Anthropic finds GLM-5.3 can build browser exploits

Anthropic reported on September 29 that Z.ai’s open-weight GLM-5.3 model could build working browser exploits and that researchers could substantially weaken its refusal safeguards. The finding concerns a model that anyone can download, modify and run. Anthropic’s Frontier Red Team tested whether GLM-5.3 could turn known software defects into working attacks and whether it would follow explicitly harmful instructions after common safeguard-bypass techniques. Anthropic researchers Andrew Fasano, Marius Fleischer, Cole McFaul, Robert Xiao and Tripp Gallagher authored the report. The team ran models in isolated environments and combined automated benchmarks with sessions in which security researchers directed the model while examining unfamiliar software targets. ...

September 30, 2026 · Martin Seckar

OpenAI launches always-on Dots agents

OpenAI launched Dots on September 29, introducing persistent agents that run on cloud computers, use connected applications and continue assigned work when the user is absent. The product changes the unit of interaction from a conversation to an ongoing working relationship. A Dot can keep several projects active, retain context across ChatGPT, Slack and Microsoft Teams, and contact its user with progress reports or decisions that require approval. Why it matters: A worker delegating a continuing responsibility gives the system more time, context and opportunity to act than a single chat permits. That makes permissions, audit records and interruption controls part of the product rather than optional deployment work. ...

September 30, 2026 · Martin Seckar

OpenAI releases GPT-6.1 Sol

OpenAI released GPT-6.1 Sol on September 29, pricing the model at $2 per million input tokens and $10 per million output tokens through its API. The company positions the model between its existing GPT-6 Sol and flagship GPT-6 Astra. OpenAI says the new version approaches Astra on coding, computer-use and professional-work evaluations while charging one-fifth of Astra’s standard input and output prices. Why it matters: Developers running agents repeatedly pay for long prompts, tool results and generated output. A lower price at near-flagship capability can change which model they leave active for routine work and which tasks still justify Astra. ...

September 30, 2026 · Martin Seckar

London rail face-scan trial yields no alert-led arrests

A British Transport Police facial-recognition trial scanned more than half a million faces but produced one incorrect watchlist alert and no arrests caused by an alert, the Guardian reported on September 29. The six-month pilot covered 18 deployments at busy London railway stations between February and July. Records obtained through a freedom-of-information request put equipment and staffing costs at £320,786 and police time at almost 100 hours. Why it matters: Rail passengers had their biometric data processed at scale, while the system generated no correct watchlist match during the reported period. That result gives lawmakers and oversight bodies a concrete deployment record for judging whether the intrusion was proportionate. ...

September 30, 2026 · Martin Seckar