Google Threat Intelligence disclosed this week the first confirmed case of a threat actor deploying an AI-developed zero-day exploit in the wild — novel enough to ship, caught mid-staging before wide-scale damage landed. On the same day, a $250K bug bounty paid out to an AI on a vulnerability top human auditors missed. Both are real. Both are happening this week. The attack surface and the defense capability are scaling together, and the gap between them is not closing.
What's underneath it is a leverage asymmetry that the capital side hasn't priced. Frontier models are now producing offensive artifacts good enough for production use; the defenders who catch them are also running frontier models. But Joe Fielding's founder — six months into a $15M Series A, now planning to return the cash because Claude erodes the product's defensibility long-term — is the tell. One camp is compounding on the capability curve. The other raised into a moat that the same models are dissolving. Those two bets don't end in the same place.
Top developments
Supply-chain crisis broadens — Mini Shai-Hulud jumped from TanStack to Mistral AI, OpenSearch, Guardrails, and UiPath, hooks into Claude Code and VSCode settings so it re-fires after the infected package is uninstalled, while a separate RubyGems campaign pulled 120+ malicious packages harvesting SSH keys and credentials and forced the registry to pause signups. The blast radius is no longer one ecosystem — package registries themselves are now the contested surface, and "uninstall" stopped being a fix. x x x
Google Threat Intelligence — disclosed the first known case of a threat actor using an AI-developed zero-day exploit in the wild, caught mid-staging before a wide-scale strike landed. The defender-side counter is the headline; the underlying signal is that frontier-model offensive capability has now produced a novel vuln good enough to ship — exactly the asymmetry Daybreak/Mythos arguments have been theorizing for months. x
Anthropic — launched Claude for Legal: 20+ connectors into legal-tech products and 12 practice-area plugins covering contracts, privacy, employment, litigation, IP, AI governance, and access-to-justice work, with legal already the top power-user function in Claude Cowork. After AWS-native distribution and finance agents, this is the third vertical in a fortnight where Anthropic ships pre-built workflows directly into the buyer's tools instead of selling raw API. x x
Anthropic — in advanced talks to acquire Stainless for at least $300M, per The Information — the New York firm that auto-generates SDKs from API specs and already builds the official SDKs for OpenAI, Anthropic, and Cloudflare. Anthropic is buying the integration layer most labs share, which makes the developer-platform race less about API design and more about who owns the surface customers' clients ship against. x
Isomorphic Labs — closed $2.1B led by Thrive, with Alphabet, GV, CapitalG, MGX, Temasek, and the UK Sovereign AI Fund joining — the "in talks" round from May 9 priced and added sovereign capital. AI-for-drug-design is now a sovereign-backed category at frontier-lab ticket sizes, and the UK fund picking Isomorphic over a US lab is a small but real signal on where strategic-AI patience capital is flowing. x
Google — unveiled Gemini Intelligence and the Googlebook laptop, a fall-launch flagship that builds Gemini into the OS layer and syncs natively with Android, alongside refreshed Android AI for multi-step task automation. The Apple-style hardware-plus-model bundle is finally Google's playbook too; the open question is whether owning the device tier wins back the consumer-AI surface Gemini has been losing to ChatGPT. x x
Notable discussions
FDE wars escalate — Aaron Levie argued forward-deployed engineering is becoming one of the most in-demand roles in tech because deploying agents is professional services, not software install; Google Cloud committed $750M to ecosystem transformation partners in a clear FDE-style move; PostHog and Eric Siu started hiring globally, while Ed Sim and Arvind Jain warned the FDE-led approach masks unsolved governance and agent-sprawl issues. The split is whether AI rollouts are a temporary services bulge (collapses once products mature) or the new permanent shape of enterprise software delivery — and which side you're on determines whether you're hiring 200 FDEs or building eval platforms. x x x x
Sharp takes
Fei-Fei Li — argues the industry's fixation on language models is dangerously narrow: most of the real economy is physical, perceptual, and spatial, and once AI fully understands the visual world it stops being a chatbot and becomes infrastructure — a direct rebuke to the agent-everywhere consensus from someone who saw the last vision-AI cycle from inside Google. x
Lee Rob — pushes back on the "code is dead, markdown is the new code" framing rising around skills and HTML artifacts: agent-generated slop compounds, the right response is fewer-but-verifiable lines (typed languages, robust tests, better architecture up front), not lossy markdown summaries of code no one reads. x
Aakash Gupta — reads Ilya Sutskever's sworn testimony that OpenAI needs a for-profit arm as the closing argument Musk's lawyers didn't want: the same man who tried to fire Altman in 2023 over the nonprofit mission is now running his own $30B Delaware C-corp because frontier compute can't be funded by donations. The compute won the argument. x
Mark Cuban — says OpenAI will never recoup the trillion-dollar AI infrastructure spend the industry is committed to, and the cost-of-capital reckoning has not been priced into private valuations yet — worth surfacing on the same day Anthropic's tokenized market sees a $500B paper-value swing on a single tweet. x
BonesawMD — calls the 10-1000x productivity narrative vapor and challenges anyone to name a single product made in one year with AI that would have taken a dedicated solo developer ten years — entire comment section produced no examples, just "you know nothing." The sharpest framing yet of the gap between LLM-PR reels and shipped artifacts. x
Joe Fielding — flags a founder who raised a $15M Series A from a top-tier VC six months ago and is now planning to return the cash because Claude will erode the product's defensibility long-term. The first concrete data point we've seen of vertical-AI capital being voluntarily un-deployed against the Claude-Skills/agent-templates threat. x
Amjad Masad — argues you haven't felt AI progress until you've run orchestrated parallel agents that merge back cleanly; sequential single-agent work is local, the unlock is fan-out plus correct re-integration, and the developers who get this are 10x ahead of the ones running one chat at a time. x
Other news
Models & releases
Perceptron Mk1 — frontier video and embodied-reasoning model released x
Claude Opus 4.7 fast mode — research preview on API and Claude Code x
Meta AI Voice Conversations — interrupt/switch-language voice + live camera AI on Muse Spark x
Krea 2 — new aesthetic-control foundation model targeting Midjourney x
OpenMed 100B — open-source medical model available for local use x
Ash open-source SLMs — SOTA accuracy at 93x smaller; second model beats a recent OpenAI release x
Interfaze — new model beats Sonnet/Gemini/GPT on OCR, vision, and speech tasks x
MiniCPM-V 4.6 — solo-dev multimodal fine-tuning on a single GPU x
Funding & deals
Vapi — $50M Series B led by Peak XV, 1B calls served, 10x enterprise ARR x
n8n — $5.2B secondary led by SAP, double October's mark, multi-year embed in Joule Studio x
A* Ventures — $450M early-stage Fund III, >$1B AUM in under five years x
Judgment Labs — $32M to build production-data infrastructure for AI agents x
Cognition — $445M ARR with <$20M cumulative burn x
Stripe Climate / equity transfers — Anthropic and OpenAI issue formal statements voiding unapproved share transfers x
Devtools & coding agents
OpenAI Symphony — every open task gets a running Codex agent x
Todoist Claude connector — task management inside the Claude session x
Jotform Claude app — natural-language form building x
Mobbin MCP — 600k real app screens piped into Claude and Cursor x
Conductor — adopts Codex with GPT-5.5 as default harness x
Pullfrog — open-source CodeRabbit alternative running in GitHub Actions x
Cloudflare agent fetch — fetches and markdownifies pages for agent consumption x
Claude Code Desktop — remote control now on by default x
Industry & policy
GitLab — CEO publishes 14-tweet AI-pivot thread alongside layoffs and country footprint cut by 30% x
Ilya Sutskever testimony — under oath in Musk v. OpenAI: "no funding, no big computer"; $7B stake disclosed x
Anthropic and OpenAI — back-to-back statements declaring unapproved secondary transfers void x
AI bias — PM-interview probe surfaces hiring tool that recommends 15% fewer candidates from certain demographics x
Codex install spike — 90M installs in seven days as Anthropic restricted Claude Code pricing tiers x
Security
Shai-Hulud worm — open-sourced as a fully weaponized tool after GitHub takedown, mirrored by vx-underground x
$250K AI bug bounty — largest payout ever to an AI, on a vuln top human auditors missed x
PROMPTSPY — Google flags new Android backdoor designed to exfil agent context x
pnpm v11 — ships smart defaults blocking newly-published packages by default x
Infisical Honey Tokens / Agent Vault — fake AWS creds and credential management for agent runtimes x
TanStack hardening guide — official post-mortem and mitigation recommendations x
Infrastructure & platforms
AWS Lambda Firecracker — 125ms boot times powered by a 50K-line Rust binary x
Modal — new infrastructure stack purpose-built for AI inference x
Supabase + Stripe Sync Engine — automatic data sync into Postgres x
Upstash — agents can spin up free Redis instances without signup x
Daytona — scales to 5M concurrent sandboxes x
GitHub Copilot — token-based billing preview after years of flat-rate pricing x
Web & frontend
Shopify — official llms.txt support added natively x
Tailwind CSS v4.3 — new scrollbar, zoom, and tab-size utilities x
Oxlint/Oxfmt — experimental Svelte support x
styled-components v7 — runtime-dependency-free release x
Continuing threads
Anthropic secondary squeeze — yesterday's debate continues with $500B of paper value wiped on tokenized markets after Anthropic/OpenAI statements x x
Codex eating Claude Code — 90M installs in seven days; Cursor now consumes more tokens than Claude + Codex combined x x
HTML vs Markdown — Lavish ships an HTML-artifact editor, Lee Rob counters with "code is the right abstraction" (covered as Sharp take) x
Mini Shai-Hulud expansion — Shai-Hulud worm open-sourced and mirrored; community converges on pnpm + 7-day minimum release age as mitigations x x