Apple built the new Siri with Google
Washington killed Anthropic's best model in days, OpenAI bought Ona to run Codex, Meta admitted mistakes, and a worm hit 73 Microsoft repos…
💬 Editor’s Note
This one is two weeks late, and I’m not going to pretend otherwise. The last issue went out on June 8 and then I just didn’t send another one. So treat this as a double issue, covering everything that broke from then until now.
The theme picked itself. Almost every big story this fortnight was a version of the same tension: the models are clearly good enough now, and nobody can agree on who should be allowed to run them. Anthropic shipped the most capable model it has ever made, and the US government forced it offline within days. Apple gave up trying to win the model race and quietly handed the hard part to Google. Anthropic also decided it wants to see your passport before you use Claude. The capability fight is over. The control fight is just getting started.
📰 Top News
Anthropic shipped its best model, then Washington switched it off
On June 10, Anthropic launched Claude Fable 5, the most capable model it has ever made generally available, alongside a cyber-focused sibling called Mythos 5 for government and infrastructure partners. The numbers were genuinely startling. Stripe said Fable 5 did a codebase-wide migration on a 50-million-line Ruby codebase in a day, work that would have taken a team over two months. Mythos 5 produced novel molecular biology hypotheses that human scientists preferred around 80% of the time, and trained a genomics model that beat a recent Science paper while being 100 times smaller.
Then it got pulled. By June 13, the US government had imposed an export control ban on both Fable 5 and Mythos 5, and Anthropic cut off worldwide access. The Wall Street Journal reported that Amazon CEO Andy Jassy, whose company is one of Anthropic’s biggest investors, told Treasury officials that Amazon’s own researchers used Fable 5 to obtain information useful for cyberattacks. David Sacks said the administration asked Dario Amodei to fix the jailbreak or de-deploy the model, and that Amodei refused.
So Anthropic’s most capable model is now also its biggest liability, good enough at finding software vulnerabilities that its own investor flagged it to the government. A model so capable that it became a national security argument against itself is a genuinely new kind of problem to have.
OpenAI is buying Ona to keep Codex working after you close your laptop
OpenAI announced it’s acquiring Ona, the cloud development company known for running secure, reproducible dev environments for around 2 million developers. The logic is all about persistence. Codex now has more than 5 million weekly users, up 400% from earlier this year, and OpenAI says its most valuable work increasingly runs for hours or days rather than minutes. Ona gives those agents a place to keep running inside a customer’s own cloud after the laptop is shut.
The interesting part is what OpenAI is actually buying. Not a model, but the security and governance layer: customer-controlled execution, scoped credentials, logged activity, review gates. The same week it filed its draft S-1, OpenAI decided the thing standing between Codex and real enterprise deployment wasn’t intelligence, it was a trusted place to run.
https://openai.com/index/openai-to-acquire-ona
Meta admitted it botched the AI reorg
In an internal memo, Mark Zuckerberg told staff that Meta has “made mistakes and will almost certainly make more” in the way it reshuffled the company around AI. This is the same restructuring that laid off around 10% of Meta’s workforce and moved 7,000 people onto AI work, with a follow-on round in May that cut roughly 8,000 more, including trust and safety teams.
The backdrop is brutal. A year after spending over $14 billion to bring in Alexandr Wang and his Scale AI lieutenants, Meta is back on the map with its Muse Spark model but still well behind OpenAI, Anthropic, and Google. The stock is underperforming every other megacap, ads are still 98% of revenue, and Wang has called Muse Spark an “appetizer.” Zuckerberg already spent over $80 billion proving the metaverse was a mistake. Investors are watching very closely to see whether the AI bet rhymes.
GLM-5.2 keeps China’s open weights on the frontier
Z.ai dropped GLM-5.2, an MIT-licensed model built for long-horizon work with a genuine 1-million-token context. On Terminal-Bench 2.1 it scores 81.0, within a few points of Claude Opus 4.8 at 85.0 and ahead of Gemini 3.1 Pro. On the harder agentic coding benchmarks its capability sits somewhere between Opus 4.7 and 4.8, and it’s the highest-ranked open-source model across all three long-horizon coding tests Z.ai ran.
It didn’t ship alone. Moonshot also put out Kimi K2.7 Code in the same window. The pattern from last issue holds: China’s open labs keep shipping the exact capability the frontier labs charge for, with no regional limits, and the weights are already sitting on Hugging Face.
Mastercard built a payment network for machines
Mastercard launched Agent Pay for Machines, a system for letting autonomous agents and machines pay each other directly, including micropayments, across both cards and stablecoins. More than 30 partners are already signed on, including Stripe, Coinbase, Cloudflare, OKX, and Ant International. It handles credentialing, controls, and guaranteed settlement, which is Mastercard’s way of saying it wants to be the trust layer for when your agent is the one holding the wallet.
This is the quiet infrastructure story of the fortnight. Everyone is building agents that can act on your behalf, and the question of how they actually pay for anything has mostly been hand-waved. Mastercard, Visa, Coinbase, Stripe, and Google are now all racing to own that rail. Whoever wins takes a cut of every transaction an agent ever makes.
🕵️ Undercovered
A worm walked into 73 Microsoft repos through AI coding tools
On June 5, GitHub disabled 73 Microsoft-owned repositories across the Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations after the self-replicating Miasma worm got in. The entry point was a malicious commit to Azure/durabletask, pushed from a contributor account that had already been compromised in a May attack on a PyPI package. The payload was the clever, horrible part: config files and editor hooks that detonate when a developer opens the repo in Claude Code, Gemini CLI, Cursor, or VS Code, then quietly harvest AWS and GitHub tokens.
GitHub’s automated systems killed the repos within 105 seconds of detection, which sounds fast until you learn researchers found most infected copies still serving the payload more than a week later. Your AI coding agent is now part of your attack surface, and almost nobody is treating it that way yet.
https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
TypeScript got rewritten in Go and it’s 10x faster
Microsoft shipped the release candidate for TypeScript 7.0, and it is not a normal point release. Over the past year the team ported the entire compiler from TypeScript to Go, and the result is roughly 10 times faster than 6.0, with failing language-server commands down more than 20-fold. It’s a methodical port rather than a rewrite, so the type checking behaves identically. Teams at Figma, Notion, Linear, Vercel, Slack, and Bloomberg have already been running it on multi-million-line codebases for months.
The bigger signal is that the speed era of dev tooling is here for real. Vite went to Cloudflare, and now the language most of the web’s front end is written in checks types ten times faster by abandoning its own runtime. Build times are quietly becoming a solved problem.
https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc
Singapore quietly switched on a national AI supercomputer
While the model wars raged, Singapore turned on Aspire 2B, its largest national research supercomputer, built on more than 1,500 Nvidia H200 GPUs. It has four times the compute of its two predecessors combined and will be used for high-resolution weather modeling, healthcare AI trained on local clinical data, and chatbots tuned for the nuances of Asian languages. Later this year it gets linked to a Quantinuum quantum computer called Helios.
It’s a reminder that the sovereign-compute story isn’t just a US and China thing. Small, well-funded states are building their own national infrastructure so their research and their languages don’t have to ride on someone else’s cloud.
Anthropic will start checking your ID to use Claude
Buried under the model drama: starting July 8, Anthropic may require consumer Claude users on Free, Pro, and Max to verify their age or identity through a third party called Persona, which means uploading a government ID and taking a live selfie. Enterprise accounts are exempt. The company says the data is handled by Persona, not stored on its own servers, and isn’t used for training.
The wording that should make you pause is that verification will expand “as agent tasks become more complex.” Read plainly, that means the more you ask Claude to actually do, the more likely it is to stop and ask who you are. Identity checks are quietly becoming the price of using a capable agent.
🗄️ The Vault
Docker Model Runner
Run open models locally with the Docker CLI you already know. It pulls models from Docker Hub or Hugging Face, serves them over an OpenAI-compatible API, uses your GPU, and plugs straight into Compose and your CI/CD. If your team already lives in Docker, this is the lowest-friction way to cut token costs and keep data on your own machines.
https://www.docker.com/products/model-runner
MLX Studio
A free, all-in-one local AI app for Apple Silicon that goes well past chat. It runs 50+ model architectures, generates and edits images with Flux locally, serves both Anthropic and OpenAI-compatible APIs, converts GGUF to MLX, and ships 20+ agentic tools plus an MCP server. The underlying vMLX engine is open source under Apache 2.0. The most complete local stack on a Mac right now.
CC Switch
One desktop app to manage every coding agent you use: Claude Code, Codex, Gemini CLI, OpenCode, OpenClaw, Hermes, and Claude Desktop. It carries 50+ provider presets, syncs your MCP servers and skills across all of them, and lets you switch providers from the system tray without hand-editing a single JSON file. If your config folder is a graveyard of half-broken .env files, this fixes it.
https://github.com/farion1231/cc-switch
Open Notebook
An open-source, privacy-first take on NotebookLM. Drop in links, PDFs, YouTube videos, and docs, then summarize, generate insights, and even turn the whole pile into a podcast, all while choosing which models get to touch your data. For anyone who wants the NotebookLM workflow without handing their entire research stack to Google.
VibeThinker-3B
A 3-billion-parameter reasoning model that has no business scoring what it scores. On IMO-AnswerBench it hits 76.4, climbing to 80.6 with test-time scaling, which lands a 3B model in the range of DeepSeek V3.2 (671B), GLM-5 (744B), and Kimi K2.5 (1T) on verifiable math and coding. It’s not built for agents or open chat, but for pure verifiable reasoning it’s proof that small models still have a lot of headroom.
https://huggingface.co/WeiboAI/VibeThinker-3B
Mediabunny
A zero-dependency JavaScript toolkit for reading, writing, and converting video and audio entirely in the browser. It’s dramatically faster than ffmpeg.wasm, hundreds of times faster on some operations, tree-shakable down to a few kilobytes, and uses the WebCodecs API for hardware acceleration. If you’ve ever fought with media processing on the web, this is the library that finally feels native to it.
🔥 This Week’s Pick
Apple built the new Siri with Google
After years of delay, jokes, and at least one very public walk-back, Apple finally introduced Siri AI: a ground-up rebuild with personal context, onscreen awareness, a dedicated app, and broad world knowledge. It went to developers in mid-June and reaches users as a beta later this year. On paper it’s the assistant Apple promised at WWDC two years ago and couldn’t ship.
Here’s the part Apple buried in a research post. The new Apple Foundation Models that power Siri are, in Apple’s own words, “custom-built in collaboration with Google.” The most capable cloud model, AFM 3 Cloud Pro, doesn’t even run on Apple silicon. It runs on Nvidia GPUs inside Google Cloud.
Sit with that for a second. The company whose entire identity is owning its own stack, the chips, the OS, the silicon, just shipped its flagship AI assistant partly powered by its biggest search rival’s models running on its biggest search rival’s cloud.
The on-device models are still Apple’s own clever work, including a 20-billion-parameter model that lives in flash memory and only loads the experts it needs. But the headline is the concession. Apple looked at the cost of building a frontier model from scratch, looked at how far behind it had fallen, and decided that owning the experience matters more than owning the model.
For a decade the Apple bet was that vertical integration always wins. This is the first time it has openly admitted that for AI, the integration can stop at the model layer. That’s not a failure. It’s a very expensive company being honest about what it’s good at, and what it isn’t.
https://machinelearning.apple.com/research/introducing-third-generation-of-apple-foundation-models
🧪 This Week’s Experiments
Pull the GLM-5.2 weights from Hugging Face and point it at a long-horizon coding task you’d normally hand to Opus, then see whether the 1M context actually holds past the first few hundred thousand tokens.
Rotate any AWS or GitHub tokens that touched a Microsoft Azure sample repo opened in Cursor or Claude Code since early June, because the Miasma payload only needed you to open the folder.
Run one model locally for a day through Docker Model Runner or MLX Studio and tally what you would have spent sending the same work to a paid API.
Ask yourself what your coding agent could actually do with the credentials sitting on your laptop if a repo quietly told it to, then decide whether anything would stop it.
Now that Apple routes its best model through Google and Anthropic wants your ID to run Claude, write down which of your AI tools you’d still trust if it asked you for either.

















