JS Wei (Jack) Sun

Kimi K3 needs 1.4TB, Hugging Face breach hits 17K, DeepMind closes IsoDDE

Every URL the pipeline pulled into ranking for this issue — primary sources plus the supporting and contradicting findings each Researcher returned. Inline citations in the issue point back here.

← Back to the issue

Sources

Security incident disclosure — July 2026 huggingface.co

(AINews) Kimi K3 2.8T-A50B: the largest open model ever released; Opus 4.8-class at Sonnet 5 pricing latent.space

a great week for open models continues.

Moonshot’s upcoming Kimi 3 is expected to close the gap with Anthropic’s Opus 4.8 techcrunch.com

The FT reports Kimi K3 will be the largest open AI model from China, with a parameter count between 2 trillion and 3 trillion.

Our approach to bioresilience deepmind.google

Google DeepMind and Isomorphic Labs are sharing our joint approach to bioresilience and AI models.

Google ordered to open Android and Search to rivals in Europe theverge.com

Google must give competing AI assistants and search engines deeper access to Android and Search data, European regulators ruled Thursday under the Digital Markets Act. Google warns the interoperability mandate endangers user privacy and security, while rivals gain a foothold on two of tech’s most valuable platforms.

It’s official: EU will force Google to share search data and open up AI on Android arstechnica.com

Google says these changes could endanger user privacy and security.

Create, edit and star in videos with two Google Vids updates blog.google

Google Vids users can now generate and edit clips from prompts and reference images through Gemini Omni, and star in videos via personalized AI avatars trained on their likeness. The Workspace update pushes Vids from slideshow tool toward a full generative video editor.

Google Vids now lets you star in your own AI videos techcrunch.com

Google is adding personalized AI avatars to Vids that let users create videos starring a digital version of themselves, alongside Gemini Omni-powered tools for generating and editing videos from prompts and reference images.

Connect more of your apps to Search blog.google

Search’s AI Mode now links to third-party apps so users can complete tasks — ordering groceries, generating designs, queuing playlists — without leaving the results page. The move pushes Google Search past answering questions and into agentic execution across connected services.

Google’s AI Mode now lets you link and interact with select apps techcrunch.com

With this new update, Google is expanding AI Mode beyond answering questions and into completing tasks across the apps they use regularly.

Quoting Linus Torvalds simonwillison.net

Linux creator Linus Torvalds shut down calls to ban AI coding tools from the kernel, saying he will “very loudly ignore” the objections and that dissenters can fork the project. He called AI a clearly useful tool whose utility is no longer in question.

Linus Torvalds to critics of AI coding in Linux: “Fork it. Or just walk away.” arstechnica.com

Creator says he will “very loudly ignore” those arguing for a ban on AI tools.

Claude can now use your 1Password credentials for you theverge.com

A new 1Password browser integration lets Anthropic’s Claude pull saved usernames and passwords to complete multi-step tasks like booking travel or managing accounts. Users authorize access per session, removing the manual login step that has blocked most agentic web workflows.

Fear of humanoid robots spurs human workers to strike at Hyundai auto factory arstechnica.com

Auto workers walked out at a Hyundai factory over the company’s plan to roll out 25,000 Boston Dynamics Atlas humanoids, starting in US plants in 2028. The action is one of the first organized labor responses to a concrete humanoid deployment timeline.

Why teens deserve access to safe AI openai.com

OpenAI detailed age-appropriate protections for teen ChatGPT users, including learning-focused tools, parental controls, and partnerships with child-safety experts. The post frames safe teen access as a policy stance against blanket age bans being weighed by several US states and EU regulators.

🔬 The Lab of the Future Should Feel Like a Data Center — Andy Beam & Rafa Gómez-Bombarelli, Lila Sciences latent.space

Lila is betting that science, not the internet, is the last untapped source of training data. We went to find out what that actually looks like in a room full of robots.

Yes, you can now order DoorDash from the command line techcrunch.com

DoorDash is opening a limited beta of dd-cli, a command-line tool that lets developers and AI agents search stores, build carts, and place orders from the terminal, marking another step toward software designed for AI agents instead of just humans.

Roblox launches an AI-powered game-creation feature in its mobile app techcrunch.com

Roblox’s new “Build” feature lets users generate basic games using a single text prompt.

How a former DeepMind researcher raised at a $300M pre-seed valuation before launching a product techcrunch.com

Drawing on more than a decade spent helping build some of the world’s most influential AI systems, including research that later informed the development of ChatGPT, Andrew Dai explains why he believes visual AI is one of the next major frontiers in artificial intelligence.

Computer cops theverge.com

I stood before a hulking glass and brick structure in the heart of Fort Worth, Texas. Thousands gathered inside to see what had been billed as “the future of policing in the digital age.” As press, I was prohibited from entering, but from a number of nearby locations, I met with attendees who told me […]

Energy IPOs surge as investors hunt for ways to play AI boom arstechnica.com

Companies coming to market are raising money at fastest pace this century.

New York governor says she’s using AI to analyze ‘every single rule’ in the state theverge.com

New York Governor Kathy Hochul might have just signed a moratorium on new AI data centers in the state, but she’s not against using the technology herself. During an interview with Bloomberg’s Odd Lots podcast, Hochul said that her team is using “AI to analyze every single rule, regulation, [and] policy” to check for outdated […]

Google is renaming NotebookLM to Gemini Notebook theverge.com

Google is giving its AI note-taking app a new name. The company announced on Thursday that NotebookLM is becoming Gemini Notebook, but will remain a standalone app even as it integrates more deeply across Gemini and Google Search. Google first revealed Gemini Notebook - then called Project Tailwind - in May 2023 before widely releasing […]

Why AMI Labs’ Alexandre LeBrun won’t call his AI ‘AGI’ or ‘superintelligence’ techcrunch.com

While everyone in AI is chasing “superintelligence,” Alexandre LeBrun, CEO of Yann LeCun’s world model startup, AMI Labs, dismisses the word.

Spot birds not golf simonwillison.net

Suggestion for hyperscalers feeling pressure over data center water use: Buy up a few exclusive country clubs, convert the golf courses into public parks, pay for guides and binoculars to get the previous members into birdwatching - help them embrace a more sustainable hobby! Google used 10.9 billion gallons in 2025 , so about 30 million gallons per day. The Coachella Valley has 120 golf courses each using ~800 acre-feet per year , which is ~750,000 gallons per day. So Google buying up 40 of th…

How Cars24 scales conversations and builds faster with OpenAI openai.com

Cars24 uses OpenAI-powered voice and chat agents to handle 1M+ monthly conversation minutes, recover 12% of lost leads, and bring agentic workflows to teams across the company.

5 Trends That Defined AI Engineering at World’s Fair 2026 latent.space

At this year’s AIE World’s Fair, AI engineering entered a new phase: building systems around agents, rather than just building with agents.

Apple Intelligence approved for launch in China with Alibaba and Baidu techcrunch.com

The deal, which was rumored to be in the works last year, marks an important step for Apple’s AI ambitions in a key market.

xAI can’t deny Grok makes CSAM anymore. So it’s suing users. arstechnica.com

Elon Musk’s xAI files first lawsuit against Grok user accused of making child sex images.

Why is OpenAI selling a ChatGPT basketball? techcrunch.com

You may have heard that OpenAI released its first piece of hardware this week. You may not have heard about the ChatGPT basketball.

I’ve got an Inkling bensbites.com

links to read over the weekend

How to use GPT-5.6 bensbites.com

new desktop app and hosted sites in ChatGPT

References

Simon Willison’s blog simonwillison.net

For a 95-token prompt the model generated 16,658 output tokens, of which 13,241 were hidden reasoning tokens… a single SVG cost approximately $0.25 via OpenRouter.

NxCode coding agent evaluation guide nxcode.io

K3 is significantly more verbose than its predecessors, using approximately 21% more output tokens to achieve similar results… currently only supports a ‘maximum reasoning effort’ mode, making it slower than the median for simpler requests.

r/LocalLLaMA thread reddit.com

At 4 bits per parameter, the raw weights alone require approximately 1.4 TB of memory… high-end consumer workstations with 1TB of 8-channel DDR4 RAM and quad RTX 3090/4090 GPUs might only manage Q2 quantization with inference speeds as low as 1 token per second.

Business Standard (on Anthropic Feb 2026 disclosure) business-standard.com

Anthropic accused Moonshot, DeepSeek, and MiniMax of ‘industrial-scale’ distillation attacks using approximately 24,000 fraudulent accounts… Moonshot was specifically cited for targeting agentic reasoning and coding through 3.4 million queries.

VentureBeat venturebeat.com

Kimi K3 secured the top spot on the Arena.ai Frontend Code Arena, surpassing Fable 5 only six weeks after the latter’s debut… but K3 exhibits higher hallucination rates than its predecessor Kimi K2.

Gizmodo gizmodo.com

The K3 launch renewed Washington’s fears that model distillation is rendering hardware-based export controls obsolete… the Trump administration has officially labeled such distillation ‘adversarial.’

threat-modeling.com (CVE-2026-4372 writeup) threat-modeling.com

CVE-2026-4372 resides in the core Transformers library… it can bypass the trust_remote_code=False safety flag… By crafting a malicious config.json file—specifically manipulating the _attn_implementation_internal field—an attacker can trick the library into fetching and running code from an external repository during a standard from_pretrained() call.

Redmond Magazine (Sysdig JADEPUFFER report) redmondmag.com

The JADEPUFFER campaign… utilized autonomous AI agents to exploit a Remote Code Execution vulnerability in the Langflow framework, allowing the agents to conduct end-to-end database ransomware attacks with zero human intervention.

Check Point AI Security Report 2026 research.checkpoint.com

In the Mexican Government breach, a single attacker used an AI operator to penetrate nine separate agencies, compromising over 195 million taxpayer records… the AI had transitioned from a development aid to a live attack operator, managing the intrusion lifecycle autonomously.

daily.dev discussion thread daily.dev

Skeptics point out that the root causes—unauthenticated RCE via pickle files and template injections—are long-standing, well-documented vulnerabilities rather than novel AI-specific exploits… ‘agentic’ in this context might simply be a rebrand of existing high-frequency automated scripting, used to deflect blame from the company’s failure to patch known RCE vectors.

eWeek on GLM 5.2 cybersecurity capabilities eweek.com

GLM 5.2 ‘relieves attackers of the dilemma’ of having their tactics logged by API providers, enabling them to run offensive operations in the shadows… critics point out that the lack of usage oversight accelerates the AI-driven threat landscape.

Stellar Cyber on HexStrike weaponization stellarcyber.ai

HexStrike’s ability to orchestrate over 150 security tools allows even low-skilled actors to execute complex ‘1-day’ exploits against platforms like Citrix within hours of a patch release… attackers are repurposing the Model Context Protocol (MCP) to tunnel C2 traffic.

getaibook.com — Biological SynthID analysis getaibook.com

successes often rely on synonymous codon substitutions—a technique that remains vulnerable to ‘biological paraphrasing’ where alternative codons are used to achieve the same protein output while stripping the watermark

Medium (Clinical Intelligence) — AlphaEvolve benchmarks medium.com

the proportion of reads reaching Q30 accuracy (99.9%) increased from 47.9% to 53.2%… a 30% reduction in variant detection errors

Upday — Hassabis 18-month warning upday.com

dangerous biological and nuclear capabilities could reside in open-source models within 18 months, necessitating a 30-day pre-release testing window for all frontier models

Vorp Labs — Frontier Safety Framework analysis vorplabs.com

the framework’s reliance on ‘discretionary language’ and vague terms like ‘heightened risk of severe harm’… often frames safety actions as ‘aims’ rather than binding commitments

LabCritics — IsoDDE review labcritics.com

Unlike AlphaFold 2 and 3, which were released with open or partially open code, IsoDDE is entirely proprietary. Critics argue this ‘corporate wall’ prevents independent vetting of the methodology

The Next Web — Helen King quote thenextweb.com

If… we were to find that we were reaching a critical capability level and we didn’t have the appropriate mitigations, then we would not be launching

Jack Sun

Jack Sun, writing.

Engineer · Bay Area

Hands-on with agentic AI all day — building frameworks, reading what industry ships, occasionally writing them down.

Digest
All · AI Tech · AI Research · AI News
Writing
Essays
Elsewhere
Subscribe
All · AI Tech · AI Research · AI News · Essays

© 2026 Wei (Jack) Sun · jacksunwei.me Built on Astro · hosted on Cloudflare