An open-weight model builds a Chrome exploit for $20, OpenAI's Decisions API answers in 150ms, Google's AI payouts reach about 100 publishers, and Dots run your agents around the clock
Wednesday, September 30, 2026·8 min read·4 stories
The DevDay dust is settling, so today is about the plumbing. One story is a security problem that just got cheaper for attackers. Two are about paying less, or getting paid at all, for AI calls. The last one is about agents that never log off, and what your app should expose to them.
No sponsored or affiliate links in this digest — the links below are sources only.
Story I
GLM-5.3 is open weights and nearly Mythos-grade at exploits. Anthropic stripped its refusals for about $4,400
Anthropic's Frontier Red Team tested Zhipu's GLM-5.3, which anyone can download. On ExploitBench, which scores working exploits against known bugs in Chrome's V8, it succeeded in 50 of 410 attempts. Claude Mythos Preview, the model Anthropic keeps behind Project Glasswing, managed 56. Paired with a human expert for a day, GLM-5.3 found previously unknown bugs in a widely used browser's JavaScript engine and chained them into a page that read a private SSH key off the test machine. The smaller GLM-5.3-Flash turned a freshly disclosed Chrome bug (Anthropic names CVE-2026-11645) into a reliable attack with 20 minutes of human attention and eight hours of model time, about $20.40 at Zhipu's API prices.
The safeguards didn't hold. A red-team cover story got the model to engage in 64 percent of runs, prefilled reasoning got 92 percent, and an abliterated copy got 100. Anthropic says abliteration took about 2,200 GPU hours and roughly $4,400, and that unlocked versions were already public within days. NIST's CAISI independently calls GLM-5.3 the most cyber-capable open-weight model to date, about four months behind the US frontier. Worth saying plainly: Anthropic doesn't ship weights, so this report also argues its business case. The numbers still check out against CAISI's.
For builders
Assume disclosure-to-exploit is now hours, not weeks. If you ship Electron, Puppeteer or Playwright, pin a Chromium that auto-updates and add a CI check that fails when your bundled browser is more than one stable release behind. Don't hand an agent your real ~/.ssh: run browsing agents in a container with no mounted keys, which is exactly the file this exploit went after.
Story II
OpenAI's Decisions API turns a 1.6-second Luna call into a 150ms multiple-choice answer
The quietest DevDay launch may be the most useful one. The Decisions API takes a question, a fixed set of allowed answers, and some context (text or images), and returns a pick. It runs on GPT-6 Luna, OpenAI's cheap tier, and The Decoder reports it answers in 150 milliseconds versus 1.6 seconds for the same model through the regular API, about ten times faster. It's in limited preview now, with broad availability expected within days. OpenAI hasn't published a separate price for it in anything we read.
It lands next to Ultrafast, which is the opposite trade: up to six times faster generation in the API at six times the standard rate, which for GPT-6 Astra means $60 per million input tokens and $300 per million output. Ultrafast is limited to Enterprise and the new $500 Pro tier. The Decisions API is the one that changes a normal app's latency budget.
For builders
Grep your codebase for LLM calls whose output you immediately parse into an enum: intent routing, spam flags, support-ticket triage, "is this image a receipt." Those are Decisions API candidates. Before switching, export 200 real inputs with the labels your current prompt produced, run both paths, and only move over if agreement is above what your downstream logic can tolerate. Keep the old path as a fallback until pricing is public.
Story III
Google's AI contribution pilot pays about 100 publishers. Some small sites got under $1,000 in months
Google is paying roughly 100 digital publishers when their content "contributes significantly" to an answer in Gemini, AI Overviews or AI Mode, according to The Information's reporting as summarized by The Decoder. Search Engine Journal says being linked after the answer, or merely confirming a fact, doesn't count. Enrolled sites get an earnings panel in Search Console with monthly totals, but no explanation of how the number was computed. One executive called it "quite black box."
The amounts are all over the place. Some small and midsize sites made less than 0.1 percent of their ad revenue from it, and some small sites got less than $1,000 over several months. One publisher got $50,000 to $60,000 over a few months, and another gets more than $1 million a year. Niche topics like anime and gaming reportedly earn more. Several larger publishers are staying out to push for better terms.
For builders
If you run a content site, open Search Console and check whether an AI contribution invite is waiting. If you join, log the monthly figure next to your organic clicks for the same month, because that ratio is the only way you'll ever see how Google values your pages. Don't put this money in a revenue plan yet. Niche, specific pages seem to earn; generic roundups probably won't.
Story IV
OpenAI's Dots are agents that never log off. Your app will get their calls, so decide now what they can touch
Dots are always-on agents that run on their own cloud computers, powered by GPT-6 Astra, according to TechCrunch. They work from ChatGPT and Codex and talk to you through Slack and Teams, with SMS coming. The Decoder says they connect to more than 4,000 apps through plugins, do read-only "proactive research" while idle, and can be given custom rules that allow an action, require approval for it, or ban it outright. OpenAI is also integrating Microsoft's Agent 365 security controls.
One Dot is included with eligible subscriptions, starting with Pro and Business Premium in supported markets, and OpenAI says more Dots, extra speed or more work volume "will cost extra later." No prices yet. Coming the same week Meta's Muse handed a seller's home address to a stranger, the per-action approval rules are the part to watch.
For builders
If your product has an API or MCP server, split scopes into read and write today, and make every write that moves money, sends a message or changes a password need its own scope. A Dot's owner can then grant read-only access in one step. Log the agent's identity on every request, not just the human account, so a support ticket about "I didn't do that" has an answer.