NextWith.ai Daily

Coverage: (UTC) · 6:24 · English

AI-generated narration. Based on NextWith.ai reporting.

Download MP3

In this episode

  • Meta hotfixes Muse after a local dictation hijack demo
  • Rabbit makes OS3 available without the R1
  • Snorkel AI raises money as data shifts toward expert environments
  • OpenAI and Anthropic lower prices, but buyers still have to test
  • Synthesis and close
Read the full transcript

Welcome

Welcome to the NextWith.ai Daily, an AI-narrated roundup of the latest AI news. Today we’re looking at how agent products are being pushed by both progress and pressure: a security hotfix at Meta, a broader rollout from Rabbit, a big funding story for Snorkel AI, and new pricing moves from OpenAI and Anthropic. The pattern across all of it is pretty clear: the market is moving past simple chat and into systems that act, connect, and cost real money to run.

Meta hotfixes Muse after a local dictation hijack demo

Now, to AI security. Meta says it issued a hotfix for its Muse Mac app on September 22 after researcher Patrick Wardle showed that a local process could redirect the agent’s dictation traffic to an attacker-controlled endpoint. The reporting here says the weakness was not in Muse’s cloud model itself, but in the Mac client’s handling of a setting called endo_voyager_dictation_endpoint. In other words, a low-privilege process on the same machine could alter where dictated prompts were sent, and that could expose the authentication token tied to the session. Once that token is in the wrong hands, the concern is not just eavesdropping. The reporting says a hijacked Muse account could potentially write files to the Mac, take photos with the camera, and retrieve the location of a linked iPhone. The important limit is also spelled out clearly: this was a local attack, not a remote internet worm. An attacker still had to get code running on the user’s Mac, which makes the issue narrower, but not harmless. The takeaway is simple: if an AI agent can act across apps and accounts, then the local client and its input path are part of the security boundary, not just the user interface. Meta’s response matters because it acknowledges that boundary, but the sources do not independently establish exactly which build was fixed or how complete the patch is.

Rabbit makes OS3 available without the R1

Now, to agent platforms. Rabbit says OS3 is now generally available, and the big shift is that the service no longer appears to depend on owning an R1 device. According to Rabbit’s Sept. 22 update, OS3 is designed around an outcome: the system works across the models you choose and the computers you connect. The Verge’s reporting says the new agent can operate across Windows, Mac, and Linux devices, which broadens access beyond early hardware buyers. Rabbit’s own material says OS3 works in a browser, that the R1 is only one way to reach the same account, and that each channel keeps its own thread while drawing on shared memory and relevant context. The company also says users can install a rabbit agent on a computer with a single command, turning that machine into a node OS3 can operate with the user’s approval, and that one account can manage up to five connected devices. That is a real change in product framing: the handheld is no longer the center of gravity, the account and connected machines are. But Rabbit is also careful to keep the rollout in beta territory. The company says OS3 and the rabbit agent are experimental and probabilistic, not meant for production, enterprise, regulated, safety-critical, or unattended use. So the practical takeaway is mixed: access is broader, but the product is still asking users to treat it as a preview, not finished infrastructure.

Snorkel AI raises money as data shifts toward expert environments

Now, to AI data and infrastructure. Snorkel AI says the training-data market has moved beyond mass labeling, and its latest funding round is meant to back that view. The company announced a $350 million Series E at a $3.5 billion valuation, co-led by Insight Partners and S32, and said the money will expand its work on data and environments for frontier AI systems. Snorkel’s argument is that the old “Data 1.0” model was mostly about volume, while the newer “Data 2.0” layer is about expert tasks, simulated environments, and evaluation rubrics that can take qualified humans hours or days to design. That matters because frontier models are no longer just being trained on more labels; they need data that captures subtle failure modes, reward signals, and cheating behavior. Snorkel says the new capital will support an “agentic data factory,” more work in vertical and enterprise AI, and open research programs such as its Open Benchmarks Grants initiative. The company also says its business has grown more than 18x since launching its data-as-a-service offering and has crossed a $375 million annualized revenue run rate, but those are company-reported figures in the material provided here, not independently verified market data. The useful takeaway is not that every buyer should rush in, but that the economics of AI data appear to be moving toward specialized environments and expert judgment, not just cheaper labor. That shift could make the market harder to standardize, but also more relevant for serious deployment.

OpenAI and Anthropic lower prices, but buyers still have to test

Now, to model pricing. OpenAI and Anthropic both introduced lower-priced models on September 22, but the part buyers can actually verify is narrower than the launch hype. OpenAI’s changelog confirms that GPT-6 Sol and GPT-6 Luna are live in the Responses and Chat Completions APIs, and it lists token prices for text and image inputs, plus separate pricing for cache writes and longer prompts. Sol is positioned at the more capable end, while Luna is aimed at high-volume tasks such as extraction and summarization, according to CNBC’s reporting. Anthropic, meanwhile, says Claude Opus 5.5 costs 40% less to run than Opus 5, with published list prices that are lower across input, output, and cache reads. Anthropic also says the model was tested by external evaluators before release and claims stronger benchmark scores in areas such as coding, computer use, and knowledge work, along with better resistance to prompt injection and hard-to-reverse actions. Those are meaningful claims, but they are still vendor claims unless a buyer validates them in their own workflow. The more practical point is that pricing only matters in context. If your workload is dominated by input tokens, output tokens, cache reuse, or latency, then the real savings may come from how often a model can reuse context or finish a task in fewer steps. So the takeaway here is not simply that prices fell. It is that AI buyers now need to match the model to the workload, and test the economics rather than assuming the cheapest sticker price will win.

Synthesis and close

To wrap up, today’s stories all point in the same direction from different angles. Meta’s Muse hotfix shows that agent security can fail at the client boundary, even when the cloud side is designed to be careful. Rabbit’s OS3 rollout shows that agent products are becoming more distributed, but still experimental. Snorkel’s funding round suggests the hardest part of AI may be shifting toward expert data and evaluation environments. And the pricing changes from OpenAI and Anthropic show that the race is now as much about economics and workload fit as it is about raw capability. If there’s one thing to carry forward, it’s that AI systems are moving from demo objects to operational tools, and that makes trust, deployment, and cost control just as important as model quality. For the transcript and sources, visit NextWith.ai.

Reporting and sources

  1. Meta hot-fixes Muse Mac app after local dictation hijack demo
  2. Rabbit makes OS3 generally available without requiring R1 hardware
  3. Snorkel AI raises $350 million as frontier AI data shifts toward expert environments
  4. OpenAI and Anthropic Launch Cheaper AI Models: What Buyers Can Verify

Browse all episodes →