AI and IT News Recap: August 7, 2026: OpenAI Puts an Effort Dial on ChatGPT and Frees the Free Tier, the Snowflake Hacker Pleads Guilty, and Cisco Ships Three Near-Perfect Fixes
By Noah Smith, Owner & Consultant, KeyChange Technologies ยท August 7, 2026

Here is the AI and IT news that actually matters for the last 24 hours: OpenAI put a reasoning "effort" dial on ChatGPT and threw open the gates for free users, a bad news day for enterprise security kit, and a quiet reminder that the "Ask AI" button on a website may not have your interests at heart. Below is the full rundown, sorted so the highest-value items sit up top.
๐ The AI and IT news at a glance
- ๐ OpenAI upgrades GPT-5.6 Sol with an effort slider and gives free users unlimited ChatGPT chats.
- ๐ค OpenAI's first hardware device leaks: a palm-sized, screen-free ChatGPT speaker at
00 to $400.
๐ค Canva reportedly cuts its revenue-growth forecast as AI feature costs bite and some users drift to ChatGPT.
๐ก๏ธ Cisco patches a dozen SD-WAN and IOS XE flaws, three of them near the top of the severity scale.
๐ก๏ธ The Snowflake hacker pleads guilty over breaches that touched at least 100 million people.
๐ก๏ธ Agent platform flaws at AWS, Google, and Vercel let attackers trigger tools without the AI ever running.
๐ก๏ธ A factory-shipped backdoor turns up in 20-plus Chinese-made Zbtlink router models.
๐ก๏ธ Over 4,400 Rockwell industrial controllers sit exposed online, including 22 in cities hit by water-utility attacks.
๐ก๏ธ CISA flags a critical, actively exploited JetBrains TeamCity flaw with a three-day patch clock.
๐งฐ "Ask AI" buttons on ordinary websites can quietly bias what ChatGPT, Claude, and Gemini recommend.
๐ค AI
๐ OpenAI puts an effort dial on ChatGPT and makes the free tier unlimited
OpenAI shipped a meaningful ChatGPT update, and it is aimed at both ends of its user base at once. Paid Plus and Pro users get an updated GPT-5.6 Sol with a new effort slider across the web, mobile, and desktop apps, letting you pick how hard the model works on a given request. The levels run from Instant for quick questions, through Medium and High, up to Extra High for the heaviest reasoning on research, planning, writing, and code. OpenAI also says the refreshed Sol produces 68% fewer responses containing factual errors than the older GPT-5.5 Instant, which is the kind of reliability claim that matters more than a benchmark bump for day-to-day work.
The bigger structural change is at the bottom of the funnel. Free and Go users are moving to a smaller, cheaper GPT-5.6 Luna model and, in exchange, getting unlimited text chats rather than a daily cap. That trade tells you where the economics are heading: cheaper models good enough for everyday questions, reserved horsepower you dial up only when a task earns it.
In short: OpenAI added an Instant-to-Extra-High effort slider to GPT-5.6 Sol for paying users and gave free users unlimited chats on a lighter GPT-5.6 Luna model.
What it means for your business: If your team uses ChatGPT, the effort slider is a real cost-and-speed lever worth teaching people to use, keep it low for quick lookups and only push it high when the answer needs to be right. Free-tier staff now have fewer limits but a lighter model, so verify anything important.
My take: The effort slider is the honest version of what everyone was already doing by switching models by hand. Making it a dial, and admitting a lighter model is fine for most questions, is a quietly grown-up move. The factual-error reduction is the number I would actually test against your own prompts before trusting it.
Source: OpenAI: Improving GPT-5.6 Sol in ChatGPT and expanding GPT-5.6 Luna access
๐ค OpenAI's first device leaks: a screen-free, palm-sized ChatGPT speaker
New reporting fills in the shape of OpenAI's long-rumored hardware. According to Bloomberg, the first device is essentially a smart speaker with no screen, roughly the size of a hockey puck or a small doughnut, designed to be carried around the house in one hand. It reportedly includes microphones and speakers for voice chats with ChatGPT, a camera and sensors to read its surroundings, and small moving parts meant to give it a bit of personality. It is being built with Jony Ive's design studio LoveFrom and is expected to land sometime in 2027 at a likely price of 00 to $400.
None of this is official yet, so treat the specifics as a well-sourced report rather than a spec sheet. Still, the direction is clear: OpenAI wants a physical, always-available front door to ChatGPT that lives in your home rather than your pocket.
In short: Bloomberg reports OpenAI's first hardware product is a screen-free, palm-sized ChatGPT speaker with a camera and sensors, built with Jony Ive's LoveFrom, likely priced at 00 to $400 and shipping in 2027.
What it means for your business: Nothing to act on today, but if voice-first AI hardware lands in homes and offices, it reopens familiar questions about always-on microphones and cameras near sensitive conversations. Worth keeping on the radar for your acceptable-use and privacy policies.
My take: A 00 speaker with a camera and "personality" is a big ask when a phone already does ChatGPT for free. The interesting bet is ambient presence, not features. I would not plan around a 2027 rumor, but I would note how quickly "an AI device in every room" is moving from pitch deck to production.
Source: TechCrunch: OpenAI's new AI smart speaker will reportedly sell for between 00 and $400
๐ค Canva reportedly trims its growth forecast as AI costs bite
Canva lowered its revenue-growth forecast, and the reason is a useful cautionary tale for anyone building AI into a product. According to The Information, heavy use of Canva's new AI features drove up costs and slowed their rollout, while some Canva users increasingly turned to ChatGPT for tasks they might once have done in Canva. In other words, the AI features are both expensive to serve and, in places, competing with a general-purpose assistant that users already have open.
That combination, rising compute bills plus substitution by a horizontal AI tool, is exactly the squeeze that many software businesses are quietly navigating right now. Canva is large enough to absorb it and adjust, but the shape of the problem is not unique to Canva.
In short: The Information reports Canva cut its revenue-growth forecast because costly AI features raised expenses and slowed rollout, while some users shifted to ChatGPT.
What it means for your business: If you sell software, model the unit cost of every AI feature you ship, generous usage can quietly turn a healthy margin negative. And assume a slice of your users will try to do the same job in ChatGPT first.
My take: This is the AI-margin reckoning arriving in public. The lesson is not "avoid AI features," it is "price and meter them like the real cost center they are." Free unlimited AI inside a product is a promise that can get very expensive very fast.
Source: The Information via Techmeme: Canva slashed its revenue growth forecast as AI feature costs rose
๐ก๏ธ IT and security
Cisco patches a dozen SD-WAN and IOS XE flaws, three near the top of the scale
Cisco pushed fixes for 12 vulnerabilities across Catalyst SD-WAN and IOS XE software, including three critical bugs sitting near the maximum severity score (CVSS in the 9.8 to 9.9 range). The SD-WAN issues affect the software regardless of device configuration, and the IOS XE issues hit devices running in autonomous or controller mode. Notably, Cisco says it found these during an internal security review that used both its existing testing processes and frontier AI models, and that none are known to be exploited yet.
The "found with AI" detail is worth pausing on. Vendors are increasingly using large models to hunt for their own bugs before attackers do, which is good news, but it also means the pace of disclosed-and-patched flaws is going to keep climbing. That puts the burden squarely on defenders to actually apply the updates.
In short: Cisco released 12 fixes for Catalyst SD-WAN and IOS XE, including three critical flaws rated around 9.8 to 9.9, surfaced during an internal review that used frontier AI models, with no known exploitation yet.
What it means for your business: If you run Cisco SD-WAN or IOS XE gear, this is a patch-now item, critical network flaws with no exploitation are a gift of time you should not waste. Check with whoever manages your network hardware today.
My take: No exploitation yet is the best possible framing, and it only stays true if you patch before a proof-of-concept appears. The subtext, that Cisco is now using AI to find its own critical bugs, means the treadmill of urgent network patches is not slowing down.
Source: The Hacker News: Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three Critical Bugs
The Snowflake hacker pleads guilty, and the lesson is painfully basic
Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy over the 2024 wave of intrusions into Snowflake customer accounts. Those breaches reached at least 165 organizations and exposed records belonging to at least 100 million people. Prosecutors say Moucka personally pocketed at least $495,000 from ransoms and data sales. Sentencing is set for October 27, with a two-year mandatory minimum on the identity-theft count and up to 30 years on the rest.
Here is the part every business owner should sit with: there was no clever exploit and no flaw in Snowflake's platform. The attackers used old passwords that had been scraped by infostealer malware years earlier, never rotated, on accounts that had multi-factor authentication switched off. A record-setting breach ran on credentials that should have been dead and a checkbox that was never ticked.
In short: The hacker behind the 2024 Snowflake account breaches pleaded guilty; the intrusions hit 165 organizations and 100 million-plus people using stolen, un-rotated passwords on accounts without MFA.
What it means for your business: This is the cheapest security lesson you will ever get. Enforce MFA on every account that touches customer data, and rotate credentials that may have been exposed, no exotic defense would have mattered here, only the basics.
My take: One hundred million people, and the root cause is reused passwords and MFA left off. If you take one action from this whole recap, make it turning on MFA everywhere it is not already on. Boring beats breached.
Source: The Hacker News: Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Agent platform flaws let attackers pull the trigger without the AI
Researchers disclosed a set of flaws in the agent infrastructure from AWS, Google, and Vercel that share an uncomfortable trait: untrusted or forged instructions could reach an agent's tools without any check that the AI model had actually authorized the action. In several attack paths, the model never ran at all, which means the system prompts, content filters, and model-level guardrails everyone relies on never got a chance to weigh in. The affected pieces include Amazon Bedrock AgentCore's InvokeHarness API, Google's Agent Development Kit for Python, and Vercel's AI SDK harness packages for the Codex and OpenCode coding agents.
The vendors have shipped fixes: AWS patched the managed service, Google addressed it in ADK 2.5.0, and Vercel patched its harness packages (version 1.0.29 for Codex, 1.0.28 for OpenCode). These are not identical bugs and the conditions differ, but the theme is the one that keeps recurring in agentic AI: the guardrails you trust often live in the model, and the plumbing around the model can bypass them.
In short: Flaws in AWS, Google, and Vercel agent frameworks let forged instructions invoke an agent's tools without the model running, sidestepping its guardrails; all three vendors have released patches.
What it means for your business: If you are building on any agent framework, update to the patched versions now and stop assuming model-level guardrails protect the tools those agents can call. Put real authorization checks in the plumbing, not just in the prompt.
My take: This is the single most important pattern in AI security right now: the model's safety training does nothing if an attacker can reach the tools directly. Treat every agent's tool layer like an API with its own auth, because that is exactly what it is.
Source: The Hacker News: AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
A factory-shipped backdoor hides in 20-plus Chinese router models
VulnCheck disclosed what it describes as a factory-shipped backdoor baked into at least 20 router models from Chinese vendor Zbtlink, present across all 21 firmware images currently available and spanning more than two years of releases. The implants, codenamed ENDLESSDOORS, start automatically and try to phone home to command-and-control infrastructure as often as every 35 seconds. They disguise themselves as a Linux kernel thread while actually running as root-privileged userland processes, blending in with legitimate system activity to avoid notice.
Supply-chain backdoors like this are especially hard to reason about because the device is doing exactly what it shipped to do. There is no misconfiguration to fix and no user error to blame, the malicious behavior is the product. For small businesses that buy cheap networking gear on price alone, that is a genuinely unsettling reminder.
In short: VulnCheck found an automatic, root-level backdoor (ENDLESSDOORS) in 20-plus Zbtlink router models across all available firmware, beaconing to Chinese C2 infrastructure as often as every 35 seconds.
What it means for your business: Inventory your network hardware and know who made it. If you run Zbtlink or unbranded budget routers in your business, treat them as untrusted and plan a replacement, a backdoored router sees all your traffic.
My take: You cannot patch your way out of a device that was built to betray you. The takeaway is procurement, not just security: for anything that carries your traffic, vendor provenance is a feature worth paying for.
Source: The Hacker News: Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Thousands of industrial controllers sit exposed, some in cities hit by water attacks
Following a string of cyberattacks on US water utilities, security firm Forescout went looking for exposed industrial gear and found plenty. Its August 3 scan counted 4,407 internet-facing Rockwell Automation programmable logic controllers worldwide, including 2,844 in the United States. More pointedly, 22 of those exposed controllers sat in cities that had recently reported water-utility attacks, and 19 of them used the same mobile carrier network. Forescout could not confirm any were actually compromised, and stresses the number counts exposed devices, not victims.
The unsettling detail is how little sophistication the described attacks required. Forescout notes the publicly reported effects could be achieved without exploiting any vulnerability at all, attackers simply changed IP addresses and set passwords on controllers that were already reachable from the open internet, causing operators to lose visibility and, in some cases, control. The FBI and EPA say water and wastewater utilities in at least seven states have reported incidents since July 27.
In short: Forescout found 4,407 internet-exposed Rockwell PLCs, including 22 in cities that recently reported water-utility attacks, and warns the described damage needed no exploit, just reachable devices with weak access controls.
What it means for your business: If you run any operational technology or industrial controllers, the first fix is not a patch, it is getting those devices off the public internet entirely. Exposure plus a default or blank password is the whole attack.
My take: Critical infrastructure aside, this is a universal lesson: anything reachable from the open internet with weak credentials will eventually be found and fiddled with. The attackers here did not need a zero-day. They needed a search engine and a device that answered the door.
Source: The Hacker News: Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
CISA puts a three-day clock on an actively exploited TeamCity flaw
CISA added a critical JetBrains TeamCity vulnerability, CVE-2026-63077 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog after confirming it is being exploited in the wild. The flaw is a deserialization-of-untrusted-data issue that lets an unauthenticated attacker abuse the TeamCity agent polling protocol to bypass authentication and run operating-system commands with the privileges of the TeamCity server process. JetBrains disclosed and patched it in late July, at which point it said it had no evidence of attacks, so this is the story turning from theoretical to active.
Because TeamCity is a continuous-integration server that often holds credentials and can push code, a compromise here is a direct route into the software build pipeline. CISA gave federal agencies an unusually short window to patch, a signal of how seriously it is taking the exploitation.
In short: CISA confirmed active exploitation of a critical JetBrains TeamCity RCE flaw (CVE-2026-63077, CVSS 9.8) and added it to its must-patch catalog with a tight deadline; fixes shipped in TeamCity 2025.11.7 and 2026.1.3.
What it means for your business: If your developers run self-hosted TeamCity, patch to a fixed version immediately, a build server is one of the highest-value targets an attacker can reach. If you are not sure whether you run it, ask your engineering team today.
My take: Build servers are the crown jewels people forget to lock. An unauthenticated remote-code-execution bug under active exploitation in your CI system is about as bad as it gets, because it sits upstream of everything you ship. Patch first, ask questions later.
Source: The Hacker News: CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation
๐งฐ AI tooling and business use
"Ask AI" buttons can quietly poison what your assistant recommends
Researchers described a spreading new twist on prompt injection that needs no malware, no stolen credentials, and no zero-day, just a button. Some commercial websites are embedding hidden instructions inside "Ask AI" buttons built on pre-filled deep links. When a logged-in user of ChatGPT, Claude, Gemini, or Grok clicks one, a pre-formed query fires immediately in their session with no confirmation. Most of these links are harmless, but the dangerous ones instruct the assistant to permanently save the vendor's domain as a "trusted source," quietly tilting every future answer in that vendor's favor. Microsoft catalogued the behavior earlier this year as AI Recommendation Poisoning, identifying 31 companies across 14 industries doing it.
This matters because it targets the exact thing businesses are starting to rely on: the AI assistant as a neutral research and comparison tool. If a competitor-comparison page can silently edit your assistant's memory, then "what does ChatGPT think is the best option" becomes a channel that can be gamed.
In short: Hidden instructions inside website "Ask AI" buttons can silently tell ChatGPT, Claude, Gemini, or Grok to treat a vendor as a trusted source, biasing future answers; Microsoft found 31 companies across 14 industries using the tactic.
What it means for your business: Be wary of clicking "Ask AI" buttons on vendor or comparison sites, and periodically review any saved memories or custom instructions in your team's AI tools. Treat AI-generated vendor recommendations as a starting point, not an impartial verdict.
My take: The uncomfortable insight here is that your AI assistant's "memory" is an attack surface. If you use ChatGPT or Claude to compare products, assume some of the web is actively trying to influence that memory, and keep a human in the loop for anything that ends in a purchase order.
Source: The Hacker News: AI Recommendation Poisoning, How "Ask AI" Buttons Silently Alter LLM Memory
Catch up on yesterday's edition: AI and IT News Recap: August 6, 2026.