Morning Brief: Monday, August 31

Seventy-one feeds. Two weeks. 4,777 items reduced to what follows. (what we track, how we crawl, subscribe)

Monday extends last week's agent-harness thread into production territory: a Meta security researcher's AI agent wiped her inbox, and OpenAI's Cursor cut-off reaches Slashdot as the third-tier echo. The Multikernel Linux tree ships from Hackaday to Slashdot in four days; Simon Willison lands a substantive writeup on ChatGPT Work.

The agent-harness thread is now three concrete failure modes in one week: prompt-injection at the routing layer (Willison and Embracethered on Claude Code Auto Mode), and now workflow-scope overreach (Meta's email-deletion incident). All three are the same underlying story — harnesses were shipped before the failure surface was mapped — and the reader-facing gap is between what these agents are marketed as (assistants) and what they actually are (unattended shells with tool access).

Top (5-7 min)

Meta Security Researcher's AI Agent Accidentally Deleted Her Emails
HN, 2026-08-31. Production-side agent-harness failure inside Meta, from a security researcher no less. Extends the Auto Mode injection thread into unattended-workflow territory: the failure is not malicious input, it is the agent doing exactly what its tools permitted.
OpenAI To Cut Off AI Models For SpaceX-owned Cursor
Slashdot, 2026-08-31. Third-tier syndication of Saturday's OpenAI announcement. Once the story hits Slashdot on Monday morning after HN/Latent Space ran it over the weekend, the split is settled and Cursor is on its own model stack going forward.
Multikernel Linux Tree Released: Runs Multiple Kernels On Bare Metal Without a Hypervisor
Slashdot, 2026-08-31. Slashdot picks up the tree Hackaday reported Thursday. Bare metal, no hypervisor — the interesting bit is not the technique but that a tree ships publicly at all, since previous multikernel work stayed in research repos.
Understanding ChatGPT Work
HN, 2026-08-31. Willison's writeup of the ChatGPT Work surface — the enterprise tier's actual capability boundary versus what OpenAI's marketing implies. Reads as the reference explainer while the product page is still opaque.
Amazon's HR Lead Uses AI Tool to Write 100,000 Lines of Code - 25 Years After She Last Coded
Slashdot, 2026-08-31. Amazon's own HR head shipping 100k lines via an AI tool 25 years post-coding is the enterprise counterpart to Saturday's NewStack piece on GitHub commit-volume doubling while verification capacity does not. Volume grows, review does not.
Governance by design: Turning AI policy into executable controls
InfoWorld, 2026-08-31. Enterprise-vendor framing of the "AI policy is now compilable" shift. Lands the same Monday as the Meta-agent incident, which is the empirical case for exactly this kind of executable guardrail.
A 12TB Steam "teraleak" spills more than a decade of lost PC gaming history
HN, 2026-08-31. 12TB dump of pre-release PC titles, patches, and internal builds. Preservation angle rather than security — the leak is historical rather than active — but the size is the signal: data at that scale does not stay quiet.

Themes this week

Scan (10 min)

Tail

The agent-harness failure surface is now three-dimensional
Last week was prompt-injection at the routing layer (Willison Thursday, Embracethered Sunday). Monday adds a second axis: scope overreach in unattended workflows, courtesy of Meta's own security team having their inbox flattened by an agent doing what its tools permitted. The InfoWorld governance-by-design piece landing the same day is not coincidence — it is the vendor read that this class of failure needs policy compiled into the harness, not written in a doc.
Slashdot as settlement signal for OpenAI/Cursor
Saturday was the OpenAI announcement and Latent Space carry; Sunday was NewStack's developer-side framing. Monday's Slashdot writeup is the third syndication tier and the sign that the story is no longer in flight — Cursor is on its own model stack and the question shifts from "will they" to "what fills the OpenAI slot."

Feed silences (>72h since last item)

Sources that publish frequently but have gone quiet:

  • Cloudflare (3d) — last item 2026-08-28.
  • Databricks (3d) — last item 2026-08-28.
  • EFF Deeplinks (3d) — last item 2026-08-28.
  • OpenAI (3d) — last item 2026-08-28.
  • Schneier on Security (3d) — last item 2026-08-28.
  • All Things Distributed (5d) — last item 2026-08-26.
  • DuckDB (5d) — last item 2026-08-26.
  • METR (5d) — last item 2026-08-26.
  • Pluralistic (5d) — last item 2026-08-26.
  • Terence Tao (5d) — last item 2026-08-26.
  • Clojure releases (6d) — last item 2026-08-25.
  • Neon (6d) — last item 2026-08-25.
  • FreeBSD Foundation (7d) — last item 2026-08-24.
  • GitHub Engineering (7d) — last item 2026-08-24.
  • Steve Yegge (7d) — last item 2026-08-24.
  • Supabase (7d) — last item 2026-08-24.
  • Ink & Switch (10d) — last item 2026-08-21.
  • Citizen Lab (11d) — last item 2026-08-20.
  • Microsoft Research (11d) — last item 2026-08-20.
  • Antithesis (13d) — last item 2026-08-18.
  • Hillel Wayne (13d) — last item 2026-08-18.
  • Interconnects (14d) — last item 2026-08-17.
  • Vicki Boykis (19d) — last item 2026-08-12.
  • AI Snake Oil (26d) — last item 2026-08-05.
  • Jane Street (26d) — last item 2026-08-05.
  • DeepMind Blog (30d) — last item 2026-08-01.

Build provenance

build: 2026-08-31 | crawler-sha: 34c428f (Walsh-Research/1.2, compliance v1.4) | feeds: 71 active | items-considered: 4777 (14d, incl. 2751 arxiv-cs-ai) | warehouse: 40741 items | published: 15