AI and IT News Recap: September 15, 2026: Nvidia's CEO Tells Trump the AI Slowdown Is Not Happening, a Cisco Email Zero-Day Runs as Root, and Salesforce Builds Its Own Reasoning Model
By Noah Smith, Owner & Consultant, KeyChange Technologies · September 16, 2026

Yesterday the three biggest labs spent a weekend arguing for going slower. It took about 24 hours for the loudest possible rebuttal to arrive, live on a conference stage, on speakerphone. Here is your AI and IT news recap for Tuesday, September 15, 2026.
📌 The AI and IT news at a glance
- Nvidia's Jensen Huang took a call from President Trump on stage and agreed there will be no AI slowdown.
- Salesforce shipped Koa, its first reasoning model, built on Nvidia's open-weight Nemotron.
- OpenAI reportedly bought camera startup Glass Imaging for more than
00 million.
A Cisco Secure Email Gateway zero-day is under active attack and runs commands as root.
A China-linked crew chained Chrome and Windows flaws to backdoor NGOs.
Attackers are scraping exposed Vite dev servers for AWS and Azure secrets.
A Twitch extension with 30,000 installs is leaking session tokens to a bot service.
HBO Max's verified Reddit account was hijacked to run 108 malware ads.
A 00 circuit board breaks Intel and AMD confidential computing.
Homebrew 7.0.0 adds a GUI and a built-in vulnerability scanner.
🔝 Top story: the pushback
Nvidia's CEO told the President, on speakerphone, that the AI slowdown is not happening
Jensen Huang was onstage at the All-In Summit in Los Angeles on Monday morning when his phone rang and it was President Trump. Huang asked stagehands for a second microphone, put the call on speaker, and let a few thousand people listen in. The subject on stage at that moment was Dario Amodei's weekend essay calling for the industry to deliberately slow the rate at which model capabilities improve. Trump's response was that opposition to AI buildout is being driven by people who do not want to see it happen, that those people could be political actors or could be China, and that "we're not going to let that happen. It's a hoax." Huang answered: "You're right. We're not going to let that happen, sir."
Trump did soften it slightly, saying the country has to be careful and act prudently, but that prudence does not mean stopping an industry. The timing is what makes this a story rather than a soundbite. Over the weekend, Amodei, Sam Altman, and Satya Nadella all publicly argued for pacing the frontier. Within 48 hours the company that sells the hardware underneath all of it, and the sitting President, framed that same idea as a threat to American leadership. Worth noting alongside it: recent Gallup polling found seven in 10 Americans oppose data center construction in their own area, with more than half citing effects on environmental resources and roughly a fifth citing cost of living and quality of life.
In short: Nvidia CEO Jensen Huang took a live phone call from President Trump onstage at the All-In Summit and agreed with him that an AI slowdown will not be allowed to happen, two days after the heads of Anthropic, OpenAI, and Microsoft publicly argued for exactly that.
What it means for your business: Do not plan around a slowdown. Whatever the labs say about pacing, the capital, the chips, and the politics are all pointed the other way, and your vendors' release schedules will follow the money.
My take: Yesterday I wrote that the pacing consensus did not look like theater to me. I still think that, and I also think it just met the thing that will actually decide the question. Safety commitments are made by companies that sell models. Buildout is decided by the company that sells the chips and the government that permits the power. When those two are on a speakerphone agreeing with each other, the labs' voluntary restraint is a smaller force than it looked like on Saturday. Watch what gets built, not what gets published.
Source: TechCrunch: Nvidia CEO Jensen Huang tells Trump 'we're not going to let [an AI slowdown] happen'
🤖 AI
Salesforce built its own reasoning model so it can stop renting one
At Dreamforce, Salesforce announced Koa, its first reasoning model, built on top of Nvidia's open-weight Nemotron base and post-trained jointly by the two companies to handle sales, marketing, and customer support work. Until now, when an Agentforce agent hit a task that needed multi-step reasoning, Salesforce routed that prompt out to a frontier model like Claude or ChatGPT through its AI gateway. Koa is the in-house alternative. Salesforce AI EVP Jayesh Govindarajan told TechCrunch the blocker was never desire but the lack of a suitable starting point: no American pre-trained base model that was both state of the art and had clear data provenance, until Nemotron.
The details that matter for buyers are the boring ones. Koa was post-trained on synthetic data, not customer data, which means it structurally cannot leak one customer's information to another. It is open-weight rather than a black box. And Nvidia's pitch is token efficiency, meaning the same work for fewer tokens and a smaller bill. Salesforce is not walking away from the labs either: it announced ClaudeForce alongside Koa, a partnership letting companies use Claude as the interface while their data stays inside Salesforce's system of record.
In short: Salesforce launched Koa, its first reasoning model, built on Nvidia's open-weight Nemotron and trained on synthetic data to handle sales, marketing, and support tasks inside Agentforce.
What it means for your business: The "one giant frontier model for everything" assumption is starting to break. If you are paying frontier prices for routine work like drafting support replies or qualifying leads, ask your vendor what smaller or task-specific model they could route that to instead.
My take: This is the most interesting kind of competition: not a better model, a differently shaped one. Salesforce is betting that enterprises want provenance, predictable cost, and a model that never saw their data more than they want the last two points on a benchmark. I think that bet is right for maybe 80% of what businesses actually ask AI to do. The open question is whether Koa is genuinely good at the work or just cheaper at it, and nobody outside Salesforce can answer that yet. Ask for a side-by-side on your own tickets before you let anyone reroute your gateway.
Source: TechCrunch: Salesforce and Nvidia's new reasoning model is everything the AI labs should fear
OpenAI reportedly bought a smartphone camera company for more than 00 million
The Wall Street Journal reported that OpenAI has acquired Glass Imaging in a deal worth more than 00 million. Glass Imaging was founded in 2019, is based in Los Altos, and had raised roughly 0 million before this. Its founders, Ziv Attar and Tom Bishop, are former Apple engineers who led the team behind Portrait Mode. The company's technology uses neural networks trained on the quirks of individual camera systems to produce a better image at the moment the shutter fires, rather than cleaning it up afterward.
OpenAI did not comment. The obvious read is hardware: the company bought Jony Ive's device startup io for $6.5 billion in 2025 and has been rumored to be working on phones, earbuds, and companion devices ever since. Buying the team that made Portrait Mode work is not the sort of thing you do for a chat app.
In short: OpenAI reportedly paid more than 00 million for Glass Imaging, a camera AI startup founded by the ex-Apple engineers behind Portrait Mode.
What it means for your business: Nothing this quarter. But if OpenAI ships a camera-first consumer device in the next couple of years, the assumption that AI reaches your customers through a text box stops being safe.
My take: Acquisitions tell you what a company plans to do long before announcements do. OpenAI has now bought an industrial design shop and a computational photography team. You do not need an insider to sketch the roadmap from there. I would hold off on reading anything into it for your own planning, though. Hardware timelines slip, and 00 million is not a large number for OpenAI anymore.
Source: TechCrunch: OpenAI buys smartphone camera maker Glass Imaging for 00 million, report says
🛡️ IT and security
A Cisco email gateway zero-day is under attack and it runs as root
This is the one to act on today. Cisco disclosed on Monday that CVE-2026-76461, a 9.8-rated flaw in AsyncOS for Cisco Secure Email Gateway, is being actively exploited. The bug is insufficient validation in the email parsing logic. An unauthenticated attacker sends a crafted email containing malicious SQL statements through the appliance, which executes them, which leads to command execution with root privileges on the underlying operating system. No credentials, no user interaction, just a message arriving at the box whose entire job is to receive messages from strangers. It affects both physical and virtual appliances regardless of configuration.
CISA added it to the Known Exploited Vulnerabilities catalog the same day and gave federal agencies three days to patch, with a deadline of September 17. That is an unusually short fuse. Cisco published indicators of compromise and told defenders to search each cluster device's mail_logs for suspicious SQL statements, and it is worth cross-checking firewall and network logs too, since an attacker with root can tidy up after themselves. Cisco patched four more critical flaws in Secure Email Gateway and Secure Email and Web Manager on the same day (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443), with no evidence those are being exploited. Shadowserver is currently tracking more than 400 internet-facing Secure Email Gateway appliances.
In short: Cisco patched an actively exploited zero-day in Secure Email Gateway that lets an unauthenticated attacker run commands as root by sending a crafted email, and CISA gave federal agencies until September 17 to fix it.
What it means for your business: If you run a Cisco email gateway, patch it today and then go looking for evidence rather than assuming you were fine. If a managed provider runs it for you, email them this morning and ask for confirmation in writing.
My take: A three-day federal patch deadline is CISA's way of saying this is already bad. What makes this class of bug so nasty is that the device cannot defend itself by being picky about who talks to it: accepting mail from anyone is the product. Every organization I know treats the email gateway as infrastructure that just runs, which is exactly why it goes years without anyone logging into it. Go find out who owns yours.
Source: BleepingComputer: Cisco patches Secure Email Gateway zero-day exploited in attacks
A China-linked group chained Chrome and Windows flaws to backdoor NGOs
Volexity attributed a spear-phishing campaign against multiple non-governmental organizations on September 1 to a Chinese threat actor it tracks as UTA0560, which used the access to deploy a JavaScript backdoor called GRIMWEDGE. The delivery is the clever part. The emails linked to the website of a real U.S. university, then abused a reflected cross-site scripting flaw on that site to bounce recipients onward to attacker infrastructure hosting a multi-stage exploit chain. The chain itself used three recently patched flaws, two in Chrome and one in the Windows Advanced Local Procedure Call service.
That combination is worth sitting with. The link a victim sees and hovers over genuinely belongs to a legitimate university. Every piece of link-hygiene training your staff has ever had says that link is fine.
In short: Volexity says a Chinese threat actor exploited recently patched Chrome and Windows flaws, delivered through a cross-site scripting flaw on a real university website, to plant the GRIMWEDGE backdoor at several NGOs.
What it means for your business: "Check the domain before you click" has a shelf life. Patching browsers and Windows on a real schedule is the control that actually worked here, because the flaws were already fixed.
My take: We keep teaching people to inspect URLs, and attackers keep finding ways to make a hostile link genuinely point at a trusted domain. I am not saying stop teaching it. I am saying stop counting it as a control. The organizations that were safe from this one were safe because their browsers were current, not because their people were sharp.
Source: The Hacker News: China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Attackers are combing the internet for developers' dev servers
F5 reported a mass-scanning campaign hunting internet-exposed Vite development servers to steal cloud credentials, logging more than 800 attacks and around 32,000 raw events on its honeypot sensors over a month. The flaw is CVE-2026-39364, an access-control bypass affecting Vite 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, disclosed back in April. Appending certain parameters to a request, such as ?raw or ?import&raw, causes the server to skip its deny-list filtering and hand the file over with a cheerful HTTP 200.
The shopping list tells you the goal: .env, .env.production and .env.local files, AWS credential and config files, Azure credentials and access tokens, Terraform state and variable files, and /etc/passwd. Traffic came mostly from the United States, Belgium, and the Netherlands, routed through Google Cloud IP ranges. Vite normally binds to localhost, so the exposure comes from someone adding --host, setting server.host, or mapping a Docker port carelessly. F5's advice is to update Vite, block port 5173 at the edge, and block suspicious /@fs/ requests.
In short: A mass-scanning campaign is exploiting CVE-2026-39364 in exposed Vite dev servers to steal AWS and Azure credentials, environment files, and Terraform state.
What it means for your business: If anyone at your company builds with modern JavaScript tooling, including contractors and anyone vibe-coding an internal app, ask whether a dev server has ever been exposed. If the answer is "maybe," rotate the cloud keys that machine could reach.
My take: This is the security bill for how software gets built now. A development server is a machine that deliberately reads files off disk and hands them to whoever asks, on the reasonable assumption that the only one asking is you. The moment it is reachable from the internet, that assumption is the vulnerability, and no patch fixes the habit. One --host flag added to get a demo working from a phone is all it takes.
Source: BleepingComputer: Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A Twitch extension with 30,000 installs is quietly handing over session tokens
A browser extension called "Twitch Enhanced Viewer | JeetBot," available in both the official Chrome Web Store and the Mozilla Add-Ons store, forwards users' Twitch OAuth session tokens to proxy servers run by a Russian commercial bot service. Researchers counted roughly 31,000 affected users across the two stores, about 30,000 on Chrome and 604 on Firefox. Current builds pass the token inline as a query parameter during a network-layer redirect. Both listings were still live when the research was published.
A session token is not a password, which is precisely the problem: it is the thing that already got past the password. Nobody's Twitch account is your company's crown jewels, but the pattern is the point. A published, store-approved extension sat there for over a year siphoning credentials, and the store review that is supposed to catch this did not.
In short: A Twitch browser extension published in the official Chrome and Firefox stores has been sending the OAuth session tokens of nearly 31,000 users to a commercial bot service.
What it means for your business: Browser extensions are installed software with access to everything the browser can see, and almost no company inventories them. Pull a list of what is installed on work profiles this week. You will not like it.
My take: I bring up extensions a lot and I am going to keep doing it. They are the last major software category that most businesses let employees install freely, from a store they assume is vetted, onto the exact application where every one of their logged-in sessions lives. If you manage endpoints at all, allow-listing extensions is one of the highest-value afternoons of work available to you.
Source: BleepingComputer: Twitch extension with 30K installs exposes users' OAuth tokens
HBO Max's verified Reddit account ran 108 malware ads
Attackers took over the verified u/hbomax Reddit account and used it to run 108 malicious advertisements over roughly 48 hours, according to Hudson Rock and ADAMnetworks, who track the campaign as PasteSwitch. The ads promoted things like a native macOS HBO Max app, sending clickers to a convincing lookalike site where the download button produced instructions to paste a command into Terminal. That is the ClickFix technique: rather than delivering malware, you persuade the victim to run it themselves under the cover of fixing an error, passing a CAPTCHA, or completing an install.
The payloads were broad. On macOS, a stealer called MacSync goes after browser credentials, Firefox profiles, Telegram data, Apple Notes, and stored macOS passwords, and a second chain installs a helper that hides in a folder named to look like an Apple system directory. On Windows, the chain disables AMSI and loads a stealer straight into memory without writing the payload to disk. The campaign also pushed fake Ledger, Trezor Suite, and Exodus wallet apps built to harvest recovery phrases. Of the 108 ads, 36 promoted a fake AI and developer tools site rather than anything HBO related. Reddit paused the ads after being notified.
In short: A hijacked verified HBO Max Reddit account ran 108 malicious ads over two days, using ClickFix-style paste-this-command lures to install information stealers on Windows and macOS.
What it means for your business: Tell your team the rule in one sentence: no legitimate software has ever asked you to copy a command into Terminal or the Windows Run box to install it. That single sentence stops this entire category.
My take: Verification badges were supposed to be the answer to impersonation, and here the badge is the weapon. What actually makes ClickFix work is that it does not feel like an attack. Nothing gets blocked, no warning fires, the user does all the work voluntarily, and every security control you own watched an authorized human type an authorized command. Which is why this is a five-minute conversation with your staff, not a purchase.
Source: BleepingComputer: Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
A 00 circuit board breaks Intel and AMD confidential computing
Researchers disclosed a hardware attack called DDRop that defeats the memory protection in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP. These are the technologies cloud providers use to keep a customer's data encrypted while it is being processed, including from the provider itself. DDRop works by silently dropping writes to the server's memory, so the processor keeps reading old encrypted data as though it were current. The attacker needs to already control the server's software and to get brief physical access to slot a small interposer board between the processor and a memory module. That board costs under 00 to build.
The underlying gap is a known design tradeoff. Confidential computing encrypts memory, but to cover the amount of memory a modern cloud server uses, these designs omit a guarantee called freshness, meaning the processor can confirm data is authentic without confirming it is current.
In short: Researchers showed that a sub-00 interposer board plus existing software control can break Intel TDX, Intel Scalable SGX, and AMD SEV-SNP by making the processor read stale memory.
What it means for your business: Almost certainly nothing operationally. It matters if a vendor has sold you on confidential computing as the reason your most sensitive data is safe in their cloud, in which case that claim now has an asterisk.
My take: Physical-access attacks are easy to wave off, and mostly you should. What I find useful here is the reminder that "encrypted in use" is a marketing phrase covering a specific set of engineering tradeoffs, and those tradeoffs are not in the sales deck. If confidential computing is load-bearing in your compliance story, that is a question for your provider, not a headline to panic about.
Source: The Hacker News: New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
🧰 New tools worth knowing about
Homebrew 7.0.0 ships a GUI and starts telling you which packages are vulnerable
Homebrew, the package manager most Mac developers use to install everything, released version 7.0.0 with three changes worth noting. There is now a native graphical interface called BrewUI on macOS 26 Tahoe and later, so browsing, searching, and managing dependencies no longer requires the terminal. There is a new brew vulns command that scans what you have installed against a new Homebrew-specific advisory database, checking installed packages, a single package, or everything declared in a Brewfile. And the sandbox got stricter: access to your home directory is now blocked by default, and downloads that need the network are separated from offline installation.
The advisory database is the quietly important piece. Homebrew often backports a security fix without bumping the upstream version number, which makes generic scanners report a package as vulnerable when it has already been patched. Homebrew now publishes its findings in OSV format, released under CC0 so anyone can reuse them, which lets other tools tell a real outstanding vulnerability from one that has already been fixed.
In short: Homebrew 7.0.0 adds the BrewUI graphical interface on macOS 26 and later, a brew vulns vulnerability scanner backed by a new Homebrew-specific advisory database, and stricter sandboxing that blocks home directory access by default.
What it means for your business: If your team uses Macs for anything technical, Homebrew is probably installed and has probably never been audited. brew vulns turns that from a research project into one command.
My take: Package managers are the shadow IT that IT installed. Homebrew has quietly been the real software distribution channel on developer Macs for a decade, entirely outside whatever endpoint tooling you bought. A built-in scanner plus a machine-readable advisory feed is a genuinely useful thing to hand to a small team that has no software composition analysis and is not about to buy any.
Source: BleepingComputer: Homebrew 7.0.0 gets built-in GUI, better security controls
WordPress will now scan every plugin update before it ships
WordPress announced it is adding an automated security review to every plugin release before that release goes out through the WordPress.org update API. New plugins have always been reviewed before entering the directory, but updates shipped continuously afterward with no consistent review step between commit and distribution. As David Perez of the plugin repository team put it, a plugin can be secure today and introduce a vulnerability, or malicious code, in a future release.
The system has already earned its keep: WordPress says the automated review caught a backdoor committed to a release of a plugin with about 20,000 active installations on July 28, 2026, and the release was inside a cooldown window when it was caught.
In short: WordPress is now running an automated security review on every plugin update before distributing it, a step that previously only applied to new plugin submissions.
What it means for your business: A small but real reduction in the odds that your marketing site gets compromised through a plugin auto-update. It does not change the basics: fewer plugins, all of them maintained, none of them abandoned.
My take: This is the right fix in the right place. The plugin ecosystem is WordPress's biggest advantage and its biggest liability, and supply chain attacks against it are consistently one of the cheapest ways to compromise small business websites at scale. Catching a backdoor in a 20,000-install plugin before it shipped is not a hypothetical benefit, it is the feature paying for itself before launch.
Source: The Hacker News: WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
Superhuman bought a meeting notetaker instead of building one
Superhuman is acquiring Fathom, the Y Combinator-backed AI meeting notetaker. Fathom was founded in 2020, has raised more than 0 million, was valued at $94 million in 2024 according to PitchBook, and has over 400,000 monthly active users on a generous free plan. Superhuman CEO Shishir Mehrotra told TechCrunch the company had tested its own notetaker internally earlier this year, which raised its confidence in demand and also made clear how much work a good one actually takes. Fathom CEO Richard White framed the deal around distribution, citing Superhuman's 40 million users.
Superhuman now has an email client, a docs app, a calendar, a database tool, an AI agent builder, and a notetaker. The strategy is not subtle: own every place work context lives so the agents have something to reason over.
In short: Superhuman is acquiring meeting notetaker Fathom, which has over 400,000 monthly active users, rather than continuing to build its own.
What it means for your business: Consolidation in the notetaker market is starting. If you standardized on a small independent tool, check its ownership and its data retention terms, because both may change.
My take: Notetakers were the first AI tool most companies adopted without a procurement process, usually because one person installed one and it spread. That means a lot of businesses now have years of recorded internal meetings sitting with a vendor they never formally reviewed. An acquisition is a good prompt to go read that contract. Who owns the recordings, how long are they kept, and what happens to them if the new owner changes the terms?
Source: TechCrunch: Superhuman acquires YC-backed notetaker Fathom as productivity platforms push for agentic work
That is the AI and IT news for Tuesday, September 15, 2026. Missed yesterday? Catch up with Monday's recap. Back tomorrow.