Daily brief at 7am Melbourne. Unsubscribe any time.

Wednesday 26 August 2026

OpenAI's Jalapeño Chip Is the Quiet Revolution Hiding Behind Every ChatGPT Response

OpenAI's custom Jalapeño inference chip outperforms everything on the market — and that's a bigger deal for AI economics than any model release this year.

Lead story

OpenAI's Jalapeño Chip Is the Quiet Revolution Hiding Behind Every ChatGPT Response

For the past few years, running OpenAI's models has meant renting Nvidia's hardware at eye-watering cost. That arrangement just got a lot shakier. Independent benchmarking firm SemiAnalysis has released results from its InferenceX benchmark showing OpenAI's custom silicon — codenamed Jalapeño — beats the current state of the art on two metrics that actually matter: tokens delivered per user, and throughput per kilowatt.

That second number is the one CFOs care about. Inference — the process of running a trained model to generate an answer — is now OpenAI's dominant cost. Training a model is expensive once. Running it billions of times a day is expensive forever. A chip that does more work per watt of electricity isn't just a performance trophy; it's a structural margin advantage that compounds every time someone asks ChatGPT a question.

Why this changes the competitive landscape. Google has its TPUs, Amazon has Trainium, and now OpenAI has Jalapeño. The common thread is that hyperscalers who run AI at massive scale all eventually decide Nvidia's general-purpose GPUs — brilliant as they are — leave efficiency gains on the table. Custom silicon lets you prune exactly for the workload you run most. OpenAI runs inference, all day, every day. Jalapeño is shaped around that specific job.

The benchmark results also put pressure on Anthropic, Mistral, and any other frontier lab that remains fully dependent on external hardware. If Jalapeño gives OpenAI a meaningful cost-per-token advantage, they can cut prices without sacrificing margin — something rivals would struggle to match.

What we still don't know. SemiAnalysis benchmarked Jalapeño, but OpenAI hasn't confirmed when or whether the chip will see broader deployment, or whether it will remain purely internal. There's a non-trivial precedent — Google eventually offered TPU access to cloud customers — but OpenAI's commercial model is different enough that a public cloud play isn't obvious.

The Nvidia angle is also worth watching. Nvidia's share price has ridden the AI wave largely on the assumption that nobody else could build competitive inference silicon at scale. Jalapeño doesn't dethrone Nvidia overnight — training still runs on GPUs, and the installed base is enormous — but it's a credible data point that the moat is narrowing at the edges.

For Australian readers, the cost-of-inference question has direct relevance: every Australian organisation building on OpenAI's API is, in effect, a downstream beneficiary if Jalapeño drives prices down. The federal government's AI in Government Framework and several state-level AI procurement policies have flagged cost and reliability of frontier AI access as key concerns. Cheaper, faster inference makes the policy calculus easier — and the vendor lock-in calculus harder.

Watch for OpenAI to use Jalapeño as quiet leverage in enterprise contract negotiations well before any public announcement. The chip's existence is now confirmed. The question is how aggressively they use it.

Also today

CISA Gives Agencies Three Days to Patch a Perfect-10 Oracle Flaw

CISA has added CVE-2026-21962 — a CVSS 10.0 vulnerability in Oracle WebLogic Server and Oracle HTTP Server — to its Known Exploited Vulnerabilities catalogue and issued one of its tightest-ever patching deadlines: three days for federal agencies to comply. The flaw allows an unauthenticated attacker with HTTP access to reach critical data inside WebLogic environments. Honeypots began lighting up shortly after the vulnerability was disclosed in January, and exploitation is now confirmed in the wild. Oracle WebLogic remains widely deployed across Australian government and enterprise environments, and ASD's ACSC guidance on internet-exposed middleware means patching timelines here should mirror the urgency CISA is signalling.

The Register

NVIDIA NemoClaw Flaw Lets a Malicious Webpage Poison Your Local AI Model

Security researchers at Oasis Security have disclosed a vulnerability in NVIDIA's NemoClaw framework that allows an attacker-controlled webpage to silently take over a local Ollama instance — the server running an AI agent — without authentication, and plant hidden instructions directly inside the model. The attack works through the Ollama API and requires no user interaction beyond visiting a crafted page. NVIDIA's Product Security Incident Response team has been notified. The implications are significant for developers running local AI agents for code assistance or data processing: a single malicious link could corrupt the model's behaviour in ways that persist across sessions.

The Hacker News

Taiwan Charges Nine Over Illegal AI Server Exports to China

Taiwanese prosecutors have charged nine people — including employees of Nvidia and Super Micro Computer — with illegally exporting advanced AI server hardware to China in violation of export controls. The case centres on high-end semiconductors and server infrastructure that sit at the heart of US-China technology competition. The charges highlight how AI infrastructure has become a geopolitical flashpoint, not just a commercial one. For Australia, the case is a reminder of how deeply integrated Australian research institutions and cloud providers are in the same global AI hardware supply chain — and why the government's technology supply chain security reviews have increasingly focused on AI compute.

SecurityWeek

Mirage2FA Campaign Hits 4,500 Companies by Abusing Microsoft 365 Login Flows

A phishing-as-a-service operation called Mirage2FA has compromised or potentially compromised close to half of its targeted email accounts across 4,500 US and European companies since 2024, according to research by ANY.RUN. The kit is notable for abusing legitimate Microsoft 365 authentication flows rather than cloning login pages — making it significantly harder for users to detect something is wrong. Two-factor authentication provides no protection against the technique. The findings reinforce a pattern The Cipher has tracked all year: MFA bypass toolkits are now commoditised, and "we have MFA" is no longer a meaningful security posture without phishing-resistant alternatives like passkeys.

The Hacker News

First Malware Built Specifically for Car Head Units Joins the BadBox Botnet

Kaspersky researchers have identified the first known malware purpose-built for automotive head units — the infotainment computers embedded in modern vehicles — and have linked it to the BadBox botnet, a criminal network that has already compromised millions of Android-based consumer devices. Car head units run Android variants and share many of the same vulnerabilities as cheap Android TV boxes, which BadBox has exploited extensively. The practical risk today is device abuse — spam, proxy traffic, ad fraud — but researchers note the same access pathways could theoretically be used to probe vehicle systems, making this a category worth watching as cars become more software-defined.

SecurityWeek

CISA Red Team Report: Water Sector Caught the Attack. Government Didn't.

A newly published CISA red team assessment compared two real-world exercises: one against a water utility, one against a government agency. Both were successfully breached at the perimeter. The difference is what happened next. The water utility detected the intrusion, isolated affected systems, and shut down the attack before red teamers could achieve their objectives. The government target did not. The report is a rare piece of direct comparative data on incident response maturity — and it cuts against the intuition that civilian critical infrastructure is the weaker link. Australia's water sector sits under SOCI Act obligations, where similar red-team exercises are now mandated for critical asset operators.

CyberScoop

Apple Refreshes Mac Studio and Mac Mini With Local AI Inference as the Pitch

Apple has updated its Mac Studio and Mac Mini lines with new silicon explicitly designed to handle local AI inference workloads at scale. The refresh acknowledges a growing trend of developers daisy-chaining multiple Macs to run large language models locally — and the new hardware makes that considerably more practical with improved memory bandwidth and unified memory configurations. Apple's pitch is clear: for teams that want the power of frontier AI without their data leaving the building, Apple silicon now makes a credible case. It's a direct play for enterprise developers and researchers who've been running Ollama and similar frameworks on commodity hardware.

Ars Technica

Ukraine Will Share Battlefield AI Training Data With British Researchers

Ukraine has agreed to give the United Kingdom access to a large collection of battlefield data gathered during its war with Russia, specifically so that British companies and researchers can use it to train and test artificial intelligence systems — primarily for drone targeting and autonomous defence applications. The deal is the most significant known transfer of live conflict data for AI training purposes, and it accelerates UK efforts to build military AI capabilities grounded in real-world conditions rather than simulations. The arrangement also raises novel questions about data governance, consent, and the ethics of using wartime surveillance data for commercial AI development.

The Record

Israel Is Running a State-Funded Synthetic Think Tank to Game AI Search Results

An investigation by 404 Media has found that an Israeli government-funded organisation is producing AI-generated essays and policy papers at scale, designed specifically to be picked up and cited by AI chatbots and search engines. The operation functions as a synthetic think tank — producing content that looks credible to automated systems even when it would not survive human editorial scrutiny. The tactic is a significant evolution in information operations: rather than targeting human readers directly, it targets the training data and retrieval systems that AI tools use to form answers. It's an early but important example of AI-native influence at infrastructure level.

404 Media

The GTA VI Leak Is a Textbook Extortion Playbook — Just With a Bigger Audience

The ongoing leak of Grand Theft Auto VI development assets — accompanied by a memecoin launch and a public manifesto — looks chaotic, but security researchers say the playbook is familiar: slow-drip leaks designed to maximise media pressure and force a payment or response from the victim. What's unusual is the scale of the audience and the attacker's apparent comfort operating publicly. Rockstar Games, the developer, has not commented substantively. Researchers note the incident follows the same extortion logic used in corporate ransomware campaigns, except the leverage here is reputational damage and fan anticipation rather than operational disruption.

CyberScoop

UK Government Seeks Power to Secretly Ban Risky Tech Vendors

The British government is pursuing new legislative powers that would allow it to quietly exclude specific technology vendors from supplying companies operating in critical sectors — potentially without any public announcement. The proposal borrows from the model used for telecommunications security, where vendors like Huawei were removed from 5G infrastructure through a combination of public policy and private directive. The extension to broader critical sectors — including financial services, energy, and logistics — reflects growing concern about supply chain risk from state-linked technology providers. Australia passed similar supply chain security provisions under the SOCI Act and Telecommunications legislation, making this a policy area where the two countries' approaches are converging.

The Record

Sources consulted