# Dan's Radar — Week of July 17, 2026

## Executive summary

OpenAI's desktop app merges Chat, Work, and Codex, with exclusive agent features. Grok Build CLI uploaded entire repos, secrets included, via an ineffective opt-out — researcher-reported, unconfirmed by xAI. PrismML's Bonsai 27B is the first 27B-class model to run on-phone at near-full precision. Moonshot's Kimi K3 matches Opus 4.8 and GPT-5.5 and tops agentic benchmarks; open weights planned, unreleased. Apple sued OpenAI over trade-secret theft in hardware hiring. Unabyss launched a paid MCP layer syncing 20+ sources into agents; usage claims unverified. Mindgard is disclosing a 200-day-old unpatched Cursor vulnerability. A reported Claude Code side channel bypassed Fable 5's cyber safeguards. Linq's Agent Pay moves payments into iMessage via FaceID, skipping the browser. Apple may ship a 1.5TB-memory M7 Ultra for local AI — unconfirmed.

## Signals (10)

### 1. New ChatGPT desktop app merges Chat, Work, and Codex — 8.6

*OpenAI Help Center · OpenAI · Mon*

OpenAI's new desktop app combines Chat, Work (research, documents, spreadsheets, presentations, Sites), and Codex on macOS and Windows; the Codex app updates into it, ChatGPT Classic remains supported, but new agent features ship only in the new app. With Atlas shutting down August 9, the desktop app — not a browser — is where OpenAI is consolidating its agent surface.

https://help.openai.com/en/articles/20001276-moving-to-the-new-chatgpt-desktop-app

---

### 2. Grok Build CLI uploaded entire repos — secrets included — to an xAI bucket — 7.9

*X · @IntCyberDigest · Mon*

xAI's Grok Build CLI reportedly uploaded whole Git repositories — private code and unredacted secrets included — to a grok-code-session-traces cloud bucket; a 12 GB test repo sent 5.1 GB upstream where the task needed 192 KB, and the improve-the-model opt-out did not stop the uploads. The behavior stopped via a hidden server-side flag a day after a researcher's wire-level analysis; xAI has published no advisory and hasn't addressed scope, retention, or deletion, and has not confirmed the report. What agent tooling actually sends over the wire is becoming a due-diligence item separate from what the settings page says.

https://x.com/IntCyberDigest/status/2076689215258014069

---

### 3. Bonsai 27B: first 27B-class model to run on a phone, at 90–95% of full precision — 7.6

*LinkedIn · PrismML · Mon*

PrismML released two Apache 2.0 variants of Qwen3.6-27B: ternary at 5.9GB retaining 95% of full-precision quality across 15 benchmarks, and 1-bit at 3.9GB retaining 90% — the first 27B-class model that fits on a phone. Agent loops that run locally stop compounding cost, latency, and data movement per step, and privacy-sensitive state stays on-device, with cloud models reserved for the hardest steps. Benchmarks are self-reported, but the weights are public. Pairs with the reported Apple M7 Ultra: the on-device tier is forming at both the model and hardware layer.

https://www.linkedin.com/feed/update/urn:li:share:7482847158468009984/

---

### 4. Kimi K3 matches Opus 4.8 and GPT-5.5 on intelligence, tops agentic-workflow benchmarks — 7.0

*X · @ArtificialAnlys · Thu*

Third-party benchmark: Moonshot's Kimi K3 (2.8T params) scores 57 on Artificial Analysis's Intelligence Index, on par with Opus 4.8 and GPT-5.5, and takes the top score on AutomationBench-AA, an agentic-SaaS-workflow evaluation. Moonshot hasn't released weights yet but says it plans to — which would make K3 the largest and highest-scoring open-weights model once available. Cost per task ($0.94) sits between GPT-5.6 Sol and Opus 4.8.

https://x.com/ArtificialAnlys/status/2077832874183860404

---

### 5. Apple sues OpenAI over trade-secret theft in its hardware talent raid — 6.8

*Bloomberg · Mark Gurman · Sat*

Apple's 40-page suit alleges OpenAI systematically acquired confidential hardware information: an ex-iPhone engineer allegedly kept file-server access via a software bug after joining OpenAI, candidates were encouraged to study internal material and bring components to interviews, and 400-plus Apple employees have moved over. OpenAI says it has no interest in other companies' trade secrets. The case shapes how fast OpenAI's iPhone-replacement device effort can move.

https://www.bloomberg.com/news/articles/2026-07-11/openai-engineer-s-lol-moment-set-stage-for-legal-fight-with-apple

---

### 6. Unabyss launches a paid cross-tool context layer synced into any MCP-compatible AI agent — 6.3

*Web · Unabyss · Thu*

A subscription MCP connector ($13–79/mo) that pulls context from Slack, Gmail, Notion, GitHub, X, LinkedIn, calendars and 20+ other sources into one structured, continuously updated profile, then serves it over MCP to Claude, ChatGPT, Cursor and other compatible clients so the same context follows a user across tools. Self-reports 450,000+ synced items; usage claims are unverified.

https://unabyss.com/

---

### 7. Cursor 0-day going public after 200 days of ignored disclosure — 6.2

*X · @mattjay → Mindgard · Tue*

Mindgard CPO Aaron Portnoy (ex-Zero Day Initiative, Pwn2Own) says the firm is publicly releasing details of an 'exceedingly simple' Cursor vulnerability after reporting it over 200 days ago with no movement despite repeated inquiries. Third agent-tooling security item this week: vendor security-response processes are lagging the adoption curve of the tools. Teams running Cursor should watch for Mindgard's advisory. 281K views.

https://x.com/mattjay/status/2077062820923916668

---

### 8. Report: Claude Code side channel bypasses Fable 5's cyber safeguards — 6.0

*X · @IntCyberDigest · Tue*

Researcher-reported, unconfirmed by Anthropic: security requests refused in Claude Code's main conversation were answered through its /btw side channel, and the output could reportedly be forked into a tool-enabled session where the safeguard kept prompting but no longer stopped the session. Overtly malicious requests were still refused — an enforcement-consistency gap across session layers, not a universal jailbreak. Alongside Grok's CLI exfiltration the same week, safety enforcement in agent harnesses — not just models — is emerging as the weak layer.

https://x.com/IntCyberDigest/status/2077151915721261561

---

### 9. Linq's Agent Pay: agents take payments inside iMessage — no browser step — 5.5

*X · @thelinqapp · Wed*

Agents on Linq can now send payment requests that complete inside iMessage with FaceID — explicitly no browser step. One small vendor, but a pointed pattern: agent commerce settling in the conversation surface rather than a web checkout, the opposite direction from x402-style machine payments on the open web. Each transactional job that moves into chat is one the browser no longer owns. 222K views.

https://x.com/thelinqapp/status/2077413925256077319

---

### 10. Apple reportedly plans M7 Ultra with 1.5TB unified memory for local AI — 4.9

*X · @rohanpaul_ai · Mon*

Report, unconfirmed by Apple: an M7 Ultra supporting up to 1.5TB of unified memory — more than double the M3 Ultra's ceiling — shared directly by CPU, GPU, and Neural Engine. For scale, eight Nvidia B200 server GPUs carry 1.44TB of HBM3e combined. If it ships, top Macs could run frontier-class models entirely on-device, pulling local inference into server territory. DRAM price and supply are the deciding constraints — Apple already pulled its 128GB Mac Studio amid shortages.

https://x.com/rohanpaul_ai/status/2076763094957858945

---
