RisiAi Logo
RisiAi Tech News
Daily Brief

OpenAI's Astra Hits the Cyber Red Line as Texas and NYC Rein In AI

daily tech

OpenAI’s Astra Hits the Cyber Red Line as Texas and NYC Rein In AI

AI & Machine Learning

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1, calling them its most advanced models for coding, knowledge work and long-running agentic tasks. The two are the same underlying model shipped with different safeguards: Fable 5.1 is generally available, while the more permissive Mythos 5.1 is restricted to vetted “trusted access” programs for cybersecurity and life-sciences work. Anthropic says the model beats Fable 5, Opus 5 and OpenAI’s GPT-5.6 Sol across a range of benchmarks and roughly doubled its internal agentic-science scores. Pricing drops sharply — about 25% cheaper than Fable 5 for typical workloads and up to 45% cheaper for heavily agentic use, driven by a 75% cut to cached-input reads. The launch lands alongside a companion “Enterprise Frontier Safeguards” program that pairs zero data retention with automated misuse detection inside customer-controlled cloud storage. Source: VentureBeat Verified: True

OpenAI said its forthcoming Astra model is the first it has rated at the “Critical” cybersecurity tier of its Preparedness Framework, meaning it can find and exploit previously unknown software vulnerabilities with little or no human guidance. In testing, Astra scored a perfect result on the ExploitBench hacking benchmark and discovered and weaponized two zero-day flaws in a modified internal build of OpenAI’s own systems. The company says access to its most dangerous capabilities will be tightly gated through a limited “Daybreak Blue” tester program, with chain-of-thought monitoring, account-risk scoring and jailbreak classifiers layered on top. The disclosure came the same week Google unveiled Gemini 3.8 Flash Cyber and a “Fairwind” early-access program for governments, hospitals and telecoms, and Anthropic restricted its Mythos 5.1 model on similar grounds. Frontier labs are now openly treating offensive-security capability as a release-gating risk rather than a selling point. Source: TechCrunch Verified: True

Consumer Hardware

Perplexity began rolling out “Hybrid Compute” for its Computer agent, letting a single AI task start in the cloud and hand the sensitive portions to a smaller open-weight model running locally on an Apple-silicon Mac. The company says it is the first agent that can dynamically split one job this way without restarting or losing context, keeping data such as financial and health records on the device while cloud models handle heavy reasoning. A built-in privacy classifier — which Perplexity open-sourced so enterprise IT can audit it — decides what stays local. The feature runs in Perplexity’s desktop app for opted-in enterprise, Pro and Max subscribers on Macs with at least 24GB of unified memory, using local models including Google’s Gemma 4 and Alibaba’s Qwen3.6. It is a concrete answer to the data-residency objections that have slowed agent adoption in regulated industries. Source: VentureBeat Verified: True

Meta has started permanently disabling the cameras on second-generation Ray-Ban Meta, Oakley Meta and Meta smart glasses when a device detects that its recording-indicator LED has been covered or physically altered. The move follows a wave of reports of wearers filming strangers without consent, and the emergence of paid services — one charging about $60 — that rewire the internal circuitry to kill the privacy light. Meta estimates fewer than 0.1% of glasses sold have been tampered with, which given roughly 7 million units sold in 2025 still puts the affected population in the thousands. The camera lockout ships as a mandatory firmware update that cannot be declined. It is one of the first cases of a hardware maker remotely disabling a core feature specifically to enforce the privacy of bystanders rather than the owner. Source: Semafor Verified: True

Cybersecurity

Attackers are actively exploiting CVE-2026-82329, a critical authentication-bypass flaw in the default configuration of JFrog Artifactory that lets an unauthenticated attacker on the network forge administrative tokens. Researchers at watchTowr observed threat actors “minting themselves admin tokens” in the wild, which grants the ability to read stored artifacts, alter security settings and poison packages that downstream build systems automatically consume. JFrog patched the issue on August 28 across a long list of releases (7.111.21, 7.117.28, 7.125.20 and others) and says its cloud service was never exposed. Crucially, upgrading does not revoke tokens that were already issued, so administrators must rotate credentials and hunt for signs of earlier compromise. Software supply-chain infrastructure such as artifact registries stays a high-value target because a single foothold can taint many builds. Source: BleepingComputer Verified: True

Exploitation has begun against CVE-2026-0768, a CVSS 9.8 unauthenticated remote-code-execution bug in the code validator of Langflow, a widely used open-source tool for building LLM workflows. VulnCheck reported continuous attacks starting August 29 from roughly 20 IP addresses across more than six countries, with its UK honeypots alone hit by at least 50 attempts over one weekend and observed attack volume climbing into the hundreds. Successful exploitation runs code as root without any login, after which attackers search the host for Langflow secret keys, .env files, SSH keys and cloud credentials — specifically hunting AWS secrets and OpenAI API keys. All Langflow releases up to version 1.4.2 are affected; the flaw was first disclosed as an unpatched zero-day in January 2026. The episode underscores how quickly AI-tooling servers, often stood up informally by developers, are being folded into commodity credential-theft campaigns. Source: SecurityWeek Verified: True

Enterprise Infrastructure

Oilfield-services giant SLB agreed to buy German thermal-management specialist Kelvion for about $4.1 billion — $3.4 billion in cash plus roughly $700 million of assumed debt — a bet that cooling is becoming the binding constraint on AI data centers. Kelvion builds heat exchangers, dry coolers and hybrid and waterless cooling systems, which SLB plans to bundle with its modular data-center infrastructure business. The company noted that modern GPU racks already exceed 100 kW of power density and that some announced chip architectures approach 1 MW per rack, well beyond what air cooling can handle. SLB values the deal at about 11 times Kelvion’s estimated 2026 EBITDA, or 8.5 times after expected synergies, with closing targeted for the first half of 2027. It is another sign of industrial and energy firms repositioning around the AI buildout. Source: Data Center Knowledge Verified: True

Tencent-backed Chinese AI-chip designer Enflame Technology opened subscriptions on September 2 for a Shanghai STAR Market listing aiming to raise about 6.1 billion yuan ($908 million), and drew extraordinary demand. Online retail orders ran to roughly 6,109 times the shares on offer — about 5.98 trillion yuan chasing the retail tranche — forcing Enflame to move millions of shares out of the institutional book and leaving successful applicants with a 0.025% allocation rate. Tencent owns about 20% of the company and remains its largest customer; proceeds are earmarked for Enflame’s fifth- and sixth-generation accelerators and related software. Enflame is one of the “four little dragons” of Chinese GPU startups being pushed to fill the gap left by restricted Nvidia supply. The frenzy reflects how aggressively Chinese capital is backing a domestic AI-silicon stack. Source: Investing.com Verified: True

Policy & Regulation

New York City, the largest school district in the US, will bar students through eighth grade from using generative AI tools for the 2026-27 school year, a one-year moratorium Mayor Zohran Mamdani’s administration is calling the most expansive such prohibition in the country. The ban covers “all software that uses student-facing generative AI” for roughly 600,000 elementary and middle-school students, and companion chatbots are prohibited at every grade level. High schools move the other way: the city is adding twice-yearly AI-literacy classes for all high-schoolers and piloting supervised access to a handful of vetted AI platforms. Officials framed the split as protecting younger children’s foundational skills while preparing older students for AI-heavy workplaces. The decision followed a City Council letter, signed by more than half its members, urging a two-year pause over data-privacy and pedagogy concerns. Source: Engadget Verified: True

Texas has become the first major US data-center hub to halt new grid connections for the facilities while it investigates whether the demand is real. Requests to connect large loads to the ERCOT grid have ballooned from about 48 GW in 2023 to more than 474 GW — over five times the state’s record peak demand — and officials say there is no consistent standard for how utilities report projects, so much of the pipeline may be “ghost” demand from speculative or duplicated filings. Under Governor Greg Abbott’s order, developers must supply information letting regulators verify a project is genuine or be denied interconnection. Pennsylvania Governor Josh Shapiro has since made a similar move. The pause is an early test of how grid operators separate committed AI-infrastructure investment from a queue inflated by optionality. Source: Utility Dive Verified: True