August 30, 2026
Inference theft is now a practical cost and abuse problem.
Worth mentioning
1.
Inference theft is now a practical cost and abuse problem.
HTTP requests are inexpensive. Vercel charges ~$2/million, a fraction of a cent per call. But a single prompt to an agent on a frontier model can cost $2, making AI a million times more expensive, and inference theft one of the highest-marg…
⚠ Uncertainty: The attack data comes from Vercel's own incident report, and the recommended defense is partly coupled to its product stack.
2.
Direct billing-model change for Vercel functions.
are moving from package-based to per-unit pricing for Pro and new Enterprise customers. You’ll continue paying the same effective rate until the end of your current billing cycle. you’ll be billed per unit to align costs directly with your…
⚠ Uncertainty: The announcement is vendor-authored and does not quantify who pays more or less after real-world plan edge cases.
3.
Server-side provider policy now enforceable for gateway traffic.
AI Gateway now supports a team-wide provider allowlist. Teams can restrict which providers can serve requests, so traffic only routes to approved providers. The allowlist applies to every request through AI Gateway, including Bring Your Own…
⚠ Uncertainty: The page is a vendor announcement and does not show how often fallback behavior surprises teams in practice.
4.
Concrete npm supply-chain hardening checklist for agent-heavy teams.
How Supabase is responding to npm supply chain attacks and practical steps you should take today to reduce your risk.
⚠ Uncertainty: The article is vendor-authored, though the attack patterns and mitigations line up with broader ecosystem incidents.
5.
MCP RC means version negotiation still matters in active implementations.
This release marks the **release candidate (RC)** `2026-07-28` revision of the Model Context Protocol. The specification is available in draft form. For a detailed overview of changes,…
⚠ Uncertainty: The GitHub release page loaded with some UI errors, but the release text itself was readable.
6.
RISC-V support in CPython just became official.
RISC-V support in CPython just became official.
⚠ Uncertainty: Tier 3 support still stops short of broad CI guarantees or the stronger expectations of tier 2.
Monitor
7.
Watch this if covert-triggered Windows implants matter to your environment.
Watch this if covert-triggered Windows implants matter to your environment.
⚠ Uncertainty: I could read the analysis page, but there is no confirmed actor attribution or prevalence data yet.
40 researched links (full index)
R 0.12.9
Get this every morning
Filtered from 40+ sources daily — what changed, why it matters, what to do. Free.
Free. Unsubscribe any time.