AI Briefing — 12.09.2026
🚀 Innovation
DeepSeek V4.1 Flash is out: 552B MoE, only 8B active, open weights. Released on 10.09.2026, the multimodal model pairs a 552B-parameter MoE backbone with a new asymmetric Causal-Encoder-Decoder architecture (8B active input, 16B output), 1M token context and a roughly 4x smaller KV cache than V4 Flash. Two days after launch it topped LiveBench as the best open model (5th overall, best-in-class for agentic coding). The architecture is the story, not the size: it makes frontier-class performance affordable on commodity hardware and at API prices.
🚀 Innovation
GPT-6 Sol quietly appears in the OpenAI API. A new tier below Astra showed up ahead of any announcement, completing the ladder Astra > Sol > Terra > Luna, OpenAI's version of Anthropic's Fable > Opus > Sonnet > Haiku. Expected pricing puts Sol at $5/$30 per million tokens versus Astra's $10/$50, with Sol Pro and Sol Ultra heavy-compute modes. For agentic teams it gives a high-end fallback that costs a fraction of the flagship.
🔬 Research
OpenAI claims a Navier-Stokes solution, and the math community pushes back. OpenAI published a claimed solution to the Navier-Stokes existence and smoothness problem, one of the seven Millennium Prize Problems, produced by an unreleased internal model over about a week and verified in Lean. The result is overshadowed by a priority dispute: NYU's Tristan Buckmaster and Anthropic's Levent Alpöge say their unpublished work was leveraged, then OpenAI tried to control or block their independent publication. Terence Tao publicly warned that the scooping behavior would do serious long-term damage to mathematics, and the controversy has become the defining AI-science ethics story of the week.
🔬 Research
OpenAI says it reached its "automated research intern" milestone. As of mid-August its research organization runs 3.1 agent-workdays for every human workday, and it targets an "automated AI researcher" by March 2028. The number measures aggregate agent runtime, not a 3.1x productivity gain, but it signals that agentic research is now standard practice inside a frontier lab. If the ratio keeps climbing, lab output starts to scale with compute and orchestration rather than headcount.
🔒 Security
Cisco FMC auth bypass (CVE-2026-20079, CVSS 10.0) is being exploited in the wild. Cisco confirmed active exploitation of an unauthenticated bypass in Secure Firewall Management Center that yields root access, and CISA added it to the KEV catalog with a 12.09. patch deadline. There are no workarounds, and Talos warns hotfixes prevent future abuse but may not clear existing compromises. Roughly 300 to 700 FMC instances sit exposed on the public internet, a small but high-value target set.
🔒 Security
SonicWall SMA1000: one SSRF chains into full Active Directory compromise. CVE-2026-15409 is an unauthenticated SSRF, but the published chain ends in automated DCSync: an attacker reaches a local Erlang node with a hardcoded cookie, gets os:cmd() execution, decrypts LDAP bind passwords with a static AES key, then runs Impacket secretsdump from the appliance itself. No credentials needed to go from one edge device to domain takeover. Anyone running SMA1000 should treat it as exposed until patched.
🔒 Security
Skullcandy Dime 3 earbuds can be hijacked and can't be fixed. CERT/CC disclosed CVE-2025-20701: the earbuds accept Bluetooth pairing from any nearby device without a PIN or approval, letting an attacker hijack audio and pull live microphone audio. A patched firmware exists, but Skullcandy offers no consumer update path, so sold units stay vulnerable indefinitely. The same Airoha SDK flaw hit other earbud brands, making it a broader consumer IoT supply-chain problem.
💰 Market
DeepSeek cuts Flash pricing and routes V4 Pro traffic to the cheaper model. New Flash pricing took effect 10.09 with off-peak rates at half of peak (cache-hit input at ¥0.02), and all V4 Pro requests will be served by V4.1 Flash at Flash prices until V4.1 Pro ships. The community calls it "market crash as a service": a frontier-tier model at commodity prices, with the price cut formalized in the API docs. Expect renewed pressure on OpenAI and Anthropic mid-tier pricing in the coming weeks.
💰 Market
Anthropic's IPO takes concrete shape. An S-1 was confidentially filed in June, a $15B revolving credit facility is being finalized with Goldman Sachs and JPMorgan, and market-implied odds put the listing in October 2026 at roughly 59%, with private valuation near $965B. A new flagship-level release is rumored for just before the debut to build demand. The listing will be the clearest public test yet of how markets value frontier AI beyond the hype cycle.
🏛️ Politics
Dario Amodei calls for a unified industry slowdown, Altman signals openness. Amodei published "We Must Pace the Frontier" arguing labs should coordinate a pause, while Bloomberg reported OpenAI is considering pacing its own development and Altman wants other labs to join. Amodei says RSI has effectively started and an AI swarm could take over the entire internet within 6 to 12 months, framing the slowdown as existential risk management. Skeptics note China and open-weight labs have no incentive to pause, so a unilateral slowdown may just cede ground.
🏛️ Politics
US agencies accuse six Chinese AI firms of industrial-scale model theft. In a joint advisory, the FBI, NSA and CISA named DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI for distilling "billions of tokens" from US frontier models since at least late 2024, with likely government awareness. China dismissed the claims as politically motivated. The advisory cites concrete cases: DeepSeek pulling reasoning and agentic capabilities from GPT-4, GPT-5 and Claude for R1 and V3, and Moonshot distilling Claude Fable 5 into Kimi K3.
🏛️ Politics
Anthropic reports seven China-based labs ran industrial-scale distillation on Claude. Its September threat report details Moonshot silently forwarding some customer requests to Claude and returning Claude's answers as if they were Kimi's, plus 151M+ exchanges attributed to Alibaba between May and July. Anthropic tightened controls, including thinking-signature mechanics that make extracted reasoning traces harder to use for training. The report strengthens the case, already circulating in Washington, for access restrictions on frontier model APIs.
📎 Sources
- DeepSeek V4.1 Flash is out (r/LocalLLaMA)
- DeepSeek V4.1 Flash now the #1 open model in LiveBench (r/DeepSeek)
- GPT 6 Sol is Coming Soon (r/OpenAI)
- Breakthrough for Navier-Stokes from Buckmaster + Alpoge? (r/singularity)
- OpenAI and the Navier-Stokes controversy (r/LocalLLaMA)
- Terence Tao calls out OpenAI on scooping (r/singularity)
- OpenAI nearing solving another millennium prize (r/singularity)
- OpenAI AI agents now perform 3.1 researcher-workdays (r/singularity)
- Cisco confirms max-severity FMC bug exploited in the wild (r/cybersecurity)
- SonicWall SMA1000 SSRF to Erlang RCE to DCSync (r/netsec)
- Skullcandy Dime 3 earbuds unpatchable Bluetooth flaw (r/cybersecurity)
- Price Reduction for DeepSeek-Flash (r/DeepSeek)
- Market crash as a service (r/DeepSeek)
- Rumour in SF: Anthropic drops a new model week before IPO (r/singularity)
- Dario Amodei demands a plan for unified slow-down (r/singularity)
- OpenAI is considering slowing down development (r/singularity)
- OpenAI wants to slow down, Altman seeks industry-wide safety push (r/OpenAI)
- US accuses Chinese AI firms of 'malicious' copying (r/LocalLLaMA)
- Countering misuse of AI: September 2026 / Anthropic (r/LocalLLaMA)
Key external sources: OpenAI on Navier-Stokes, Anthropic threat report, Talos on FMC exploitation, CERT/CC VU#859658, Dario Amodei: We Must Pace the Frontier
📎 Sources
- Rumour in SF: Anthropic drops a new model week before IPO
- OpenAI: AI agents now perform 3.1 researcher-workdays for every human researcher-workday, says it has reached “automated research intern” level, and expects “automated AI researcher” by March 2028
- Breakthrough for Navier-Stokes from Tristan Buckmaster + Levent Alpoge?
- Terence Tao calls out OpenAI on scooping other people's work, says it would do serious long term damage to the field of Mathematics in the future.
- Price Reduction for DeepSeek-Flash!
- US accuses Chinese AI firms of 'malicious' copying of AI technology
- OpenAI and the Navier-Stokes controversy
- Cisco confirms max-severity FMC bug (CVE-2026-20079) is being exploited in the wild
- DeepSeek V4-1 Flash is out
- Market crash as a service
- Skullcandy Dime 3 earbuds will pair with strangers' devices automatically and there's no way to patch them
- Big news is that OpenAI is nearing solving another millennium prize, but OpenAI now saying categorically it’s impossible that Levent/Buckmaster’s recent codex usage influenced their model’s output
- 🕵️♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
- OpenAI wants to slow down, Sam Altman seeks industry-wide AI safety push
- Deepseek V4.1 Flash now the #1 open model in Livebench
- OpenAI Is Considering Slowing Down The Development Of Cutting-edge AI, Sam Altman Is Hoping Other AI Companies Will Do The Same
- GPT 6 Sol is Coming Soon
- Countering misuse of AI: September 2026 / Anthropic
- Dario Amodei demands and suggest a plan for unified slow-down