Tuesday, 22 September 2026
Anthropic drops Opus prices, a Muse zero-day, and a benchmark reproducibility push.
Anthropic launches Claude Opus 5.5 and cuts token prices
Anthropic released Claude Opus 5.5 on 22 September, the first model in a new Claude 5.5 family, and priced it below the model it replaces [1][2]. The company says Opus 5.5 performs at the level of its larger Claude Fable 5.1 on most work while costing 40% less to run than Opus 5 [1]. Input and output tokens are $4 and $20 per million, which Anthropic says is 20% less than Opus 5; cache reads, which it says make up most agentic and coding costs, drop to $0.20 per million, 60% less [1]. The model also generates output more than 30% faster, and a Fast mode runs at up to 2.5x speed for $8 input and $40 output per million [1].
Alongside the price cut, Anthropic says it is raising the five-hour usage limits on Pro, Max, Team, and seat-based Enterprise plans, and giving subscription users a rate-limit reset they can save and use later [1]. Sonnet 5.5 and Haiku 5.5 are due in the coming weeks [1]. On safety, the company says Opus 5.5 scored best of any of its models on its automated behavioural audit, but because it is comparable to its Mythos 5.1 model in biology and cybersecurity, it ships with the stricter safeguards used for Fable 5.1 [1].
TechCrunch frames the release as Anthropic pushing frontier-level coding performance down the price curve rather than up the capability curve [2]. Anthropic says one tester finished a 680,000-line code migration in under a day [1].
A zero-day let any Mac app hijack Meta's Muse assistant
Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse assistant on 21 September that let any locally installed app or terminal command take control of the AI agent's account, according to Ars Technica [1]. Muse, which launched this month and runs only on macOS, asks for wide access to a user's files, microphone, camera, WhatsApp, email and calendar so it can book appointments, make purchases and act across accounts [1]. Wardle, founder of the macOS-security nonprofit Objective-See, found that any process could change an undocumented setting controlling where Muse sends voice for transcription; redirecting it to an attacker's server hands over the token that controls the whole account [1].
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle told Ars, adding that a simple ClickFix social-engineering trick is enough to trigger it [1]. He built proof-of-concept attacks that wrote malicious files and took photos with no sign to the user [1]. Meta issued a hotfix shortly after midnight on 22 September, removing the setting that allowed the endpoint change, according to Gizmodo [2].
Meta's David Singleton said it was "a local privilege escalation attack, not a remote exploit" [2]. Wardle argues the ClickFix path means the risk is not purely local [1]. Separately, Amazon began blocking Muse from its site the day before the disclosure [1].
NVIDIA ships Isaac ROS 5.0 with skills built for AI agents
NVIDIA released Isaac ROS 5.0 at ROSCon on 22 September, a GPU-accelerated add-on to the open-source ROS robotics framework aimed at letting AI agents help build and run robots [1]. The release adds agent-ready documentation and reusable skills for setup and manipulation, so a coding agent can wire up perception or pick-and-place work rather than a human doing it by hand [1]. NVIDIA says a new FoundationPose library estimates object pose up to 5.5x faster, and that the software now supports the latest ROS release and Ubuntu 24.04 [1].
The packages run across NVIDIA's Jetson line, from the entry-level Orin Nano to the high-end Jetson Thor, and work with its open Nemotron models [1]. NVIDIA says it also contributed a standard data-handling interface upstream to ROS so GPU acceleration works across different hardware, and that pick-and-place now ships as a standalone skill [1]. The company puts the global ROS user base at roughly 1.3 million developers [1].
The code is free and open source, hosted in NVIDIA's Isaac ROS repositories with the packages and setup scripts [2]. The pitch is narrow but concrete: robotics teams spend heavily on integration, and NVIDIA wants agents to absorb some of that glue work [1].
The UK's AI institute publishes benchmark results others can reproduce
The UK AI Security Institute and the EvalEval Coalition released a shared, open set of AI benchmark results this week, aimed at a basic problem: evaluation scores are scattered and often cannot be reproduced [1]. The two groups published results for five benchmarks — HealthBench, FrontierMath, Humanity's Last Exam, SWE-Bench Pro and Terminal-Bench 2.0 — run across six frontier models, published on the coalition's open Evaluation Cards platform [1]. They also shipped two pieces of shared plumbing: a schema for documenting an evaluation end to end, and an Evaluation Cards platform that records the metadata, data and model details needed to rerun a test [1].
The point is that most benchmark claims arrive without enough information to check them, and rerunning an evaluation is usually too expensive to bother [1]. AISI, a UK government body, has been building open evaluation tools for model safety and security testing [2]. The release comes with a paper on how the amount of compute a model is given at test time changes its benchmark score — a reminder that a single headline number hides a lot [1].
For operators, the takeaway is practical: when a vendor cites a benchmark, ask whether the run is documented well enough to reproduce, or whether it is a number you are simply asked to trust [1].
Nscale files to go public, and two customers hold up most of its book
Nscale, a British AI data-centre operator, has filed to list on the New York Stock Exchange under the ticker NSCL, and the filing shows how concentrated the AI build-out has become [1][2]. Revenue for the six months to 30 June 2026 reached $140.6 million, up from $10.4 million a year earlier, while its net loss widened past $1 billion as the company poured money into new capacity [1][2]. The revenue is real and growing fast, but so is the dependence on a few very large buyers [1].
The catch is concentration. TechCrunch reports that about 85% of Nscale's contracted book comes from just two customers, Microsoft and Anthropic, with one of those deals carrying clauses that let the customer cancel if Nscale misses milestones [1]. Nscale is targeting a valuation reported near $35 billion and a raise of about $3 billion, according to TechCrunch [1]. Nvidia is among the backers of a $3.1 billion financing package tied to the company [1].
For anyone renting AI compute, the filing is a window into the neocloud model: heavy debt, take-or-pay contracts, and revenue that leans on a handful of hyperscalers [1]. It also underlines how much current AI-infrastructure spend is committed years ahead rather than earned, and how quickly that can turn if a single anchor customer pulls back [1].
