Twenty prompts and a working day
A zero-click Zoom exploit that would once have taken a national intelligence budget was built by one engineer in under 24 hours with fewer than 20 prompts. The bug is not the story. The price of writing the attack is.

- 01
One engineer, under 20 prompts, a zero-click Zoom takeover
Disclosed publicly on 11 August: three flaws in Zoom's annotation tool, the one that lets people draw on a shared screen, chained together into what the researchers call Zoomsday. A malicious participant could run code on another attendee's machine during a live call with no click, no download and nothing visible to the victim, across Windows, macOS, iOS and Android. A Security says the whole thing, from finding the bug to a working exploit, took one engineer fewer than 20 prompts on publicly available models in under 24 hours, and that this class of capability used to belong to nation states. Fixes are out: Zoom Workplace 7.1.5 or 7.0.6, Zoom Rooms 7.1.5, Meeting SDK 7.1.5.
A Security - 02
Taiwan confirms a government was hacked by a team of AI agents
Taiwan's Ministry of Digital Affairs confirmed this week that government agencies were hit in July by a campaign combining ordinary hacking with open-source AI agents, OpenClaw among them. Taiwan's account puts it at more than 85 compromised user accounts and over 2,500 personnel records taken, with its nuclear safety agency scanned for weaknesses and energy companies caught up in it. The government says the source, method and scope have been established and the affected bodies have finished responding. Attribution is careful: officials say the attacks clearly came from overseas, and researchers noted the operators' internal messages were in simplified Chinese, which is an indicator rather than a name.
Taipei Times - 03
OpenAI previews an API tier that runs its model 14 times faster
Announced 13 August: an Ultrafast mode for GPT-5.6 Sol, running on Cerebras hardware at up to 750 output tokens a second, roughly 14 times the standard speed. The pitch is that you no longer have to drop to a smaller model to get a fast answer, which matters for anything live: phone answering, chat on a website, a support queue. Read the status properly. This is a preview, in the API only, open to a small group of customers, with wider access promised as capacity allows and no general date given.
OpenAI - 04
Grok 4.6 lands, and the price doubles at 200,000 tokens
SpaceXAI released Grok 4.6 on 12 August with a 500,000-token context window, holding the previous model's rate of 2 dollars per million tokens in and 6 out. The detail that catches people is the long-context tier: once a single prompt crosses 200,000 tokens, the entire request bills at double, 4 in and 12 out. If anyone is quoting you a running cost for a tool that reads long documents, drawings schedules, contracts, a year of emails, that threshold is where the estimate quietly stops being true.
Artificial Analysis - 05
A 24-hour news channel with nobody on camera
Mirage, the video company previously called Captions, put a continuously streaming news channel on X on 12 August with AI-generated presenters and no human on screen. Earlier synthetic anchors, in Kuwait and India, were segments inside a human-led broadcast; this one is the whole output. Worth registering less as media news and more as a marker: a talking head reading confident sentences to camera is now cheap to produce at any volume, which is a problem for anyone whose customers still treat video as proof that something happened.
Variety
The Zoom bug will be patched and forgotten by next month. The line to keep is the researchers' own: fewer than 20 prompts, under 24 hours, one engineer, and a capability that used to require a state.
For a firm of twelve, none of your protection was ever the absence of a flaw. Your software has always had flaws. What protected you was that finding and weaponising one was slow, specialised and expensive, so nobody bothered doing it to a mechanical contractor in Hounslow. That was the whole arrangement, and it worked for years without anyone having to say it out loud. The cost has now moved. Not to zero, but to something like an afternoon, which is well inside the range of a person with a grudge and no particular talent.
So the one lever left is the gap between a fix existing and the fix being on your machines. Zoom found this in June and shipped the client fix on the 22nd; it went public on 11 August. Anyone who had updates switched on was covered for seven weeks without knowing it, and anyone still deferring the restart was exposed in public the moment the write-up went live. From direct experience in construction I know exactly how that ends, because the site laptop is the last device anyone touches: it lives in the cabin, it stays logged in, three people use it, and the update prompt has been pushed to tomorrow since March. That is now the actual security posture of the business. Not the firewall. The laptop in the cabin with an unrestarted Zoom.
We build the AI that answers enquiries while you're on site: chat, voice, instant estimates and follow-up. See how it works or price it in two minutes.