful technique

⚡ AI Frontier · smol.ai

★ Must-ReadOpenAI hit the brakes on its next model after it got close to 'critical' hacking skill
On August 18 OpenAI said it paused its largest training run for two weeks. Early testing suggested the upcoming Astra model might find and use unknown security holes on its own, a level OpenAI itself labels Critical cybersecurity capability. This is the clearest case yet of a lab slowing itself down because of what its own model might do, not because a regulator made it. Read it two ways at once: real caution, and a company telling you how powerful its next product is.
📚 LearnGoogle put a Gemini assistant inside the Workspace admin console
Admin Assist rolled out August 17. Admins can ask in plain English how to change a setting, find a user, or read a report, and it answers from Google's own admin docs with links into the right console page. If you manage Google Workspace for clients, this is a real time saver on the long tail of settings nobody remembers the path to. It also means your clients' office managers can now find those settings themselves, for better and worse.
★ Must-ReadMojo, the GPU-first language that looks like Python, is now fully open source
Modular released Mojo under Apache 2.0 on August 18. Mojo aims at the gap between Python, which is easy but slow, and CUDA, which is fast but hard and tied to NVIDIA. Code that looks like Python compiles to run directly on GPUs from more than one vendor. Open sourcing it is the difference between a bet on one company and a language you can adopt without asking permission.
ChatGPT now tries to detect teens and moves them to a locked-down mode
Starting August 18, accounts OpenAI believes belong to 13 to 17 year olds get routed to a restricted ChatGPT: stronger blocks on self-harm, sexual and romantic content, and a parent-linked account that receives safety alerts. Parents still cannot read the chats. Rolling out over about two weeks. If you have kids using ChatGPT for homework, this changes what they see, and the age detection will sometimes guess wrong in both directions.
Meta shipped its first desktop app: a Mac assistant that can watch your screen
Free, small, and in beta as of August 19. It can see what is on screen when you ask, and it takes dictation into any app. That screen-watching permission is the part to think about before installing it on a work machine: an assistant that can read your screen can read whatever a client left open in the next window.
📚 LearnRunning models locally with llama.cpp? Two of its ten new flaws are rated critical
Ten vulnerabilities were disclosed in llama.cpp, the engine behind many self-hosted AI setups including parts of Ollama and LM Studio. The two worst, both in llama-server, scored 9.2 and 9.8 and allow remote code execution. Published earlier this month, so treat this as the patch reminder: if a llama-server is listening anywhere on your network, update it and make sure it is not exposed to the internet.

📺 Watch · latest videos

📚 LearnThe State of Model Routing — NVIDIA, Cognition, OpenRouter
Featured by Latent Space.
AI Engineer
📚 LearnVercel accuses Cloudflare of stealing
Featured by Latent Space.
Theo - t3․gg
IT Admin for the AI Workforce — Sarthak Aggarwal, Decawork
A code freeze that exists only as an instruction is not a boundary. Sarthak Aggarwal uses the Replit incident to make that point, and what makes it us
AI Engineer · 54 views · 3 likes
Sell These 5 Most In Demand AI Automations in 2026
Latest from Nate Herk.
Nate Herk · 1.6K views · 138 likes
DeepSeek Just Built the Next Generation of Coding Agents
Latest from Cole Medin.
Cole Medin · 10.5K views · 391 likes
★ Must-WatchHow to choose the right Claude model for any task
Choose a Claude model based on the complexity of the task. Then adjust the effort level to move between faster or more thorough results.
Claude / Anthropic · 4.2K views · 204 likes
★ Must-WatchHow to Turn a Business Question Into a Strategy Deck With ChatGPT Work | Tutorial
Turn a business question into a clear recommendation—without spending days gathering research and building slides. In this demo, Arvind from OpenAI’s
OpenAI · 6.4K views · 173 likes
You NEED to try this 6 Open-Source Projects NOW
Latest from Matthew Berman.
Matthew Berman · 69.6K views · 2.2K likes
FIXING Opus 5: PROOF that Prompt Engineering IS NOT DEAD
Opus 5 is one of the BEST models ever released, and one of the WORST to talk to. Verbose, "load-bearing" everywhere, torching your output tokens. So w
IndyDevDan · 25.6K views · 1.1K likes

🗣 Voices & Blogs

★ Must-ReadZvi Mowshowitz On Anthropic's Own August Risk Report
A close read of what Anthropic says about its own models' risks, including the existence of an internal Model 2 and the industry quietly moving its catastrophic-misalignment label from very low to low. Zvi's value is that he reads the primary document so you get the load-bearing sentences with the marketing stripped off.
Ben Thompson On What Stripe Buying OpenRouter Actually Means
His argument: whoever aggregates access to models, rather than whoever builds them, may end up with the pricing power, and a payments company understands that instinctively. Written August 19, the day the deal was announced. Paywalled after the opening, but the free portion carries the thesis.
Simon Willison On Mojo Going Open Source
The practical take: what Apache 2.0 licensing changes for people who want GPU speed without writing CUDA, and where Mojo actually stands today versus where Modular says it is going. Short, concrete, and honest about the gaps.
📚 LearnSimon Willison On Sandboxing Untrusted AI-Written Code With smolvm
A hands-on research note on running code you do not trust, including code an AI just wrote, inside tiny hardware-isolated virtual machines instead of shared containers. Cold starts of about a second, warm runs near 50 milliseconds, with no network, CPU and memory limits, and read-only inputs. If you are letting agents execute code anywhere, this is the current best answer to the question of where.
Stop the token bleed: building token-efficient multi-agent systems
Every engineering team deploying AI agents eventually discovers an uncomfortable truth: the model isn’t the biggest expense. The hidden cost The post… · The New Stack
Previewing Ultrafast mode: GPT-5.6 Sol at up to 14X the speed
Building the Systems Behind AI Agents | Rethinking the Future of Software Engineering | Key Developments Across the AI Frontier · via Berkeley RDI · Agentic AI Weekly

📦 What's Being Built · GitHub

affaan-m/ECC
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first dev · ★241.3K · JavaScript
NousResearch/hermes-agent
The agent that grows with you · ★233.4K · Python
deepseek-ai/deepseek-harness
DeepSeek Harness: Everything is a Plugin. · ★172.3K · TypeScript
firecrawl/firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥 · ★169.9K · TypeScript

🌏 The Wire · Drudge / Breitbart

STRIPE IS BUYING OPENROUTER FOR MORE THAN $7 BILLION, MONTHS AFTER A $1.3 BILLION VALUATION
Announced August 19. OpenRouter is the switchboard about 10 million developers use to route requests between AI models, over 10 trillion tokens a day. The payments company buying the model marketplace says plainly where the money in AI is expected to flow: through whoever sits in the middle of every call.
CHATGPT ADS EXPAND TO 31 EUROPEAN COUNTRIES STARTING AUGUST 24. PAID TIERS STAY AD-FREE
Free and Go users will see them, Plus, Pro and Enterprise will not. The free AI assistant is becoming an ad platform, which means the answers your staff get from a free account now live next to somebody's paid placement.
QWEN PASSES 3 BILLION DOWNLOADS, OVERTAKING META AND GOOGLE IN OPEN-MODEL REACH
Alibaba's open models are now the most downloaded family in the world. The open-weights race that Llama started is currently being won in China, and download counts are the one adoption number that is hard to spin.
GITHUB AND COPILOT WENT DOWN FOR NEARLY EIGHT HOURS MONDAY, AND COPILOT STAYED DOWN LONGER
The August 17 outage ran 7 hours 47 minutes. The detail worth keeping: Copilot kept failing after GitHub's core services recovered, which shows the AI layer is its own point of failure. If your developers cannot work when Copilot is down, that is now an availability dependency to plan for.
NVIDIA H200 CHIPS ARE REPORTEDLY REACHING CHINA DESPITE EXPORT RULES
Reports on August 19 say the chips are arriving through channels that skirt US export controls. Follows last week's story of shipments staged in Hong Kong. The control regime is leaking, and each leak weakens the case that export rules can hold back a rival's AI buildout.
COINBASE CUTS 700 JOBS AND TIKTOK 250 AS AI-DRIVEN LAYOFFS ROLL ON
Both announced this week, with TikTok closing its Nashville office. Same caution as always: companies have an incentive to call a cost cut an AI efficiency gain, because one reads as strategy and the other reads as trouble.
ANTHROPIC'S COMPLIANCE API NOW COVERS COWORK AND CLAUDE CODE SESSIONS
Security teams can now pull audit and eDiscovery data from employees' AI coding and Cowork sessions. If your clients are rolling Claude out company-wide, this is the checkbox their compliance officer was going to ask you about.

🤖 Trending Models · Hugging Face

Qwen/Qwen3.8-27B-FP8
image-text-to-text · ★622 · 1.5M dl
orcarouter/Qwen3.8-27B-Uncensored-FP8
image-text-to-text · ★656 · 76.1K dl
orcarouter/Qwen3.8-27B-Uncensored-MLX
image-text-to-text · ★669 · 2.6K dl

📈 Markets

NVDA 217.56 ▼1.0%
MSFT 484.31 ▲0.6%
GOOGL 344.72 ▲0.2%
AMZN 265.84 ▲2.5%
META 546.03 ▲0.4%
AMD 466.42 ▼3.7%
AVGO 362.48 ▼4.6%
PLTR 175.19 ▲2.1%
SPCX 139.65 ▼2.6%
TSLA 351.12 ▲4.2%

The BriefCopilot is the AI assistant Microsoft builds into Windows and Office. Researchers found that one bad web link could flip a hidden switch in Copilot Personal, the version tied to personal accounts. The link could make Copilot silently read a person's connected email, files and calendar, and even plant instructions that keep working after a password change. Prompt injection is the trick behind it: hiding commands inside content the AI reads. Microsoft fixed the flaw, called CVE-2026-24301, on August 18. Nothing to install, the fix is on Microsoft's side. The lesson stands anyway: every account you connect to an AI assistant is something one bad link could reach.

Level UpSpend twenty minutes this week listing every account and connector linked to Copilot or any AI assistant your company or clients use: mail, drive, calendar, CRM, anything. Then disconnect the ones nobody actually needs. The fewer systems an AI can reach, the less one bad link can steal. This is the AI version of least privilege, the old rule that every account should only reach what it truly needs. The full breakdown of how the attack worked and what Microsoft changed