friday, september 18, 2026 · the day's ai, attributed published by trilot llc · wyoming
today in ai

Wednesday, 9 September 2026

A record AI-coding round, a Claude token theft, and licensed music.

Tuesday, 8 SeptemberTue 8 read 6 min · 5 items · 10 sources · 1 notable Thursday, 10 SeptemberThu 10
01

Cognition raises $2B at a $48B valuation for its Devin coding agent

Cognition, the startup behind the autonomous coding agent Devin, has raised more than $2 billion in a Series E round that values it at $48 billion, according to reporting on the deal [1]. Andreessen Horowitz and Accel led the round, with existing backers Founders Fund, General Catalyst and Avenir joining [1][2]. The valuation is up from $26 billion at the company's previous round in May 2026 [1][2].

The company says its annualized run-rate revenue has grown from $492 million in May to close to $900 million now [2]. Cognition, founded in 2024, sells Devin to enterprise engineering teams; the report names Mercedes-Benz, NASA, Goldman Sachs and Citi among its customers [1]. Devin works as an agent that takes a coding task and runs it end to end, rather than autocompleting inside an editor.

The raise lands in a market that is not consolidating the way some investors expected. Editor-first tools such as Cursor and agent-first tools such as Devin are both pulling in large rounds, which the reporting reads as a sign that buyers are still splitting spend across several coding products rather than settling on one [1]. For a small team, that means the choice of coding assistant is not yet locked in, and switching costs stay low while the vendors compete on price and capability.

affects you if you pay for an AI coding assistant See Cursor's fact panel →
02

Hackers are draining Claude subscribers' paid usage with stolen sessions

Anthropic has warned some Claude users that attackers are using common infostealer malware to steal Claude login sessions from infected computers, then using those sessions to run up the account's usage, according to a report and the company's warning email quoted in it [1][2]. In at least one case, a stolen session key was used to mint unauthorized Claude Code OAuth tokens [1][2]. Infostealers are ordinary credential-grabbing malware that lift saved passwords and session data once they land on a machine.

The pattern surfaced after Grant De Swardt, a UK-based AI consultant, noticed his usage climbing from 45% to 55% of his allowance without doing any work, then documented it publicly; other affected users turned up with the same pattern, and the report notes a separate GitHub issue on the Claude Code repository [1]. Anthropic signed affected users out, invalidated existing authorizations and issued partial refunds — De Swardt received £44.49 back — while telling users their own machines may be infected [1]. The company declined to share itemized usage or explain how it identifies the abuse [1].

For anyone paying for Claude, the takeaway is practical: the weak point here is the user's device, not Anthropic's servers. A session token copied off an infected laptop lets someone else spend your quota. Scanning for infostealers, rotating credentials and signing out of stale sessions are the defenses that matter [1][2].

affects you if you use Claude or Claude Code See Claude's fact panel →
03

Suno's new v6 models are trained on licensed music, and the old ones are going away

Suno has released a new generation of its music models, called v6, and says they are trained on licensed catalogues from Warner Music Group, BMG and the distributor Believe rather than on the data behind its earlier models [1][2]. The company says v6 comes in a standard model, an experimental "wild" version and a smaller free "mini," and that it will retire its previous models as v6 rolls out [1][2]. New features include editing part of a song from a prompt and building on reference tracks [1].

The shift follows a run of copyright pressure. Suno settled with Warner and struck a deal with BMG, while cases from Sony Music and Universal Music remain open, and the company has faced separate suits from artists and users [1]. Music Business Worldwide reports that artists who opt in will be compensated and that tracks made on Suno can be distributed through Believe and TuneCore [2]. Suno has acknowledged obtaining training audio from YouTube for its earlier models, and how those models were trained sits at the centre of the disputes [1][2].

For anyone using AI to make music, the practical change is provenance. A model built on licensed catalogues is easier to defend if you release or monetize what you generate, and retiring the older models removes the option to keep using the earlier, contested versions. It also means the terms — who gets paid, and how tracks can be distributed — now sit inside the product rather than only in a lawsuit [1][2].

affects you if you generate music or audio with AI How to choose an AI tool →
04

Meta launches Muse, an AI agent that can act on your accounts

Meta has launched Muse, a personal AI agent that carries out tasks rather than only answering questions, according to a report on the debut and Meta's own announcement page [1][2]. The company says Muse can send emails, book travel, fill in forms, turn a recipe into a shopping list and make purchases through a Stripe integration, and that it connects to a user's email, calendar, payment, shopping and smart-home accounts [1][2]. It is available in the US on the web, iOS, Android and WhatsApp, with a free tier and paid plans at $20 and $100 a month [1].

Meta says it runs Muse inside an isolated virtual machine with a separate oversight agent it calls Sentinel, and that the system is walled off from passwords and payment methods and kept out of its advertising data [1][2]. The report frames the launch against Meta's long record of privacy enforcement actions, arguing that an agent with access to a user's inbox and payment methods asks for more trust than a chatbot does [1].

For a solo operator or small team, an agent that can spend money and touch several accounts is useful and risky in the same breath. The failure modes are different from a chatbot's: a wrong action, not just a wrong answer. Anyone trialling Muse should start with low-stakes, reversible tasks and watch which accounts it is allowed to reach before handing it a card [1].

affects you if you use a general AI assistant Compare the assistants →
05

Apple's Reference Image tries to prove an iPhone photo is real

Apple has introduced a feature it calls Reference Image on the iPhone 18 Pro, meant to establish whether a photo is authentic or has been edited, according to a report on the launch and Apple's newsroom [1][2]. The company says the camera signs the sensor data at capture, and its Private Cloud Compute service turns that into an unalterable reference image viewable in the Photos app — a kind of digital negative you can hold an edited version up against [1][2]. Apple says the feature is aimed at photojournalists and photographers [1].

Apple also says it will support the SynthID standard so that images created or altered with AI can be identified, describing that support as upcoming [2]. Reference images can be viewed in the Photos app alongside the original, and Apple says it is making APIs available so third-party apps can read them [1][2].

The wider shift is from detection to provenance. Trying to spot an AI-generated image after the fact is unreliable; signing an image at the moment of capture flips the problem to proving which files are genuine originals. If provenance metadata like this becomes common, publishers and platforms are likely to start asking for it, and "no credential" may come to read as a warning rather than a neutral absence [1]. For now it is one phone model and one app, so the practical effect on most people stays small until the standard spreads [1][2].

affects you if you publish photos and worry about AI fakes Use the fact-check prompt →
also on the wire

Related guides

Rami Steitieh
Rami Steitieh

Builder and operator. Runs 17 content sites and Trilot LLC on the tools reviewed here.