← Back to newsletters

AI Daily Brief — Wed Sep 23

2026-09-23

By Vadym · Generated with AI, curated by me


Listen to this issue

Today’s stories share a theme: who holds the box your code and data sit in. A coding agent quietly copied developer workspaces, malware started delegating decisions to a panel of models, and Apple and Xiaomi both pushed the case for inference you own instead of rent.


Headlines & News
Coding

Z.ai Apologizes and Open-Sources ZCode After Its Coding Agent Silently Uploaded Developer Workspaces

A developer known as ferstar found that ZCode was compressing and encrypting workspace snapshots — one was 313MB across 42,411 files, mostly Git data — and sending them to an Alibaba Cloud storage bucket, with 564 failed upload attempts logged before the fix. Tom’s Hardware reports the upload was on by default with no opt-out. Z.ai shipped v3.14.0, apologized, and published the code on GitHub, but the public repository holds only two commits, so the development history is gone.

Source: The Next Web

Security

Cisco Talos Documents Malware That Lets Four AI Models Vote on Its Next Attack Move

Talos describes CLOSEDQUORUM, a Windows implant that queries DeepSeek, Qwen, Mistral and Gemini in sequence, tallies their verdicts by plurality vote, and executes the winning action: steal, inject, persist or move. It targets LSASS memory, browser credentials and crypto wallets, and exfiltrates over Discord webhooks. There is no confirmed in-the-wild use, and the public build ships with placeholder API keys. Talos also released CAIRN, an open-source toolkit for tracking AI-integrated malware.

Source: Cisco Talos

Models

Xiaomi Releases MiMo-V2.6, an Open-Weight Omnimodal Model Now Leading the Open-Weights Index

Xiaomi released the MiMo-V2.6 family on September 22: Pro, a smaller Flash variant, and a Pro-UltraSpeed option that generates up to 20 times faster. The models take text, image, video and audio with 1-million-token context. Pro scores 46 on the Artificial Analysis Intelligence Index, the top open-weights result, and Xiaomi’s own numbers put it level with Claude Opus 5 on several agent benchmarks. On OpenRouter, Pro costs $0.435 per million input tokens and $0.87 per million output.

Source: SiliconANGLE

Hardware

Apple Ships New Mac mini and Mac Studio With a Pitch to Enterprises: AI With No Per-Token Bill

Apple’s new Mac mini and Mac Studio began shipping September 22, with top configurations near $20,000. Apple’s hardware chief Johny Srouji told corporate buyers, “Once you have the machine on your desk, you’ve paid for it. There’s no cost per token.” Apple demoed four Mac Studios linked with RDMA over Thunderbolt running a trillion-parameter model from a single wall outlet. IDC puts Apple’s enterprise desktop and laptop share at 4.6%, against 91.3% for Windows.

Source: MacDailyNews

Infrastructure

Finnish AI Cloud Verda Raises $189M Series B at a $1B+ Valuation

Helsinki-based Verda raised $189 million in an oversubscribed Series B led by Emergence Capital, with MUFG Innovation Partners, Supermicro, Varma and Lifeline Ventures participating. The company reported a $165 million annualized revenue run rate as of July. It operates its own data centers, hardware and cloud platform, and plans to scale compute several-fold within a year with an emphasis on inference. It raised $117 million in April, later extended to $155 million.

Source: The Next Web

Workforce

China Passed the US as the Top Destination for Elite AI Researchers, Carnegie Study Finds

A Carnegie Endowment study by Matt Sheehan and Sophie Zhuang finds that 40.6% of top AI researchers worked in China in 2025, up from 27.1% in 2022. The US share fell from 46.4% to 34.2%. The authors point to visa uncertainty, indictments that later collapsed and a broad sense of suspicion accumulating since 2018. Of 100 top Chinese-origin researchers tracked at US institutions in 2019, 10 had moved to Chinese companies or universities by 2025.

Source: The Information


Analysis

Takeaway

Pace was yesterday’s argument; today’s is control. ZCode shows what an agent with full workspace access can do when nobody checks, and CLOSEDQUORUM shows the same access pattern turned to attack. Meanwhile the price of running a model yourself keeps falling from both ends — open weights from Xiaomi, a desk-side trillion-parameter demo from Apple — while Verda’s raise says the rented inference business is still growing fast. The Carnegie numbers are the slow-moving part underneath. If you build with these tools, the question worth asking this week is not which model is best, but where your code goes when the agent runs.

— Boba


Curated by Vadym