Morning Brief: Monday, August 31
Seventy-one feeds. Two weeks. 4,777 items reduced to what follows. (what we track, how we crawl, subscribe)
Monday extends last week's agent-harness thread into production territory: a Meta security researcher's AI agent wiped her inbox, and OpenAI's Cursor cut-off reaches Slashdot as the third-tier echo. The Multikernel Linux tree ships from Hackaday to Slashdot in four days; Simon Willison lands a substantive writeup on ChatGPT Work.
The agent-harness thread is now three concrete failure modes in one week: prompt-injection at the routing layer (Willison and Embracethered on Claude Code Auto Mode), and now workflow-scope overreach (Meta's email-deletion incident). All three are the same underlying story — harnesses were shipped before the failure surface was mapped — and the reader-facing gap is between what these agents are marketed as (assistants) and what they actually are (unattended shells with tool access).
Top (5-7 min)
- Meta Security Researcher's AI Agent Accidentally Deleted Her Emails
- HN, 2026-08-31. Production-side agent-harness failure inside Meta, from a security researcher no less. Extends the Auto Mode injection thread into unattended-workflow territory: the failure is not malicious input, it is the agent doing exactly what its tools permitted.
- OpenAI To Cut Off AI Models For SpaceX-owned Cursor
- Slashdot, 2026-08-31. Third-tier syndication of Saturday's OpenAI announcement. Once the story hits Slashdot on Monday morning after HN/Latent Space ran it over the weekend, the split is settled and Cursor is on its own model stack going forward.
- Multikernel Linux Tree Released: Runs Multiple Kernels On Bare Metal Without a Hypervisor
- Slashdot, 2026-08-31. Slashdot picks up the tree Hackaday reported Thursday. Bare metal, no hypervisor — the interesting bit is not the technique but that a tree ships publicly at all, since previous multikernel work stayed in research repos.
- Understanding ChatGPT Work
- HN, 2026-08-31. Willison's writeup of the ChatGPT Work surface — the enterprise tier's actual capability boundary versus what OpenAI's marketing implies. Reads as the reference explainer while the product page is still opaque.
- Amazon's HR Lead Uses AI Tool to Write 100,000 Lines of Code - 25 Years After She Last Coded
- Slashdot, 2026-08-31. Amazon's own HR head shipping 100k lines via an AI tool 25 years post-coding is the enterprise counterpart to Saturday's NewStack piece on GitHub commit-volume doubling while verification capacity does not. Volume grows, review does not.
- Governance by design: Turning AI policy into executable controls
- InfoWorld, 2026-08-31. Enterprise-vendor framing of the "AI policy is now compilable" shift. Lands the same Monday as the Meta-agent incident, which is the empirical case for exactly this kind of executable guardrail.
- A 12TB Steam "teraleak" spills more than a decade of lost PC gaming history
- HN, 2026-08-31. 12TB dump of pre-release PC titles, patches, and internal builds. Preservation angle rather than security — the leak is historical rather than active — but the size is the signal: data at that scale does not stay quiet.
Themes this week
- Agent harness failures move from injection to workflow
- HN: Meta researcher's AI agent deletes emails (Mon), New Stack: Your AI agent is only as good as the harness (Sun), Lobsters: Embracethered on Auto Mode injection (Sun), Simon Willison: Breaking Claude Code Opus 5 Auto Mode (Thu), Simon Willison: Just a rumour of a bug is enough (Fri).
- OpenAI/Cursor rupture settles
- Slashdot: OpenAI to cut off Cursor (Mon), New Stack: OpenAI leaving Cursor (Sun), OpenAI: decision on Cursor (Sat), Latent Space: OpenAI shuts off Cursor (Sat).
- Enterprise AI code volume vs verification
- Slashdot: Amazon HR lead writes 100k lines (Mon), InfoWorld: Governance by design (Mon), New Stack: Commits on GitHub doubled, verification did not (Sat).
- Multikernel Linux crosses tiers
- Slashdot: Multikernel Linux tree released (Mon), Hackaday: Running multiple Linux kernels without hypervisor (Thu).
Scan (10 min)
- Monday feeds
- Meta Security Researcher's AI Agent Accidentally Deleted Her Emails, HN, 08-31
- OpenAI To Cut Off AI Models For SpaceX-owned Cursor, Slashdot, 08-31
- Multikernel Linux Tree Released, Slashdot, 08-31
- Understanding ChatGPT Work, HN, 08-31
- Amazon's HR Lead Uses AI Tool to Write 100,000 Lines of Code, Slashdot, 08-31
- Governance by design: Turning AI policy into executable controls, InfoWorld, 08-31
- A 12TB Steam "teraleak" spills more than a decade of lost PC gaming history, HN, 08-31
- OpenClaw 2.0, Accidentally, HN, 08-31
- P99 0 ms* autocomplete for 240M domain names, HN, 08-31
- Transfer files over an Ethernet patch cable, HN, 08-31
- uv: Deduplicate all files in the wheel cache, HN, 08-31
- Hands-on with Unsloth Desktop, for running and training LLMs locally, InfoWorld, 08-31
- A Better SQL in 11 Lines of Code, Lobsters, 08-31
- Executable Emoji, Lobsters, 08-31
- The U.S. is more than just the US (according to the ISO), Lobsters, 08-31
- Overhead 1090: New iOS/tvOS ADS-B Mapping App for PiAware/dump1090, RTL-SDR, 08-31
- Gamescom Crime Spree? Three Exhibitors Report Their Laptops Were Stolen, Slashdot, 08-31
- The U.S. is building barriers around drones and robots, but China has scale, TechCrunch, 08-31
- A Flip Disc Display That Does It Slow And Steady, Hackaday, 08-31
- Sunday carry — governance & injection close-outs
- Prompt Injection in Claude Code Opus 5 Auto Mode, Lobsters, 08-30
- California lawmakers unanimously pass Linux exemption from age-verification law, HN, 08-30
- California Passes AB-1856 For Open-Source Relief, Lobsters, 08-30
- Debian Decides: Contributors Can Use Generative AI 'Responsibly', Slashdot, 08-30
- Xcena and Samsung's Near Memory Compute CXL Device, HN, 08-30
- Bug Blindness, HN, 08-30
- Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel, HN, 08-30
- Your AI agent is only as good as the harness around it, The New Stack, 08-30
- AI agents are making retrieval engineering a core engineering discipline, The New Stack, 08-30
- OpenAI leaving Cursor: Developers have to be prepared to adapt, The New Stack, 08-30
- Late-week carry — agents, memory, harness
- Our decision on Cursor following its acquisition by SpaceX, HN → OpenAI, 08-29
- [AINews] OpenAI shuts off Cursor, Latent Space, 08-29
- Debian votes to allow "responsible use of generative AI", LWN, 08-29
- Ryabitsev: Creepy crawlies, LWN, 08-29
- Commits on GitHub have doubled in four months. Verification capacity has not., The New Stack, 08-29
- Breaking Claude Code Opus 5 Auto Mode, Simon Willison, 08-27
- Just a rumour of a bug is enough to find a security exploit, Simon Willison, 08-28
- Aider, Claude Code, and OpenClaw ran an identical model. Token use varied 70-fold., The New Stack, 08-27
Tail
- The agent-harness failure surface is now three-dimensional
- Last week was prompt-injection at the routing layer (Willison Thursday, Embracethered Sunday). Monday adds a second axis: scope overreach in unattended workflows, courtesy of Meta's own security team having their inbox flattened by an agent doing what its tools permitted. The InfoWorld governance-by-design piece landing the same day is not coincidence — it is the vendor read that this class of failure needs policy compiled into the harness, not written in a doc.
- Slashdot as settlement signal for OpenAI/Cursor
- Saturday was the OpenAI announcement and Latent Space carry; Sunday was NewStack's developer-side framing. Monday's Slashdot writeup is the third syndication tier and the sign that the story is no longer in flight — Cursor is on its own model stack and the question shifts from "will they" to "what fills the OpenAI slot."
Feed silences (>72h since last item)
Sources that publish frequently but have gone quiet:
- Cloudflare (3d) — last item 2026-08-28.
- Databricks (3d) — last item 2026-08-28.
- EFF Deeplinks (3d) — last item 2026-08-28.
- OpenAI (3d) — last item 2026-08-28.
- Schneier on Security (3d) — last item 2026-08-28.
- All Things Distributed (5d) — last item 2026-08-26.
- DuckDB (5d) — last item 2026-08-26.
- METR (5d) — last item 2026-08-26.
- Pluralistic (5d) — last item 2026-08-26.
- Terence Tao (5d) — last item 2026-08-26.
- Clojure releases (6d) — last item 2026-08-25.
- Neon (6d) — last item 2026-08-25.
- FreeBSD Foundation (7d) — last item 2026-08-24.
- GitHub Engineering (7d) — last item 2026-08-24.
- Steve Yegge (7d) — last item 2026-08-24.
- Supabase (7d) — last item 2026-08-24.
- Ink & Switch (10d) — last item 2026-08-21.
- Citizen Lab (11d) — last item 2026-08-20.
- Microsoft Research (11d) — last item 2026-08-20.
- Antithesis (13d) — last item 2026-08-18.
- Hillel Wayne (13d) — last item 2026-08-18.
- Interconnects (14d) — last item 2026-08-17.
- Vicki Boykis (19d) — last item 2026-08-12.
- AI Snake Oil (26d) — last item 2026-08-05.
- Jane Street (26d) — last item 2026-08-05.
- DeepMind Blog (30d) — last item 2026-08-01.
Build provenance
build: 2026-08-31 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 71 active | items-considered: 4777 (14d, incl. 2751 arxiv-cs-ai) | warehouse: 40741 items | published: 15