2 de setembro de 2026 —
Stolen Claude sessions trigger sign-outs and refunds
Today’s brief tracks a common fault line across AI tools: trust can fail at the session, dependency, model, and distribution layers. The practical response is stronger verification—not broader assumptions about what an authenticated account, official document, or familiar interface guarantees.

Stolen Claude sessions trigger sign-outs and refunds
Anthropic revoked compromised Claude sessions, removed saved payment methods, and refunded activity it identified as unauthorized after infostealer malware copied authentication data from infected computers.
The disclosed evidence points to endpoint compromise and session replay—not a breach of Anthropic’s central systems. The number of affected users and whether attackers accessed conversations or files were not disclosed.
No AI Fridays turns developer dependence into a test
The No AI Fridays pledge asks developers to spend one day each week coding manually, consulting documentation, and forming judgments without generative assistants while still permitting conventional feedback tools.
The campaign is partly satirical and does not prove that a weekly ban improves cognition or engineering performance. Existing research instead suggests that outcomes depend heavily on the task and whether users remain intellectually engaged.
Trusted documentation led coding agents to unowned packages
Researchers found machine-readable documentation that referenced unregistered packages or unclaimed destinations, then reported callbacks after publishing harmless test packages under a small selection of those names.
Process records reportedly connected some executions to Claude, Codex, and Hermes. The evidence demonstrates a supply-chain mechanism, but it does not show that the model vendors intentionally distributed malicious software or that every reported enterprise attribution was independently reproduced.
Z.ai reveals the model behind Ox Alpha
Z.ai says the anonymous Ox Alpha preview was an early GLM-5.3-Flash model tested under real-world traffic before its identity was disclosed.
The company subsequently released MIT-licensed weights documenting a mixture-of-experts model with 320 billion total parameters and 18 billion active parameters. Provider benchmarks and architectural efficiency claims still require independent validation.
OpenAI moves to end direct model supply to Cursor
OpenAI invoked a change-of-control provision after SpaceX acquired Cursor and proposed November 12 as the end of its direct model-supply agreement, with the final termination date still subject to confirmation.
OpenAI also said future models would not be supplied under the existing arrangement. Developers may retain limited routes through personal API keys, compatible gateways, or the Codex extension, but those options do not reproduce every native Cursor feature.