4 min read5 storiesAIBig TechChipsDev ToolsPolicy

The Morning Build for September 23, 2026: OpenAI expands GPT-6, Qualcomm ships 30B MoE phone silicon, Microsoft shutters EvilTokens

Today’s stories focus on where AI meets systems and security: OpenAI widened its GPT-6 family with lower-cost Sol and Luna releases; Qualcomm detailed phone SoCs that can run 30-billion-parameter mixture-of-experts models locally; Microsoft led a disruption of an AI-assisted scam platform that compromised 12,000 accounts; British Columbia sued OpenAI over a ChatGPT-linked school shooting; and Trail of Bits published a technical critique arguing SAML should be deprecated in favor of OIDC.

OpenAI expands GPT-6 line with lower-cost Sol and Luna, halves API price vs 5.6 series

  • What happened: OpenAI released updated GPT-6 Sol and Luna models and began rolling them into ChatGPT Work, Codex for most paid accounts, and the ChatGPT API; Luna is also available for Free and Go desktop users and the company said rollout to ChatGPT app and website would occur gradually throughout the day. OpenAI said the 6 series models will be available at half the cost of the 5.6 series and that internal factuality evaluations show GPT-6 Sol makes about half as many mistakes as its predecessor, reaching Astra-level reliability at lower cost.
  • Why it matters: Engineers get access to GPT-6 family models with explicit lower API pricing and claimed reductions in factual errors and coding mistakes, which affects cost modeling for production inference and reliability expectations for Sol (coding/complex tasks) and Luna (high-volume clerical tasks).
  • Outlook: Rollout to the ChatGPT app and website, which OpenAI said would happen gradually throughout the day, is the immediate milestone that will show availability for broader user traffic and free-tier access.

Sources: techcrunch.com

Qualcomm announces Snapdragon 8 Elite Gen 6 and Elite Extreme Gen 6, Extreme can run 30B-parameter MoE locally

  • What happened: At Snapdragon Summit Qualcomm introduced Snapdragon 8 Elite Gen 6 and Snapdragon 8 Elite Extreme Gen 6. The chips include sensing hubs that run models up to 200 million parameters and the Extreme version can run a 30-billion-parameter mixture-of-experts model locally. Qualcomm showed use cases including a local voice-in/voice-out agent, speaker differentiation, on-device memory building for personalization, and pixel-level camera control; Motorola announced the Motorola Signature 27 using the Elite Extreme Gen 6 with general availability sometime this year.
  • Why it matters: Smartphone SoC inference capability expands from tiny local models to large Mixture-of-Experts models where only subsets of parameters activate, changing what kinds of on-device personalization, real-time agents, and media processing can run without cloud round trips and affecting mobile model deployment plans.
  • Outlook: Motorola’s Motorola Signature 27, powered by the Snapdragon 8 Elite Extreme Gen 6, has general availability planned sometime this year and will be the first commercial device to validate Extreme Gen 6’s local 30B MoE capabilities.

Sources: techcrunch.com

Microsoft leads disruption of ‘EvilTokens’ AI-assisted scam platform after 12,000 account compromises

  • What happened: Microsoft said it led an industry disruption of EvilTokens, a subscription fraud platform that used an AI-style chatbot to analyze victim inboxes and draft targeted fraud messages; Microsoft reported EvilTokens users compromised 12,000 customer accounts across about 10,000 organizations and that the operation used device code authentication flows. Microsoft seized 50 websites and 150 additional domains tied to the service and the UK Metropolitan Police arrested two men in connection with the platform.
  • Why it matters: The operation shows criminals integrating inbox-analysis chatbots and automation into large-scale account takeover workflows and abusing legitimate OAuth device code authentication, which raises concrete security concerns for services supporting device code flows and for defenders who must detect AI-assisted reconnaissance and tailored social-engineering payloads.
  • Outlook: SpyCloud’s detailed victim report, which Microsoft said assisted the disruption and contains more victim details, is the named follow-up resource that will provide further visibility into affected sectors and compromise patterns.

Sources: arstechnica.com

British Columbia sues OpenAI and Sam Altman seeking rebuilding costs after ChatGPT-assisted school shooting

  • What happened: British Columbia filed a complaint asking OpenAI and Sam Altman to pay rebuilding and recovery costs after an 18-year-old used ChatGPT in planning a shooting that left eight dead and led to the demolition of Tumbler Ridge Secondary School. The province asked the court for damages and injunctive relief, including requiring OpenAI to update ChatGPT to automatically terminate violent conversations. The community began demolition in August and hopes to have a replacement school built by the end of this year if all goes to plan.
  • Why it matters: The lawsuit links consumer-facing model behavior and vendor liability to tangible emergency and reconstruction costs and requests operational changes to ChatGPT’s conversational controls, which engineers and legal teams must track because the case seeks product-level injunctions and monetary damages tied to model use.
  • Outlook: The community’s goal of completing a replacement school by the end of this year, cited in the complaint, is the immediate timeline tied to recovery costs and is the concrete milestone the filing uses to frame damages and emergency spending.

Sources: arstechnica.com

Trail of Bits publishes technical critique arguing SAML should be retired in favor of OIDC

  • What happened: A Trail of Bits post traces SAML’s committee-driven, XML-based origins and enumerates recurring implementation problems such as XML canonicalization, enveloped signatures, signature-wrapping attacks, XML parser differentials, and broad unused features; the author recommends deprecating SAML and migrating to modern alternatives like OpenID Connect (OIDC). The post documents historical vulnerabilities and implementation incidents, including XML round-trip and libxml2 quirks cited in 2020–2025 research and real-world bypasses.
  • Why it matters: The post compiles concrete failure modes that continue to produce exploitable differences across SAML implementations, which should inform engineering risk assessments for organizations maintaining SAML-based SSO and for teams deciding whether to invest in migration to OIDC.
  • Outlook: The post’s call to deprecate SAML in favor of OIDC, grounded in the cited 2020–2025 parser and canonicalization incidents, frames migrations and deprecation plans by identity providers and large organizations as the next practical milestone to watch for.

Sources: blog.trailofbits.com