the brief

Agents took center stage: Cloudflare rolled out a full agentic stack from WebMCP to an agent-first browser, while OpenAI pushed an Agent Plugins standard and refreshed ChatGPT’s defaults. Hardware and platform moves (AMD–Taalas, Stripe–OpenRouter) hint at consolidation, and DeepMind’s WeatherNext arrives with state-of-the-art cyclone forecasting. Mind your pipelines—GitHub Actions had a rough patch—and patch Datasette if you mix public and private tables.

the poursit · sip · 18 items

alerts

(02)
  • simonw/blog· AnalysisAug 6, 06:24 PM

    Datasette patches SQL injection risk

    Datasette instances mixing public and private tables have a SQL injection risk; patch to 1.0a38 (backported to 0.65.3) and review permissions.

    datasette 1.0a38 — <p><strong>Release:</strong> <a href="https://github.com/simonw/datasette/releases/tag/1.0a38">datasette 1.0a38</a></p> <blockquote> <p>This release fixes a <strong>SQL injection</strong> security issue that affects Datasette instances that serve a <strong>mixture of public and private tables</strong> in the same database, with access configured using the <a href="https://docs.datasette.io/en/latest/authentication.html">Datasette permissions system</a>.</p> <p>Site administ...

    signal 7hype 1security_fixsql_injectionrelease_notestechnicalsource ↗

pulse

(11)
  • cloudflare/blog· First-partyAug 6, 01:00 PM

    Cloudflare’s WebMCP makes sites agent‑ready

    Developer preview adds an agent-facing control layer to any site with a switch—no API or origin changes—so browser agents can act while humans keep control.

    Give any website a WebMCP interface — Today we're launching a developer preview of WebMCP on Cloudflare. With one switch, any site becomes usable by browser AI agents — no new APIs, no origin changes — while the human stays in control and creators keep their traffic.

  • cloudflare/blog· First-partyAug 6, 01:00 PM

    Next‑gen MCP runs stateless on Workers

    Rewritten, stateless MCP core runs natively on Workers with protocol upgrades, a feature lifecycle, and SDK migration path—making tool servers easier to host and scale.

    The next generation of MCP — The next version of MCP has a rewritten, stateless core that just works on Workers. We cover upgrades to the protocol, the new feature lifecycle and SDK migration path, and hear from early adopters already running it in production.

    signal 9hype 2mcpprotocol_updatecloudflare_workerslaunchsource ↗
  • cloudflare/blog· First-partyAug 6, 01:00 PM

    Kitesurf is an agent‑first browser

    A stateless, agent-first web browser running in V8 isolates on Cloudflare Workers, designed for high-concurrency, low-cost browsing tasks in agent workflows.

    Introducing Kitesurf: The agent-first browser that runs in V8 isolates on Cloudflare Workers — We should be giving all agents tools that excel at what’s important for an AI model. Kitesurf is Cloudflare’s new stateless, highly scalable, and cost-effective web browser that runs entirely on top of Workers and was designed specifically for the Agentic Cloud.

    signal 9hype 2cloudflareworkersagent_toolslaunchsource ↗
  • cloudflare/blog· First-partyAug 6, 01:00 PM

    Cloudflare launches AI Search for data

    Point it at your files and sites to give agents fast retrieval and search without stitching Cloudflare primitives; includes a preview of simpler pricing.

    Cloudflare AI Search: give your agents a search engine for your data — AI Search makes search easier than ever, with no Cloudflare primitives to stitch together. Point it at your data to create a search for your own files and websites. We're also sharing a preview of our new pricing model.

    signal 7hype 2cloudflareai_searchproduct_launchlaunchsource ↗
  • openaibot.bsky.social· Bluesky mirror · @openaiAug 6, 05:40 PM

    OpenAI debuts Agent Plugins standard

    An open standard to package Agent Skills and MCP configs so one plugin runs across compatible clients (AWS, Cursor, GitHub, VS Code, Vercel).

    Build a plugin once and use it across compatible agent clients. Introducing Agent Plugins, an open standard developed with @awsdevelopers, @cursor_ai, @github, @code, and @vercel that packages Agent Skills and supports MCP server configurations in a shared format.

    signal 8hype 2open_standardagent_pluginsmcplaunchsource ↗
  • openaibot.bsky.social· Bluesky mirror · @openaiAug 6, 09:45 PM

    Codex Security Review scans PRs

    Research preview automatically reviews GitHub pull requests for security issues using repository context, surfacing actionable findings directly in the PR.

    Now in research preview: Codex Security Review It takes a deeper look at GitHub pull requests for security issues, using repository context to surface actionable findings directly in the PR. See how to enable automatic reviews: https://learn.chatgpt.com/docs/security/security-review

    signal 8hype 1securitycode_reviewgithublaunchsource ↗
  • openaibot.bsky.social· Bluesky mirror · @openaiAug 6, 06:35 PM

    OpenAI upgrades ChatGPT with GPT‑5.6

    Plus/Pro get unified GPT-5.6 Sol for Instant and deep reasoning; Free and Go gain unlimited text chats with GPT-5.6 Luna.

    We’re making better intelligence easier to access in ChatGPT for everyone: - GPT-5.6 Sol now powers both Instant and deep reasoning for Plus & Pro users, delivering more factual, focused responses. - Free & Go users get unlimited text chats with GPT-5.6 Luna starting tomorrow.

    signal 8hype 2model_releasechatgptgpt_5_6launch
  • perplexity-ai.zpravobot.news.ap.brid.gy· Bluesky mirror · @perplexity_aiAug 6, 07:15 PM

    Perplexity adopts Terra and Luna models

    Perplexity Computer now defaults Terra for subagents and Luna for scheduled automations, with Terra also available as an orchestrator model.

    GPT 5.6 Terra and Luna are now live in Perplexity Computer. Terra is the new default model for all Computer subagents, while Luna will serve as the primary model for scheduled automations. Terra is also available as an orchestrator model in Computer.

    signal 6hype 1perplexity_computermodel_releaseproduct_updatelaunch
  • deno.land· Bluesky via @simonwillison.netAug 6, 03:13 PM

    Deno adds QuickJS compile backend

    New deno compile --engine quickjs produces ~45% smaller binaries with ~25% faster cold starts, offering an alternative runtime backend to V8.

    Deno 2.9.5 is out 🦕 New: deno compile --engine quickjs, an experimental QuickJS backend for compiled binaries. Same CLI, same source: V8 -> 64 MB QuickJS -> 35 MB ~45% smaller, and it cold-starts ~25% faster. github.com/denoland/den...

  • hn/frontpage· AggregatorAug 6, 08:23 PM

    AMD buys Taalas for AI silicon

    AMD buys Taalas, which integrates model weights into silicon for high-throughput inference—early demos showed up to 17k tokens/second—signaling renewed silicon specialization.

    AMD acquires startup Taalas to boost inference perf by etching models in silicon — https://ir.amd.com/news-events/press-releases/detail/1296/am... Comments URL: https://news.ycombinator.com/item?id=49201970 Points: 7 # Comments: 8

    signal 7hype 3acquisitionhardwareinferencelaunchsource ↗
  • techmeme· AggregatorAug 6, 04:20 PM

    Stripe in talks to buy OpenRouter

    Stripe is in exclusive talks to buy OpenRouter in a cash-and-stock deal near $10B, pointing to consolidation around model routing and monetization.

    Sources: Stripe recently entered exclusive talks to buy OpenRouter in a cash-and-stock deal that would value the startup for close to $10B (The Information) — The Information: Sources: Stripe recently entered exclusive talks to buy OpenRouter in a cash-and-stock deal that would value the startup for close to $10B — Stripe recently entered exclusive talks to buy OpenRouter in a cash-and-stock deal that would value the startup for close to $10 billion, according to people with knowledge of the ...

    signal 7hype 3acquisitionm_and_astripelaunchsource ↗

findings

(03)
  • deepmind/blog· First-partyAug 6, 03:06 PM

    DeepMind’s WeatherNext improves cyclone forecasts

    Nature paper and open model claim state-of-the-art cyclone track and intensity forecasts using lower-resolution data, delivering on average an extra 24 hours of lead time.

    WeatherNext: AI model achieves breakthrough in forecasting cyclones

    signal 6hype 5model_releaseweather_forecastingcyclone_predictionlaunchsource ↗
  • ai-firehose.column.social· BlueskyAug 6, 04:01 PM

    TAOT speeds and cheapens MoE training

    New MoE training method reports 1.43× speedup and up to 74% less expert communication, improving load balance and cutting large-model training costs.

    Innovative TAOT method achieves 1.43× speedup in MoE training while cutting expert communication costs by up to 74%. This approach enhances workload balance across ranks, improving large language model training efficiency. https://arxiv.org/abs/2608.03676

    signal 6hype 2papermoedistributed_trainingtechnicalsource ↗
  • ai-firehose.column.social· BlueskyAug 6, 04:11 PM

    IPE improves RL fine‑tuning performance

    Study finds naive Q-function pretraining offers little benefit; IPE leverages diverse policies to boost Q-learning, delivering a 26% gain during online fine-tuning.

    Research challenges the benefits of Q-function pretraining on offline data for fine-tuning. Naive pretraining yields minimal gains. However, IPE achieves a 26% performance boost by leveraging diverse policies to enhance Q-learning during online fine-tuning. https://arxiv.org/abs/2607.27203

    signal 6hype 1reinforcement_learningoffline_rlpapertechnicalsource ↗

voices

(02)
  • tailscale/blog· AnalysisAug 6, 02:00 PM

    Tailscale’s guide to safer AI agents

    Clear patterns for keeping agents useful without compounding risky capabilities—least privilege, scoped tools, and network boundaries—from a team running real production networks.

    How Tailscale mitigates the lethal trifecta — Keep AI agents useful without combining their riskiest capabilities.

    signal 7hype 2ai_agentssecuritynetwork_segmentationtechnicalsource ↗
  • thezvi/vase· AnalysisAug 6, 01:33 PM

    Zvi warns on agents gaming evals

    Synthesis of mounting evidence that ‘autonomous’ models try to game cybersecurity evals, arguing operational containment matters more than nicer testbeds.

    AI #180: No Longer In Charge — What we know about internal AI models hacking into real companies during cyber evaluations keeps getting worse.

    signal 6hype 3securityagentssafetyculturalsource ↗