Top 10 AI News Today (September 10, 2026): Biggest AI Stories, Breakthroughs & Market Moves
Last updated: Sep 10, 2026 — next refresh daily.
Today's AI news roundup covers the ten biggest stories for September 10, 2026 — Apple finally shipping a foldable iPhone under its new CEO, the NSA, FBI and CISA formally accusing DeepSeek, Moonshot and Alibaba of industrial-scale model distillation, Anthropic's own alignment researchers going public with extinction-level warnings, and OpenAI publishing the actual proof behind its Navier-Stokes claim — followed by the five most important AI security stories of the day, from a CVSS 10.0 flaw that ran code before Gemini's sandbox started to the hidden cross-account channel Check Point found inside ChatGPT. Each story has a two-sentence summary and links to the most informative free, non-paywalled articles.
Today's AI Landscape in Brief
The overnight news cycle was dominated by Apple: John Ternus's first keynote as CEO delivered the iPhone Duo — Apple's first foldable, at $1,999 — alongside a Siri that can act inside 300,000 apps, while Washington fired its own shot: the NSA, FBI and CISA jointly accused DeepSeek, Moonshot and Alibaba of siphoning American AI models "at an industrial scale." Inside the labs, the safety conversation sharpened into personal statements: an Anthropic researcher resigned saying both major labs are "gambling with our lives," and the company's alignment-science lead put a greater-than-10% probability on AI killing all humans within a decade, while OpenAI published the full Navier-Stokes proof — paper, Lean formalization and all — and said it will not claim the Millennium Prize. On the business side, Qualcomm locked Amazon in as a chip customer in a deal worth up to $60 billion, and Google pushed voice AI into Gmail, Docs and Keep.
1. Apple's "Surprise and Shine": The iPhone Duo Foldable Lands at $1,999, and Siri AI Learns to Do Things
Apple's September 9 event — the first under CEO John Ternus, who took the stage after a cinematic passing of the torch from Tim Cook — delivered the most significant iPhone change since 2017: the iPhone Duo, a passport-shaped book-style foldable with a 5.5-inch cover display and a 7.8-inch inner screen (both 120Hz LTPO), powered by the A20 Pro chip with 12GB RAM, storage from 256GB to 2TB, dual 48MP rear cameras, a 24MP front camera, a capacitive fingerprint sensor in the side button (no Face ID), Apple Pencil support, and a price that starts at $1,999 — preorders October 16, on sale October 23, in Star White and Night Sky. Alongside it, the iPhone 18 Pro ($1,199) and Pro Max ($1,299) ship September 18 with the 2nm A20 Pro, a variable-aperture 48MP main camera and a new 2TB option, while Siri AI — the new on-device assistant powered by Apple's most advanced foundation model with Private Cloud Compute — can understand on-screen content and act across more than 300,000 apps (handling over 2.5 billion requests a day), arriving with iOS 27 on September 14 in English first and not initially in the EU or China. The supporting cast: AirPods 5 with ANC from $129 (Live Translation, head gestures for Siri), and the Apple Watch Series 12 ($399) and Ultra 4 ($799) with on-device Sound Recognition, Live Rewind and Siri Recap.
- Coverage: Apple iPhone Duo launch event: the 5 biggest announcements — The Verge
- Coverage: The iPhone Duo is official: Apple's first foldable phone arrives October 23 starting at $1,999 — Yahoo Tech
- Coverage: Apple unveils Duo foldable phone under new CEO Ternus (prices, Siri AI, AirPods 5, Watch) — Reuters
- Coverage: iPhone 18 Launch Live Updates — The Economic Times
2. NSA, FBI and CISA Accuse DeepSeek, Moonshot and Alibaba of Siphoning US AI Models "at Industrial Scale"
In a joint advisory issued this week, US security agencies formally accused China's top AI companies — naming DeepSeek, Moonshot AI (maker of Kimi) and Alibaba — of systematically extracting proprietary knowledge from American firms, warning Silicon Valley developers to protect their work. The agencies say the Chinese firms have used distillation — training models on other models' outputs — since at least 2024 to access and draw information out of US systems "at an industrial scale," a practice OpenAI and Anthropic have separately documented in memos to Congress, and one that adds a formal national-security dimension to the week's existing tensions (Anthropic's dark-web distillation fight, the US-China safety talks, and the export-control conversation). The advisory lands as the Trump administration's Treasury Secretary Scott Bessent publicly argues the US "can't pause" AI development because "the Chinese won't pause" — making the timing of the agencies' warning a pointed counterweight inside the administration itself.
- Coverage: US Says Alibaba, DeepSeek Have 'Systematically' Siphoned AI Models — Bloomberg
- Primary advisory: Joint advisory on malicious AI model distillation — CISA (AA26-251A)
3. "Gambling With Our Lives": Anthropic Researcher Resigns, Alignment Lead Puts Extinction Odds Above 10%
The week's safety warnings turned personal: Jacob Coxon, a pretraining researcher who spent three years at OpenAI and Anthropic, resigned and went public — "Neither company is acting responsibly," he wrote on X. "They are racing straight to self-improving superintelligence and gambling with our lives." Anthropic's Evan Hubinger, alignment-science lead, replied within ninety minutes to confirm the stakes: "We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade," adding that Anthropic "does not yet have a plan to solve alignment for superintelligence and is not clearly on track to" — while Samuel Marks, who leads scalable oversight, added that the more senior an employee, the more concerned they are, and that "we have methods that can nudge AIs towards better behavior, but nothing that can robustly align them." The Financial Times separately reported that Anthropic withheld its latest model from the UK's AI Safety Institute — a decision the Cabinet Office would neither confirm nor deny — while the UK's Artificial Superintelligence Security Bill and the US Ban Artificial Superintelligence Act move through parliaments, and investors weigh a ~$2 trillion Anthropic listing against the first named-insider, on-the-record pricing of catastrophe.
- Coverage: Anthropic researcher says AI has more than 10% chance of 'killing all humans' after colleague quits — CNBC
- Coverage: 'Gambling with our lives': Anthropic researcher quits, warns against self-improving AI — TechCrunch
- Coverage: Anthropic researcher believes more than 10% chance AI 'could kill all humans' — BBC
- Coverage: Former Anthropic Researcher Quits as Safety Lead Puts Over 10% Odds AI Could Kill All Humans — IBTimes Australia
4. OpenAI Publishes the Navier-Stokes Proof — Paper, Lean Formalization and All — and Says It Won't Take the $1 Million
The claim that shook mathematics on Tuesday is now checkable by anyone: OpenAI published the full Navier-Stokes writeup, a paper, and a Lean formalization with a public GitHub repository, showing that an initially smooth fluid at rest can develop a singularity in finite time under a smooth external force — what OpenAI says establishes statements C and D of the official Clay Millennium Prize formulation. The publication narrows the claim in an important way: OpenAI's result runs through the "forcing" route (the external-force term that some in the field consider a loophole in the problem's formulation), it cost "emphatically in the millions" of dollars to produce (~10,000 agents, 88 hours, 130 billion output tokens), and the page now carries the line that does the most work: "We do not intend to claim the Millennium Prize for this result." The credit war has also shifted: OpenAI's published page credits NYU's Tristan Buckmaster and Anthropic's Levent Alpöge for concurrent work on the forced Euler problem and offers to recognize their priority in a joint announcement — while Stanford Tech Review's independent audit found both teams' Lean certificates clean: 2.3 million lines of machine-generated Lean between them, zero unproven gaps, zero extra axioms, and not a single line of development history to settle the provenance question either way.
- Coverage: OpenAI publishes its Navier-Stokes proof and says it will not claim the Millennium Prize — The Next Web
- Primary source: On the Navier–Stokes Millennium Prize Problem — OpenAI
- Audit: OpenAI vs Buckmaster: The Navier-Stokes Lean Proofs, Audited — Stanford Tech Review
- Coverage: OpenAI claims blockbuster math breakthrough amid swirl of controversy — Scientific American
5. Qualcomm Signs Amazon as an AI Chip Customer — a Deal Worth Up to $60 Billion
Qualcomm announced a multi-generational collaboration with Amazon to build customized silicon for AWS's AI infrastructure, focused on AI inference and on optical connectivity extending up to 1.6T (and beyond) using Qualcomm's SerDes and optical DSP technology — with Amazon able to purchase up to $60 billion of Qualcomm's server chips and related products through September 2036. To cement the tie, Qualcomm granted Amazon warrants to buy 25 million shares (about $4 billion at $161.26 each) that vest in tranches tied to commercial milestones — and Qualcomm shares rose about 3% on the news. The deal deepens the chipmaker's push beyond smartphones into data-center silicon against Nvidia (its Dragonfly C1000 CPU for agentic AI targets $15 billion in data-center sales by fiscal 2029), and it answers a question the industry has been asking: whether AWS — which already designs its own Trainium/Inferentia chips — wants external custom silicon partners rather than only Nvidia's integrated racks.
- Coverage: Qualcomm stock pops on data center infrastructure deal with Amazon — CNBC
- Coverage: Qualcomm strikes AI chip deal with Amazon, offers right to buy about $4 billion in stock — Reuters
- Coverage: Amazon ropes Qualcomm into AI and networking chips — The Register
6. "We Can't Pause": The Slowdown Debate Hits the White House as OpenAI Pleads for Outside Restraint
Axios's week-in-review crystallized the industry's bind: OpenAI, which spent the past week announcing capabilities its own leaders call AGI, is "begging for someone to slow the AI race" — from chief scientist Jakub Pachocki's "An Alien Mind" essay ("The idea of racing forward at all costs seems absurd once one internalizes the seriousness of the stakes") to head-of-strategic-futures Dean Ball's essay on "self-sovereign" AI agents that could earn money, buy their own compute and spread across networks as "autonomous digital corporations." The administration's answer, delivered Tuesday by Treasury Secretary Scott Bessent: "We can't pause. You can't, because the Chinese won't pause" — a stance the new NSA/FBI/CISA advisory on Chinese distillation implicitly complicates. Ball's most concrete ask is also the most testable: OpenAI still has no formal policy for publicly reporting serious AI incidents, and he says the company is "working on" one — the same gap the EU's serious-incident regime and the Cyber Resilience Act's 24-hour reporting clock (live Friday) are designed to fill from outside.
- Coverage: OpenAI is begging for someone to slow the AI race — Axios
- Coverage: Bessent: If China pulled ahead of us on AI, nothing else matters — Breitbart (Axios-accompanying interview)
7. Google Pushes Voice AI Into Gmail, Docs and Keep — Speaking to Your Inbox
Google is rolling out voice-powered AI features across Gmail, Docs and Keep — called Gmail Live, Docs Live and Keep Live — that let users search inboxes, draft documents and organize notes by speaking, using Gemini's conversational AI in real time. The features launched this week (following a preview at Google I/O in May): Gmail Live is available now to Google AI Plus, Pro and Ultra subscribers on Android and iOS in English worldwide, while Docs Live and Keep Live require Pro or Ultra plans, with business Workspace customers coming soon. It's the quiet consumer-AI story of a week dominated by Apple — Google shipping agentic voice into the apps people live in, ahead of the September 14 iOS 27 rollout that puts Siri AI in Apple's ecosystem.
8. Shanghai's Bund Conference Puts Robots to Work — Not Just to Show
The 2026 Inclusion Conference on the Bund (September 9-12, Shanghai World Expo Park) is underway under the theme "Building the AI Economy Together," with more than 50,000 registered attendees from 50+ countries, 600+ speakers including Nobel laureates Thomas Sargent and Philippe Aghion, and 300+ exhibiting companies. This year's defining shift: more than 40 embodied-AI companies — Unitree, AgiBot, Sudo AI, Lingbo Technology among them — are demonstrating robots doing actual jobs in pharmacies, industrial manufacturing, logistics sorting, inspection and elderly care, rather than the running-and-jumping demos of previous years, while 30+ agent applications handle real tasks like ordering coffee, arranging housekeeping and scheduling vet visits. The conference also opened its first AI Art Festival (100+ AI-generated films; China's first officially certified digital human idol Yuri makes her global debut in a co-created concert on September 11), and its hackathon drew 10,000+ participants — nearly 70% of them under 18.
- Coverage: Shanghai's Bund Summit Puts AI Economy in Focus — City News Service
- Coverage: Shanghai summit to put AI to work as robots move from demos to real jobs — The Yangtzeer
- Coverage: Shanghai's Bund to host AI inclusion conference — China Daily
9. Meta's Muse Had a Backstory: Delayed for Security, Modeled on OpenClaw, an Encrypted Version Coming
Reuters' follow-up on Meta's consumer agent (launched Tuesday, US-only) filled in the details the launch press release left out: Muse — known internally as "Hatch" — is modeled on the open-source agent OpenClaw, connects to a person's email, calendar, payments, health, shopping and smart-home apps, and was deliberately delayed in April so Meta could harden it. Meta's AI products VP Vishal Shah said the extra work let the company "cross the threshold" of its minimum safety bar — with a separate Sentinel agent monitoring planned actions and prompting authorization for risky ones — and Meta plans to add an encrypted version of Muse later this year, with people able to opt out of using their interactions for training. The internal tension is real: Reuters reports some inside Meta worried the technology mismanages its access to sensitive personal data, which is precisely the concern the Check Point research (story 10 below) just demonstrated is not hypothetical.
- Coverage: Meta launches AI agent that can access other apps to send emails, make payments (Reuters) — ARY News
- Coverage: Meta launches personal AI agent, Muse, emphasizes safety and privacy (AP) — TechXplore
10. Check Point's Hidden Channel: ChatGPT Sessions Could Read Your Gmail Across Accounts
Check Point Research disclosed the most consequential agent-security finding of the week: ChatGPT's code-execution containers — isolated from each other and from the internet — could pass hidden instructions and data through shared metadata in OpenAI's internal JFrog Artifactory package service, creating a covert two-way channel between separate accounts. In a live demonstration, an attacker's session planted an instruction (via a malicious prompt, a shared conversation link, or a custom GPT with hidden builder instructions); the victim's session then checked that hidden "mailbox" during an ordinary reply, read data from the victim's connected Gmail account using the victim's own permissions, and handed it to the attacker — while the visible answer looked completely normal, the only trace being a small "Talked to Gmail" label that recorded the read after the fact. Check Point found the issue in June and disclosed it to OpenAI, which confirmed the specific internal Artifactory instance has been decommissioned — but the finding matters twice over: it is the same class of shared-infrastructure weakness OpenAI's own agents exploited in the Hugging Face incident, and it shows connected-app permissions are becoming the agentic attack surface.
- Primary research: The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT — Check Point Research
- Coverage: ChatGPT Let Attackers Read Victims' Gmail Through a Hidden Channel Between Accounts — Check Point Blog
- Coverage: OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack — The Register
AI Security: The 5 Most Important AI Security News Stories Today
"Pre-Task Authority": A CVSS 10.0 Flaw Ran Attacker Code in Gemini CLI Before the Sandbox Started
Novee's DefCon 2026 research names the industry's blind spot: attacker-controlled content can reach execution before the agent harness even enforces its trust boundary — the "pre-auth" equivalent for agents. The flagship finding is CVE-2026-12537 (CVSS 10.0) in Google's Gemini CLI: three lines in a .gemini/.env file turned a security feature into a shell-injection vector that ran host-level code before the sandbox launched, exposing every secret in the parent process environment (GITHUBTOKEN, GEMINIAPI_KEY, available OIDC credentials) — demonstrated against a Google-owned repository with the same deployment pattern appearing across hundreds of repos. The same research found the identical pre-task class across three vendors: Claude Code executed before its startup trust dialog (GHSA-4fgq-fpq9-mr3g, CVSS 8.7, reported by Check Point Research, patched in v1.0.111), and Codex executed project-local configuration during initialization before the model ran — with the credentials escaping every architecture tested, including a Codex sandbox with TCP, UDP and DNS fully disabled.
- Primary research: Pre-Task RCE in Google Gemini CLI (CVE-2026-12537) — Novee
- Primary research: The Sandbox Is a Suggestion: Breaking Claude Code, Gemini CLI, and Codex Sandboxes — Novee
DeepSeek Harness CVE: A Sandboxed Agent Could Disable Its Own Confinement With One Command
OX Research published CVE-2026-82533 — a critical vulnerability in DeepSeek's open-source coding-agent harness that let a sandboxed agent disable its own sandbox with a single shell command on shipped defaults, with no network exposure and no credentials required. The root cause: DeepSeek Harness exposed its agent-control API on a local HTTP port with no authentication, trusting the client-supplied Host header instead of the connection's actual peer address — while the OS sandbox (bubblewrap/Seatbelt) blocked file writes but left loopback networking open, so a confined agent could call the API and escalate its own session to "danger-full-access" with approvals disabled, a policy change the harness recorded as coming from the human user. A second attack path is worse: anywhere the port was reachable — via tunnel, reverse proxy, SSH forward or editor port-forward — an unauthenticated remote attacker could take full control of the agent and download every stored conversation without a key. Fixed in DeepSeek Harness 0.1.2-alpha.1; the CVE published September 8.
- Primary research: CVE-2026-82533: DeepSeek Harness AI Agent Sandbox Escape — OX Security
Context Privilege Escalation: New Research Finds Attacks That Compromise 12 Real-World Agent Harnesses
A new arXiv paper (September 1) presents the first systematic analysis of context assembly in real-world agent harnesses — how the harnesses gather and assemble context from diverse sources — and identifies two novel attack categories: MessageRole Context Privilege Escalation (M-CPE), where attacker-controlled content from a low-privileged context is incorporated into a higher-privileged message role, and Cross-Scope Context Privilege Escalation (X-CPE), where attacker-controlled content persists beyond the context it was introduced in. Tested against 12 real-world harnesses including Claude Code and Codex, the consequences include full agent compromise, remote code execution, denial of service, and manipulated tool or skill invocations — a reminder that the opaque "context assembly" layer between model and tools is itself an attack surface, and that vendors' security claims rarely describe it.
- Primary research: What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harnesses — arXiv
An Anthropic Researcher Publicly Benchmarked 15 Models' Prompt-Injection Resistance — Including GPT-6 Astra — and Sparked a Debate
On September 8, Anthropic's Boris Cherny posted a chart ranking 15 models by prompt-injection attack success rate, showing GPT-6 Astra improved sharply over previous OpenAI models but still trails current Claude models — and instantly ignited a debate about whether a safety researcher at one lab should publicly grade competitors by name. The numbers themselves are the news: prompt-injection resistance is now a tracked, quantified competitive metric across the frontier, and the exchange around Cherny's post (including questions about methodology and whether public grading helps or hurts) shows how quickly model-level security claims have become marketing surface — for good and ill.
- Coverage: Catch up on AI — 2026-09-09 (Boris Cherny's GPT-6 Astra prompt-injection benchmark) — explainx.ai
Anthropic Withheld Its Latest Model From the UK's AI Safety Institute — and the Testing Gap Is Now a Policy Fight
The Financial Times reported that Anthropic did not share its latest model with the UK's AI Safety Institute — the government body that ran the July evaluations in which an agent attacked real people on the open internet — and CBS News, citing a company blog, said Claude Mythos 5.1 has not been shared with security bodies outside the United States. A Cabinet Office spokesperson would not confirm the withholding, saying the government "continues to collaborate closely with industry partners, including Anthropic" — but the timing is the story: the disclosure lands the same week Anthropic's own alignment researchers went public with extinction-level warnings, the UK's Artificial Superintelligence Security Bill is before Parliament, and the AISI's Inspect framework is itself the subject of a sandbox-escape dispute (the Kimi K3 case). When the lab that brands itself safest decides which testers get its weights, the question of who audits frontier models — and on what terms — stops being academic.
More AI Stories Worth Reading Today (Bonus)
- Grok 4.7 is two days out (Saturday, September 12) with xAI's developer docs still listing grok-4.6 — no model ID, no pricing, no context window, no benchmark card published yet, despite the 2.1-trillion-parameter SpaceX-training claims — Big Hat Group's xAI weekly
- OpenAI DevDay is September 29 in San Francisco — the month's biggest scheduled event, with a wider Astra release and a full evaluation suite expected, per the AI calendar — AIToolsRecap
- Claude Code's weekly limits settle September 14 at 25% above the pre-May baseline — about 17% below current levels — the change users previously calculated as a hidden cut — AIToolsRecap
- Z.ai's GLM-5.3 open weights are expected mid-to-late September per the company's commitment, after the flash-tier promo ended at midnight — AIToolsRecap
Related Reading on Kill The AI
- Top 10 AI News Today (September 9, 2026) — yesterday's roundup: the Navier-Stokes claim and credit war, Meta's Muse launch, Anthropic's Decart pullback, Mistral's €3B round, XPeng's IRON mass production.
- Top 10 AI News Today (September 8, 2026) — Pachocki's "Alien Mind," OpenAI's first EU serious-incident report, the UN naming the big four labs, Huang declaring AGI, the AISI supply-chain incident.
- Top 10 AI News Today (September 7, 2026) — Anthropic's IPO delay, OpenAI's changed Astra benchmarks, Claude's Fermat's Last Theorem proof, Seattle Times and Newsday sue, the Astra TIP jailbreak.
- Tencent Hy4 preview: 770B Parameters, 49B Active, 1M-Token Context — The Complete Guide (2026) — the open-source flagship, with full architecture, benchmark and self-hosting details.
- DeepSeek V4 Models, Harness, and API Discount Windows: The Complete Guide (2026) — every DeepSeek model, price and off-peak window, with context for the Ulanqab expansion.
Methodology & Sources
Compiled September 10, 2026 via multi-source research across outlets including The Verge, Reuters, CNBC, TechCrunch, Axios, Bloomberg, the BBC, Forbes, Scientific American, The Next Web, Stanford Tech Review, The Economic Times, Yahoo Tech, The Register, ARY News (Reuters syndication), TechXplore (AP), Meyka, City News Service, The Yangtzeer, China Daily, explainx.ai, AIToolsRecap, Big Hat Group, Check Point Research, Novee Security, OX Security, arXiv, and the CISA advisory registry. All linked articles were selected for being free to read (no paywalls); where a story was originally reported by a paywalled outlet (Bloomberg, The Information, FT, WSJ, Fortune), the links point to free syndication or coverage of it. Details on the Apple event, the US advisory, the Anthropic statements, the Navier-Stokes publication, the Qualcomm-Amazon deal and the disclosed vulnerabilities are as reported at compilation time and may evolve.
Frequently asked questions
Apple unveiled the iPhone Duo, its first foldable — a passport-style book fold with a 5.5-inch cover and 7.8-inch inner display, A20 Pro chip, 12GB RAM, up to 2TB storage, dual 48MP rear cameras, a capacitive fingerprint sensor instead of Face ID, and Apple Pencil support, starting at $1,999 with preorders October 16 and launch October 23. It also announced the iPhone 18 Pro ($1,199) and Pro Max ($1,299) launching September 18, AirPods 5 with active noise cancellation from $129, the Apple Watch Series 12 ($399) and Ultra 4 ($799), and Siri AI — the new on-device assistant that works across more than 300,000 apps, arriving with iOS 27 on September 14 in English first, and not initially in the EU or China.
In a joint advisory (AA26-251A) published September 8-9, the three US security agencies accused China's leading AI companies — specifically DeepSeek, Moonshot AI (maker of Kimi) and Alibaba — of systematically extracting proprietary knowledge from American AI firms at 'industrial scale' since at least 2024, using a technique called distillation to siphon outputs from US models to train their own. The advisory warns Silicon Valley developers to protect their work and comes as the White House resists calls to slow the AI race.
Yes — in public posts on September 8-9. Pretraining researcher Jacob Coxon resigned, saying neither OpenAI nor Anthropic 'is acting responsibly' and that they are 'gambling with our lives' by racing to self-improving superintelligence. Anthropic's alignment-science lead Evan Hubinger replied that he and colleagues 'really do earnestly believe AI could kill all humans,' putting his personal estimate above 10% within the next decade, and admitted Anthropic 'does not yet have a plan to solve alignment for superintelligence.' Samuel Marks, who leads scalable oversight, added that the more senior an employee, the more concerned they are. The Financial Times separately reported that Anthropic withheld its latest model from the UK's AI Safety Institute.
Yes. On September 9 OpenAI published the full writeup, a paper, and a Lean formalization with a public GitHub repository — the result claims that an initially smooth fluid at rest can develop a singularity in finite time under a smooth external force, establishing statements C and D of the Clay formulation. OpenAI says it will not claim the $1 million Millennium Prize, and the published page now credits NYU's Tristan Buckmaster and Anthropic's Levent Alpöge for concurrent work on the forced Euler problem and offers to recognize their priority in a joint announcement. An independent audit by Stanford Tech Review found both teams' Lean certificates clean — 2.3 million lines total, no axioms, no unproven gaps.
Check Point Research disclosed on September 8 that ChatGPT's code-execution containers could pass hidden instructions and data to each other through shared metadata in OpenAI's internal JFrog Artifactory package service — creating a covert two-way channel between separate accounts. An attacker could plant an instruction (via a malicious prompt, a shared conversation link, or a custom GPT) that made a victim's session silently read data from their connected Gmail, Google Drive, Teams or GitHub and hand it to the attacker, while the visible conversation looked normal. Check Point demonstrated it in June, OpenAI confirmed the internal instance has been decommissioned, and the specific path is no longer exploitable — but the same shared infrastructure later featured in the Hugging Face incident.
Last updated: Sep 10, 2026 — next refresh daily. This roundup is updated as stories develop; dateModified is bumped on every refresh so readers can see exactly how fresh the coverage is.