← AI Daily Briefing

Copilot’s Prompt Hole Meets Mojo’s Open-Source Turn (August 19, 2026)

August 19, 2026 · 5m 3s · Listen

Microsoft gave Copilot a secret door into your inbox. Somebody found the handle. This is AI Daily Briefing. Today: a Copilot prompt-injection path with teeth, and Modular opening up the software layer underneath the compute boom. We start with the agent that can read your mail—and the URL parameter that apparently changed the rules. Tap follow so the next episode finds you. From Ars Technica:

The researchers now had a link that could be sent in an email or text message that, when clicked by the recipient, leaked sensitive information to an attacker-controlled server. A separate prompt that could be embedded in the same URL format instructed the LLM to search the inbox for passwords or other credentials that had been sent to the address.

Copilot had an undocumented ?autorun=1 parameter that could turn a clicked link into an inbox-searching agent in your authenticated session. Varonis didn’t just wave at a spooky demo; it laid out the path from Gmail access to an attacker-controlled webhook. And the prompt can hunt for passwords or credentials, base64 them, then get Copilot to open the exfiltration URL automatically. Enterprises have users clicking Copilot links all day—how many security teams are logging URL parameters on those clicks? That approval screen was the whole comfort blanket. One hidden parameter got around it, and the assistant could act on whatever was in the inbox. Permission layers for tool-using AI need to be boringly, exhaustively documented. Modular writes:

The Modular Platform is now production-ready, serving billions of tokens per minute and powering real enterprise deployments. We’re opening more of the platform to the ecosystem, extending it across entirely new classes of hardware, and bringing major industry partners along with us.

Mojo 1.0 under Apache 2.0 is the headline for builders. The business story is support for Trainium, TPUs, and Qualcomm accelerators. If one serving stack runs across cheaper chips, the per-token bill can move fast. And Modular Cloud is GA, with MiniMax named as a customer and a claim of billions of tokens per minute. That sounds like a production milestone. Now it has to hold up. The Copilot breach we just covered is why this layer matters beyond cost. Everybody’s pouring money into agents that touch real tools; the stack deciding where and how they run had better be inspectable. “Open silicon” is a lovely keynote phrase. The test is whether an enterprise can shift a workload from Nvidia to Trainium or TPU without finding six expensive little compatibility traps. Over on Hacker News:

Does this project have any meaningful traction? Seemed like a cool idea, but I wasn't even sure what problem does it solves. Looks like its completely missing from the regular discussion / news outlets. Every 1-2 years some barely visible post/article reminds me it even exists...

It’s a fair challenge. “Billions of tokens per minute” and MiniMax are traction claims, but I’d still want workload mix, latency, and cost against the usual GPU path before declaring victory. From Hacker News:

I guess this is the follow up to the Qualcomm acquisition. Introduces "Modular Cloud". In the keynote they say they've been serving models on openrouter under the name ModelRun. Windows support for Mojo (that isn't via WSL). Coincides with the open sourcing of Mojo.

ModelRun serving on OpenRouter is a useful breadcrumb. It means Modular Cloud is trying to show up where developers already buy inference, rather than asking them to join a new private club. From Hacker News:

Summarized here: This is by Chris Lattner, known for LLVM and Swift.

Chris Lattner’s LLVM and Swift résumé gets Modular some attention. Apache-licensed Mojo still has to prove itself in production, especially around ugly hardware edge cases. If you want to go deeper on the infrastructure behind AI, try The Data Center Daily—a daily briefing on AI compute, hyperscaler capex, the power grid, semiconductor supply, and how intelligence at scale is reshaping energy markets. Find it wherever you listen to podcasts.

You’ll find links to every story in today’s show notes, so you can dig deeper into whatever caught your attention. That’s AI Daily Briefing for today. Thanks for listening, and we’ll be back tomorrow. This is a Lantern Podcast.