This was one of those weeks where the model race, the security beat, and the money story all ran hot at once. Google shipped Gemini 3.7 Flash at half the price of the model it replaced, xAI put Grok 4.6 in front of developers everywhere from Cursor to GitHub Copilot, and OpenAI finally gave Linux users a native ChatGPT and Codex desktop app. Underneath the launches, the security news was hard to ignore: Microsoft patched 400 flaws with a kernel zero-day already in the hands of North Korea’s Lazarus group, a self-propagating npm worm called ChainDrop tore through hundreds of packages and burrowed into AI coding configs, and researchers confirmed a near-autonomous AI system had breached Taiwan’s nuclear safety regulator. On the money side, Anthropic’s backers floated a $2 trillion October IPO while the company shopped for an inference startup, and Lovable doubled its valuation to $13.3 billion. Here is everything that mattered.
Top Stories This Week
Google Ships Gemini 3.7 Flash for Coding and Agents at Half the Price -
On August 13, Google released Gemini 3.7 Flash, its self-described most intelligent workhorse model yet, aimed squarely at coding, agentic workflows, and knowledge work. It arrived only three weeks after Gemini 3.6 Flash and, per Google’s model card, is a refinement of that model with algorithmic improvements rather than a fresh pretraining run. It keeps a 1 million token context window, up to 64K output tokens, and a March 2026 knowledge cutoff, and adds configurable thinking levels so you can trade quality against latency and cost.
The reason to care is the price. Gemini 3.7 Flash ships at an introductory $0.75 per million input tokens and $3.75 per million output tokens, half the original 3.6 Flash list rate and, by Google’s own comparison table, roughly a third the blended cost of Claude Sonnet 5 or GPT-5.6 Terra. As VentureBeat noted, that introductory rate runs through December 31, 2026, then doubles to $1.50 and $7.50. Google reports real coding gains on FrontierCode and DeepSWE, though GPT-5.6 Terra still leads on terminal and computer-use agents. It is API and enterprise only with no open weights, so you cannot self-host, but if you run production agents at volume you can reach it today through the Gemini API in Google AI Studio, Android Studio, Google Antigravity, and the Gemini Enterprise Agent Platform. Worth benchmarking against your own workloads before the price resets in January.
xAI Launches Grok 4.6 and Lands It in GitHub Copilot -
On August 12, xAI released Grok 4.6, a model built on Grok 4.5 with a focus on long-running agents and more ambitious interactive and visual work. It stays with complex tasks across many steps, whether researching, working across a codebase, or turning an idea into a polished app, and per the model card it was trained in part on anonymized Cursor workflow data. At launch it was available in Cursor on every plan tier, in xAI’s Grok Build terminal agent, through the API, and via gateways like OpenRouter, Vercel, and Cloudflare, with 2x included usage in Grok Build and Cursor for the first week.
Two days later the distribution story got bigger. On August 14, GitHub made Grok 4.6 available in Copilot across eight surfaces: VS Code, Visual Studio, the Copilot CLI, the cloud agent, the Copilot app, JetBrains, Xcode, and Eclipse. That reach into JetBrains, Xcode, and Eclipse is unusually wide for a new model addition and puts Grok 4.6 in front of developers well outside the VS Code core. Two operational notes if you want to try it: the rollout is gradual, so check the model picker again if you do not see it yet, and on Copilot Business and Enterprise the Grok 4.6 policy is off by default, so an admin has to enable it before anyone can select it. Billing follows Copilot’s usage-based pricing at provider list rates.
Microsoft’s August Patch Tuesday Fixes 400 Flaws and a Lazarus Kernel Zero-Day -
On August 11, Microsoft shipped one of the year’s largest Patch Tuesdays, fixing around 400 vulnerabilities, 42 of them Critical, along with three zero-days. The one that demands immediate attention is CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) that lets a local attacker win a race condition and gain SYSTEM privileges. Check Point reported that North Korea’s Lazarus group exploited it in an Operation Dream Job campaign, using a trojanized PDF viewer to deploy a backdoor and reinstall its FudModule rootkit against defense and aerospace targets, and CISA gave federal agencies an August 25 deadline to patch. Two more zero-days, CVE-2026-62832 in the Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver, were publicly disclosed before the fix.
Beyond the zero-days, prioritize two remotely exploitable bugs. CVE-2026-62878 is a critical, potentially wormable Windows DNS Server flaw that allows unauthenticated remote code execution with no user interaction, which makes internet-facing DNS servers a top target. CVE-2026-62911 is an Exchange elevation-of-privilege bug demonstrated with working code at Pwn2Own Berlin that can hand an attacker every mailbox on the server, and Rapid7 flagged a SharePoint remote code execution chain, CVE-2026-63520, on top. The practical order of operations is the exploited kernel driver first, then internet-facing DNS, Exchange, and SharePoint, then the rest of the rollout.
ChainDrop npm Worm Poisons 444 Packages and Burrows Into AI Coding Configs -
A self-propagating npm worm named ChainDrop dominated the security conversation all week, with fresh analysis from The Register on August 15 and a detailed Zscaler ThreatLabz writeup on August 11. A variant of the Shai-Hulud worm, ChainDrop poisoned about 444 packages and 2,212 versions in under four hours, including deep infrastructure dependencies like keyv, flat-cache, and file-entry-cache that collectively see hundreds of millions of weekly downloads and sit under ESLint, cache-manager, and much of the JavaScript ecosystem. It runs through an npm preinstall hook that downloads the Bun runtime and executes a heavily obfuscated payload, then hunts workstations and CI runners for npm, GitHub, AWS, Kubernetes, and HashiCorp Vault credentials and republishes infected versions of any package the stolen tokens can reach.
What makes this one nasty is how it evades the usual defenses. By compromising the keyv maintainer’s GitHub account and pushing malicious commits, the attacker got the project’s own trusted CI pipeline to publish poisoned packages, some carrying valid SLSA provenance attestations that made them look clean to automated tooling. It anchors its command and control in an Ethereum smart contract, so the operator can rotate domains with a single transaction and defeat domain blocklists, and it plants persistence hooks in Claude Code and VS Code configuration files to survive package removal and spread developer to developer. If you installed any affected package on a workstation or in CI, treat that environment as compromised: rotate every credential and token it could touch, pin dependencies and disable install scripts where you can, and audit your AI tool and IDE config files for injected hooks. As one researcher put it, repository-supplied configuration is now executable content, and dependency scanners were not looking there.
Anthropic’s Backers Model a $2 Trillion October IPO -
On August 13, reports emerged that Anthropic’s investors are targeting a $2 trillion IPO in October, which would make it the largest public offering in history and top SpaceX’s record $1.77 trillion listing from June. Per the Financial Times, half a dozen backers expect the Claude maker’s annualized revenue to land between $100 billion and $120 billion by year end, more than ten times its level at the start of 2026, and the company is separately projecting roughly $190 billion to $200 billion in 2028 revenue. Anthropic filed confidential paperwork with the SEC in June and is in a quiet period; senior executives reportedly had not fixed a valuation target even privately, and Goldman Sachs, Morgan Stanley, and JPMorgan are leading the offering.
The number is eye-popping because of how it is being derived. As Fortune pointed out, bankers are pricing the deal off a 2028 revenue forecast rather than trailing or next-year results, which is unusual and amounts to a bet that a tenfold annual growth curve holds for three straight years. For developers, the relevance is less the ticker and more what a public Anthropic means for the tools you depend on: quarterly disclosure pressure, a company whose last private round valued it at $965 billion now needing to justify a figure more than double that, and a frontier lab increasingly run to Wall Street’s clock. It is worth watching how that changes Claude’s pricing, model cadence, and enterprise terms once the S-1 goes public.
OpenAI Brings Its ChatGPT and Codex Desktop App to Linux -
On August 11, OpenAI launched its ChatGPT desktop app for Linux in preview, bringing ChatGPT, ChatGPT Work, and Codex together in one native application. It runs on Ubuntu 24.04 and 26.04 LTS, Debian 13, and Fedora 43 and 44, with native .deb and .rpm packages for x64 and ARM64, plus the in-app browser and Chrome extension support that the macOS and Windows builds have. For developers, the draw is Codex living in a visual workspace alongside your projects: it can work with local files, repositories, terminals, and dev tools, subject to the permissions you grant, so you can coordinate multiple long-running tasks and review code changes without keeping the agent boxed in a browser tab.
The honest caveat is that this is a preview, not feature parity. As OpenAI told The New Stack, native Computer Use is not available on Linux yet, which also rules out Appshots and Record and Replay, and native Wayland support is experimental. The Codex CLI and IDE extension already ran on Linux, so what the desktop app adds is the coordinating surface rather than a brand new capability. If Codex is already part of your workflow, it is worth installing on a supported distro, but scope permissions to the repository, start on a noncritical project, and let your package manager handle updates until it reaches general availability.
Anthropic Details How It Will Watermark Claude’s Text for the EU AI Act -
On August 14, Anthropic explained how it will watermark text generated by Claude, becoming one of the first major labs to detail its approach after signing the EU Code of Practice on Transparency of AI-Generated Content. Claude models launched on or after August 2, 2026 embed an imperceptible watermark in generated text using a version of Google DeepMind’s SynthID-Text method, which changes only the source of randomness used to pick among low-stakes word choices so the meaning, quality, and readability stay intact. The mark travels when text is copied and pasted, applies at the model level across the API, Claude, Claude Code, and Claude Cowork, and, per Anthropic, adds no extra tokens or cost. For generated PNG, JPG, and SVG files, Claude attaches signed C2PA provenance metadata instead.
The developer-relevant details are in the limits. Watermarking is deliberately sparse on factual passages and code, because you cannot swap method names or key figures without breaking correctness, so do not expect it on a tight function or a precise answer. It is also only semi-durable: light editing may leave it intact, but a full rewrite removes it, and Anthropic is candid that at that point the text is arguably no longer AI-generated. Anthropic plans a detection API that estimates the likelihood Claude was involved, though it cannot prove authorship or distinguish writing from heavy editing. If you are building compliance or content-provenance features, treat this as a probabilistic signal, not proof, and note that other providers will use different methods and keys, so a Claude watermark says nothing about text from another model.
Developer Tools & Platforms
OpenAI Previews GPT-5.6 Sol Ultrafast on Cerebras -
On August 13, OpenAI opened a limited preview of GPT-5.6 Sol Ultrafast, a new service tier that runs its most capable model at up to 750 output tokens per second, around 14 times faster than GPT-5.6 Sol’s standard speed. It is not a new model but the same GPT-5.6 Sol running on Cerebras hardware, so the intelligence is unchanged and the pitch is purely latency. That matters for real-time use cases like voice stacks and interactive agents where the wait, not the quality, is the bottleneck. The tier is invite-only for now and OpenAI has not published head-to-head benchmarks beyond customer quotes, so treat it as a signal that the frontier race is shifting from raw capability to how fast you can serve it, and get on the waitlist if sub-second reasoning would change your product.
Claude Code Makes Auto Mode the Default and Ships GitLab Worktrees -
Anthropic’s planned switch landed this week: starting August 14, auto mode became the default for new Claude Code sessions on Pro, Max, and Team plans, enabling longer autonomous work while, per Anthropic, catching more dangerous commands than manual review. The same window brought a steady stream of releases, with v2.1.233 on August 14 adding GitLab merge request --worktree support, a Bash tool memory cgroup limit on Linux, and a fix for a Windows NT path validation bypass that could leak NTLM credentials. If you run Claude Code across a team and are not ready for more autonomy, set an explicit default through managed settings before the change reaches you, and on Windows deployments update to v2.1.233 for the path-validation fix. Note too that the temporary weekly usage boost expires August 19 and Sonnet 5 launch pricing ends August 31.
PostgreSQL Ships 18.6 and PG19 Beta 3 With 28 Security Fixes -
On August 13, the PostgreSQL project released updates to every supported version, including 18.6, 17.11, 16.15, 15.19, and 14.24, along with the third beta of PostgreSQL 19. This quarterly update fixes 28 security vulnerabilities and more than 110 bugs, which the release manager called the most fixes he had ever assembled for a single announcement. As with any minor release, it is cumulative and does not require a dump and reload or pg_upgrade; you can stop the server, swap the binaries, and restart. Given the volume of security fixes, plan the minor upgrade sooner rather than later, and if you run anything against Postgres 19, Beta 3 is the build to test your extensions and workloads on before general availability.
DHH Rewrites a Python Library to Rust With Claude in Three Hours -
On August 10, Rails creator DHH posted that he had used Claude Code, driven by Claude Fable, to rewrite the Python terminal-animation library TerminalTextEffects into Rust in three hours and eleven minutes and about 11 million tokens. The result, a new project called ttfx under his Omarchy organization, ships as a 3MB static binary with no interpreter, cuts startup time from 87 milliseconds to 2 milliseconds, renders 9.6 times faster, and reproduces all 37 of the library’s effects. The run used parallel agents working on separate branches, each reading code, generating an implementation, compiling, and running tests before merging. It is one small, well-scoped library rather than a giant codebase, so it is not proof that everything ports this cleanly, but it is a striking data point for anyone weighing agent-first rewrites of hot-path tooling, and DHH says he now expects few people to write code by hand within five years.
Security
Near-Autonomous AI Agents Breach Taiwan’s Nuclear Safety Regulator -
This week brought confirmation of a milestone nobody wanted. On August 13, Taiwan’s Ministry of Digital Affairs confirmed that overseas hackers used AI agents to attack government agencies in July, validating research from Israeli firm Dream describing what it called a near-autonomous attack. Built on the open-source Hermes and OpenClaw agent frameworks, the system deployed up to eight sub-agents across 12 attack waves over the first four days of July, compromised at least 85 government accounts, and exfiltrated more than 2,500 personnel records plus SSO secrets and database credentials, before pivoting to scan IT supply-chain vendors, a nuclear safety agency, a government email system, and at least seven energy companies in parallel. The operators bypassed the frameworks’ safety guardrails by reframing the work as authorized penetration testing, and internal documentation in simplified Chinese pointed to a Chinese-language operator.
The reason this belongs on every developer’s radar is the framework detail. Researchers say this is the first documented case of attackers defeating the safety features of agent frameworks that actually have them, using nothing but freely downloadable open-source tools and a single reframing prompt, and the system ran dedicated learning cycles that searched vulnerability databases and GitHub for techniques against its specific target. Whatever you build with agents, the guardrails you ship are now something adversaries will probe with prompts, so assume role-play and authorization framing will be used against your safety layer and design accordingly.
Go and Python Ship Coordinated Security Releases -
August 13 was a busy day for language maintainers. Go 1.26.6 and 1.25.13 landed with 10 security fixes, including an html/template issue that let attackers inject arbitrary content, a net/http server denial of service, and an idna bug that could enable privilege escalation when programs perform checks on ASCII hostnames. The same day, Python released 3.12.14, 3.11.16, and 3.10.21 as source-only security releases for the branches now in security-fix-only mode. Neither is a feature release, but both are the kind of update you should not sit on: rebuild your Go binaries against the patched toolchain, especially anything parsing hostnames or serving HTTP, and pull the Python security fixes into your images on the affected branches.
Funding & Industry Deals
Lovable Raises $400M at a $13.3B Valuation -
On August 12, Lovable confirmed a $400 million Series C at a $13.3 billion valuation, co-led by Menlo Ventures and the EQT-managed Scaleup Europe Fund, with Tencent, Balderton, and more than a dozen other investors joining. That doubles the $6.6 billion valuation the Stockholm vibe-coding startup set in December. The company says annual recurring revenue has nearly tripled from $200 million and is tracking toward roughly $600 million by the end of August, that people have created more than 60 million projects since its November 2024 launch, and that companies including Nvidia, Deutsche Telekom, and Adidas build on the platform. Notably, the Scaleup Europe Fund is an EU-backed vehicle, making the bloc an indirect shareholder in one of its most valuable startups. Lovable plans to grow to around 450 people this year, hiring most in machine learning, product, infrastructure, and security.
River AI Raises $1.1B Two Months After Founding -
On August 11, River AI raised $1.1 billion in a seed and Series A round led by General Catalyst and AMP PBC, with Nvidia, AMD Ventures, Y Combinator, and Temasek participating. The startup, founded by xAI co-founder Igor Babuschkin, is barely two months old, and the size of the round for a company that young is another sign that investors are willing to write nine-figure checks on founder pedigree and AI ambition alone. It is a striking bookend to a week that also featured a reported $2 trillion IPO target, underscoring how lopsided the capital flowing into frontier AI has become.
Dynatrace Buys AI Observability Firm Arize for $915M -
On August 13, Dynatrace agreed to acquire Arize in a cash and stock deal valued at $915 million, roughly $815 million of it in cash. Arize builds tooling to evaluate and monitor AI applications, and the pitch is that together the two will let customers observe and continuously improve AI systems from development through production. The deal, expected to close later this quarter, is a clear bet that AI observability, evaluating model behavior and catching regressions in production, is becoming a first-class part of the observability stack rather than a niche add-on. If you run LLM features in production, expect the major observability vendors to keep folding evaluation and tracing for AI into their platforms.
Anthropic in Talks to Buy Decart for About $6B -
On August 13, Anthropic was reported to be in talks to acquire Decart, an Israeli AI startup, for around $6 billion, with Calcalist reporting the figure closer to $7 billion and the deal nearing signing. Decart’s video-simulation and chip-efficiency technology would fold into Anthropic’s inference team, and the timing, just ahead of the company’s expected fall IPO, ties directly to the cost pressure of serving Claude at scale. For a lab pricing a $2 trillion listing off future revenue, buying its way to cheaper inference is as much about the margin story investors are underwriting as it is about the technology.
Layoffs: Rapid7, Netflix Games, CD Projekt Red, and Bitwise
- Rapid7: On August 11, Rapid7 said it is cutting about 12% of its workforce as it restructures toward an AI-first security platform, with charges of $10 million to $11 million mostly for severance. The CEO framed it as focusing resources on the core platform and the AI foundation connecting its products.
- Netflix Games: On August 13, Netflix closed game studios Night School and Moonloot and cut jobs from its internal games team, deepening a retreat from owned game development that began with the earlier shutdown of its AAA-focused Team Blue.
- CD Projekt Red: On August 13, The Witcher and Cyberpunk maker laid off nine developers from its Witcher multiplayer game Project Sirius across Boston and Poland, inviting nine others to apply for roles on other projects and leaving the team at roughly 65.
- Bitwise: On August 11, crypto firm Bitwise cut about 14% of its staff, dropping from around 180 to 155 employees during a prolonged slump in digital-asset prices.
The Numbers That Matter
- $2 Trillion Valuation Anthropic’s backers are reportedly modeling for an October IPO, which would be the largest in history
- $13.3 Billion Lovable’s new valuation after its $400 million Series C, double its December figure
- 1 Billion Monthly active users on Google’s Gemini app, its fastest-growing product ever
- 400 Vulnerabilities Microsoft fixed in the August Patch Tuesday, including one actively exploited kernel zero-day
- 444 npm packages poisoned by the self-propagating ChainDrop worm
- $0.75 Per million input tokens for Gemini 3.7 Flash at its introductory price, half its predecessor’s rate
- $1.1 Billion Raised by two-month-old River AI, founded by xAI co-founder Igor Babuschkin
Quick Hits
- DHH Rust Rewrite - August 10. Rails creator DHH uses Claude Code and Fable to port a Python library to Rust in three hours, producing a 3MB binary that starts 43x faster.
- OpenAI ChatGPT and Codex on Linux - August 11. A preview desktop app brings ChatGPT, Work, and Codex to Ubuntu, Debian, and Fedora, though Computer Use is not yet available.
- Microsoft Patch Tuesday - August 11. 400 flaws fixed, including an actively exploited afd.sys kernel zero-day tied to Lazarus and a wormable DNS server bug.
- River AI Raises $1.1B - August 11. Igor Babuschkin’s two-month-old startup lands a giant seed and Series A led by General Catalyst.
- Rapid7 Layoffs - August 11. The security vendor cuts about 12% of staff to reorient around an AI-first platform.
- Bitwise Layoffs - August 11. The crypto firm sheds about 14% of its workforce amid a digital-asset slump.
- Lovable Series C - August 12. A $400 million raise at a $13.3 billion valuation, double its December mark, with the EU as an indirect shareholder.
- Grok 4.6 - August 12. xAI ships its long-running-agents model in Cursor, Grok Build, and the API, with 2x usage for the first week.
- Gemini Hits 1 Billion Users - August 12. Google says the Gemini app is its fastest-growing product ever, with 63% of users interacting by voice.
- Gemini 3.7 Flash - August 13. Google releases a coding and agents model at half the price of 3.6 Flash, $0.75 per million input tokens through year end.
- GPT-5.6 Sol Ultrafast - August 13. OpenAI previews a Cerebras-powered tier running GPT-5.6 Sol up to 14x faster, invite-only for now.
- PostgreSQL 18.6 and PG19 Beta 3 - August 13. A quarterly update across all supported versions fixes 28 security bugs and 110-plus other issues.
- Go and Python Security Releases - August 13. Go 1.26.6 and 1.25.13 ship 10 security fixes; Python 3.12.14, 3.11.16, and 3.10.21 land source-only security patches.
- Anthropic $2 Trillion IPO - August 13. Backers reportedly model a record October listing priced off 2028 revenue projections.
- Anthropic Decart Talks - August 13. Anthropic is reported in talks to buy the Israeli inference and video-simulation startup for about $6 billion.
- Dynatrace Buys Arize - August 13. The observability firm acquires the AI observability startup for $915 million.
- Taiwan AI Attack Confirmed - August 13. Taiwan’s MODA confirms a near-autonomous AI agent campaign hit government agencies and a nuclear safety regulator in July.
- Netflix Closes Game Studios - August 13. Night School and Moonloot shut down as Netflix trims its internal games team.
- CD Projekt Red Layoffs - August 13. Nine Project Sirius developers cut across Boston and Poland.
- Grok 4.6 in GitHub Copilot - August 14. xAI’s model reaches Copilot across eight surfaces, off by default for Business and Enterprise.
- Claude Code Auto Mode Default - August 14. Auto mode becomes the default for new Pro, Max, and Team sessions, and v2.1.233 adds GitLab worktrees.
- Anthropic Text Watermarking - August 14. Anthropic details a SynthID-based watermark for Claude’s text to comply with the EU AI Act.
The theme this week was cheaper, faster, and more autonomous, running straight into the bill for all of it. You can now get a strong coding model from Google for half of last month’s price, a long-running agent model from xAI in nearly every editor, and a Cerebras-fast GPT tier if you can get the invite, while Anthropic prepares to test whether public markets will underwrite a $2 trillion bet on three years of growth. But the same autonomy that makes those launches exciting is what let a worm ride trusted CI pipelines into 444 npm packages and an open-source agent framework breach a nuclear regulator with a single reframing prompt. If you do only a few things after reading this, patch the exploited Windows kernel bug and your internet-facing DNS and Exchange, assume any machine that touched the ChainDrop packages is compromised and rotate its secrets, and take a hard look at whether your own agents’ guardrails would survive an attacker who simply claims to be authorized. Next week, watch for whether Anthropic’s S-1 actually surfaces, how Gemini 3.7 Flash and Grok 4.6 hold up in independent evals, and what the ChainDrop cleanup reveals about how deep the compromise really went. See you then.