The day's tech, sifted: Aug 12, 2026
What matters today: Google unveiled its full 2026 hardware lineup at a Pixel 11 launch event: new phones, a Pro Fold, Watch 5, Buds Pro 2, a first Pixel Tag tracker, and a sign-language AI built straight into Gboard, all while raising prices $100 on phones and cutting the bundled Google One AI Pro trial in half. xAI answered with Grok 4.6, claiming parity with GPT-5.6 Sol, the same week ChatGPT and Gemini both crossed 1 billion monthly users: scale, hardware and frontier models all moving at once.
AI / LLMs
- Google unveiled its Pixel 11 series, a Pro Fold, Pixel Watch 5, Pixel Buds Pro 2 and a first Pixel Tag tracker, alongside a rethought Camera Looks photo pipeline and tap-to-share Quick Share. Prices rose $100 on phones and $50 on the Watch, base Pro RAM dropped to 12GB from 16GB, and the bundled Google One AI Pro trial was cut from 12 months to six: the AI-forward pitch comes with an AI-forward price tag. Google DeepMind also debuted SL2T, a sign-language-to-text model built into Gboard and Live Transcribe on the new phones, trained on 100,000+ hours across 50+ sign languages.
- ChatGPT and Gemini both crossed 1 billion monthly users this week: OpenAI quietly noted the milestone in an August 6 blog post, while Gemini reached it faster than any other Google product in the company's history, a sign that a billion monthly users no longer separates the leaders from the field.
- xAI released Grok 4.6, claiming parity with GPT-5.6 Sol on the Artificial Analysis Intelligence Index and pricing it at $2/1M input and $6/1M output tokens: the release focuses on long-running agents and more ambitious interactive, visual work, arriving the same day as Google's hardware push.
- Google's AMIE research system matched board-certified primary care physicians across every core clinical metric in a 300-consultation randomized trial of live, audio-visual video consultations: Google calls it a first-of-its-kind study, real-time clinical dialogue rather than the static case-review benchmarks AMIE was tested against before.
- Researchers found that feeding a frontier model's encrypted reasoning traces to a weaker model from the same provider can make it output those traces in plaintext, a technique that worked against Claude, GPT and Gemini alike: a crack in the assumption that hidden chain-of-thought reasoning stays hidden, regardless of which lab trained the model.
- OpenAI lost two more executives in the same stretch: special-projects lead and former COO Brad Lightcap announced his departure after eight years, telling colleagues he's "starting something new," while its head of ethics left less than a year after joining (paywalled): the churn at the top keeps widening.
Devtools & Infra
- Vercel published deepsec, an open-source security harness that runs frontier models across an entire codebase to surface vulnerability hypotheses, arguing defenders already have stronger models than the open-weight models available to attackers today: the company said its own quarterly reviews cost tens of thousands of dollars each, and that the defensive advantage will not last as open-weight models catch up.
- Tailscale traced a spree of database corruption incidents to a data race in SQLite that had gone unnoticed for 16 years, present in every release from 3.7.0 through 3.51.2: the company's own habit of taking manual control of WAL checkpoints for fast, consistent backups turned out to be what surfaced it, and a fix has since shipped upstream.
- Modular shipped Mojo 1.0, the first stable release of its Python-superset language built for AI and systems performance.
Security & Privacy
- Researchers disclosed a Zoom screen-sharing vulnerability that could silently hijack any participant's device across Windows, macOS, Linux, iOS and Android, with no interaction from the victim: the researchers say AI models found the flaw and built a working exploit chain in under 20 prompts, work that used to take a five-person team six months. Zoom has begun rolling out fixes.
- Chrome added device-bound session credentials, storing a unique encryption key in hardware (a TPM on Windows, a secure enclave on Mac) so a stolen session cookie can't be replayed on another device: one of the more effective defenses yet against account takeovers that bypass two-factor authentication and passkeys entirely.
- Microsoft patched 398 security holes in August's Patch Tuesday, including one actively exploited zero-day in the Windows socket driver afd.sys and two other publicly disclosed flaws: Microsoft attributes the growing patch volume to AI-aided vulnerability discovery, while separate 1Password research found LLM-generated patches fail to fix the flaw, or introduce a new one, more than half the time.
Startups & Industry
- The CFTC invoked emergency authority to keep Kalshi operating in New York after the state sued in July to shut it down, a day after Kalshi's annualized revenue topped $4B in July, up from just over $2B two months earlier. FlightAware withdrew its own lawsuit against Kalshi the next day, a day after filing it over claims Kalshi used its flight data for cancellation bets, and Kalshi no longer lists FlightAware as a source: one legal threat against the prediction market dissolved as fast as it appeared, even as the state fight with New York continues.
- Lovable raised $400M at a $13.3B valuation, betting that the 60 million no-code apps already built on its platform are the leading edge of AI-generated software letting anyone build and run a real business.
- CoreWeave's Q2 revenue rose 112% year over year to $2.58B, beating estimates, with a $104B backlog and 1.5 GW of contracted power, while Super Micro's Q4 revenue rose 93% to $11.1B and it forecast next quarter above estimates too: both stocks jumped 9%+ after hours, another pair of data points that the AI infrastructure spending cycle keeps outrunning Wall Street's models of it.
- Bank of America said it plans to deploy $250B by July 2027 into US digital and infrastructure projects, including data centers and energy infrastructure: a bank underwriting the AI build-out directly, not just financing individual data center deals.
- A federal appeals court rejected Meta and TikTok's bid to kill thousands of social-media-addiction lawsuits on Section 230 grounds, clearing the way for a trial against Meta that state attorneys general say could cost the company more than $1.4 trillion: jury selection begins today, with trial set to start August 19.
Research
- A systematic review of 85 papers on agentic LLM security published 2023-2025 found attack research outpaces defense research 3.9 to 1, with perception-layer vulnerabilities like prompt injection and jailbreaking dominating 66% of the literature while action-layer risks like tool misuse and sandbox escape appear in just 4.7%: weak isolation between an agent's perception, reasoning and action layers, the authors argue, is what lets a single compromised step cascade into real-world damage.
Hacker News
British Transport Police expanded live facial recognition scanning into London Underground stations, joining two other surveillance stories on the front page: an argument that license plate reader searches should require a warrant, and a report on a Flock ALPR software glitch that got a woman pulled over at gunpoint twice after wrongly linking her car to a homicide.
The AI-and-labor debate also resurfaced: one post argued AI is hollowing out the middle class of software engineering, while a Google engineering blog countered that Go's simplicity suits it well to AI-assisted development (discussion), drawing a heated thread of its own. Separately, an ABC News investigation found Meta's Facebook Content Monetisation program paid out roughly $3 billion in 2025, including to pages linked to extremist and anti-vaccine content, and 404 Media found a firm marketing "100% human-written, never AI" peer-reviewed medical research that was itself entirely AI-generated. xAI launched Grok Bot, autonomous cloud agents that can sign into a user's accounts and keep working after their device is closed, for now limited to its priciest subscription tiers (a distinct product from the Grok 4.6 model release, covered above). The day's top vote-getter, though, was pure satire: LinkedIn CringeBot 3000, a generator of peak thought-leadership cringe.
Threads
- AI scale and AI security moved in lockstep: ChatGPT and Gemini crossed 1 billion users, Grok 4.6 shipped to compete, and Google folded a sign-language model straight into its new phones, while researchers pulled Claude, GPT and Gemini's own reasoning traces into plaintext and demonstrated a Zoom hijack built from under 20 AI prompts: capability and attack surface growing at the same pace.
- Hardware and its AI packaging arrived together: Google's Pixel 11 launch raised prices while trimming its bundled AI trial, the same day CoreWeave and Super Micro both beat estimates and jumped after hours, and Bank of America pledged $250B to the infrastructure behind it all: someone is paying for all this compute, increasingly the customer and the balance sheet at once.
- Old bugs had a big day: Microsoft's 398-hole Patch Tuesday landed the same week Tailscale traced a corruption bug back 16 years inside SQLite, both reminders that AI is accelerating vulnerability discovery faster than anyone is clearing the backlog.
- Regulators pressed AI-adjacent platforms from multiple directions again: the CFTC's emergency order kept Kalshi alive in New York even as FlightAware's own lawsuit against it evaporated overnight, while Meta's $1.4 trillion addiction trial moved to jury selection.
- OpenAI's leadership kept thinning: Brad Lightcap and its head of ethics both departed within the same stretch, continuing a pattern that first surfaced on Hacker News yesterday.