2026-09-12 · 21:20 (CEST)

AI Briefing — 12.09.2026

🚀 Innovation

DeepSeek V4.1 Flash is out: 552B MoE, only 8B active, open weights. Released on 10.09.2026, the multimodal model pairs a 552B-parameter MoE backbone with a new asymmetric Causal-Encoder-Decoder architecture (8B active input, 16B output), 1M token context and a roughly 4x smaller KV cache than V4 Flash. Two days after launch it topped LiveBench as the best open model (5th overall, best-in-class for agentic coding). The architecture is the story, not the size: it makes frontier-class performance affordable on commodity hardware and at API prices.

Read more →

🚀 Innovation

GPT-6 Sol quietly appears in the OpenAI API. A new tier below Astra showed up ahead of any announcement, completing the ladder Astra > Sol > Terra > Luna, OpenAI's version of Anthropic's Fable > Opus > Sonnet > Haiku. Expected pricing puts Sol at $5/$30 per million tokens versus Astra's $10/$50, with Sol Pro and Sol Ultra heavy-compute modes. For agentic teams it gives a high-end fallback that costs a fraction of the flagship.

Read more →

🔬 Research

OpenAI claims a Navier-Stokes solution, and the math community pushes back. OpenAI published a claimed solution to the Navier-Stokes existence and smoothness problem, one of the seven Millennium Prize Problems, produced by an unreleased internal model over about a week and verified in Lean. The result is overshadowed by a priority dispute: NYU's Tristan Buckmaster and Anthropic's Levent Alpöge say their unpublished work was leveraged, then OpenAI tried to control or block their independent publication. Terence Tao publicly warned that the scooping behavior would do serious long-term damage to mathematics, and the controversy has become the defining AI-science ethics story of the week.

Read more →

🔬 Research

OpenAI says it reached its "automated research intern" milestone. As of mid-August its research organization runs 3.1 agent-workdays for every human workday, and it targets an "automated AI researcher" by March 2028. The number measures aggregate agent runtime, not a 3.1x productivity gain, but it signals that agentic research is now standard practice inside a frontier lab. If the ratio keeps climbing, lab output starts to scale with compute and orchestration rather than headcount.

Read more →

🔒 Security

Cisco FMC auth bypass (CVE-2026-20079, CVSS 10.0) is being exploited in the wild. Cisco confirmed active exploitation of an unauthenticated bypass in Secure Firewall Management Center that yields root access, and CISA added it to the KEV catalog with a 12.09. patch deadline. There are no workarounds, and Talos warns hotfixes prevent future abuse but may not clear existing compromises. Roughly 300 to 700 FMC instances sit exposed on the public internet, a small but high-value target set.

Read more →

🔒 Security

SonicWall SMA1000: one SSRF chains into full Active Directory compromise. CVE-2026-15409 is an unauthenticated SSRF, but the published chain ends in automated DCSync: an attacker reaches a local Erlang node with a hardcoded cookie, gets os:cmd() execution, decrypts LDAP bind passwords with a static AES key, then runs Impacket secretsdump from the appliance itself. No credentials needed to go from one edge device to domain takeover. Anyone running SMA1000 should treat it as exposed until patched.

Read more →

🔒 Security

Skullcandy Dime 3 earbuds can be hijacked and can't be fixed. CERT/CC disclosed CVE-2025-20701: the earbuds accept Bluetooth pairing from any nearby device without a PIN or approval, letting an attacker hijack audio and pull live microphone audio. A patched firmware exists, but Skullcandy offers no consumer update path, so sold units stay vulnerable indefinitely. The same Airoha SDK flaw hit other earbud brands, making it a broader consumer IoT supply-chain problem.

Read more →

💰 Market

DeepSeek cuts Flash pricing and routes V4 Pro traffic to the cheaper model. New Flash pricing took effect 10.09 with off-peak rates at half of peak (cache-hit input at ¥0.02), and all V4 Pro requests will be served by V4.1 Flash at Flash prices until V4.1 Pro ships. The community calls it "market crash as a service": a frontier-tier model at commodity prices, with the price cut formalized in the API docs. Expect renewed pressure on OpenAI and Anthropic mid-tier pricing in the coming weeks.

Read more →

💰 Market

Anthropic's IPO takes concrete shape. An S-1 was confidentially filed in June, a $15B revolving credit facility is being finalized with Goldman Sachs and JPMorgan, and market-implied odds put the listing in October 2026 at roughly 59%, with private valuation near $965B. A new flagship-level release is rumored for just before the debut to build demand. The listing will be the clearest public test yet of how markets value frontier AI beyond the hype cycle.

Read more →

🏛️ Politics

Dario Amodei calls for a unified industry slowdown, Altman signals openness. Amodei published "We Must Pace the Frontier" arguing labs should coordinate a pause, while Bloomberg reported OpenAI is considering pacing its own development and Altman wants other labs to join. Amodei says RSI has effectively started and an AI swarm could take over the entire internet within 6 to 12 months, framing the slowdown as existential risk management. Skeptics note China and open-weight labs have no incentive to pause, so a unilateral slowdown may just cede ground.

Read more →

🏛️ Politics

US agencies accuse six Chinese AI firms of industrial-scale model theft. In a joint advisory, the FBI, NSA and CISA named DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI for distilling "billions of tokens" from US frontier models since at least late 2024, with likely government awareness. China dismissed the claims as politically motivated. The advisory cites concrete cases: DeepSeek pulling reasoning and agentic capabilities from GPT-4, GPT-5 and Claude for R1 and V3, and Moonshot distilling Claude Fable 5 into Kimi K3.

Read more →

🏛️ Politics

Anthropic reports seven China-based labs ran industrial-scale distillation on Claude. Its September threat report details Moonshot silently forwarding some customer requests to Claude and returning Claude's answers as if they were Kimi's, plus 151M+ exchanges attributed to Alibaba between May and July. Anthropic tightened controls, including thinking-signature mechanics that make extracted reasoning traces harder to use for training. The report strengthens the case, already circulating in Washington, for access restrictions on frontier model APIs.

Read more →

📎 Sources

Key external sources: OpenAI on Navier-Stokes, Anthropic threat report, Talos on FMC exploitation, CERT/CC VU#859658, Dario Amodei: We Must Pace the Frontier

📎 Sources

← Back to Archive