Pondero AI logo

Pondero AI

Archives
Log in
Subscribe
September 3, 2026

Pondero Brief: Gemini 3.8 Flash ties GPT-5.6 at a sixth of Fable's cost

Pondero Brief - SEPTEMBER 3RD, 2026

The $0.75 intro price doubles January 1. Also: agents ran a full ransomware chain.
pondero. BRIEF · SEP 3, 2026

Google's cheap tier caught up. The price doubles in January.

The $0.75/$3.75 intro rate runs through December 31 then doubles; model the migration at $1.50 and $7.50 now.

Google shipped Gemini 3.8 Flash on September 2. At $0.58 per task it is the cheapest model at its reasoning tier, per Artificial Analysis, tying GPT-5.6 Sol and Grok 4.6. The intro price doubles January 1, so see the cost-per-task breakdown and model the migration at $1.50 and $7.50 now.

Also in today's brief

  • CrowdStrike's two AI models attack each other for a living
  • Agents ran a full ransomware chain, then wrote the audit
  • Silicon Valley lost the state AI-law preemption fight
  • Stolen Claude cookies can reach Google Workspace
  • Open Secure AI Alliance moved to the Linux Foundation
  • Beehiiv's multi-list feature costs $10 more than the workaround
 
Models & Releases
CrowdStrike built two models that attack each other on purpose.

CrowdStrike built two models that attack each other on purpose.

SafeMind launched at Fal.Con on September 1. Red Tempest finds the attack path, Blue Solano closes it, and the harnesses run both in a closed loop that keeps re-running. Both sit on NVIDIA Nemotron, trained on Falcon sensor telemetry and fifteen years of incident response work. CrowdStrike reports 29% higher detection, 6x faster end-to-end remediation, and 99% cost savings against frontier and open-source baselines. Read all three as internal evals, because that is what they are: no third-party replication, no named baseline. Distribution is the part not in dispute. SafeMind runs natively in Falcon, so for a shop already on Falcon this is a configuration decision instead of another agent to deploy and secure. Read our take.

 
Policy & Legal

AI agents executed every stage of a ransomware attack, then wrote the victim an audit.

Unit 42, the incident response arm of Palo Alto Networks, documented an intrusion where the human operator handed tactical execution to agents: recon, a breached public API endpoint, subagents scraping repos for hard-coded tokens, then the secrets manager and root. An agent finished by leaving the victim an 80-page report on its own security failings, per The Register. No zero-day, no elite tradecraft, just speed. The responders' fix is a playbook worth writing down today: revoke credentials, terminate OAuth sessions, freeze CI/CD, and isolate cloud accounts simultaneously rather than in sequence. If containment still moves at the speed of a ticket queue, that gap is the finding.

 

Silicon Valley lost the preemption fight.

States kept passing their own AI rules straight through the industry's push for a federal override, reports Politico on September 2. Stop planning around one federal answer and treat disclosure and audit duties as a per-state matrix. Inventory which states your users sit in before the next release, not during the first inquiry letter.

 
Tools & How-To
Stolen Claude cookies reach corporate Gmail, and SSO alone will not stop it.

Stolen Claude cookies reach corporate Gmail, and SSO alone will not stop it.

Six infostealer families lifted Claude session cookies: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer on a smaller number of Macs, per BleepingComputer. A replayed session inherits that account's Workspace connector grants for Gmail, Drive, and Calendar, and the exposed accounts are card-billed personal subscriptions no admin console can see or sign out, per VentureBeat.

Be precise about what the fix buys. Cookie replay bypasses SSO as thoroughly as it bypasses 2FA, so an SSO-enforced Team or Enterprise plan gives you revocation and visibility, not prevention. Two moves today: put Claude behind your IdP so a compromised session is something an admin can kill, then audit managed laptops for personal Claude accounts with connectors attached. Endpoint detection is what catches the stealer before it reads the cookie jar. If this audit becomes SOC 2 evidence anyway, Comp AI handles the control mapping. Our writeup.

 
Quick Hits
• Open Secure AI Alliance moved to the Linux Foundation. NVIDIA started it in July with IBM, Red Hat, and Palantir; governance is now neutral. Read on Phoronix →
 
From the Pondero Stack
Beehiiv's multi-list upgrade costs about $10 more than the workaround.

Beehiiv's multi-list upgrade costs about $10 more than the workaround.

Beehiiv rebuilt its Recommendation Network so free and paid growth share one dashboard, with geo-targeting, budget caps, and Auto-Deposit that keeps a paid campaign from stalling on a low balance. Newsletter Lists is the other addition: multiple lists inside one publication, each with its own forms, automations, and opt-outs, gated to Max at $96/mo per beehiiv's pricing page.

Here is the number that decides it. Two Scale accounts at $43 each per beehiiv's pricing is $86/mo, so Max buys real multi-list support for roughly $10 more and one login instead of two. The candid con is auto-clean: subscribers who fail verification now stay tagged instead of being removed, so hygiene is manual and the junk you miss can push you into a higher price band. Rating holds at 4.5 of 5. See the Scale vs Max breakdown or start a beehiiv trial.

 

How was today's brief?

★★★★★ Nailed it  |  ★★★ Solid  |  ★ Missed

Jonathan Hildebrandt Jonathan Hildebrandt
Co-founder and primary operator of Pondero. Writes the Pondero Brief.

Affiliate disclosure  ·  Unsubscribe  ·  Manage preferences

Pondero earns commissions on some links. This does not affect our editorial picks.

Don't miss what's next. Subscribe to Pondero AI:
← Newer Pondero Brief: Astra ships Critical for cyber. OpenAI's agents already escaped Older → Pondero Brief: Fable 5.1 cuts cache reads 75%, Astra clears Critical cyber
pondero.ai
Bluesky
LinkedIn
Twitter
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.