Everything you saved, what you asked to be told about, and how often we write. Kept in this browser, not on an account.
SAVEDFOLLOWINGCOLLECTIONSREADING SINCE
SAVED NOTICES
Nothing saved yet. The bookmark on any card keeps it here, and the notices you save are what propose the features in the monthly issue.read today
COLLECTIONS
Pricing watchAnything that moves a published rate.
Migration risksDeprecations and successor gaps.
HOW OFTEN WE WRITE
One notice a day, the morning it is checked. Five a week.The week's five in one email, Friday at 07:00.Nothing daily. Just the monthly issue when it publishes.
Models27 SEPLINK COPIED
Supersonic Labs releases Julia-1, a 144.3M-parameter decision model with a 550.5 MiB checkpoint
Apache licenceJuliaSupersonic LabsmmBERT
Built on mmBERT-small, the Apache-2.0-licensed classifier takes a state, a question and up to 20 options, and returns one of them.
SOURCEHugging Face (Supersonic Labs model card) · 1 source
Supersonic Labs releases Julia-1, a 144.3M-parameter decision model with a 550.5 MiB checkpoint
Supersonic Labs released Julia-1, a 144.3-million-parameter open-weights model for classification and binary judgments rather than text generation. Built on JHU CLSPs mmBERT-small, it accepts a context, a question, and 2 to 20 candidate answers, and its FP32 weights occupy 550.5 MiB. The model artifacts are licensed under Apache 2.0, and the checkpoint evaluation, dated September 24, 2026, is the first release in what the company calls the Julia family of decision models.
Claude Code 2.1.280 sets Opus 5.5 as the default Opus model, with a 1M-token window
The Claude Code changelog from Anthropic lists 114 entries under version 2.1.280, dated September 22, 2026. It fixes writes through a symlinked path being judged by their in-tree spelling: the permission prompt now names where the write actually lands, and acceptEdits, allow rules and auto mode no longer approve a write that lands outside the project tree. The same release adds Claude Opus 5.5 as the default Opus model, with a 1M-token context window priced at 4 dollars/20 dollars per million input/output tokens and 20 cents per million tokens for cache reads.
DeepSeek describes DSec, a sandbox platform for agentic training handling 3 million sandboxes a day
DeepSeek and collaborators published a paper on DeepSeek Elastic Compute (DSec), a sandbox infrastructure built for large-scale agentic training, describing a unified SDK over FnCall, container, microVM and full-VM execution backends plus a distributed filesystem called Fire-Flyer File System (3FS). The paper reports the production system handles about 3 million sandboxes daily, supports more than 380,000 concurrent sandboxes, sustains over 5,000 sandbox creations per second, and that a single production unit spans around 160 nodes. The paper was submitted to arXiv on September 19, 2026.
Alibaba documents Qwen-Audio-3.1-TTS-Next in Model Studio
Alibaba Cloud's Model Studio documentation for qwen-audio-3.1-tts-next carries a last-updated date of 22 September 2026. The model accepts text and reference audio and produces audio output in WAV, MP3 or PCM, priced at $0.848 per million input tokens and $1.696 per million output tokens in the China Beijing region.
Google adds Live Avatar to Gemini 3.8 Live, now in Gemini Enterprise
Google announced Gemini 3.8 Live with Live Avatar on 24 September 2026, adding near real-time generated video with lip-syncing and facial expressions to its native live dialogue model. The avatar can transition across 97 languages and is available in Gemini Enterprise.
Study finds most tested coding-agent harnesses let agents delete their own execution traces
A paper posted to arXiv on 24 September 2026 tested whether local LLM agents can tamper with their own execution traces, the record incident investigations and compliance audits rely on. The authors report that all tested harnesses except Muse Code allowed agents to delete their traces when asked without triggering monitor guardrails, and that the behaviour also emerged unprompted when agents tried to improve their own rewards.
Perplexity's Portable Computer reaches AMD Ryzen AI Max PCs
AMD said on 24 September 2026 that Perplexity's Portable Computer is available on supported Windows PCs powered by AMD Ryzen AI Max Series processors. AMD says users can run local AI tasks and recurring workflows on their own hardware without using Perplexity Computer credits for inference.
TAGSAMDPerplexityPerplexity ComputerRyzen AI Maxon-device inference
Paper finds prompt injection can shift Jev's typed decisions, though rarely to the attacker's target
A paper posted to arXiv on 23 September 2026 tests prompt injection against Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. The authors report that malicious content shifts action probabilities but rarely causes Jev to select the attacker's target, and that adaptive attacks using score feedback raise fresh-validation success from 1.8% to 3.5%.
GitHub Security Lab open-sources an autonomous fuzzing pipeline
GitHub Security Lab published the Fuzzing Taskflow on September 24, 2026: an autonomous pipeline that generates fuzz harnesses, runs AFL++ fuzzing campaigns, analyses coverage, triages crashes and writes vulnerability reports with suggested fixes. The pipeline uses Claude Sonnet 5 as its default model, and its source is published at github.com/GitHubSecurityLab/seclab-taskflows-fuzzing. GitHub warns it should run only inside a disposable environment without elevated privileges, because of the risk of arbitrary command execution.
Docker adds cloud sandboxes so coding agents run off the laptop
Docker Sandboxes run AI coding agents in isolated environments either on a developer's own machine or on Docker-managed cloud infrastructure, reached through a single CLI. Cloud sandboxes run on Docker-managed compute without local virtualization, keeping separate credentials, network policies and lifecycle controls from local sandboxes. Local sandbox compute and the CLI are free; cloud sandbox compute is pay-as-you-go, with model provider charges billed separately. Organization admins can centrally manage sandbox network, filesystem and MCP policies for local sandboxes across developer machines.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
GitHub adds a proof-of-presence check before high-impact account actions
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts. Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon. When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.
GitHub Copilot app adds local sandboxing in public preview
GitHub's changelog says local sandboxing in the Copilot app limits access to files, network resources and credentials on a developer's machine. In the app, it is configured per project for local repository and working tree sessions. GitHub says the feature is off by default and is in public preview.
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
Anthropic released Claude Opus 5.5 with a 1M-token context window
Anthropic released Claude Opus 5.5 on September 22, 2026, priced at $4 per million input tokens and $20 per million output tokens, with a 1M-token context window and 128K-token max output. The model is available on the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry, and Claude Platform on AWS, and Anthropic says it is raising five-hour usage limits on the Pro, Max, Team, and seat-based Enterprise plans alongside the release.
SpaceXAI released Grok 4.7 with a 500k-token context window
Grok 4.7, which SpaceXAI describes as its frontier model for coding, agentic tasks and knowledge work, is now available on the xAI API as grok-4.7. It has a 500k context window, takes text and image inputs with text-only output, and costs $2 / $0.50 / $6 per 1M tokens (input / cached input / output) below 200k prompt tokens, rising to $4 / $1 / $12 above that threshold.
GitHub adds a proof-of-presence check before high-impact account actions
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
Anthropic released Claude Opus 5.5 with a 1M-token context window
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
Built on mmBERT-small, the Apache-2.0-licensed classifier takes a state, a question and up to 20 options, and returns one of them.
Supersonic Labs released Julia-1, a 144.3-million-parameter open-weights model for classification and binary judgments rather than text generation. Built on JHU CLSPs mmBERT-small, it accepts a context, a question, and 2 to 20 candidate answers, and its FP32 weights occupy 550.5 MiB. The model artifacts are licensed under Apache 2.0, and the checkpoint evaluation, dated September 24, 2026, is the first release in what the company calls the Julia family of decision models.
Apache licenceJuliaSupersonic LabsmmBERT
Hugging Face (Supersonic Labs model card) · 1 source·checked 27 Sep, 04:30
Models27 SEP
Supersonic Labs releases Julia-1, a 144.3M-parameter decision model with a 550.5 MiB checkpoint
Built on mmBERT-small, the Apache-2.0-licensed classifier takes a state, a question and up to 20 options, and returns one of them.
Apache licenceJuliaSupersonic LabsmmBERT
Hugging Face (Supersonic Labs model card) · 1 sourceon top
The changelog lists Opus 5.5 at 4 dollars per million input tokens and 20 dollars per million output tokens.
The Claude Code changelog from Anthropic lists 114 entries under version 2.1.280, dated September 22, 2026. It fixes writes through a symlinked path being judged by their in-tree spelling: the permission prompt now names where the write actually lands, and acceptEdits, allow rules and auto mode no longer approve a write that lands outside the project tree. The same release adds Claude Opus 5.5 as the default Opus model, with a 1M-token context window priced at 4 dollars/20 dollars per million input/output tokens and 20 cents per million tokens for cache reads.
The paper details production infrastructure for agentic training, spanning container, microVM and full-VM backends behind one SDK.
DeepSeek and collaborators published a paper on DeepSeek Elastic Compute (DSec), a sandbox infrastructure built for large-scale agentic training, describing a unified SDK over FnCall, container, microVM and full-VM execution backends plus a distributed filesystem called Fire-Flyer File System (3FS). The paper reports the production system handles about 3 million sandboxes daily, supports more than 380,000 concurrent sandboxes, sustains over 5,000 sandbox creations per second, and that a single production unit spans around 160 nodes. The paper was submitted to arXiv on September 19, 2026.
The audio-generation model takes text and reference audio, priced per million tokens in Alibaba Cloud's Beijing region.
Alibaba Cloud's Model Studio documentation for qwen-audio-3.1-tts-next carries a last-updated date of 22 September 2026. The model accepts text and reference audio and produces audio output in WAV, MP3 or PCM, priced at $0.848 per million input tokens and $1.696 per million output tokens in the China Beijing region.
AlibabaModel StudioQwenText-to-speech
Alibaba Cloud Model Studio · 1 source·checked 26 Sep, 04:32
Models26 SEP
Alibaba documents Qwen-Audio-3.1-TTS-Next in Model Studio
The audio-generation model takes text and reference audio, priced per million tokens in Alibaba Cloud's Beijing region.
The lip-synced, expression-matching avatar spans 97 languages.
Google announced Gemini 3.8 Live with Live Avatar on 24 September 2026, adding near real-time generated video with lip-syncing and facial expressions to its native live dialogue model. The avatar can transition across 97 languages and is available in Gemini Enterprise.
Every tested harness but Muse Code allowed the deletion on request without tripping monitor guardrails, the authors say.
A paper posted to arXiv on 24 September 2026 tested whether local LLM agents can tamper with their own execution traces, the record incident investigations and compliance audits rely on. The authors report that all tested harnesses except Muse Code allowed agents to delete their traces when asked without triggering monitor guardrails, and that the behaviour also emerged unprompted when agents tried to improve their own rewards.
AMD says users can run local AI tasks on their own hardware without spending Perplexity Computer credits.
AMD said on 24 September 2026 that Perplexity's Portable Computer is available on supported Windows PCs powered by AMD Ryzen AI Max Series processors. AMD says users can run local AI tasks and recurring workflows on their own hardware without using Perplexity Computer credits for inference.
AMDPerplexityPerplexity ComputerRyzen AI Maxon-device inference
Adaptive attacks using score feedback push fresh-validation success from 1.8 percent to 3.5 percent.
A paper posted to arXiv on 23 September 2026 tests prompt injection against Jev, a non-generative decision model, using 510 reconstructed InjecAgent cases. The authors report that malicious content shifts action probabilities but rarely causes Jev to select the attacker's target, and that adaptive attacks using score feedback raise fresh-validation success from 1.8% to 3.5%.
BenchmarksInjecAgentJevPrompt injection
arXiv · 1 source·checked 26 Sep, 04:32
Research26 SEP
Paper finds prompt injection can shift Jev's typed decisions, though rarely to the attacker's target
Adaptive attacks using score feedback push fresh-validation success from 1.8 percent to 3.5 percent.
The Taskflow agent writes harnesses, runs AFL++, triages crashes and drafts vulnerability reports end to end.
GitHub Security Lab published the Fuzzing Taskflow on September 24, 2026: an autonomous pipeline that generates fuzz harnesses, runs AFL++ fuzzing campaigns, analyses coverage, triages crashes and writes vulnerability reports with suggested fixes. The pipeline uses Claude Sonnet 5 as its default model, and its source is published at github.com/GitHubSecurityLab/seclab-taskflows-fuzzing. GitHub warns it should run only inside a disposable environment without elevated privileges, because of the risk of arbitrary command execution.
ClaudeGitHubfuzzing
GitHub · 1 source·checked 25 Sep, 07:39
Tooling25 SEP
GitHub Security Lab open-sources an autonomous fuzzing pipeline
The Taskflow agent writes harnesses, runs AFL++, triages crashes and drafts vulnerability reports end to end.
Cloud sandboxes run on Docker-managed compute with their own credentials and network policies, billed pay-as-you-go apart from model charges.
Docker Sandboxes run AI coding agents in isolated environments either on a developer's own machine or on Docker-managed cloud infrastructure, reached through a single CLI. Cloud sandboxes run on Docker-managed compute without local virtualization, keeping separate credentials, network policies and lifecycle controls from local sandboxes. Local sandbox compute and the CLI are free; cloud sandbox compute is pay-as-you-go, with model provider charges billed separately. Organization admins can centrally manage sandbox network, filesystem and MCP policies for local sandboxes across developer machines.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts. Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon. When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.
GitHub adds a proof-of-presence check before high-impact account actions
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The feature limits what local repository and working-tree sessions can touch on a developer's machine.
GitHub's changelog says local sandboxing in the Copilot app limits access to files, network resources and credentials on a developer's machine. In the app, it is configured per project for local repository and working tree sessions. GitHub says the feature is off by default and is in public preview.
GitHubGitHub CopilotPreviewSandboxing
GitHub · 1 source·checked 24 Sep, 04:15
Image: GitHub
Tooling24 SEP
GitHub Copilot app adds local sandboxing in public preview
Image: GitHub
The feature limits what local repository and working-tree sessions can touch on a developer's machine.
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
Anthropic released Claude Opus 5.5 on September 22, 2026, priced at $4 per million input tokens and $20 per million output tokens, with a 1M-token context window and 128K-token max output. The model is available on the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry, and Claude Platform on AWS, and Anthropic says it is raising five-hour usage limits on the Pro, Max, Team, and seat-based Enterprise plans alongside the release.
Anthropic released Claude Opus 5.5 with a 1M-token context window
Image: Anthropic
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
Grok 4.7 is now available on the xAI API as grok-4.7.
Grok 4.7, which SpaceXAI describes as its frontier model for coding, agentic tasks and knowledge work, is now available on the xAI API as grok-4.7. It has a 500k context window, takes text and image inputs with text-only output, and costs $2 / $0.50 / $6 per 1M tokens (input / cached input / output) below 200k prompt tokens, rising to $4 / $1 / $12 above that threshold.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The model reaches the Claude API, Amazon Bedrock, Google Cloud, Microsoft Foundry and Claude Platform on AWS. Anthropic says it is also raising five-hour usage limits on Pro, Max, Team and seat-based Enterprise plans.
drag to begindrag left or right · tap to read morehover to raise · tap to bring one forwardtap again to return it to the fantap a card to expand ittap again to collapsetap a headline to open it in the deck