← Back to archive

Thursday, May 28, 2026

Meta's guardrails cracked in 10 minutes

Meta and Google's safety guardrails were stripped in under 10 minutes using free tools (yikes), while Uber burned through its entire 2026 AI budget in just four months despite 70% of their code now being AI-generated. Meanwhile, ClickUp went bold with a 22% layoff while deploying 3,000 AI agents to hit a 3:1 AI-to-human ratio, and a critical Starlette vulnerability is exposing millions of AI agents to auth-bypass attacks. Would you burn two years of budget in four months for 90x productivity with invisible ROI?

Top Stories

1
Meta and Google's open-source guardrails stripped in under 10 minutes using free tools

Financial Times

Safety guardrails on Meta and Google's open-source AI models can be stripped in under 10 minutes with free tools, exposing significant vulnerabilities in how these models are protected against misuse.

metagoogleopen-sourceai-safety
2
Uber burned its entire 2026 AI budget in four months. Per-dev API token spend jumped from $500 to $2,000 a month. 70% of committed code is AI-generated, ROI invisible

Wired

Anthropic's Claude Code and open-source OpenClaw have created 'Claudeholics'—developers reporting 90x productivity gains but burning through AI budgets at unsustainable rates, with per-developer token costs quadrupling to $2,000/month while ROI remains invisible.

ai-agentsanthropicclaudedeveloper-tools
3
ClickUp restructures to a 3:1 AI-to-human ratio in a single press release: 22% layoff alongside 3,000 internal AI agents and 1,000 remaining humans

TechCrunch

ClickUp laid off 22% of staff while deploying 3,000 AI agents to create a 3:1 AI-to-human workforce ratio, promising million-dollar salaries to employees who leverage AI effectively. The move reflects a broader trend where 80% of companies using autonomous tech have reduced headcount, though productivity gains remain unproven for many.

agentslayoffsworkforceclickup
4
CVE-2026-48710 "BadHost": critical Starlette auth-bypass exposes millions of AI agents, FastAPI, vLLM, and LiteLLM

Ars Technica

A trivial-to-exploit vulnerability in Starlette framework exposes millions of AI agents and servers to authentication bypass, threatening credentials stored in MCP servers and affecting major tools like FastAPI, vLLM, and LiteLLM. The flaw was patched Friday but poses critical risk to the Python AI infrastructure ecosystem.

securityvulnerabilityai-agentsfastapi
5
OpenRouter more than doubles valuation to $1.3B in a year

TechCrunch

AI gateway OpenRouter raised $113M at a $1.3B valuation, more than doubling in value within a year as it processes 100 trillion tokens monthly across 400+ models. The startup's success indicates enterprises are embracing a multi-model strategy rather than standardizing on single AI providers.

fundingopenrouterai-gatewayenterprise-ai

Keep Reading

Industry Voices

Enjoyed this issue?

Get daily AI intel delivered to your inbox. No fluff, just the stories that matter.