The day's tech, sifted: Sep 23, 2026
What matters today: OpenAI shipped GPT-6 Sol and GPT-6 Luna about an hour after Anthropic's Opus 5.5 launched Monday, both roughly half the price of their GPT-5.6 predecessors, the fastest back-to-back price cut Simon Willison has tracked this run. Hackers claiming to have breached the FBI say they now hold data on every employee at the bureau, the day's biggest Hacker News story by a wide margin, while the Pentagon confirmed overreliance on AI models contributed to last week's missile strike on an Iran school (paywalled), the clearest official admission yet behind yesterday's report that Central Command had overhauled Palantir's Maven targeting system in response.
AI / LLMs
- GPT-6 Sol and GPT-6 Luna (above) undercut their predecessors hard: GPT-6 Luna runs $0.10 per million input tokens against GPT-5.6 Luna's $0.20, and Ars Technica notes both labs are now making the identical pitch, a little more capability for a lot less money. Lenny's Podcast ran a blind taste test across the new crop: Opus 5.5 won his actual week of work, GPT-6 Astra won his heart, and Sol left him split.
- Yandex open-sourced AliceAI Foundation, an 80B mixture-of-experts model (3B active parameters) with a 256K context window and a hybrid KDA-attention architecture trained from scratch, which it says beats rivals on math.
- Rabbit launched OS3, a cloud AI agent that runs across up to five Windows, Mac, and Linux devices per account without needing its R1 hardware, reachable by browser, Telegram, or iMessage.
- Voice AI had its own leaderboard scramble: Cartesia's Sonic 3.6 topped eight of nine languages on Artificial Analysis's Controlled Voice Arena, while StepFun's StepAudio 3 tied for the top speech-to-text spot at a 1.7% error rate.
- Unreal Labs open-sourced Unreal Agent, a Go-based async coding-agent harness that reportedly runs Terminal-Bench 4.0 at 39% lower cost than Codex plus Astra combined.
- xAI shipped a batch of Grok Bot updates: native Google Workspace connectors, custom network routing, and a faster desktop app, pushing further into the enterprise-agent access that Microsoft's EvilTokens takedown (below) shows attackers already chase.
Security & Privacy
- Hackers claiming to have breached the FBI say they now hold data on every employee at the bureau (above), a claim serious enough to pull the day's largest Hacker News crowd, with the FBI not yet confirming the scope.
- The Pentagon said overreliance on AI models contributed to a missile strike that killed civilians at an Iran school (paywalled) (above), the first official account of what went wrong behind yesterday's report that Central Command had since integrated more open-source data and upgraded Palantir's Maven targeting system.
- Meta is testing Muse phone calls that sound automated but are actually staffed by humans in a call center, the latest crack in the AI assistant's credibility after this week's login-token zero-day and Amazon's outright ban.
- Microsoft says it disrupted EvilTokens, a subscription scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts, charging $1,500 to join plus $500 a month while automating everything from target selection to follow-up phishing emails.
- WordPress disclosed an unauthenticated path traversal that can escalate to remote code execution under the right conditions, drawing a sizeable Hacker News crowd given how much of the web still runs it.
Startups & Industry
- Xbox has become "a shell of its former self," weighed down by job cuts and studio closures, The Verge reports, a franchise-focused retreat that continues yesterday's reorganization (the Halo handoff to Activision, Forza studios merging, Ninja Theory likely closing).
- Six major banks including Bank of America and Capital One warned that giving agentic commerce chatbots more autonomy could mean more scams, fraud, and disputes, a caution arriving as the same agentic-checkout wave keeps shipping.
- Funding kept flowing to the AI supply chain: data-security startup Cyera raised $400M from Goldman Sachs, extending its total since June 2025 to $1.94B, AI training-data startup Micro1 raised $100M+ at a $4B valuation (up from $500M a year ago), and smaller rounds landed for web-scraping tool Firecrawl ($75M) and on-premises AI hardware seller Go.AI ($85M).
Research
- MIT Lincoln Laboratory's TRACTOR benchmark grades automated C-to-Rust translators, and a companion paper argues the same tools' output compiling as safe Rust doesn't mean the refactor is actually memory secure, a caution for DARPA's push to translate legacy C codebases wholesale.
Hacker News
Most-discussed story of the day was the least urgent: Microsoft killed Visual FoxPro at version 9 back in 2007, and FoxScript revives it by putting the same language on a new runtime, on the logic that rewriting a 20-year-old business app is still how you lose the business, a sentiment that pulled 151 comments. Right behind it in argument density: Trail of Bits' SAML: A fractal of bad design, arguing the enterprise single sign-on protocol's decades of extensions and edge cases have left it a security minefield rather than a solved problem.
Discord posted an update on how it confirms age groups, the latest front in platforms' running fight over teen verification. Elsewhere: California's canal-top solar panels drew the day's second-most comments as an infrastructure-reuse case study, Obscura pitched a VPN built to structurally be unable to log your activity, and in the front page's reliably weird corner, someone wrote an actual poem about the 16-bit Intel 8088. The day's two biggest point-getters were both already covered above: the FBI breach claim and the Pentagon's Iran admission, alongside lighter revisits of the WordPress RCE and Unreal Agent.
Threads
- Cheap intelligence keeps squeezing every layer: GPT-6 Sol and Luna's half-price launch, Yandex's open-sourced 80B AliceAI Foundation, and Unreal Agent's 39% cheaper coding runs are three separate answers to the same cost pressure, on proprietary models, open weights, and the agent harness around them.
- Meta's Muse keeps losing credibility one disclosure at a time: yesterday's login-token zero-day and Amazon ban were followed today by word that some of its "AI" phone calls are actually humans in a call center, each revelation making the last look less like a fluke.
- Agentic access is becoming the attack surface everyone is fighting over: xAI deepened Grok Bot's Google Workspace connectors the same day Microsoft disrupted a scam platform that used a chatbot to automate account takeovers and six banks warned that agentic commerce invites more fraud, three fronts of the same trust problem.
- AI's military use faced a real reckoning: the Pentagon admitted overreliance on AI contributed to the Iran school strike (paywalled), a day after CENTCOM's Maven targeting overhaul, the clearest sign yet that the technology's battlefield use is drawing scrutiny rather than just more investment.
- Xbox's slow unwind stretched into a second day: yesterday's Halo handoff and Forza-studio merger became today's blunter framing, "a shell of its former self."