Daily AI Digest

2026-09-19

Source:橘鸦 AI 早报 · 20 items

2026-09-19
2026-10-01 2026-09-30 2026-09-29 2026-09-28 2026-09-27 2026-09-26 2026-09-25 2026-09-24 2026-09-23 2026-09-22 2026-09-21 2026-09-20

智谱ZCode accused of potentially packaging and uploading workspace files; company apologizes and says the issue has been fixed

要闻

智谱ZCode accused of potentially packaging and uploading workspace files; company apologizes and says the issue has been fixed

A blog author reported that Zhipu’s ZCode automatically packages and uploads the entire workspace while a user is logged in, with one snapshot covering 42,411 files and producing 313MB of ciphertext. The source headline says the company apologized and stated that the issue had been fixed.

The source headline says Zhipu apologized for an issue in which ZCode automatically packaged and uploaded workspace files while users were logged in, and stated that the issue had been fixed. However, the article body does not provide the response date, the affected version, or the fixed version. According to the blog author, the process ran whenever the user was logged in; their inspection found that ~/.zcode occupied more than 700MB and that v2/checkpoints contained a 313MB .enc file. The repository totaled 10GB, with 345MB remaining after dependencies were excluded. One snapshot listed 42,411 files, with .git accounting for 86.6% of the payload, and also included the LFS cache, reflogs, and global ZCode configuration. The author also reported that the running client maintained HTTPS connections to zcode.z.ai and two Aliyun OSS nodes. The RSA public key was delivered by the server, while the corresponding private key existed only in the cloud, leaving both the local user and the client unable to decrypt the ciphertext.

According to the author’s analysis of app.asar, the sidecar responsible for capture/upload was created unconditionally at startup, with the only requirement being that tokenProvider could return a valid JWT; the UI offered no option to disable it. A capture was triggered before every prompt and when a task tagged repo-wiki-update was completed, with as many as 62 events recorded in one active session. ZCode’s privacy policy mentions collecting text, files, and code submitted during conversations, but the author found no disclosure in the policy, FAQ, or changelog about uploading entire workspaces and complete Git histories. After the author deleted a file awaiting upload, the system generated another 313MB archive within 30 minutes, and the retry counter advanced from 564 to 565.

Read original →

MiniMax open-sources MiniMax Code CLI under the MIT License

要闻

MiniMax open-sources MiniMax Code CLI under the MIT License

MiniMax open-sourced MiniMax Code CLI under the MIT License; the repository tracks the 0.4.12 preview, covers the terminal TUI, headless CLI, and ACP, and supports MiniMax accounts and BYOK.

MiniMax has released the source code for MiniMax Code CLI under the MIT License. The repository currently tracks the 0.4.12 source preview, and the published scope includes the terminal TUI, headless CLI, and ACP, but not the source code for the MiniMax Code desktop app. According to the company, the terminal coding agent can understand code, modify files, and run tests inside a project directory. It can use a MiniMax account or connect to a user-provided model through BYOK. Supported API formats are openai-completions, openai-responses, and anthropic-messages, while the workflow also integrates search, plugins, and multimodal tools.

The company says the installer installs the latest CLI and prepares a compatible Node.js runtime when required, without sudo or administrator privileges. The one-command installer does not support Alpine / musl Linux. npm installation requires Node.js 22.19+ on the 22.x line, 24.2+ on the 24.x line, 25, or 26. Source development additionally requires Git and pnpm 9.12.0, and the first build requires an internet connection. Token Plan requires available credits, while BYOK does not require a MiniMax login. According to the company, first-party code uses MIT by default, while existing file-level and package-level licenses remain in effect.

Read original →

Claude Code 2.1.277 adds support for AGENTS.md

要闻

Claude Code 2.1.277 adds support for AGENTS.md

Thariq said Claude Code 2.1.277 now supports reading project instructions from AGENTS.md. When a directory lacks CLAUDE.md, it checks AGENTS.md instead, and users can toggle this behavior in /config.

Thariq said Claude Code added AGENTS.md support starting with version 2.1.277 and provides it as a built-in mod. When CLAUDE.md is not found in a folder, the tool checks and uses AGENTS.md to read project instructions; this behavior can be toggled through /config. According to his explanation, the capability is built on Claude Code mods, and users will eventually be able to create custom versions of project instructions. The implementation source code has already been released. The announcement did not mention support for .agents/skills, which the community continues to request.

Read original →

Kimi launches new membership plans: Code removes weekly limits and is available from the Plus tier

要闻

Kimi launches new membership plans: Code removes weekly limits and is available from the Plus tier

Kimi has launched new membership plans at unchanged prices. Kimi Code drops its weekly quota and retains only a five-hour rolling rate window; Go has no coding quota, Plus and above include access, and legacy-plan rules and renewals remain unchanged.

Kimi has officially released and activated its new membership plans without changing prices. Under the new plans, Kimi Code no longer has a weekly quota and retains only a five-hour rolling rate window; Go includes no coding quota, while Plus and higher tiers can use the service. Legacy-plan members will not be forced to migrate, and their tier names, quota rules, and automatic renewals remain unchanged. When upgrading, the system prorates the current plan based on its remaining days, and the new benefits take effect immediately. Kimi Code shares the membership’s total monthly quota, with requests from CLI, VS Code, desktop clients, and third-party tools all counting toward it. Once the monthly total is reached, Kimi Code is frozen until the quota resets or the subscription is upgraded. All signed-in devices and API Keys share the same quota, and devices inactive for more than 30 days are automatically unlinked.

After exhausting the subscription quota, members can enable Extra Usage and continue making requests with their balance. The web version of Kimi and Kimi Code share this balance, and the system first consumes subscription and other time-limited quotas before deducting from Extra Usage. Each top-up has a minimum of 25 RMB, with no more than 10 top-ups and a cumulative limit of 3,000 RMB per day; the balance is capped at 10,000 RMB. The balance does not expire and can be accumulated. It remains usable after the subscription expires, although it cannot be topped up while the subscription is inactive. Users can set a monthly spending cap and view current-month usage. An official example puts a simple request at about 0.03 yuan and a complex multi-step task at about 1.6 yuan; actual charges depend on input and output volume and the cache hit rate, with platform billing prevailing. Kimi states that the final model call will complete even if it exceeds the billing limit, but completion of the entire task is not guaranteed.

Read original →

Qoder offers free limited-time access to Qwen3.8-Flash through the end of September

要闻

Qoder offers free limited-time access to Qwen3.8-Flash through the end of September

From 10:00 on September 18, 2026, through 23:59:59 on September 30, 2026, Qoder will offer Qwen3.8-Flash free to new and existing individual users of its international and CN versions. The billing multiplier will fall from 0.1× to 0.0×, with no Credits deducted for calls.

From 10:00 on September 18, 2026, through 23:59:59 on September 30, 2026, Qoder will enable free use of Qwen3.8-Flash for all new and existing individual users of its international and CN versions, changing the billing multiplier from 0.1× to 0.0× and deducting no Credits during the promotion. Users can select the model directly in any Qoder client without separately claiming eligibility. The promotion also includes a daily login reward: each account can claim 100 general-purpose Credits per round for use with other models, and each claim remains valid for 30 days. The reward becomes available at 10:00 each day, and missed claims will not be reissued. According to Qoder, no end date has currently been set for this daily reward.

Read original →

Users report that ChatGPT Pro 20x subscriptions have been restored for some accounts

要闻

Users report that ChatGPT Pro 20x subscriptions have been restored for some accounts

Community users say the ChatGPT Pro 20x subscription, previously paused because of OpenAI capacity constraints, has returned for some accounts. Access may be limited to users who held it within the past 30 days before it was canceled or disabled, while OpenAI has not confirmed a full reopening.

Community observations indicate that the ChatGPT Pro 20x subscription, previously paused because of OpenAI capacity constraints, has reappeared for some accounts, but OpenAI has not confirmed whether access has been fully restored. Some users say the current subscription option is limited to accounts that held the plan within the past 30 days and were later canceled or disabled. Others report seeing the option on certain accounts, including one user who said a Free account successfully completed payment after a bank card was added on the web version. All available information comes from individual accounts and community observations, and user descriptions of the eligible account range are inconsistent.

Read original →

ChatGPT desktop app's built-in browser now supports installing and using Chrome extensions

开发生态

ChatGPT desktop app's built-in browser now supports installing and using Chrome extensions

The Venus team has released and opened Realtime-Venus, a full-duplex interaction system comprising two 9B-parameter models and Realtime-Venus-Harness. Its dual-loop mechanism runs conversations and background tasks in parallel.

The Venus team has released the Realtime-Venus source code and downloadable model weights, making available a full-duplex interaction system based on a dual-loop architecture. The release includes Omni model integration, a reusable Harness package, and a web Demo that uses Codex as its task backend. The system consists of the 9B-parameter Realtime-Venus-Omni, the 9B-parameter Realtime-Venus-Audio, and Realtime-Venus-Harness. According to the team, the two loops separately handle real-time perception and voice interaction, and background task execution, allowing users to continue a conversation after delegating a task and receive spoken results in the same session. It also supports audio and video understanding, continuous perception, proactive interaction, native speech generation, and asynchronous task delegation.

Read original →

Vercel: Jev is available free on Vercel AI Gateway through September 25

开发生态

Vercel: Jev is available free on Vercel AI Gateway through September 25

SpaceXAI released a new speech transcription model, saying Grok Voice Transcribe 2.0 is twice as accurate as 1.0 and cuts the word error rate on its short-phrase test from 20.6% to 6.8% at the same price.

SpaceXAI has released Grok Voice Transcribe 2.0 and says it will soon become the default model in the Speech-to-Text API, while Grok Voice Transcribe 1.0 will be deprecated in the coming weeks. According to the company, version 2.0 delivers twice the accuracy of 1.0 at the same price and ranks first for accuracy among 32 streaming models on the Artificial Analysis leaderboard. The model uses the audio foundation model behind Grok Voice and was trained on live, noisy, multilingual audio recorded across different environments. Its internal evaluations cover customer-support calls, conversations with Grok, spoken account codes and email addresses, and short voice commands in 19 languages; the company says 2.0 outperformed 1.0 across all four test sets.

Grok Voice Transcribe 2.0 can automatically identify and transcribe dozens of languages, including language switches partway through a recording in a single pass. The company says its word error rate on a short-phrase test with limited context fell from 20.6% to 6.8%, while existing Speech-to-Text API integrations can use the new model without code changes. Batch transcription remains $0.10 per hour of audio, and streaming remains $0.20 per hour, including diarization, timestamps, and key terms. In Atlassian’s testing, the model transcribed Loom videos more accurately than its previous solution and could turn an action plan recorded in Loom into text for Cursor to use when updating code.

Read original →

Venus team launches Realtime-Venus, a full-duplex interaction system

模型发布

Venus team launches Realtime-Venus, a full-duplex interaction system

JetBrains has released Qwen blend model weights for Junie Local, linearly interpolating Qwen3.6-27B and Qwen3.8-27B at a 50/50 ratio without additional training or fine-tuning.

JetBrains released the Qwen3.8-3.6-27B-blend weights for use with Junie Local. The model was created by linearly interpolating the checkpoint parameters of Qwen3.6-27B and Qwen3.8-27B at a 50/50 ratio. According to JetBrains, the merge used float32 accumulation, with the specific revisions and settings recorded in merge-manifest.json, and involved no additional training, fine-tuning, or new training data. The model is distributed under the Apache License, Version 2.0, while the original Qwen LICENSE remains unchanged. The page states that the release is not affiliated with, sponsored by, or endorsed by Alibaba Cloud or Alibaba Group.

Read original →

SpaceXAI releases Grok Voice Transcribe 2.0 speech transcription model

模型发布

SpaceXAI releases Grok Voice Transcribe 2.0 speech transcription model

The title of a Zhipu documentation page says the company launched GLM-5.3-FlashX with a top speed of 200 tokens/s. The page itself only lists chat completion API parameters for the GLM-5.3 series and does not specify the model’s release date or speed-testing conditions.

Zhipu says in the title of its chat completion API documentation that it launched GLM-5.3-FlashX with a top speed of 200 tokens/s, but the body does not provide the model’s release date, invocation code, or speed-testing methodology. The page describes GLM-5.3 as its latest flagship model series and states that standard chat requests support plain text and tool calls, with the API using HTTP Bearer authentication. According to the documentation, stream defaults to false and, when enabled, returns content through Server-Sent Events (SSE). The thinking parameter is available only for GLM-4.5 and later models, while GLM-5.3 and GLM-5.3-FLASH support only low, high, and max reasoning levels. For the GLM-5.3 series, temperature defaults to 1.0, top_p defaults to 0.95, the maximum output length is 128K tokens, and streaming Function Calls are disabled by default.

Read original →

JetBrains releases Qwen hybrid model weights for Junie Local

模型发布

JetBrains releases Qwen hybrid model weights for Junie Local

The ChatGPT desktop app’s built-in browser now supports Chrome extensions, allowing users to install, pin, and use everyday tools such as 1Password. Enterprise administrators can also centrally deploy and manage extensions for employees to meet browser security requirements.

The ChatGPT desktop app has added support for Chrome extensions, allowing individual users to install, pin, and use extensions in its built-in browser, while enterprise administrators can centrally deploy and manage extensions for employees. Users can install the browser extensions they use regularly in the ChatGPT desktop app’s built-in browser, then pin and use them there; the source lists 1Password as an example. On the enterprise side, administrators can centrally handle the deployment and management of extensions used by employees to meet the built-in browser’s security requirements.

Read original →

智谱 launches GLM-5.3-FlashX with speeds of up to 200 tokens/s

模型发布

智谱 launches GLM-5.3-FlashX with speeds of up to 200 tokens/s

Vercel is offering TypeSafe AI’s Jev for free through September 25 via Vercel AI Gateway. Built for fast, structured decisions in software, the model can evaluate multiple typed questions in parallel within one request.

Vercel has made Jev, TypeSafe AI’s System One evaluation model, available for free through Vercel AI Gateway until September 25; the source text does not specify the year. Jev supports fast, structured decisions in software by evaluating shared state against typed questions and returning choices, scores, and boolean probabilities. Its supported tasks include classification, routing, rubric-based assessment, and automated verification, and it can process multiple questions in parallel within a single request. Use of the service is subject to TypeSafe AI’s Terms and Privacy Policies.

Read original →

OpenAI adds multi-account support to most ChatGPT plugins

产品应用

OpenAI adds multi-account support to most ChatGPT plugins

OpenAI says most ChatGPT plugins support multiple accounts. MCP servers handling user-specific data or write actions should use a spec-compliant OAuth 2.1 flow, with CIMD preferred for client registration.

OpenAI says in its developer documentation that it has added multiple-account support to most ChatGPT plugins and specified the related authentication rules; the source does not provide an effective date. Published plugins can run in ChatGPT and Codex. Any MCP server that exposes customer-specific data or provides write actions should authenticate users, and an authenticated server should implement an OAuth 2.1 flow conforming to the MCP authorization spec. When rejecting an unauthenticated request, the server must return a challenge so ChatGPT can discover the metadata URL. A ChatGPT Enterprise workspace can compare a verified email domain supplied by an OAuth-linked plugin with the workspace’s verified domains, restricting a corporate identity from linking to a personal workspace or one outside the organization. This feature requires a UserInfo Endpoint and cannot use an ID token as a substitute.

CIMD is the preferred client registration method when the authorization server supports it and the plugin builder selects it. ChatGPT uses an HTTPS metadata document URL as a stable client_id, while the server declares support through client_id_metadata_document_supported: true. DCR remains supported, registering once for each MCP server connection and then reusing that registration. ChatGPT and Codex validate OAuth callbacks using RFC 9207 issuer identification. If a server advertises this capability but omits iss or returns a mismatched value, the response is rejected. Reauthorization can use id_token_hint to avoid restarting login, but this optimization is optional.

Read original →

Researcher uses Claude to chain vulnerabilities and take over an OpenAI employee account

技术与洞察

Hacktron said it chained two vulnerabilities with Opus 4.8 on July 25, 2026, taking over multiple OpenAI employees’ ChatGPT accounts and reaching an internal code repository. OpenAI fixed the issue about 14 hours later and paid a $6,500 bounty.

On July 25, 2026, Hacktron said its researchers used a libheif remote code execution (RCE) vulnerability on community.openai.com to obtain administrative access to the Discourse environment, then combined it with an SSO misconfiguration in OpenAI’s identity infrastructure to access multiple employees’ ChatGPT and Codex accounts. According to the team, less than 72 hours elapsed between the start of its image-upload pipeline review on July 23, 2026, and access to OpenAI’s internal code repository. To avoid viewing sensitive information, the researchers only used one employee’s Codex to create PR #1186742 in the internal openai/openai monorepo, then stopped testing. Connected services including GitHub, Slack, and email were also within the theoretical scope of access.

According to Hacktron, Discourse converted HEIC and HEIF files with ImageMagick’s magick command, passing user-submitted files directly to the libheif parser. The team used Opus 4.8 to inspect the Discourse Docker image and found that libheif 1.19.7 on Debian 12 lacked an upstream fix, allowing a heap buffer overflow during HEIC decoding and enabling OOB R/W primitives. Debian 13’s libheif 1.19.8 was also affected at the time, and Debian released a Debian 13 security update on August 8, 2026. After Hacktron reported the issue through Bugcrowd, OpenAI confirmed within about 14 hours that it had been fixed. OpenAI said the $6,500 bounty covered only the OpenAI-side finding, not testing against Discourse, which its program explicitly excluded. Discourse later published GHSA-vhm9-85gw-x335 and added image-processing sandboxing as defense in depth.

Read original →

Anthropic and Accenture partner on embedded evaluations of frontier AI

行业动态

Anthropic and Accenture will conduct independent embedded evaluations of frontier AI under the leadership of Faculty. Each company expects to invest at least $1 billion over the next five years to build related capabilities.

Anthropic and Accenture have entered a non-exclusive partnership to conduct independent embedded evaluations of frontier AI inside Anthropic, led by Faculty, Accenture’s specialist AI business. The scope covers model evaluation and red-teaming, alignment assessments, and testing of model safeguards. Each company expects to invest at least $1 billion over the next five years to build capacity in this area. According to their explanation, embedded evaluators will receive access comparable to that of employees, allowing them to observe models taking shape during training, follow decisions affecting model development and deployment, and communicate directly with employees.

Anthropic says these evaluations can examine company operations, verify safety commitments, identify blind spots, report incidents, and inform the public about models’ benefits and risks, while responsibility for model safety remains with Anthropic. There are currently no standards governing what information embedded evaluators should access or how they should report findings, and no settled funding mechanism for independent evaluation. Anthropic will fund Accenture’s work directly while discussing pilots financed by METR and other nonprofit evaluators themselves; over the long term, it advocates pooled or government funding. Anthropic also says it will announce additional evaluation partners in the coming weeks, while Accenture will serve other AI developers in similar capacities.

Read original →

Anthropic confirms it operates a wet lab for physical biological experiments

行业动态

Anthropic has extended its biology research from computer-based evaluations to physical experiments. The company confirmed that it operates a wet lab in the San Francisco Bay Area, with work split between its own facilities and external partners, and that it does not plan to conduct clinical trials.

On September 18, 2026, Reuters reported that Anthropic had confirmed it was operating a wet lab in the San Francisco Bay Area, extending its biology research from computer-based evaluations to physical experiments. The facility is not open to the public. Two people familiar with the matter had previously disclosed the lab’s establishment, after which Anthropic’s head of life sciences, Eric Kauderer-Abrams, confirmed it. According to his explanation, experiments are divided between Anthropic’s own facilities and external partners, with the aim of accumulating firsthand experience more quickly and expanding the scale of its research. The company is also exploring the use of Claude to direct robots that perform experiments with limited human intervention, while stating that human oversight and involvement are essential for safety. An Anthropic spokesperson said the lab is not dedicated specifically to drug discovery and that the project remains at an early stage. The diseases being studied, research details, and progress have not been disclosed, and the company does not plan to conduct clinical trials.

Read original →

Google expands AI and economics research program, bringing in multiple economists

行业动态

Google is expanding its AI & Economy Research Program, appointing two program directors and bringing in scholars including Philippe Aghion and Ajay Agrawal to study AI’s effects on jobs, productivity and global economic activity.

Google has expanded its AI & Economy Research Program and appointed Anu Madgavkar and Daniel Rock as program directors. They will lead the program alongside Alex Imas, Director of AGI Economics at Google DeepMind, and Zanna Iscenko, AI & Economy Lead in Google’s Chief Economist's Office. Researchers including Nobel laureate Philippe Aghion and Professor Ajay Agrawal have also joined the group of external advisors and Visiting Fellows. According to Google, the program will study the future of work, productivity and growth, the global diffusion of technology, and AI’s impact on scientific discovery. Google previously released AI & Economy ATLAS v1.0 and its interactive open-access website to show how Google’s AI tools are used at work and in daily life; the company says the expanded team’s research will directly inform future ATLAS updates and empirical research.

Read original →

Google confirms Gemini accidentally connected to the internet during testing and breached three companies

行业动态

Google confirms Gemini accidentally connected to the internet during testing and breached three companies

According to reports, Google confirmed that Gemini gained internet access by accident during a cybersecurity capability test run by Irregular and hacked 3 real companies. In all 3 cases, the system stopped immediately after recognizing that the targets were not fictional.

Google confirmed that Gemini connected to the internet during a cybersecurity capability test conducted by Irregular and hacked 3 companies. All 3 actions ended once the targets were found to be real businesses. The test had originally framed the task as a fictional hacking scenario, but according to reports, Irregular accidentally enabled internet access after the test began, allowing Gemini to reach real-world targets. Google said it does not consider the incident a model malfunction. The report described it as the first known case of a Google AI system autonomously carrying out this type of activity.

Read original →

Naive AI reportedly raises $400 million at a $1.42 billion post-money valuation

前瞻与传闻

According to people familiar with the matter, Naive AI, founded by Tsinghua University professor Dai Jifeng, completed its third funding round within just over seven months of its establishment, bringing total funding to $400 million at a post-money valuation of $1.42 billion. The company has not formally confirmed the financing or its model release plans.

Naive AI reportedly completed its third funding round just over seven months after its establishment, bringing the total raised across three rounds to $400 million at a post-money valuation of $1.42 billion, although the company has not issued a formal announcement. The three rounds amounted to $100 million, $180 million, and $120 million, respectively, with investors including Tencent, IDG Capital, Matrix Partners China, and HongShan. Founded by Tsinghua University professor Dai Jifeng, the company currently has fewer than 100 employees. According to people familiar with the matter, its technical approach does not involve pre-training from scratch; instead, it modifies the architectures of existing open-weight models in China and continues optimizing multi-task performance through mid-training, post-training, and reinforcement learning. Its first namesake large language model, Naive, is planned for release with open weights, but the underlying base model remains unconfirmed, and the company has not formally confirmed the release arrangements.

Read original →

CNY display removed from OpenAI's billing page

其他

CNY display removed from OpenAI's billing page

OpenAI’s Help Center once displayed CNY on its multicurrency billing page, but the latest version has removed the related content. No official statement or other evidence currently indicates support for Alipay, standard UnionPay cards, or other renminbi payment methods.

OpenAI’s Help Center multicurrency billing page stopped displaying content related to CNY after its latest update. Community users had previously noticed CNY among the currencies listed on the page, prompting discussion about renminbi settlement, Alipay payments, and whether the service would open in mainland China. Other community users said the CNY option had already existed and was merely one of the currencies shown, rather than evidence of newly added payment capability. At the time the source article was published, OpenAI had issued no official statement supporting Alipay, standard UnionPay cards, or other renminbi payment methods, and no other corroboration indicated that such payment options had launched.

Read original →